Designing a Responsible AI Operating Model
One of the first questions clients ask when they begin their Responsible AI journey is, "Who should own Responsible AI?"
It doesn't matter whether you're a Tier 1 financial institution with mature governance capabilities or a growing organisation introducing AI for the first time. Even organisations building their governance capabilities from scratch eventually arrive at the same question.
Who owns Responsible AI?
Ownership isn't the challenge.
Shared accountability is.
Over the years, I've helped organisations design operating models for data, analytics and governance. Some already had well-established functions. Others were building them for the first time. Regardless of where they were in their journey, the conversation almost always came back to ownership.
Responsible AI is no different.
Early on in my AI governance journey, I led Data and AI Governance for a global organisation developing AI-enabled products. While my team was responsible for the policies, standards and operating model, much of our time was spent partnering with product teams through AI Stewardship.
What surprised me wasn't the technology. Our product teams were exceptionally good at building AI. The difficult conversations were about accountability. Many didn't initially see themselves as the first line of accountability for Responsible AI. They assumed governance, privacy or risk would take ownership later in the process.
In reality, many of the most important Responsible AI decisions had already been made before those teams became involved. Decisions about the intended use of AI, appropriate human oversight, transparency, acceptable risk and customer impact were often product decisions long before they became governance decisions.
That's when I realised Responsible AI isn't something you add to a product. It's something you build into it from the very beginning.
Responsible AI isn't something to just add on to a product. It's something you build into it from the very beginning.
That lesson has shaped how I think about building AI systems from the ground up.
My view is that Responsible AI isn't owned by a single team. It's a shared responsibility between the business and IT, supported by the governance functions that already exist across the organisation.
The business owns the outcomes AI is intended to achieve. It decides where AI can create value, accepts the risks associated with those decisions and remains accountable for those outcomes. IT enables those outcomes by designing, delivering and operating the technology that makes AI possible.
Supporting both are functions such as Risk, Privacy, Legal, Compliance, Cybersecurity and Data Governance. Each contributes its own expertise, provides oversight within its domain and helps ensure AI is deployed responsibly.
Sounds familiar? It should.
If you've worked in a regulated organisation, you've almost certainly worked within the Three Lines of Defence model.
The first line, made up of the business and technology functions, owns and manages risk as part of its day-to-day operations. The second line provides governance, oversight and challenge through functions such as Enterprise Risk, Compliance, Privacy and Model Risk Management. The third line, Internal Audit, provides independent assurance that governance processes are operating effectively.
The business doesn't transfer ownership of risk to the second or third line. It remains accountable for the decisions it makes and the risks it accepts.
I believe Responsible AI should work in exactly the same way.
The business remains accountable for the outcomes AI is intended to achieve. IT remains accountable for designing, delivering and operating the technology. Governance functions continue to provide oversight, challenge and assurance within their own domains. Internal Audit continues to provide independent assurance.
The size of the organisation doesn't change the principle. In a smaller organisation, one person may perform several of these roles. In a larger enterprise, they may be spread across multiple teams. Either way, Responsible AI works best when accountability is shared and clearly understood.
That lesson became one of the guiding principles behind the Responsible AI Operating Model.
It wasn't created because I believed organisations needed another governance framework.
Quite the opposite.
One influence on my thinking was the NIST AI Risk Management Framework. I have a great deal of respect for the framework and the work that informed its development. It's publicly available, practical and intentionally written as guidance rather than regulation. It provides organisations with a flexible foundation for thinking about AI risk, but like any framework, its value comes from how those principles are put into practice.
But as I reflected on my own experience, I kept coming back to a different question.
How do you help an organisation put those principles into practice?
For me, that became an operating model challenge rather than a governance challenge.
The Responsible AI Operating Model
The model below captures the thinking that emerged from my experience. It isn't another governance framework—it is a practical way of connecting the governance capabilities organisations already have.
Click the image to view a larger version.
Key takeaway: The value of the model isn't the individual capabilities. It's the way they work together.
The model is deliberately simple. At the centre is the AI system itself, surrounded by the organisational capabilities needed to govern it consistently throughout its lifecycle.
Governance structures establish decision rights and oversight. Roles and responsibilities make accountability explicit across the business, technology and governance functions. Policies and standards translate organisational principles into practical expectations. Operating procedures provide repeatable processes for assessing, approving, monitoring and retiring AI solutions. Tools and technologies enable governance through inventories, workflows, documentation and monitoring. KPIs and reporting provide visibility into governance performance, risk and compliance. Finally, the roadmap recognises that Responsible AI is a capability that matures over time rather than being implemented all at once.
Together, these seven capabilities transform Responsible AI from a set of principles into an operational capability that can evolve alongside the organisation.
The purpose of the operating model isn't to introduce new governance functions. Its purpose is to show how existing business, technology and governance capabilities come together to make Responsible AI part of everyday operations.
The business continues to own business outcomes, while IT continues to design, deliver and operate the technology. Risk, Privacy, Legal, Compliance, Cybersecurity, Data Governance and Internal Audit continue to perform the responsibilities they've always had.
What changes isn't their accountability.
It's the way those responsibilities are connected throughout the AI lifecycle.
In my experience, organisations rarely struggle because people don't understand their own roles. More often, the challenge is that those roles become disconnected as work moves across organisational boundaries.
A business team identifies an opportunity. Data is sourced and prepared. Technology develops the solution. Risk and Privacy become involved at the appropriate stages. Legal may review contractual or regulatory obligations. Internal Audit provides independent assurance once the capability is operating.
Each team performs its role well. The challenge is ensuring those activities are coordinated rather than occurring independently.
That's the purpose of an operating model.
It provides the structure that brings together business, technology and governance so the right people are involved at the right time, decisions receive the appropriate level of oversight and accountability remains clear from the initial idea through to ongoing monitoring.
As AI becomes increasingly embedded across products, services and business processes, organisations won't succeed because they've created another committee or published another policy.
They'll succeed because they've connected the capabilities they already have into a coordinated way of working.
For me, that's what operationalising Responsible AI really means.
Reflection Questions
- If your organisation deployed a new AI solution tomorrow, who would be involved from idea to production?
- If you mapped your existing governance capabilities today, what connections are missing to effectively govern AI?
- Which governance capabilities already exist but aren't yet connected through a common operating model?