No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Governance

AI Governance Is Becoming a Named Accountability

In UK financial services, senior managers in charge of a business area are also in charge of how AI gets used inside that unit

by Paul Noon
August 21, 2026
in Governance, Opinion
ai concept nodes

Assigning an owner for AI risk is common advice by now, and rightly so. What’s less understood is that this is moving beyond best practices. AI adviser and emeritus professor Paul Noon explores the named accountability requirements in the UK, which can apply not just to technical AI experts but to senior managers across the business.

Most compliance and risk leaders never applied for the job of “named AI accountability owner.” A growing number are getting it anyway — not through a title change but through the ordinary mechanics of oversight regimes that were not built for AI but are being pointed squarely at it anyway.

The clearest example is happening in UK financial services right now, and it is more striking than a new job title. When the UK Financial Conduct Authority and the Bank of England’s Prudential Regulation Authority consulted on the senior managers and certification regime and whether AI needed its own distinct prescribed responsibility under the senior managers and certification regime a few years ago, the feedback ran against creating one. 

So the regulators confirmed something more consequential instead: The senior manager already accountable for a business area is automatically accountable for how AI is used inside it, whether or not anyone ever asked them to own that specifically. 

That means the senior manager responsible for retail lending decisions is accountable for the AI used in retail lending decisions. Nobody updated a job description or signed a new appointment letter. That person, frequently someone who already holds a compliance or risk oversight function, now has to be able to show they took reasonable steps to oversee that system and can be personally investigated and sanctioned if they cannot. 

Not every organization sits inside the senior managers and certification regime, but the underlying pattern is spreading well beyond financial services. When something goes wrong with an AI system and a regulator or a court starts asking who was accountable, they do not start with an org chart. They start with the trail: Who raised the risk internally, who had oversight of that function, who reviewed the output and signed off. In most organizations, that trail runs straight through compliance and risk, whether or not anyone formally assigned it there.

Note I didn’t say they’ll look first for your policy document. You need one, yes, but that only states the rules; it doesn’t answer the questions regulators will ask after the fact. Organizations that haven’t answered the who in all those questions are leaving it open to whomever is in the room when it counts.

rubiks cube
Featured

Put the General Counsel in Charge of AI Strategy

by Eric Dodson Greenberg
August 5, 2026

The conventional play for enterprise AI strategies is IT leads, committees advise, everyone weighs in. That produces strategies that live in slide decks and die in execution, writes Eric Dodson Greenberg, Cox Media Group’s chief legal officer.

Read moreDetails

Delayed EU AI Act doesn’t buy time

It is tempting to read the recent EU AI Act timeline change as room to breathe. In June, the Council of the EU gave its final sign-off to the digital omnibus package following the European Parliament’s endorsement earlier in the month. Those moves confirm that high-risk obligations for stand-alone systems are deferred to December 2027, and that AI embedded in regulated products is deferred further to August 2028. That is a genuine, now-final change, not a provisional one, which does provide some relief.

But it only moves one clock. It says nothing about the clocks that were never tied to that deadline in the first place. 

In the UK, for example, Section 80 of the Data (Use and Access) Act 2025 came into force in February 2026, replacing part of the GDPR, that gives individuals a right to transparency, human review and to contest automated decisions made about them. That obligation is live for any organization using AI in hiring, credit, insurance or similar automated decisions, regardless of what the AI Act’s high-risk deadline says. The AI Act’s own Article 50 transparency obligation, requiring disclosure that a person is interacting with an AI system, is also unaffected by the omnibus delay and went into effect just this month.

New tech, same governance fundamentals

When boards ask me to review their AI governance, three gaps show up more often than any others, and none of them require a new law to become a problem.

  • The first is no named owner. Plenty of organizations have an AI policy but nobody who could tell you, without checking, who is accountable if a specific system produces a biased or harmful output next week.
  • The second is no documented risk register with an owner attached to each entry. A list of the AI tools in use is a start. A list with a named accountable person for each entry, reviewed on a defined schedule, is a governance record a regulator or a court can actually rely on.
  • The third is a review cadence that exists on paper but produces no real discussion. An AI update tacked onto the end of a routine meeting, with no substantive minutes, is not evidence of oversight. It is evidence that oversight was scheduled then skipped.

None of these gaps are technical or require specialized AI knowledge. They are the same governance fundamentals that compliance and risk functions already apply to every other material risk category. The difference is that AI is moving much faster than most governance calendars.

These aren’t simple matters, but organizations can start with a simple question asked out loud before the next use of AI goes live: If this goes wrong, who is the named person who was watching it, and can they prove it?

Tags: Artificial Intelligence (AI)
Previous Post

Most Audit Leaders Are Using AI; Few Have a Strategy for It

Next Post

NIST Is Offering a New AI Evaluation Framework, Not Another Compliance Checklist

Paul Noon

Paul Noon

Paul Noon, OBE, is emeritus professor of AI and innovation and a former deputy vice chancellor at Coventry University in London. He advises UK boards on governance and AI strategy.

Related Posts

nist headquarters sign

NIST Is Offering a New AI Evaluation Framework, Not Another Compliance Checklist

by Larry Marks
August 21, 2026

Draft framework TEVV-Athlon is designed for organizational flexibility

abstract obscured data colorful

Most Audit Leaders Are Using AI; Few Have a Strategy for It

by Staff and Wire Reports
August 20, 2026

Plus: 1 in 10 UK wealth managers don’t ask for a key piece of information; ransomware payments fall while attacks...

double helix of lego

Illinois Genetic Information Protection Act Comes of Age

by Michael C. McCutcheon and Ruby Borja
August 17, 2026

Illinois’ experience with biometric privacy offers a cautionary tale for companies that keep genetic information in the AI era

news roundup bundled papers

26% of Execs Say Audit Has Caught Public-Facing AI Mistake

by Staff and Wire Reports
August 14, 2026

Few orgs say AI governance is fully mature; data center boom running into risk hurdles

Next Post
nist headquarters sign

NIST Is Offering a New AI Evaluation Framework, Not Another Compliance Checklist

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights