# AI governance policy and accountability structure

- **Record type**: Control
- **Kind**: Policy
- **Owner**: Executive sponsor for AI
- **Frequency**: Annual
- **Duties served**: 16

## What the control achieves

Gives the organisation a single approved statement of how it will develop, buy and use AI, and names the people who are answerable for it, so that every other AI control has a mandate and an owner.

## How it is typically implemented

Senior management approves a short AI policy that sets the organisation's risk appetite, the principles it commits to, the scope of systems covered and the decisions that must be escalated. The policy is backed by a responsibility map: an executive sponsor, a governance lead, system owners and the committee or forum that reviews high-risk cases. Meeting cadence, escalation routes and the relationship to existing risk, privacy and security functions are written down. The policy is reviewed at least once a year and whenever a new law or a material incident changes the picture, and decisions of the governance forum are minuted so that a regulator or auditor can trace who decided what and when.

## Evidence it produces

- AI policy (policy_document): Approved and versioned statement of scope, principles, risk appetite and escalation rules.
- Board or executive approval of the AI policy (approval_record)
- AI governance forum minutes (meeting_record): Decisions, attendees and actions from each governance meeting.
- AI responsibility map (register_entry): Named owner for each AI role and for each system.

## Legal duties this control serves

- Establish accountability processes and a risk-management process (guardrails 1 and 2) — Australian Voluntary AI Safety Standard, Australia (satisfies): https://aipolicytracker.org/obligations/australia-vaiss-accountability-and-risk-management
- Operate a quality management system — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-quality-management-system
- Providers must meet the full set of provider duties for high-risk AI — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-art-16-provider-obligations
- Establish internal governance structures and measures for AI — Singapore Model AI Governance Framework, Singapore (satisfies): https://aipolicytracker.org/obligations/singapore-mgf-internal-governance
- Providers must supply conformity evidence and log access to authorities on request — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-art-21-cooperation-with-authorities
- Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-art-26-10-post-remote-biometric-identification-authorisation
- Adopt the guiding principles and risk-based governance (voluntary) — India AI Governance Guidelines, India (satisfies): https://aipolicytracker.org/obligations/india-ai-guidelines-principles-and-risk-based-governance
- Government bodies to promote ethical, responsible and inclusive AI (policy commitment) — Nepal National AI Policy, Nepal (supports): https://aipolicytracker.org/obligations/nepal-ai-policy-responsible-ai-principles
- Operators of high-impact AI must prepare user-protection measures and keep records of their safety and trust measures — Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, South Korea (supports): https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-34-high-impact-ai-user-protection-and-documentation
- Government commitment to AI ethics, governance and regulation (strategy objective) — UAE AI Strategy 2031, United Arab Emirates (supports): https://aipolicytracker.org/obligations/uae-ai-strategy-ethics-and-governance-commitment
- Establish accountability and governance for AI — UK AI regulation framework, United Kingdom (satisfies): https://aipolicytracker.org/obligations/uk-principles-accountability-governance
- Frontier developers must protect employees who report catastrophic-risk concerns — California SB 53, California (United States) (satisfies): https://aipolicytracker.org/obligations/us-california-sb-53-whistleblower-protections
- Deployers must implement a risk management policy and programme — Colorado AI Act, Colorado (United States) (satisfies): https://aipolicytracker.org/obligations/us-colorado-deployer-risk-management-program
- Deployers must use reasonable care to avoid algorithmic discrimination — Colorado AI Act, Colorado (United States) (satisfies): https://aipolicytracker.org/obligations/us-colorado-ai-act-deployer-reasonable-care
- Federal agencies must review and revise actions inconsistent with the new AI policy — EO 14179, United States (supports): https://aipolicytracker.org/obligations/us-eo-14179-agency-review-of-prior-actions
- Establish AI governance policies, roles and accountability (Govern) — NIST AI RMF, United States (satisfies): https://aipolicytracker.org/obligations/us-nist-ai-rmf-govern

## Standards clauses it corresponds to (clause numbers only)

- ISO/IEC 42001:2023: Clause 5.1, 5.2, 5.3, 9.3; Annex A.2, A.3 — Editorial mapping to leadership, policy, roles and management review.
- NIST AI RMF 1.0: GOVERN 1.1, 1.2, 1.3, 2.1, 3.1
- OECD AI Principles: Principle 1.5 Accountability

## MIT AI Risk Repository subdomains addressed

6.5, 5.2

## Provenance

- **Record page**: https://aipolicytracker.org/controls/ai-governance-policy-and-accountability
- **Official source**: none recorded — this record is incomplete, see https://aipolicytracker.org/gaps
- **Review status**: pending review
- **Confidence**: medium
- **Facts last confirmed**: never confirmed against the official source
- **Retrieved**: 2026-09-24
- **Licence**: https://creativecommons.org/licenses/by/4.0/

> This record is a structured summary with a link to the official text. It is not legal advice. Open the official source before relying on any date or duty. How current each record type must be is published at https://aipolicytracker.org/verification; what a record must carry at all is published at https://aipolicytracker.org/coverage.
