01 / 06

Decide who is accountable

Ensure clear ownership and governance over every AI system throughout its lifecycle — from procurement and deployment through to decommissioning. Without documented accountability, AI governance does not exist.

High priority Foundational — complete this first Accountable parties: Board, Executive, IT Governance, HR
Pillar explained

What this pillar requires from your organisation.

AI systems are managed assets. That means someone must own them — with documented authority, documented responsibility, and documented consequences if governance fails. This pillar requires your organisation to establish that ownership structure before any AI system goes live.

Accountability must span the full AI supply chain. In a contractor context, this means distinguishing between the vendor who built the AI model, the integrator who embedded it in your systems, and your organisation as the deployer who puts it to work on a project. All three carry obligations. All three must be named.

This is also where training enters the framework. Accountability without competency is exposure. The people named as responsible or accountable must be assessed for AI literacy — and the gaps must be closed with documented training.

If no-one can name the executive accountable for AI in your organisation, you have already failed this pillar.
Contractor scenario — Estimating

When your AI-assisted estimate is wrong

Your estimating platform uses AI to generate cost rates. The AI produces an erroneous figure. You win the tender and take a $2M loss. Who is accountable — the estimating manager, the IT team that configured the tool, or the software vendor? Without a documented RACI, the answer is no-one. And that is the finding an auditor will make.

Contractor scenario — Scheduling

When automated scheduling causes a safety incident

An AI-powered workforce scheduler assigns a fatigued worker to a safety-critical shift. A principal investigates. They ask to see your AI governance documentation. If you cannot produce a named accountable person, documented oversight protocols, and evidence of training — the liability sits entirely with you.

Accountability mapping

The AI Accountability RACI Matrix

The RACI Matrix distinguishes liability across your AI supply chain. It is a mandatory document under this pillar — auditors will ask for it. Adapt the role titles to match your organisational structure, but the functions must all be covered.

A Accountable — owns the outcome and bears consequences
R Responsible — executes the work
C Consulted — input required before decisions are made
I Informed — kept up to date on outcomes
Function / Activity Executive Accountable Official Model Developer (Vendor / Internal) System Developer (Integrator) Deployer (Business Unit / Project) Risk & Compliance
Strategy & Policy A I C R C
Model Testing & Audit I R C I A
System Implementation C I R R I
Operational Oversight A I C R C
Vendor / Supply Chain Monitoring I R I A R

Source: AI6 Guidance — Pillar 01 implementation requirements. Adapt role titles to your organisational structure. All functions must be covered.

Required audit documentation

The four documents an auditor will ask for.

These are not internal best-practice documents. They are the specific artefacts required to demonstrate compliance with Pillar 01. If you cannot produce them on request, you are not compliant.

Document 01

Enterprise AI Governance Framework & Policy

Defines your organisation's strategic intent for AI, confirms legal compliance obligations, and documents the consequences for non-compliance. This is the foundational governance document from which all other accountability arises. Must be board-endorsed.

Requires board sign-off Download template — available in full pack
Document 02

AI Accountability RACI Matrix

The completed matrix (see above) populated with your actual role titles and named individuals. Must distinguish between model developer, system developer (integrator), and deployer roles. Must be version-controlled and reviewed when any AI system is added, changed, or decommissioned.

Living document Download template — available in full pack
Document 03

Supply Chain Accountability Agreements

Contractual documentation — or specific clauses in existing vendor agreements — that define the obligations of each party in the AI supply chain. Must cover what the vendor is responsible for testing, disclosing, and reporting. Standard software licence agreements do not satisfy this requirement.

Legal review recommended Download template — available in full pack
Document 04

AI Literacy & Training Register

A register tracking the competency requirements and training completion for every person with an Accountable or Responsible designation in your RACI Matrix. Must document what training was completed, when, and whether the current gap assessment shows the person as competent to perform their role.

Updated continuously Download template — available in full pack
Audit-ready checklist

Five questions a compliance auditor will ask.

Work through these items against your current documentation. Your progress is saved automatically. Print this page to include your checklist status in a compliance submission.

Pillar 01 — Accountability checklist

Tick each item when you have the required documentation in place.

0 of 5 items complete 0%
Audit risk

Common gaps auditors find in contractor submissions.

These are the four findings that appear most frequently when heavy industry contractors are assessed against Pillar 01. Check each one before a client or principal does.

No named executive sponsor

AI governance is sitting with the IT department or the head of digital — not with an executive who has board-level accountability. This is the most common and most serious finding. An IT owner cannot carry legal accountability. An executive must be named and the documentation must reflect this.

Supply chain accountability not documented

Contractors sign standard software agreements and assume the vendor carries liability. They do not. Unless your agreements explicitly divide accountability between model developer, integrator, and deployer — with specific obligations for testing, disclosure, and incident reporting — the liability defaults to you as the deployer.

Training records not maintained

Personnel are designated as Responsible or Accountable in the RACI Matrix but there is no record of their AI literacy assessment, no evidence of training completed, and no gap analysis on file. An accountable person without documented competency is an accountability gap, not an accountability structure.

No non-compliance escalation process

Organisations have general non-conformance processes but cannot demonstrate an AI-specific mechanism for identifying and responding to governance failures. When an AI system produces a harmful or erroneous output, there must be a documented path from detection to root cause analysis to corrective action to board notification — not a general IT helpdesk ticket.

Next step

Build the full accountability framework for your organisation.

The full AI Governance Compliance App includes completed, customisable versions of all four Pillar 01 document templates — pre-formatted for Australian heavy industry contractors and ready for submission to principals or compliance auditors.

← Back to AI6 Overview Next → 02 — Understand impacts and plan accordingly