Clause 5: Leadership, AI Policy and Assigned Responsibilities

Clause 5 is about commitment from the top. It tells you to make sure that the leaders of your organisation understand what your AI management system is for and that they have assigned responsibility for it to named people. Clause 5 also requires you to write down your AI policy, a document that sets out your values and intentions for how your organisation will approach AI.

Many organisations have quality policies, information security policies and health and safety policies. An AI policy follows the same pattern. It is a statement from your leadership that says something like: “Our organisation is committed to building and deploying AI systems that are transparent, fair, secure and accurate. We will not deploy AI systems to make consequential decisions about people unless we have conducted risk assessments, documented our assumptions and put in place oversight mechanisms. We will monitor our AI systems in operation and we will respond quickly if we find that a system is not performing as expected or is causing harm.”

An AI policy does not need to be long. Many organisations fit their whole AI policy on one page. The policy should address a few core points. First, it should set out your organisation’s commitment to responsible AI. Second, it should explain how your AI management system relates to your other management systems (security, quality, health and safety). Third, it should identify who is responsible for different parts of your AI management system. Fourth, it should say how you will manage conflicts between efficiency (building and deploying AI quickly) and safety (doing all the work needed to manage risk).

Lesson concept diagram

The second part of Clause 5 is about assigning responsibility. You must identify a named individual or team responsible for the AI management system as a whole. Some organisations create an AI governance committee with representatives from different teams: perhaps a Chief AI Officer, the head of compliance, the head of data, the head of technology and the head of the business unit that uses the most AI. Other organisations assign responsibility to the Chief Information Security Officer or the Chief Risk Officer. The choice matters less than the clarity. A regulator auditing your organisation should be able to ask “Who is responsible for this AI management system?” and get one clear answer, not a debate about whether that is the AI team or the risk team or the innovation team.

Below the person responsible for the whole system, you must have clarity about who is responsible for specific parts. Who signs off on the decision to put a new AI system into production? Who maintains the inventory of AI systems? Who conducts the impact assessments that look for risk? Who monitors deployed systems? These should not all be the same person, because no one has time to do all of this work. But every responsibility should have an owner, and people should know who that is.

Clause 5 also requires you to ensure that people at all levels of your organisation understand the policy and their role in carrying it out. This does not mean everyone needs training in technical details. A data scientist needs to understand how to build fair models and document their assumptions. A marketing manager needs to understand how to use your AI systems responsibly and when to call in specialists for advice. A board member needs to understand what risks your AI poses and what your governance framework is designed to do. Clause 5 uses the word “awareness” for this. You must create awareness of the AI policy throughout your organisation.

In practice, Clause 5 requires you to produce an AI policy document and an assignment of responsibilities. The assignment of responsibilities might be a diagram or a table showing who is responsible for what and should be part of your documented information that you keep up to date as your organisation changes.