AI Human Accountability Template
This template is used to define, approve, evidence, and review human accountability for an AI use case.
AI can assist, recommend, summarize, classify, draft, retrieve, or execute bounded actions.
But AI must not become the accountable owner of enterprise outcomes.
The purpose of this template is to ensure that business ownership, technical ownership, decision ownership, review responsibilities, approval authority, escalation paths, override rights, exception ownership, and incident ownership are clearly assigned.
1. Accountability Information
AI Use Case Name
[Enter AI use case name]
Accountability Record ID
[Enter accountability record ID]
Date
[Enter date]
Prepared By
Name:
Function:
Email:
Related AI Inventory Record
Related Risk Assessment
Related Control Assessment
2. AI Use Case Summary
Short Description
[Describe the AI use case]
AI Pattern
Select all that apply:
[ ] Copilot
[ ] Internal LLM application
[ ] RAG system
[ ] AI-enabled SaaS
[ ] Embedded vendor AI
[ ] Agent
[ ] AI-enabled workflow automation
[ ] Customer-facing AI
[ ] Employee-facing AI
[ ] Developer AI tool
[ ] Security operations AI
[ ] Decision-supporting AI
[ ] Action-capable AI
[ ] Other
Assigned Risk Tier
Select one:
[ ] Tier 1: Low-risk productivity or public-data use
[ ] Tier 2: Internal productivity with enterprise data
[ ] Tier 3: Decision-supporting AI
[ ] Tier 4: Action-capable AI
[ ] Tier 5: High-impact autonomous or regulated AI
Accountability Summary
[Summarize who is accountable for the AI use case, its outputs, decisions, actions, exceptions, and incidents]
3. Business Accountability
Business Owner
Name:
Function:
Email:
Business Outcome Owned
[Describe the business outcome owned by the business owner]
Business Owner Responsibilities
Select all that apply:
[ ] Defines business purpose
[ ] Owns business outcome
[ ] Owns operational use
[ ] Accepts business risk
[ ] Approves high-risk use
[ ] Owns user adoption
[ ] Owns business process impact
[ ] Supports incident response
[ ] Reviews continued use
[ ] Owns customer or stakeholder impact
[ ] Other
Business Accountability Notes
[Describe business ownership, accountability limits, and open issues]
4. Technical Accountability
Technical Owner
Name:
Function:
Email:
Technical Scope Owned
[Describe the systems, integrations, configurations, prompts, data flows, tools, or workflows owned by the technical owner]
Technical Owner Responsibilities
Select all that apply:
[ ] Owns technical implementation
[ ] Owns configuration
[ ] Owns model or vendor integration
[ ] Owns identity and access implementation
[ ] Owns data boundary implementation
[ ] Owns prompt/input control implementation
[ ] Owns output control implementation
[ ] Owns tool/action integration
[ ] Owns logging implementation
[ ] Owns change management
[ ] Owns technical remediation
[ ] Supports incident response
[ ] Other
Technical Accountability Notes
[Describe technical ownership, support model, and constraints]
5. Data Accountability
Data Owner
Name:
Function:
Email:
Not applicable reason, if any:
Data Scope Owned
[Describe data sources, classifications, repositories, or records owned]
Data Owner Responsibilities
Select all that apply:
[ ] Approves data access
[ ] Confirms data classification
[ ] Defines sensitive data restrictions
[ ] Defines retrieval boundaries
[ ] Defines retention requirements
[ ] Defines training/reuse restrictions
[ ] Reviews data-related exceptions
[ ] Supports data incident response
[ ] Approves cross-boundary data movement
[ ] Other
Data Accountability Notes
[Describe data ownership, approval conditions, and data handling requirements]
6. Decision Accountability
Does AI Influence a Decision?
[ ] No
[ ] Yes
[ ] Unknown
Decision Owner
Name:
Function:
Email:
Not applicable reason, if any:
Decision Type
Select all that apply:
[ ] Informal user judgment
[ ] Internal operational decision
[ ] Case prioritization
[ ] Customer-impacting decision
[ ] Employee-impacting decision
[ ] Financial decision
[ ] Legal or compliance decision
[ ] Security decision
[ ] Access decision
[ ] Production or operational decision
[ ] Regulated or high-impact decision
[ ] Other
Final Decision Authority
AI Recommendation vs Final Decision Separation
[Describe how AI output is separated from the final accountable decision]
Decision Evidence
[Describe evidence retained for AI-assisted decisions]
7. Human Review Model
Human Review Required?
[ ] No
[ ] Yes
[ ] Conditional
[ ] Unknown
Human Review Pattern
Select one:
[ ] No human review
[ ] Human-in-the-loop
[ ] Human-on-the-loop
[ ] Human-over-the-loop
[ ] Exception-based review
[ ] Sampling review
[ ] Continuous monitoring
[ ] Not yet defined
Reviewer
Name or role:
Function:
Email or group:
Reviewer Responsibilities
Select all that apply:
[ ] Reviews AI output
[ ] Validates sources
[ ] Checks accuracy
[ ] Checks policy compliance
[ ] Approves output
[ ] Rejects output
[ ] Modifies output
[ ] Escalates concern
[ ] Records review decision
[ ] Other
Meaningful Review Conditions
Select all that apply:
[ ] Reviewer has sufficient context
[ ] Reviewer has access to source material
[ ] Reviewer has authority to reject
[ ] Reviewer has authority to escalate
[ ] Reviewer has time to review
[ ] Reviewer understands AI limitations
[ ] Review decision is logged
[ ] Other
Human Review Notes
[Describe review process and how blind reliance or ceremonial review is avoided]
8. Approval Authority
Approval Required?
[ ] No
[ ] Yes
[ ] Conditional
[ ] Unknown
Approval Areas
Select all that apply:
[ ] AI use case approval
[ ] Data access approval
[ ] Vendor AI approval
[ ] Prompt change approval
[ ] High-risk output approval
[ ] Customer-facing output approval
[ ] Decision approval
[ ] Tool access approval
[ ] High-risk action approval
[ ] Exception approval
[ ] Risk acceptance approval
[ ] Production deployment approval
[ ] Restart after incident approval
[ ] Other
Approval Matrix
Approval Notes
[Describe approval authority, limits, conditions, and escalation]
9. Escalation Path
Escalation Required?
[ ] No
[ ] Yes
[ ] Conditional
[ ] Unknown
Escalation Triggers
Select all that apply:
[ ] Uncertain output
[ ] Disputed output
[ ] High-impact decision
[ ] Policy violation
[ ] Sensitive data exposure
[ ] Unsafe recommendation
[ ] Customer complaint
[ ] Prompt injection concern
[ ] Abnormal tool use
[ ] Failed approval
[ ] Incident indicator
[ ] Control exception
[ ] Vendor issue
[ ] Other
Escalation Matrix
Escalation Notes
[Describe escalation path, response expectations, and ownership]
10. Override Rights
Override Required?
[ ] No
[ ] Yes
[ ] Conditional
[ ] Unknown
Override Rights
Select all that apply:
[ ] Reject AI-generated output
[ ] Edit AI-generated draft
[ ] Override AI recommendation
[ ] Stop workflow action
[ ] Suspend agent
[ ] Revoke tool access
[ ] Reverse record update
[ ] Escalate decision
[ ] Quarantine generated output
[ ] Block customer communication
[ ] Open incident
[ ] Other
Override Authority
Override Notes
[Describe how override works and how it is recorded]
11. Risk Acceptance
Risk Acceptance Required?
[ ] No
[ ] Yes
[ ] Unknown
Risk Acceptance Owner
Name:
Function:
Email:
Not applicable reason, if any:
Risk Accepted
[Describe residual risk accepted]
Risk Acceptance Conditions
[Describe conditions, compensating controls, expiry, and review frequency]
Risk Acceptance Evidence
[Describe where risk acceptance is recorded]
12. Exception Ownership
Exceptions Required?
[ ] No
[ ] Yes
[ ] Unknown
Exception Owner
Name:
Function:
Email:
Not applicable reason, if any:
Exception Summary
Exception Ownership Notes
[Describe who owns exception risk, remediation, review, and closure]
13. Incident Accountability
Incident Owner
Name:
Function:
Email:
Incident Roles
Incident Accountability Notes
[Describe how accountability works during AI incident response]
14. Vendor Accountability
Complete this section if vendor AI is involved.
Vendor Involved?
[ ] No
[ ] Yes
[ ] Unknown
Vendor Owner
Name:
Function:
Email:
Vendor Accountability Areas
Select all that apply:
[ ] Vendor feature approval
[ ] Vendor data processing review
[ ] Vendor retention review
[ ] Vendor training/reuse review
[ ] Vendor logs/evidence review
[ ] Vendor incident escalation
[ ] Vendor contract review
[ ] Vendor assurance review
[ ] Vendor remediation tracking
[ ] Continued-use decision
[ ] Other
Internal Accountability for Vendor AI Use
[Describe who inside the enterprise remains accountable for how vendor AI is used]
Vendor Accountability Notes
[Describe vendor shared responsibility, evidence limits, and escalation path]
15. RACI Matrix
Use this section to define responsibility, accountability, consultation, and information flows.
16. Accountability Evidence
Evidence Required
Select all that apply:
[ ] Business owner record
[ ] Technical owner record
[ ] Data owner approval
[ ] Decision owner mapping
[ ] Human review record
[ ] Approval record
[ ] Rejection record
[ ] Modification record
[ ] Override record
[ ] Escalation record
[ ] Exception record
[ ] Risk acceptance record
[ ] Incident ownership record
[ ] Post-incident review record
[ ] RACI record
[ ] Governance decision
[ ] Other
Evidence Location
[Describe where accountability evidence is stored]
Evidence Retention
[Describe retention period]
Evidence Access Restrictions
[Describe who can access accountability evidence]
17. Testing and Review
Accountability Review Required?
[ ] No
[ ] Yes
[ ] Unknown
Review Checks
Select all that apply:
[ ] Business owner assigned
[ ] Technical owner assigned
[ ] Data owner assigned where required
[ ] Decision owner assigned where required
[ ] Human review model defined
[ ] Approval authority defined
[ ] Escalation path tested
[ ] Override path tested
[ ] Exception ownership defined
[ ] Incident ownership defined
[ ] RACI reviewed
[ ] Evidence retained
Review Results
Open Findings
18. Approval
Business Owner Approval
Name:
Decision:
Date:
Notes:
Technical Owner Approval
Name:
Decision:
Date:
Notes:
Decision Owner Approval, If Required
Name:
Decision:
Date:
Notes:
Not applicable reason, if any:
Risk / Governance Approval
Name or forum:
Decision:
Date:
Notes:
Final Accountability Decision
Select one:
[ ] Approved
[ ] Approved with conditions
[ ] Requires remediation
[ ] Requires exception approval
[ ] Requires additional review
[ ] Rejected
[ ] Deferred
Approval Conditions
[List conditions required before approval, production use, scaling, or continued operation]
19. Review Triggers
Review this accountability model if any of the following occur:
[ ] Business owner changes
[ ] Technical owner changes
[ ] Data owner changes
[ ] Decision owner changes
[ ] AI use case changes
[ ] Output or decision impact changes
[ ] Tool/action capability changes
[ ] Autonomy level changes
[ ] Vendor involvement changes
[ ] Risk tier changes
[ ] Exception is requested
[ ] Incident occurs
[ ] Audit finding occurs
[ ] Governance model changes
Next Review Date
[Enter date]
20. Summary
Use case:
Risk tier:
Business owner:
Technical owner:
Data owner:
Decision owner:
Human review model:
Approval authority:
Escalation path:
Override rights:
Exception owner:
Risk acceptance owner:
Incident owner:
Vendor owner:
Evidence location:
Approval status:
Next review date: