THE TRUST CENTRE / FOR COUNSEL AND THE BOARD

Every decision, owned.
Every owner, evidenced.

Governance is not a document written after the build. It is a set of decisions, each with a person who owns it and the evidence it leaves behind. Here are the decisions, the owners we usually see and a record you can take a decision through yourself.

THE ACCOUNTABILITY REGISTER

Twelve decisions.
One owner each.

A responsible AI programme is a set of decisions somebody has to own. These are the ones we work through with every client, who usually owns each, and the evidence each one leaves behind. Adapt it to your organisation; the structure is the point.

Showing every decision.

  1. Choose the use case

    Is this a problem worth solving, and how will we know it worked?

    OwnerChief executive
    • A problem statement
    • Success criteria and a baseline
    • A named owner
    Reviewed by
    Finance, the process owner
    Revisit
    At the end of every stage.
    Where the platform helps
    This decision belongs to people. The platform keeps the record.Available today
  2. Decide what data is used

    Which data does it need, on what basis, and where does it stay?

    OwnerGeneral counsel
    • A data map for the scope
    • The basis for each use
    • The agreed boundary
  3. Consult the people affected

    Have the people whose work is captured, and their representatives, agreed to it?

    OwnerPeople and HR
    • A consultation record
    • Consent where it is required
    • What is captured, and who sees it
  4. Classify the use under the law

    What is our role, and which obligations follow from it?

    OwnerGeneral counsel
    • A use-case description
    • The role assessment
    • The obligations that follow
  5. Choose the model and provider

    Which model, from whom, on what terms, and how did it perform on our examples?

    OwnerChief information officer
    • Evaluation results on representative examples
    • The provider’s terms
    • The route and its fallback
  6. Grant access to agents

    What may each agent see and do, and who owns it?

    OwnerChief information security officer
    • An identity map with owners
    • The policy for each action
    • Allowed and denied decisions, explained
  7. Set the human review boundary

    Which actions wait for a person, and which person?

    OwnerChief executive
    • Review routes
    • Approvals, with who gave them
    • Exceptions and why
  8. Release to production

    Did this version do better on our examples, and can we go back?

    OwnerChief information officer
    • Evaluation comparison
    • Release requirements checked
    • A path back to the previous version
  9. Handle an incident

    What happened, who was told, and what changed so it does not recur?

    OwnerChief information security officer
    • An incident record
    • The rollback taken
    • Notifications made
  10. Measure the value

    Against the baseline, what changed, and was it worth the cost?

    OwnerChief financial officer
    • The baseline
    • The measured result
    • The running cost
  11. Continue, expand or stop

    Does the evidence support the next step, or should we stop here?

    OwnerChief executive
    • The pilot review
    • Open risks
    • The decision, with reasons
  12. Retire or hand back

    Can our own team run it, or switch it off cleanly?

    OwnerChief information officer
    • The handback record
    • Access retired
    • Export confirmed

A register, not a compliance determination. It is a starting structure for your own programme, not legal advice; your counsel and your regulators decide what applies to you.

THE DECISION RECORD

A clear line
of accountability.

Take a decision through its life: proposed by its owner, reviewed, approved and recorded. Every step leaves a line. Every recorded decision links to the one before it, so the history cannot be quietly rewritten.

Decision record
Draft

Choose the use case

Is this a problem worth solving, and how will we know it worked?

Owner
Chief executive
Reviewers
Finance, the process owner
Evidence
  • A problem statement (not checked yet)
  • Success criteria and a baseline (not checked yet)
  • A named owner (not checked yet)
Revisit
At the end of every stage.
  1. No history yet. The owner proposes first.
  1. Propose
  2. Review
  3. Approve
  4. Record

The evidence chain

Each recorded decision carries a fingerprint drawn from its own content and the record before it.

  1. Start of the register

Illustrative. This record lives in your browser tab and is not connected to any system.

FOR THE BOARD

Five questions to ask,
every quarter.

A register earns its keep when somebody reads it. These are the questions we would want a board to ask of any AI programme, ours included. Each should be answerable from the evidence the register already keeps.

  1. Which decisions did agents take this quarter, and which waited for a person?
  2. Which evaluations failed, and what did we change because of them?
  3. What would it take to leave our supplier today, and when did we last rehearse it?
  4. Which use cases changed scope, data or users, and were they reassessed?
  5. Where did the value we measured differ from the value we expected, and why?

HOW TO READ THIS

What this register is,
and what it is not.

We would rather you knew the limits of this page than trusted it too far.

It is a structure.

The decisions, owners and evidence we work through with clients. Your organisation will name different owners and add decisions of its own.

It is not a compliance determination.

Nothing here says a use case is lawful, low risk or complete. Roles and obligations under the EU AI Act, data protection law and your sector are worked through in discovery; your counsel decides.

We have an interest.

We sell the products named in the register. Where one helps, its status says whether it is available today, in development or agreed with you. Ask to see it working.