Accept the composite decision to deploy and operate an AI system
Draft
Accept the composite decision to deploy and operate an AI system
Layer 4. Control RSKRisk acceptance
Allocation
| L4-RSK-03 | |
|---|---|
| Decides | Business Accountable Executive |
| Consulted | Domain owners, Model Owner and Head of Internal Audit |
| Executes | Model Owner |
| Evidence | Composite accountability record referencing each domain acceptance |
In plain terms
One named person accepts that this system, as a whole, should run. Each risk domain has already accepted its own part. This decision is about the whole, and the whole is not the sum.
What is being judged
Whether the system should operate, having read what each domain owner accepted and understanding that nobody else has looked at the total.
Domain acceptances do not sum. The CISO accepted the security position. The DPO accepted the privacy position. The Head of Risk accepted the enterprise position. Each is correct within its domain and none of them asked whether a system carrying all three residual positions at once should exist.
That question has no natural owner, which is why this decision exists and why every crosswalked instrument omits it. ISO 42001, COBIT and NIST all require defined accountability. None requires one name against one system.
The judgment has three parts.
Are the domain acceptances current? An acceptance that expired last quarter is not an acceptance. The composite record references them, so it inherits their expiry.
Does the combination create something no domain owns? A system with an accepted privacy position and an accepted security position may still be a system whose combination of retained data and access breadth nobody assessed. The gaps between domains are the reason for this decision.
Would you defend this in the room where it goes wrong? Not a rhetorical test. The composite record is the document produced when something fails, and the person signing it is the person asked to explain it.
What this decision does not cover
It does not re-perform the domain assessments. A Business Accountable Executive who audits the CISO’s work has misunderstood the role and has also broken the separation this layer depends on.
It does not authorize the model technically. That is L4-AUT-01, and in practice both are signed together.
When it fires
On event. Before first production use. On material change to the system, its data scope or the population it affects. When any referenced domain acceptance expires or is withdrawn. When the named executive changes, because accountability does not transfer silently.
What you need before deciding
- Every domain risk acceptance, in date
- The classification record and its consequence class
- The validation evidence, or a domain owner’s statement that they read it
- Regulatory applicability, and any impact assessment sign-offs
- What the system does when it fails, and who notices
How this goes wrong
A committee signs it. Every member present, nobody accountable, the record names a meeting. If the Decides field holds a body rather than a person, this decision has not been made. That is the whole point of the row.
The name is attached at go-live. The build ran without an accountable person and the name selected is whoever was available. Naming happens at L4-CLS-06, before the build.
Domain acceptances expire under a live composite record. The system keeps running on a composite acceptance referencing three domain acceptances, two of which lapsed. Nothing detected it because the composite has its own review date and the framework does not currently state that domain expiry invalidates the composite. See finding 2 at section 4.
The executive signs what they were handed. The consultation is real or the decision is ceremonial. An accountable executive who cannot describe the system’s failure mode in their own words has accepted a document, not a risk.
Related decisions
Upstream L4-CLS-04 or L4-CLS-05 classification. L4-CLS-06 naming. L4-RSK-01 appetite. L4-RSK-02 domain acceptances. L4-REG-01 regulatory applicability.
Downstream L4-AUT-01 production authorization. L5-05 production readiness gate. L4-AUT-05 withdrawal.
Escalation L4-RSK-05 arbitration, where domain owners cannot agree. L4-AUT-06 compelled withdrawal, where one overrides this acceptance.
Instrument references
ISO/IEC 42001 Clause 5.3 roles and responsibilities, clause 6.1.
COBIT 2019 EDM03 ensured risk optimization, APO12.
NIST AI RMF GOVERN 2, accountability structures.
No instrument requires a single named person accountable for the composite. This is recorded as KL-19 and expected to be the most resisted requirement in the framework.
Correction
The maintainer answers corrections. There is no service level. Responses are best-effort and opportunistic within a reasonable time: a correction raised on a Monday is answered that week or sooner.