Pillar 7Enablement Produces: Roles & Responsibilities Matrix

Roles & Responsibilities

Make accountability unambiguous, who decides, who builds, who answers.

Aligns withNIST · GovernISO/IEC 42001RACI

The idea

This pillar defines the human operating model: who owns AI decisions, who implements them, who reviews them, and how these roles coordinate across a decentralized institution. It translates the governance structures of Pillar 4 into named responsibilities and addresses the accountability gap, in which an AI system affects outcomes but no individual is responsible for the result.

Because a general instruction to clarify roles is difficult to act on, this pillar is made concrete through assignment tools: a RACI-style mapping for key AI decisions and processes; defined ownership for each system across its lifecycle, including sponsor, technical owner, data steward, and reviewer; and explicit coordination mechanisms that connect roles spanning IT, academics, legal, and the units. The outcome is that for any consequential AI use, the accountable individual can be named.

Why it matters

When responsibility is diffuse, two things happen: nothing gets owned in good times, and everything gets disowned when something breaks ('the algorithm did it'). Clear roles are what let an institution move quickly and answer cleanly (to a student, a provost, or a regulator) about who approved a system and who stands behind it.

The layers of responsibility

Responsibility isn't a single list of names — it operates at four distinct layers. Most accountability failures happen in the gaps between them, especially when the person who owns a system is mistaken for the person accountable for the decisions it informs. Name all four explicitly, then let your RACI hang off them.

Program layer

Institution-wide

Who answers for AI at the institution?

Who
Cabinet sponsor, AI governance body, AI lead
Owns
Strategy, policy, the operating model, and the program's overall health.

System layer

Per AI system

Who owns this tool across its lifecycle?

Who
System sponsor, technical owner, data steward, reviewer
Owns
A specific system from procurement through operation, monitoring, and retirement.

Decision layer

Per consequential decisionMost often skipped

Who is accountable for acting on what the AI produces?

Who
The human decision-maker in the domain — advisor, admissions officer, manager
Owns
The decision and its consequences. Often a different person than the system owner — this is the layer most often skipped.

Individual layer

Every user

What does each person owe when they use AI?

Who
All faculty, staff, and students
Owns
Baseline duties of disclosure, verification, and acceptable use in daily work.

Cutting across all four is coordination: roles that span IT, academics, legal, and the units, and the “orphaned ownership” problem when something falls between them. That's a connecting concern, not a fifth layer — but it's why the layers must be named together, not in isolation.

How you can tell

When it's working
  • Key AI decisions and processes have a RACI mapping that people actually use.
  • Every consequential AI system has a named sponsor, technical owner, data steward, and reviewer.
  • Coordination mechanisms connect roles across IT, academics, legal, and the units.
  • For any AI use, you can name the accountable human without a meeting.
When it's missing
  • Responsibility is assumed to be 'IT's job' or 'the committee's,' so it's no one's.
  • Systems run with no named owner; when they drift, nobody is watching.
  • Roles exist on paper but don't connect across silos.
  • After an incident, the institution can't say who approved the system.

How to operationalize it

Rate your campus

This is where the pillar stops being a principle and becomes work. Each practice below is something you can build, assign, and evidence, with a concrete first move, an owner, and what proof looks like. Move one practice up one level at a time.

1

Decision-rights & RACI matrix

For each class of AI decision, who is responsible, accountable, consulted, and informed.

Not yet rated
1Ownership is discovered during crises; everyone assumed someone else had it.
3A RACI covering the major AI decision classes is approved and published.
5The RACI is exercised, audited against real decisions, and updated as the operating model evolves.
Next moves
  1. Build the matrix for your top 10 AI decision classes using the Pillar 7 template.
  2. Resolve every cell with two owners or zero owners, those are the failure points.
  3. Test the matrix against the last three real AI decisions and fix mismatches.
Who owns it

AI governance body · Cabinet

Evidence it exists
  • Approved RACI
  • Resolution of overlap/gap cells
  • Post-decision audits
2

Cross-domain ownership assignment

Explicit owners for concerns that span offices: shadow AI, bias, vendor data, agentic systems.

Not yet rated
1Cross-cutting concerns belong to no one and stay unmanaged.
3Each named cross-domain concern has an explicit owner and escalation route.
5Cross-domain handoffs are rehearsed and reviewed; orphaned concerns are caught by annual audit.
Next moves
  1. List the cross-cutting concerns (shadow AI, bias, vendor security, agentic AI, surveillance) and name an owner for each.
  2. Define the handoff: who discovers, who remediates, who escalates.
  3. Audit annually for newly orphaned concerns.
Who owns it

AI governance body

Evidence it exists
  • Cross-domain ownership register
  • Documented handoff paths
  • Annual orphan audit
3

Operational roles & stewardship

The named, resourced roles that do the daily work: AI lead, data stewards, domain reviewers.

Not yet rated
1Governance work is volunteer overtime on top of day jobs.
3Key operational roles are named in position descriptions with allocated time.
5Roles are budgeted, backfilled, and reviewed for adequacy as the portfolio grows.
Next moves
  1. Write AI responsibilities into position descriptions, not side-of-desk assignments.
  2. Name data stewards for the data domains AI systems touch most.
  3. Review staffing adequacy annually against portfolio size.
Who owns it

CHRO · CIO · Unit leaders

Evidence it exists
  • Updated position descriptions
  • Steward roster
  • Staffing adequacy review
4

Accountability for AI-assisted decisions

When an AI-assisted decision harms someone, it is clear who answers for it and how people appeal.

Not yet rated
1Responsibility diffuses to 'the algorithm'; affected people have no recourse.
3An accountability framework assigns responsibility for AI-assisted decisions, with human review rights and notification standards.
5Appeals work in practice, exercised, tracked, and feeding improvements back to system owners.
Next moves
  1. Adopt an accountability framework: a named human answers for every consequential AI-assisted decision.
  2. Guarantee a human-review pathway and tell people when AI was involved in decisions about them.
  3. Build an appeals process with communication templates, and track its use.
Who owns it

Legal · Student affairs · HR

Evidence it exists
  • Accountability framework
  • Notification standards
  • Appeals records

In practice

Worked example

Naming the owner

An early-alert AI flagging at-risk students runs for two years; when its flags are questioned as biased, no one can say who owns it, IT built it, an advising dean requested it, institutional research feeds it. Under this pillar a RACI is drawn: the advising dean is accountable, IR is the data steward, IT the technical owner, and a governance reviewer signs off annually. The model is audited, adjusted, and (most importantly) has a human who answers for it the next time a student asks why they were flagged.

Watch for

  • Writing a RACI no one consults, it has to live in real workflows.
  • Assigning ownership without authority or time to actually exercise it.
  • Forgetting the lifecycle: someone must own a system in operation, not just at launch.

Readiness & maturity questions

Readiness asks: are we prepared? Use these to surface blind spots before you build, honest “no” answers are where the work is. Representative prompts for reflection, not a scored test \u2014 for the scored version, use the Maturity Assessment.

Strategic Leadership
  1. Do executives understand the AI landscape?
  2. Is there a clear AI strategic leader?
  3. Are role expectations documented?
  4. Is there a cabinet-level discussion on AI?
  5. Are trustees or regents informed of AI plans?
  6. Are shared-governance structures included?
  7. Are DEI leaders involved in AI planning?
  8. Are leaders trained in AI ethics and use?
  9. Are communications about AI visible and proactive?
  10. Are executives modeling responsible AI behavior?
Operational Execution
  1. Are roles for implementing AI clearly assigned?
  2. Are IT/data teams staffed for AI delivery?
  3. Are project managers familiar with AI systems?
  4. Do we have role clarity across units?
  5. Are there liaisons between tech and functional teams?
  6. Are operational leaders included in design phases?
  7. Is there budget alignment with execution plans?
  8. Are vendor and internal responsibilities clear?
  9. Are AI projects scoped with defined ownership?
  10. Are failures traced back to gaps in roles?
Enabling & Engagement
  1. Are HR and professional development units AI-aware?
  2. Are onboarding processes including AI basics?
  3. Are mentorships or peer programs available?
  4. Are communication teams equipped for AI messaging?
  5. Is IT support trained on AI troubleshooting?
  6. Are faculty development teams engaged in AI pedagogy?
  7. Are students engaged in user research or pilots?
  8. Are community engagement offices aligned with AI plans?
  9. Are marketing and recruitment staff AI-literate?
  10. Are enablers (e.g., librarians, advisors) part of AI decisions?

Apply this pillar