Domain I · Competency I.B

Establish and communicate organizational expectations for AI governance

How an organization sets up the people side of AI governance — roles and responsibilities, cross-functional collaboration, training and awareness, right-sizing the program, and the developer/provider/deployer/user distinction.

Exam weight: 5–7 questions

Quick check not attempted yet — take it below to track your score.

Performance indicators

Key terms

AI governance committee
A standing cross-functional body (often a council or board) that sets AI policy, reviews high-risk use cases, and provides oversight and accountability across the organization. The central coordinating structure recommended by the NIST AI RMF Govern function and ISO/IEC 42001.
RACI
A responsibility-assignment matrix mapping who is Responsible, Accountable, Consulted and Informed for each governance task. Used to remove ambiguity about AI roles. Exactly one party is Accountable per task.
Accountable vs. responsible
Accountable = the single owner who answers for the outcome and cannot delegate the answerability. Responsible = those who do the work. The exam relies on this distinction.
Cross-functional collaboration
Bringing legal, privacy, security, data science, product, HR, compliance, ethics and business units together so AI risk is seen from multiple expert perspectives, not just one function.
Three lines model
A governance structure: first line (business/operational owners who own the risk), second line (risk, compliance, legal who set policy and oversee), third line (internal audit who provides independent assurance).
Tone at the top
Visible senior-leadership and board commitment to responsible AI; sets culture and signals that governance is a priority, not an afterthought.
Governance maturity
How developed an organization’s AI governance is. Programs are right-sized to company size, maturity, industry, products, objectives and risk tolerance rather than copied wholesale.
Risk tolerance
The level and type of AI risk an organization is willing to accept in pursuit of its objectives. Drives how strict controls and approval gates are.
AI developer
The actor that designs, codes and trains an AI model/system. Bears responsibility for how the model is built — data, training, documentation, intended purpose.
AI provider
Under the EU AI Act, the actor that develops an AI system (or has it developed) and places it on the market or puts it into service under its own name or trademark. Carries the heaviest obligations.
AI deployer
Under the EU AI Act, the actor that uses an AI system under its own authority in a professional capacity (not as an end consumer). Responsible for proper use, human oversight and monitoring in context.
AI user
The end user or affected person who interacts with or is subject to the AI system’s outputs. Needs transparency, notice and avenues for redress.

At a glance

If competency I.A is why AI needs governance, I.B is who does it and how the organization is told about it. This competency is about the people and structure of an AI governance program: (1) defining roles and responsibilities, (2) building cross-functional collaboration, (3) delivering training and awareness, (4) right-sizing the program to the organization, and (5) distinguishing the developer / provider / deployer / user roles from a governance perspective.

A useful framing: governance is not a document, it is a set of accountable people working across functions. The exam tests the most widely accepted elements of how organizations set this up — anchored in the NIST AI RMF Govern function and ISO/IEC 42001’s management-system requirements (leadership, roles, competence, awareness) — and it tests them at the apply/analyze level, so expect short org scenarios.

I.B.1 — Define roles and responsibilities for AI governance stakeholders

Effective AI governance assigns clear, documented responsibilities so that for any AI system someone is accountable for its risks and outcomes. The NIST AI RMF Govern function and ISO/IEC 42001 both make “assign roles, responsibilities and authorities” a foundational requirement.

Common roles (titles vary; functions are what matter):

RoleGovernance responsibility
Board / senior leadershipSet tone at the top, approve the AI strategy and risk appetite, hold ultimate accountability.
Executive sponsor (e.g., Chief AI Officer)Owns the AI governance program; secures resources; reports to the board.
AI governance committee / councilCross-functional body that sets policy, reviews high-risk use cases, arbitrates trade-offs.
Legal, privacy & complianceMap legal obligations (EU AI Act, GDPR), advise on lawfulness, manage regulatory risk.
Risk & securityThreat modelling, security testing, risk acceptance.
Data science / ML engineeringBuild, test, document models within policy.
Product / business ownersOwn the use case, its value and its first-line risk.
HR, procurement, ethicsWorkforce impact, third-party/vendor risk, ethical review.
Internal auditIndependent assurance that controls work (third line).

A RACI matrix is the most widely recommended tool to remove ambiguity: for each governance task, name who is Responsible, Accountable, Consulted and Informed. The rule the exam leans on: exactly one party is Accountable for a given task, and accountability cannot be delegated away even when the work is.

Many organizations layer this onto the three lines model: business owners (first line) own the risk, risk/compliance/legal (second line) set policy and oversee, and internal audit (third line) gives independent assurance.

I.B.2 — Establish cross-functional collaboration

AI risk is multi-dimensional — legal, ethical, technical, security, privacy, reputational, commercial — so no single function can govern it alone. The BOK justifies cross-functional collaboration explicitly for efficacy and diversity of expertise and perspective. A model that looks fine to a data scientist may be unlawful to a privacy lawyer, biased to an ethicist, and a security liability to the CISO; only together do they see the whole picture.

This is why the AI governance committee is cross-functional by design. Practical mechanisms:

I.B.3 — Create and deliver a training and awareness program

Governance only works if people across the organization understand it. ISO/IEC 42001 makes competence and awareness explicit management-system requirements, and the NIST Govern function calls for a workforce that understands AI risks. The BOK requires training to all stakeholders on AI terminology, strategy and governance.

What good training programs share:

Note that AI literacy is becoming a legal obligation, not just best practice — the EU AI Act (Art. 4) requires providers and deployers to ensure a sufficient level of AI literacy among staff operating AI systems.

I.B.4 — Differentiate approaches based on company context

There is no one-size-fits-all AI governance program. The BOK requires differentiating approaches by company size, maturity, industry, products and services, objectives and risk tolerance. A program is right-sized, not copied.

FactorHow it shapes governance
SizeA startup may run governance through a few people wearing several hats; a multinational needs formal committees, dedicated officers and tooling.
MaturityEarly programs focus on inventory, policy and quick wins; mature ones run continuous monitoring, audits and metrics.
Industry / sectorRegulated sectors (health, finance, employment) face stricter legal duties and need heavier controls.
Products & servicesHigher-stakes or customer-facing AI (e.g., medical, lending) warrants more rigor than low-risk internal tools.
ObjectivesStrategy and business goals set what AI is for and how aggressively it is adopted.
Risk toleranceA risk-averse organization sets stricter gates, lower thresholds and more human oversight; a risk-tolerant one accepts more in pursuit of speed/innovation.

Governance operating models — the structural choice scenario questions ask you to name:

The constant across all of them is the principle: oversight, accountability and risk management scale proportionate to risk. Higher risk and higher regulatory exposure justify more formal, resource-intensive governance; lower risk justifies lighter touch. This proportionality idea echoes the EU AI Act’s risk-tiering and NIST’s risk-based approach.

I.B.5 — Developers, providers, deployers and users

Different actors in the AI value chain have different responsibilities, opportunities and needs. The exam aligns this with how the EU AI Act uses the roles, and the distinction drives who must do what.

ActorWho they areCore governance responsibility
DeveloperDesigns, codes and trains the model/system.How the system is built: data quality, training, documentation, intended purpose, built-in safeguards.
ProviderDevelops a system (or has it developed) and places it on the market / puts it into service under its own name or trademark (EU AI Act).The heaviest obligations: risk management, technical documentation, conformity assessment, transparency, registration, post-market monitoring.
DeployerUses an AI system under its own authority in a professional capacity (not as a consumer).Use it as intended, ensure human oversight, monitor operation, inform affected people, keep logs — responsibility in context of use.
UserThe end user / affected individual interacting with or subject to the system.Mainly a recipient of protections: transparency/notice, ability to contest, redress.

Key nuances the exam likes:

How this shows up later

Sources

Flashcards

1 / 9

Quick check

Quick check1 / 16 · score 0

In a RACI matrix used for AI governance tasks, what is the rule about the "Accountable" role?

  • ASeveral people should be jointly Accountable to spread the burden.
  • BExactly one party is Accountable for a task, and the accountability cannot be delegated away.
  • CThe Accountable party is whoever does the hands-on work.
  • DAccountability is optional for low-risk tasks.