Unclear ownership of artificial intelligence (AI) risk could leave Chief Information Security Officers (CISOs) accountable for incidents without giving them sufficient authority to prevent or control those risks, according to experts cited by TechTarget.
New research from PwC highlights the lack of consensus across organisations. Only 17% of surveyed organisations formally assign AI governance and risk management responsibility to the CISO, while 29% place responsibility with the Chief Information Officer, Chief Technology Officer or broader technology function. Another 11% distribute accountability across multiple functions, while about one-third have created dedicated AI roles such as a chief AI officer.
Experts argue that CISOs should have authority over AI security boundaries, including the ability to review AI systems and agents before deployment, control access and oversee monitoring and incident response. However, they caution that broader AI risks should not automatically become the CISO’s responsibility.
AI-related decisions can involve business operations, data, legal exposure and issues such as discriminatory outcomes from automated systems. Experts therefore recommend clearly separating responsibilities, with business leaders owning AI use cases, CISOs overseeing security, and legal and compliance teams handling relevant oversight.
The emphasis is on establishing accountability and decision rights before an incident occurs, rather than determining responsibility after a failure.
Want to deepen your expertise beyond today’s news?
Explore practical certification courses designed for banking, risk, insurance, compliance, ESG, AI, and emerging technologies professionals.
Learn from industry experts and earn certifications from RMAI and BFSI Sector Skill Council of India.
#Riskmanagementnews