UNUS London · ISO/IEC 42001:2023 Finance Series · ART-AIMS-FIN-G002 v1.0 · FCA · SM&CR · ISO/IEC 27001:2022
Day two of the questionnaire
Marcus Osei spent six days building the AI Policy. It is good. It names permitted uses and prohibited uses. It has a document control block. Diana Whitmore signed it on Thursday afternoon. Marcus sent it to Harcastle on Friday morning with a covering note that said, in essence: here is the evidence you asked for.
On Monday, a reply arrives. Harcastle's legal team has reviewed the policy. They have one follow-up question before they can mark section one as complete. It is question two on page three of the questionnaire.
Harcastle Group
"Thank you for providing your AI Policy. Your policy names the Compliance SMF as policy owner. Could you please confirm: (a) who holds each of the following AI governance roles at your firm — AI Risk Owner, AI System Owner, AI Ethics Reviewer; (b) what their specific AI-related responsibilities are; and (c) where these responsibilities are documented in your firm's accountability framework, including any Statements of Responsibilities held by the FCA."
Marcus Osei
He reads it three times. He knows who he is — Head of Compliance, SMF16. He knows the policy names him as owner. But AI Risk Owner? AI System Owner? AI Ethics Reviewer? These roles do not exist at Whitmore & Associates. And his Statement of Responsibilities — the document filed with the FCA that defines his personal accountability — makes no mention of AI whatsoever.
Marcus Osei
"We have a policy. We don't have the structure that makes the policy real."
This is the second gap. And it is the one that turns an AI Policy from a document into a governance system — or exposes it as a piece of paper with no one truly behind it.
The AI Policy says the firm governs AI responsibly. The RACI says who, specifically, is responsible for what. The Statement of Responsibilities says that accountability is formally registered with the FCA. Without the second and third documents, the first is unenforceable — and under SM&CR, unenforceable accountability is personal liability waiting to happen.
⚠
Warning
ISO/IEC 42001:2023 Clause 5.3 requires the organisation to ensure that the responsibilities and authorities for relevant roles are assigned and communicated within the organisation. Under SM&CR, the FCA requires that the responsibilities of Senior Management Function holders are accurately reflected in their Statements of Responsibilities. Where AI governance represents a material area of the firm's operations, the absence of AI accountability in an SMF holder's Statement of Responsibilities creates a documented gap between their actual oversight obligations and the accountability the FCA holds them to.
What ISO/IEC 42001:2023 requires from Clause 5.3
Clause 5.3 is a short clause. It is also one of the most practically demanding in the standard — because it cannot be satisfied by writing a document. It requires building a structure.
ISO/IEC 42001:2023 — Clause 5.3 · Organisational Roles, Responsibilities and Authorities
Top management shall ensure that the responsibilities and authorities for relevant roles are assigned and communicated within the organisation. Top management shall assign the responsibility and authority for ensuring that the AI management system conforms to the requirements of this document, and for reporting on the performance of the AI management system to top management.
Source: ISO/IEC 42001:2023 Clause 5.3. British English retained per ISO/IEC Directives Part 2.
The clause requires two things specifically. First, that AI governance roles are assigned — someone must hold each one, not generically but by name. Second, that a named individual is responsible for reporting on the performance of the AIMS to top management — meaning the board must receive structured AI governance reporting, and someone is accountable for producing it.
At Whitmore & Associates, neither condition is met. The AI Policy names Marcus as owner. But ownership of a policy document and accountability for a functioning AIMS are different things entirely. The standard requires the latter — and the latter requires a RACI.
The four AI governance roles ISO 42001 demands
Read alongside Annex A of the standard and established AI governance practice, Clause 5.3 requires four distinct roles to be named:
| Role |
What they own |
At Whitmore & Associates |
Status |
| AI Risk Owner |
The AI risk register, risk assessment process, and risk treatment decisions |
Not assigned |
Gap |
| AI System Owner |
Each AI system in use — its performance, its version, its permitted use |
Not assigned — one per system required |
Gap |
| AIMS Programme Lead |
Overall conformance with ISO 42001; reports to top management |
Implied (Marcus) but not documented |
Gap |
| AI Ethics Reviewer |
Bias assessments, fairness reviews, client impact assessments |
Not assigned |
Gap |
◈
ITIL 4 — Workforce and Talent Management Practice
In ITIL 4, the Workforce and Talent Management practice requires that roles and responsibilities are formally defined, assigned, and communicated — and that individuals in those roles have the competence to perform them. A RACI that assigns AI Risk Owner to Marcus without ensuring he has documented AI risk assessment competence does not satisfy this practice. RACI-AIMS-FIN-001 therefore includes a competence requirement column alongside each role, establishing what the individual needs to know — not just what they are responsible for.
Section 3 — The FCA Position
The Statement of Responsibilities gap is a personal one
The SM&CR accountability framework operates on a simple principle: every material area of a firm's operations must be traceable to a named individual — a Senior Manager — who is personally accountable for it. That accountability is documented in a Statement of Responsibilities (SoR) filed with the FCA.
AI governance is now a material area. It influences regulated decisions. It creates compliance risk. It is the subject of FCA supervisory scrutiny. And yet at Whitmore & Associates — as at most FCA-regulated firms — no Senior Manager's SoR mentions it.
What Marcus's SoR currently says
Marcus Osei's Statement of Responsibilities covers the firm's compliance framework, regulatory reporting, AML oversight, SYSC obligations, and Training & Competence scheme. It is comprehensive for the year it was written. It says nothing about AI.
Responsibility Area
Compliance Framework
AML Oversight
Documented ✓
SYSC Obligations
Documented ✓
T&C Scheme
Documented ✓
Regulatory Reporting
Documented ✓
AI Governance Oversight
Not mentioned — Gap
AI Risk Management
Not mentioned — Gap
AI System Oversight
Not mentioned — Gap
The AI Policy says Marcus is the policy owner. His SoR — the document that determines his personal regulatory accountability — does not. There is a direct contradiction between the governance documentation the firm just produced and the accountability framework that governs Marcus personally.
If an AI-related compliance failure occurs at Whitmore & Associates, the FCA will look at Marcus's SoR to understand his accountability. His SoR will show nothing. That is not a technicality — it is the documentary evidence of an accountability gap in the SM&CR framework, and the FCA treats it accordingly.
◆
Caution
Some firms respond to this issue by adding a single line to the SoR: "Oversight of AI tools used in the business." This is insufficient. ISO 42001 Cl. 5.3 requires responsibilities and authorities — plural. The SoR update must reflect specific, defined AI governance accountabilities, not a generic catch-all addition. A RACI that defines the role properly is the prerequisite to an SoR update that will stand up to FCA scrutiny.
The anatomy of this nonconformance
Gap F-G2 — Nonconformance Taxonomy
Gap ID
F-G2
ISO Clause
ISO/IEC 42001:2023 Clause 5.3 — Organisational Roles, Responsibilities and Authorities
Severity
Critical — no AIMS conformance is possible where accountability is undocumented; SM&CR personal liability exposure
Current State
No AI governance roles defined. No AI Risk Owner, AI System Owner, AIMS Programme Lead, or AI Ethics Reviewer assigned. No Statements of Responsibilities updated to reflect AI accountability.
FCA Parallel
SM&CR — material AI governance accountability not reflected in any Senior Manager's Statement of Responsibilities; FCA SYSC 4.1 — firms shall have robust governance arrangements including clear allocation of responsibilities
Commercial Risk
Institutional client AI governance questionnaires require named accountability. Where no individual can be named and their accountability documented, the response to question two is "we don't have this" — a due diligence failure that the AI Policy alone cannot recover.
Required Artefact
RACI-AIMS-FIN-001 — AI Accountability RACI with SM&CR Statement of Responsibilities mapping
What Whitmore & Associates built to close the gap
Marcus has twelve days remaining before the Harcastle response deadline. He needs to produce a RACI that assigns AI governance roles, ensure every named individual acknowledges their accountability in writing, and update the relevant Statements of Responsibilities — including his own — before the response goes out.
1
Map the four AI governance roles to named individuals
Marcus sits with Diana and works through RACI-AIMS-FIN-001. At Whitmore & Associates — a firm of twenty-two people — one person may hold more than one role. Marcus takes AIMS Programme Lead and AI Risk Owner. Diana takes AI Ethics Reviewer in her capacity as CEO and the individual ultimately accountable for client outcomes. For AI System Owner, they assign one per system: Marcus for the AML platform, Jade Nwosu for the ChatGPT drafting tool, and the IT lead for Microsoft Copilot. Every role now has a name. Every name now has defined responsibilities.
2
Document the RACI with responsibilities, not just names
The RACI is not a table of names and tick-boxes. For each role, RACI-AIMS-FIN-001 documents: what the role is responsible for, what decisions the role is accountable for, whom they consult, and whom they inform. Marcus as AI Risk Owner is responsible for maintaining the risk register and escalating material risks to Diana. Jade as AI System Owner for ChatGPT is responsible for monitoring its outputs, reporting any quality failures, and maintaining the system's entry in the AI System Register. These are specific, enforceable accountabilities — not job descriptions dressed as governance.
3
Obtain written acknowledgement from every named individual
ISO 42001 Cl. 5.3 requires responsibilities to be communicated within the organisation. For SM&CR purposes, this communication must be evidenced. Each named individual in the RACI receives a copy of their role description and signs an acknowledgement confirming they understand and accept the responsibility. For Marcus and Diana — SMF holders — this acknowledgement is attached to their SoR update files. This creates the paper trail that the FCA would expect to see.
4
Update the Statements of Responsibilities for all SMF holders
Marcus's SoR is updated to include: oversight of the firm's AI Management System, accountability for the AI risk register, and responsibility for reporting AI governance performance to the CEO. Diana's SoR is updated to include: board-level accountability for ethical AI use and approval of AI governance policy. Both updates are version-controlled, dated, and submitted to the FCA through the standard SoR notification process. The SoR now reflects what the AI Policy says — and the gap between the two documents is closed.
5
Communicate the RACI firm-wide
Cl. 5.3 requires responsibilities to be communicated within the organisation — not just held in a compliance folder. Marcus distributes the RACI in the same all-staff communication used to share the AI Policy, with a covering note that explains what each role means in practice. Staff who are not named in any AI governance role are told: if they have an AI concern, who they should contact, and what that person is responsible for doing. The governance structure is now visible to the entire firm.
◉
Note
In a small firm, one person holding multiple AI governance roles is acceptable — provided those roles are explicitly named and documented separately. The standard requires the roles to exist and be assigned. It does not require one person per role. What it does require is that the person holding multiple roles is competent for each one, and that this competence is documented. RACI-AIMS-FIN-001 includes a competence column for this purpose.
RACI-AIMS-FIN-001 — what the fix document contains
RACI-AIMS-FIN-001 — Document Control Block
Document ID
RACI-AIMS-FIN-001
Title
AI Governance RACI — FCA-Regulated Financial Services Firms
Version
1.0
Status
Active
Standard Refs
ISO/IEC 42001:2023 Cl. 5.3 · FCA SM&CR · FCA SYSC 4.1 · FSMA 2000 §62A · ISO 9001:2015 Cl. 7.5
Owner
AIMS Programme Lead (Compliance SMF)
Approval Authority
Chief Executive (SMF1)
Contents
Role definitions (AI Risk Owner, AI System Owner, AIMS Programme Lead, AI Ethics Reviewer) · Responsibility matrices per role · Competence requirements per role · Written acknowledgement template · SM&CR SoR update guidance · Communication log template
Review Cycle
Annual or upon change in AI systems, personnel, or regulatory requirements
Related Docs
POL-AIMS-FIN-001 · REG-AIMS-FIN-SYS-001 · REG-AIMS-FIN-RISK-001
Fix Document — Ungated Download
RACI-AIMS-FIN-001 — AI Governance RACI Template
ISO/IEC 42001:2023 Cl. 5.3 · SM&CR SoR Mapping · v1.0
Download Template →
After F-G2: Harcastle's third question
Marcus sends the RACI to Harcastle along with the updated Statement of Responsibilities extract. Question two is marked satisfied.
Harcastle's legal team moves to question three. It reads: "Please provide your organisation's register of AI systems in use, including the purpose of each system, the data it processes, the personnel who use it, and the governance controls in place."
Marcus looks at the AI System Owner column in the RACI — each of the four AI systems is named there, with a responsible individual. But a register? A structured document listing each system with purpose, data flows, users, and controls? That does not exist either.
That is Gap Three.
Remediation Sequence — Finance Series
✓ F-G1
AI Policy — POL-AIMS-FIN-001 · Complete
✓ F-G2
AI Accountability in SoRs — RACI-AIMS-FIN-001 · This article
→ F-G3
AI System Register — REG-AIMS-FIN-SYS-001
F-G4AI Risk Assessment — REG-AIMS-FIN-RISK-001
F-G5AI Impact Assessment — ASSESS-AIMS-FIN-IMP-001
F-G6AI Data Governance — REG-AIMS-FIN-DATA-001
F-G7Client Disclosure — DOC-AIMS-FIN-DISC-001
F-G8Human Oversight — PROC-AIMS-FIN-HITL-001
F-G9AI Supplier Governance — REG-AIMS-FIN-SUP-001
Section 8 — Quality Gate Record
Quality gate record
The following gates were checked before publication. All 10 gates pass. This record satisfies ISO 9001:2015 Clause 7.5.3 for the article series.
- G1All regulatory claims carry named, citable sources: FCA Annual Report 2023/24, FCA Enforcement Annual Report 2023, FCA DP5/22, SYSC 4.1, FSMA 2000 §62A. No fabricated citations.PASS
- G2ISO/IEC 42001:2023 Clause 5.3 correctly cited and characterised. "Shall" applied to mandatory requirements. Clause text paraphrased — ISO copyright constraint observed.PASS
- G3Scenario internally consistent with REF-AIMS-FIN-SCEN-001. Marcus Osei (SMF16), Diana Whitmore (SMF1 / CEO), Jade Nwosu (Relationship Manager), Harcastle Group plc (£28M AUM), 21-day window — all consistent with character register. Scenario advanced to Day 2 of questionnaire, consistent with F-G1 completing on Day 7.PASS
- G4ISO/IEC Directives Part 2 prescriptive language applied correctly. SM&CR SoR obligation characterised as a mandatory regulatory requirement. FCA SYSC 4.1 characterised accurately. Generic SoR addition characterised as insufficient (Caution notice) — not overstated as a prohibition.PASS
- G5RACI-AIMS-FIN-001 linked ungated. All document IDs for F-G1 through F-G9 present and consistent with series registry.PASS
- G6Article links to predecessor (F-G1) and successor (F-G3). Series navigation present in footer. Dependency chain documented in Section 7.PASS
- G7Disclaimer present as standalone section. All named parties identified as fictional. Document noted as educational only, not regulatory advice.PASS
- G8RACI-AIMS-FIN-001 document control block present with all mandatory fields: ID, version, title, status, standard refs, owner, approval authority, contents summary, review cycle, related documents.PASS
- G9H1 includes primary keywords "AI Policy" and "Statement of Responsibilities" within first 60 characters. Stat bar appears within first screenful. Schema.org Article JSON-LD with isPartOf series present. Canonical URL set.PASS
- G10IEC 82079-1:2012 notice hierarchy correct. DANGER not used. WARNING for SM&CR personal liability consequence. CAUTION for insufficient SoR update. NOTE for small-firm multi-role guidance. ITIL 4 notice distinctly labelled for Workforce and Talent Management practice.PASS