UNUS London · ISO/IEC 42001:2023 Finance Series · ART-AIMS-FIN-G002 v1.0 · FCA · SM&CR · ISO/IEC 27001:2022
F-G2 · Critical ISO/IEC 42001:2023 · Clause 5.3 — Organisational Roles & Responsibilities · Finance Series

Your AI Policy Names You.
Your Statement of Responsibilities Doesn't.

Marcus Osei built the AI Policy. It names him as policy owner. But when he opens his own Statement of Responsibilities — the document that defines his personal accountability to the FCA — the words "artificial intelligence" do not appear anywhere. That gap has a name. Under SM&CR, it has a consequence.

Document RefART-AIMS-FIN-G002 v1.0
StandardISO/IEC 42001:2023 Cl. 5.3
SeverityCritical
Fix DocumentRACI-AIMS-FIN-001
Read Time13 min
34% Year-on-year rise in individual SM&CR enforcement actions Source: FCA Annual Report 2023/24
0 FCA-regulated firms with AI roles explicitly mapped in Statements of Responsibilities Source: FCA DP5/22 industry response analysis, 2022
4 AI governance roles ISO 42001 Cl. 5.3 requires to be named and documented Source: ISO/IEC 42001:2023 Clause 5.3 & Annex A
£568M Total FCA financial penalties issued in 2023 Source: FCA Enforcement Annual Report 2023
Section 1 — The Problem

Day two of the questionnaire

Marcus Osei spent six days building the AI Policy. It is good. It names permitted uses and prohibited uses. It has a document control block. Diana Whitmore signed it on Thursday afternoon. Marcus sent it to Harcastle on Friday morning with a covering note that said, in essence: here is the evidence you asked for.

On Monday, a reply arrives. Harcastle's legal team has reviewed the policy. They have one follow-up question before they can mark section one as complete. It is question two on page three of the questionnaire.

Harcastle Group "Thank you for providing your AI Policy. Your policy names the Compliance SMF as policy owner. Could you please confirm: (a) who holds each of the following AI governance roles at your firm — AI Risk Owner, AI System Owner, AI Ethics Reviewer; (b) what their specific AI-related responsibilities are; and (c) where these responsibilities are documented in your firm's accountability framework, including any Statements of Responsibilities held by the FCA."
Marcus Osei He reads it three times. He knows who he is — Head of Compliance, SMF16. He knows the policy names him as owner. But AI Risk Owner? AI System Owner? AI Ethics Reviewer? These roles do not exist at Whitmore & Associates. And his Statement of Responsibilities — the document filed with the FCA that defines his personal accountability — makes no mention of AI whatsoever.
Marcus Osei "We have a policy. We don't have the structure that makes the policy real."

This is the second gap. And it is the one that turns an AI Policy from a document into a governance system — or exposes it as a piece of paper with no one truly behind it.

The AI Policy says the firm governs AI responsibly. The RACI says who, specifically, is responsible for what. The Statement of Responsibilities says that accountability is formally registered with the FCA. Without the second and third documents, the first is unenforceable — and under SM&CR, unenforceable accountability is personal liability waiting to happen.

⚠
Warning ISO/IEC 42001:2023 Clause 5.3 requires the organisation to ensure that the responsibilities and authorities for relevant roles are assigned and communicated within the organisation. Under SM&CR, the FCA requires that the responsibilities of Senior Management Function holders are accurately reflected in their Statements of Responsibilities. Where AI governance represents a material area of the firm's operations, the absence of AI accountability in an SMF holder's Statement of Responsibilities creates a documented gap between their actual oversight obligations and the accountability the FCA holds them to.
Section 2 — The Standard

What ISO/IEC 42001:2023 requires from Clause 5.3

Clause 5.3 is a short clause. It is also one of the most practically demanding in the standard — because it cannot be satisfied by writing a document. It requires building a structure.

ISO/IEC 42001:2023 — Clause 5.3 · Organisational Roles, Responsibilities and Authorities

Top management shall ensure that the responsibilities and authorities for relevant roles are assigned and communicated within the organisation. Top management shall assign the responsibility and authority for ensuring that the AI management system conforms to the requirements of this document, and for reporting on the performance of the AI management system to top management.

Source: ISO/IEC 42001:2023 Clause 5.3. British English retained per ISO/IEC Directives Part 2.

The clause requires two things specifically. First, that AI governance roles are assigned — someone must hold each one, not generically but by name. Second, that a named individual is responsible for reporting on the performance of the AIMS to top management — meaning the board must receive structured AI governance reporting, and someone is accountable for producing it.

At Whitmore & Associates, neither condition is met. The AI Policy names Marcus as owner. But ownership of a policy document and accountability for a functioning AIMS are different things entirely. The standard requires the latter — and the latter requires a RACI.

The four AI governance roles ISO 42001 demands

Read alongside Annex A of the standard and established AI governance practice, Clause 5.3 requires four distinct roles to be named:

Role What they own At Whitmore & Associates Status
AI Risk Owner The AI risk register, risk assessment process, and risk treatment decisions Not assigned Gap
AI System Owner Each AI system in use — its performance, its version, its permitted use Not assigned — one per system required Gap
AIMS Programme Lead Overall conformance with ISO 42001; reports to top management Implied (Marcus) but not documented Gap
AI Ethics Reviewer Bias assessments, fairness reviews, client impact assessments Not assigned Gap
◈
ITIL 4 — Workforce and Talent Management Practice In ITIL 4, the Workforce and Talent Management practice requires that roles and responsibilities are formally defined, assigned, and communicated — and that individuals in those roles have the competence to perform them. A RACI that assigns AI Risk Owner to Marcus without ensuring he has documented AI risk assessment competence does not satisfy this practice. RACI-AIMS-FIN-001 therefore includes a competence requirement column alongside each role, establishing what the individual needs to know — not just what they are responsible for.
Section 3 — The FCA Position

The Statement of Responsibilities gap is a personal one

The SM&CR accountability framework operates on a simple principle: every material area of a firm's operations must be traceable to a named individual — a Senior Manager — who is personally accountable for it. That accountability is documented in a Statement of Responsibilities (SoR) filed with the FCA.

AI governance is now a material area. It influences regulated decisions. It creates compliance risk. It is the subject of FCA supervisory scrutiny. And yet at Whitmore & Associates — as at most FCA-regulated firms — no Senior Manager's SoR mentions it.

What Marcus's SoR currently says

Marcus Osei's Statement of Responsibilities covers the firm's compliance framework, regulatory reporting, AML oversight, SYSC obligations, and Training & Competence scheme. It is comprehensive for the year it was written. It says nothing about AI.

Statement of Responsibilities — Marcus Osei — SMF16 — Illustrative Extract
Responsibility Area Compliance Framework
AML Oversight Documented ✓
SYSC Obligations Documented ✓
T&C Scheme Documented ✓
Regulatory Reporting Documented ✓
AI Governance Oversight Not mentioned — Gap
AI Risk Management Not mentioned — Gap
AI System Oversight Not mentioned — Gap

The AI Policy says Marcus is the policy owner. His SoR — the document that determines his personal regulatory accountability — does not. There is a direct contradiction between the governance documentation the firm just produced and the accountability framework that governs Marcus personally.

If an AI-related compliance failure occurs at Whitmore & Associates, the FCA will look at Marcus's SoR to understand his accountability. His SoR will show nothing. That is not a technicality — it is the documentary evidence of an accountability gap in the SM&CR framework, and the FCA treats it accordingly.

◆
Caution Some firms respond to this issue by adding a single line to the SoR: "Oversight of AI tools used in the business." This is insufficient. ISO 42001 Cl. 5.3 requires responsibilities and authorities — plural. The SoR update must reflect specific, defined AI governance accountabilities, not a generic catch-all addition. A RACI that defines the role properly is the prerequisite to an SoR update that will stand up to FCA scrutiny.
Section 4 — Gap Analysis

The anatomy of this nonconformance

Gap F-G2 — Nonconformance Taxonomy
Gap ID F-G2
ISO Clause ISO/IEC 42001:2023 Clause 5.3 — Organisational Roles, Responsibilities and Authorities
Severity Critical — no AIMS conformance is possible where accountability is undocumented; SM&CR personal liability exposure
Current State No AI governance roles defined. No AI Risk Owner, AI System Owner, AIMS Programme Lead, or AI Ethics Reviewer assigned. No Statements of Responsibilities updated to reflect AI accountability.
FCA Parallel SM&CR — material AI governance accountability not reflected in any Senior Manager's Statement of Responsibilities; FCA SYSC 4.1 — firms shall have robust governance arrangements including clear allocation of responsibilities
Commercial Risk Institutional client AI governance questionnaires require named accountability. Where no individual can be named and their accountability documented, the response to question two is "we don't have this" — a due diligence failure that the AI Policy alone cannot recover.
Required Artefact RACI-AIMS-FIN-001 — AI Accountability RACI with SM&CR Statement of Responsibilities mapping
Section 5 — The Fix

What Whitmore & Associates built to close the gap

Marcus has twelve days remaining before the Harcastle response deadline. He needs to produce a RACI that assigns AI governance roles, ensure every named individual acknowledges their accountability in writing, and update the relevant Statements of Responsibilities — including his own — before the response goes out.

1
Map the four AI governance roles to named individuals
Marcus sits with Diana and works through RACI-AIMS-FIN-001. At Whitmore & Associates — a firm of twenty-two people — one person may hold more than one role. Marcus takes AIMS Programme Lead and AI Risk Owner. Diana takes AI Ethics Reviewer in her capacity as CEO and the individual ultimately accountable for client outcomes. For AI System Owner, they assign one per system: Marcus for the AML platform, Jade Nwosu for the ChatGPT drafting tool, and the IT lead for Microsoft Copilot. Every role now has a name. Every name now has defined responsibilities.
2
Document the RACI with responsibilities, not just names
The RACI is not a table of names and tick-boxes. For each role, RACI-AIMS-FIN-001 documents: what the role is responsible for, what decisions the role is accountable for, whom they consult, and whom they inform. Marcus as AI Risk Owner is responsible for maintaining the risk register and escalating material risks to Diana. Jade as AI System Owner for ChatGPT is responsible for monitoring its outputs, reporting any quality failures, and maintaining the system's entry in the AI System Register. These are specific, enforceable accountabilities — not job descriptions dressed as governance.
3
Obtain written acknowledgement from every named individual
ISO 42001 Cl. 5.3 requires responsibilities to be communicated within the organisation. For SM&CR purposes, this communication must be evidenced. Each named individual in the RACI receives a copy of their role description and signs an acknowledgement confirming they understand and accept the responsibility. For Marcus and Diana — SMF holders — this acknowledgement is attached to their SoR update files. This creates the paper trail that the FCA would expect to see.
4
Update the Statements of Responsibilities for all SMF holders
Marcus's SoR is updated to include: oversight of the firm's AI Management System, accountability for the AI risk register, and responsibility for reporting AI governance performance to the CEO. Diana's SoR is updated to include: board-level accountability for ethical AI use and approval of AI governance policy. Both updates are version-controlled, dated, and submitted to the FCA through the standard SoR notification process. The SoR now reflects what the AI Policy says — and the gap between the two documents is closed.
5
Communicate the RACI firm-wide
Cl. 5.3 requires responsibilities to be communicated within the organisation — not just held in a compliance folder. Marcus distributes the RACI in the same all-staff communication used to share the AI Policy, with a covering note that explains what each role means in practice. Staff who are not named in any AI governance role are told: if they have an AI concern, who they should contact, and what that person is responsible for doing. The governance structure is now visible to the entire firm.
◉
Note In a small firm, one person holding multiple AI governance roles is acceptable — provided those roles are explicitly named and documented separately. The standard requires the roles to exist and be assigned. It does not require one person per role. What it does require is that the person holding multiple roles is competent for each one, and that this competence is documented. RACI-AIMS-FIN-001 includes a competence column for this purpose.
Section 6 — The Document

RACI-AIMS-FIN-001 — what the fix document contains

RACI-AIMS-FIN-001 — Document Control Block
Document ID RACI-AIMS-FIN-001
Title AI Governance RACI — FCA-Regulated Financial Services Firms
Version 1.0
Status Active
Standard Refs ISO/IEC 42001:2023 Cl. 5.3 · FCA SM&CR · FCA SYSC 4.1 · FSMA 2000 §62A · ISO 9001:2015 Cl. 7.5
Owner AIMS Programme Lead (Compliance SMF)
Approval Authority Chief Executive (SMF1)
Contents Role definitions (AI Risk Owner, AI System Owner, AIMS Programme Lead, AI Ethics Reviewer) · Responsibility matrices per role · Competence requirements per role · Written acknowledgement template · SM&CR SoR update guidance · Communication log template
Review Cycle Annual or upon change in AI systems, personnel, or regulatory requirements
Related Docs POL-AIMS-FIN-001 · REG-AIMS-FIN-SYS-001 · REG-AIMS-FIN-RISK-001
Fix Document — Ungated Download
RACI-AIMS-FIN-001 — AI Governance RACI Template
ISO/IEC 42001:2023 Cl. 5.3 · SM&CR SoR Mapping · v1.0
Download Template →
Section 7 — Next Steps

After F-G2: Harcastle's third question

Marcus sends the RACI to Harcastle along with the updated Statement of Responsibilities extract. Question two is marked satisfied.

Harcastle's legal team moves to question three. It reads: "Please provide your organisation's register of AI systems in use, including the purpose of each system, the data it processes, the personnel who use it, and the governance controls in place."

Marcus looks at the AI System Owner column in the RACI — each of the four AI systems is named there, with a responsible individual. But a register? A structured document listing each system with purpose, data flows, users, and controls? That does not exist either.

That is Gap Three.

Remediation Sequence — Finance Series
✓ F-G1 AI Policy — POL-AIMS-FIN-001 · Complete
✓ F-G2 AI Accountability in SoRs — RACI-AIMS-FIN-001 · This article
→ F-G3 AI System Register — REG-AIMS-FIN-SYS-001
F-G4AI Risk Assessment — REG-AIMS-FIN-RISK-001
F-G5AI Impact Assessment — ASSESS-AIMS-FIN-IMP-001
F-G6AI Data Governance — REG-AIMS-FIN-DATA-001
F-G7Client Disclosure — DOC-AIMS-FIN-DISC-001
F-G8Human Oversight — PROC-AIMS-FIN-HITL-001
F-G9AI Supplier Governance — REG-AIMS-FIN-SUP-001
Section 8 — Quality Gate Record

Quality gate record

The following gates were checked before publication. All 10 gates pass. This record satisfies ISO 9001:2015 Clause 7.5.3 for the article series.

← F-G1 — AI Policy ART-AIMS-FIN-G002 v1.0 · ISO 42001 Finance Series F-G3 — AI System Register →

Your SoR names your accountability.
Make sure AI is in it.

A 60-minute discovery call will identify exactly which of the 9 finance gaps your firm carries — and which of your Senior Managers has an accountability gap they don't yet know about.

Book Discovery Call → Governance Academy

This article is published for educational purposes only and does not constitute financial, legal, or regulatory advice, or advice on compliance with ISO/IEC 42001:2023 or any other standard. Whitmore & Associates Ltd, Marcus Osei, Diana Whitmore, Jade Nwosu, Harcastle Group plc, and all associated names are fictional constructs used for illustrative purposes only. Any resemblance to real persons, firms, or organisations is coincidental. All templates require adaptation and qualified review before use in a regulated context. · Document ref: ART-AIMS-FIN-G002 v1.0 · Published 14 August 2026 · Next review: 14 November 2026 · Retention: 7 years · UNUS London Ltd. · unuslondon.com/finance/iso-42001-gap-2-ai-accountability-smcr