Exemplar Global Certified Courses from USD 99. Ending Soon!

Roles, Responsibilities and Authorities in an AIMS: Clause 5.3 Unpacked

AW

Team @ Audit Workshop

13 min read
Roles, Responsibilities and Authorities in an AIMS: Clause 5.3 Unpacked

Why Clause 5.3 Matters More in an AI Management System

When organisations implement ISO 42001, the AI management system standard, they often focus heavily on risk assessment, impact assessments and the controls in Annex A. Clause 5.3 tends to get less attention. That is a mistake. Getting roles, responsibilities and authorities right is foundational to everything else. Without clear ownership, the most carefully designed AI governance framework falls apart in practice.

ISO 42001 Clause 5.3 requires top management to ensure that responsibilities and authorities for relevant roles are assigned, communicated and understood throughout the organisation. That wording is almost identical to the equivalent clause in ISO 9001, ISO 14001 and ISO 45001. But the context of an AI management system introduces complications those other standards do not face. AI systems cross functional boundaries in ways that quality or safety processes rarely do. A single AI application might touch procurement, HR, customer service, legal and IT simultaneously. Deciding who is responsible for what, and making sure those people actually know it, is genuinely hard.

This article unpacks what Clause 5.3 requires, what auditors look for when they assess it, and what good implementation actually looks like in an organisation deploying AI systems.

What Clause 5.3 Actually Says

The clause is short. Top management must assign and communicate roles, responsibilities and authorities. Those roles must be understood. The standard then identifies two specific responsibilities that must be assigned:

  • Ensuring the AIMS conforms to the requirements of ISO 42001
  • Reporting on the performance of the AIMS to top management

These two functions do not need to sit with one person. The standard does not require a single management representative in the way some older standards did. One person might own overall AIMS conformance while another is responsible for performance reporting. Both functions must be covered, and top management must know who holds them.

Beyond those two named responsibilities, the standard leaves it to the organisation to determine what other roles are needed. That flexibility is intentional. AI governance looks very different in a 20 person technology startup deploying a single customer chatbot compared to a large financial institution running dozens of AI models across business units. The standard does not prescribe an org chart. It requires the organisation to think clearly about what roles are needed for its AIMS to function and then make sure those roles are filled, documented and communicated.

The Specific Roles ISO 42001 Introduces

Although Clause 5.3 does not name specific job titles, ISO 42001 as a whole introduces concepts that imply distinct functional responsibilities. Understanding these helps organisations structure their role assignments sensibly.

The AI Role of the Organisation

Clause 4.3 of ISO 42001 requires the organisation to determine its AI role. Is it a provider of AI systems, a producer of AI systems, a customer deploying AI systems developed by others, or some combination? This determination directly shapes what responsibilities are relevant. A provider has obligations around how it designs and deploys systems. A customer has obligations around how it selects, monitors and governs AI systems it uses. The roles assigned under Clause 5.3 must reflect the organisation's actual AI role. If you have already read our article on determining your AI role under ISO 42001, you will understand why this matters before you even start assigning responsibilities.

AI System Owner

Someone needs to own each AI system in scope. This person is accountable for the system's ongoing conformance with the AIMS, for triggering impact assessments when changes occur, and for ensuring operational controls are applied. In practice, this is often a product manager, a data science team lead, or a business unit manager depending on the organisation's structure. The key point is that ownership must be explicit and documented. Vague shared ownership is one of the most common findings auditors raise against Clause 5.3.

AIMS Coordinator or AI Governance Lead

Someone needs to hold the two named responsibilities in Clause 5.3: ensuring conformance and reporting performance to top management. This person is often called an AI governance lead, an AIMS manager, or something similar. In smaller organisations this might be the quality manager wearing an additional hat. In larger organisations it may be a dedicated role. Whatever the title, this person must have sufficient authority to drive the AIMS across functions and sufficient access to report meaningfully to top management.

Technical and Operational Roles

Depending on the complexity of the AI systems in scope, organisations may also need to assign responsibilities for data governance, model validation, bias monitoring, incident response and supplier oversight. ISO 42001 Annex A contains controls that require someone to own them. Those owners need to be identified somewhere in the organisation's role structure, even if the formal AIMS documentation only captures the headline responsibilities.

What Auditors Look for When Assessing Clause 5.3

If you are preparing for a certification audit or conducting an internal audit of your AIMS, here is what an experienced auditor will actually examine under Clause 5.3.

Evidence That Roles Are Assigned

The auditor will look for documented evidence that responsibilities have been assigned. This might be captured in an AIMS manual, a responsibility matrix, job descriptions, terms of reference for an AI governance committee, or a combination of these. What the auditor is checking is whether the assignment exists and is current. A role matrix that was created during implementation and never updated after a restructure does not demonstrate that responsibilities are understood today.

Evidence That Roles Are Communicated

Assignment on paper is not enough. The auditor will ask people about their responsibilities. Interviews with the AI governance lead, AI system owners and relevant operational staff will test whether individuals actually know what they are responsible for. A common finding is that documented responsibilities exist but the people named in those documents describe their role differently when interviewed. That gap between documentation and reality is exactly what Clause 5.3 is designed to prevent.

Evidence That Roles Are Understood

Understanding goes deeper than awareness. An auditor might ask an AI system owner to explain what they do when a significant change is proposed to their system. Do they know they need to trigger an impact assessment? Do they know who to escalate to? Do they understand the boundary between their responsibilities and those of the data team or the IT security function? If the answers are vague or inconsistent, the auditor has reasonable grounds to raise a finding.

The Two Named Responsibilities

The auditor will specifically verify that someone is assigned to ensure AIMS conformance and that someone is assigned to report AIMS performance to top management. If those two functions are not explicitly covered, that is a nonconformity against Clause 5.3 regardless of how well everything else is documented. The auditor will also check whether the person responsible for reporting actually does report to top management, by looking at management review records. If management review minutes show no AIMS performance reporting, the assigned responsibility exists in name only.

Common Weaknesses Auditors Find Against Clause 5.3

Having conducted audits across organisations implementing ISO 42001, the following patterns come up repeatedly.

Responsibilities Assigned to Teams Rather Than Individuals

Organisations sometimes assign AIMS responsibilities to a team, committee or department rather than to a named individual. The AI governance committee is responsible for impact assessments. The data team is responsible for data quality controls. This approach creates accountability gaps. When a finding is raised or a decision needs to be made, everyone assumes someone else is handling it. Clause 5.3 does not prohibit collective governance structures, but it does require that specific responsibilities are assigned and understood. At minimum, a named individual within each team should hold the accountability.

Responsibilities That Do Not Reflect the Actual AI Role

An organisation that acts primarily as a customer deploying third party AI systems sometimes copies responsibilities from a provider template. The result is a role structure that does not match what the organisation actually does. Auditors notice this quickly. If the AIMS documentation assigns someone responsibility for model training and validation but the organisation only uses off the shelf AI tools, that responsibility either does not apply or needs to be reframed around supplier oversight and evaluation.

No Clear Escalation Path

AI systems generate novel situations. A model starts producing unexpected outputs. A bias concern is raised by a staff member. A supplier announces a significant change to an AI tool the organisation relies on. In each case, someone needs to decide what to do. Clause 5.3 does not explicitly require an escalation path, but the absence of one means the AIMS cannot function effectively. Auditors who are testing whether responsibilities are understood will probe whether people know who to go to when something unusual happens.

Responsibilities Not Updated After Organisational Change

AI governance roles are often set up carefully at the time of implementation and then forgotten. When the AI governance lead leaves the organisation, when a new AI system is deployed, or when a business unit restructure changes who owns a particular process, the role assignments need to be updated. Stale documentation is one of the most reliable indicators that Clause 5.3 has not been maintained as a living part of the AIMS.

How to Structure Role Assignments Practically

There is no single right way to document roles and responsibilities for an AIMS. Here are approaches that work in practice.

A Responsibility Matrix Linked to the AIMS Scope

A simple table that maps each AI system in scope to an owner, maps each key AIMS process to a responsible person, and identifies the two named Clause 5.3 responsibilities gives auditors exactly what they need. Keep it simple. A two page matrix that is accurate and current is more valuable than a 20 page governance framework that nobody reads.

Job Descriptions That Reference AI Governance Responsibilities

For roles that carry significant AIMS responsibilities, incorporating those responsibilities into formal job descriptions ensures they are communicated at appointment and reviewed during performance cycles. This also demonstrates that the organisation has thought about competence requirements for those roles, which connects to Clause 7.2 of ISO 42001.

An AI Governance Committee With Clear Terms of Reference

Larger organisations often benefit from a formal governance structure. If you use a committee model, the terms of reference should specify individual accountabilities within the committee, not just collective ones. The committee chair or secretariat should hold the named Clause 5.3 responsibilities, and the terms of reference should say so explicitly.

Regular Communication of Responsibilities

Roles need to be communicated, not just documented. This might happen through onboarding for new staff in relevant roles, through annual AIMS awareness activities, or through team briefings when the AIMS is updated. Auditors will ask how responsibilities are communicated to new role holders. Having a process for this, even a simple one, demonstrates that the organisation takes the communication requirement seriously.

The Connection Between Clause 5.3 and the Rest of the AIMS

Clause 5.3 does not sit in isolation. It connects directly to several other parts of ISO 42001.

The AI policy under Clause 5.2 sets the direction for AI governance. The roles assigned under Clause 5.3 are responsible for implementing that policy. If the policy commits the organisation to conducting impact assessments before deploying new AI systems, someone needs to own that process. That ownership sits in Clause 5.3. We covered the AI policy requirements in detail in our article on Clause 5.2 of ISO 42001.

The risk assessment and treatment processes under Clause 6.1 require someone to own them. The operational controls under Clause 8.1 require someone to implement and maintain them. The internal audit programme under Clause 9.2 requires someone to plan and manage it. Every process in the AIMS needs an owner, and Clause 5.3 is where that ownership is formally established.

There is also a direct link to competence under Clause 7.2. Assigning a responsibility to someone who lacks the knowledge or skills to fulfil it does not satisfy the requirement. The organisation needs to ensure that people in AIMS roles have the competence those roles demand. This is particularly relevant for AI governance, where the technical complexity of some responsibilities means that generic management skills are not always sufficient. Our article on building AI competence under Clause 7.2 explores this in more detail.

Auditing Clause 5.3 as an Internal Auditor

If you are running an internal audit of your organisation's AIMS and Clause 5.3 is on your checklist, here is a practical approach to gathering useful evidence.

Start with the documentation. Obtain the current role assignments, whether that is a responsibility matrix, job descriptions, committee terms of reference or some other form. Check when they were last reviewed and whether they reflect the current organisational structure and the current scope of AI systems.

Then interview the people named in those documents. Ask them to describe their AIMS responsibilities in their own words. Ask what they do when a new AI system is proposed. Ask who they report to on AIMS matters. Ask how they would handle a situation where an AI system was producing unexpected or potentially harmful outputs. The answers will quickly reveal whether responsibilities are genuinely understood or just nominally assigned.

Check management review records to verify that AIMS performance reporting is actually happening. If the person assigned to report on AIMS performance cannot point to evidence that they have done so, the assignment exists on paper only.

Finally, consider whether the role structure makes sense for the organisation's actual AI activities. If there are AI systems in scope that nobody appears to own, or if there are responsibilities assigned to people who have clearly moved on, those are findings worth raising.

Getting Clause 5.3 Right From the Start

Organisations that get Clause 5.3 right from the beginning of their AIMS implementation tend to find the rest of the standard much easier to manage. When everyone knows who is responsible for what, decisions get made, risks get assessed, controls get implemented and performance gets reported. When responsibility is unclear, everything stalls or gets done inconsistently.

The investment in thinking carefully about role assignments at the outset pays dividends throughout the three year certification cycle. It also makes internal audits more productive, because auditors can engage with the right people rather than spending time working out who actually owns a given process.

If you are working toward ISO 42001 certification or building your skills as an AIMS auditor, understanding how Clause 5.3 fits into the broader standard is essential. Audit Workshop offers training across foundation, internal auditor and lead auditor levels for ISO 42001 and the core management system standards. The courses are built around real audit practice, not just standard text, so you come away knowing how to apply what you have learned in actual audits.

Frequently Asked Questions

No. ISO 42001 does not require a single management representative in the way some older standards implied. The clause requires that specific responsibilities are assigned and communicated, including the two named responsibilities of ensuring AIMS conformance and reporting AIMS performance to top management. These can sit with one person or be split across multiple roles depending on the organisation's size and structure.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.