Unclear responsibilityTeams do not know who owns AI risk decisions
Impact: approvals are inconsistent, issues remain unresolved, and accountability becomes concentrated in a small governance team.
Response: role maps, decision scenarios, escalation exercises, and responsibility-specific playbooks.
Dependency: leadership must confirm decision rights and risk ownership.
Policy-practice gapAI policies are understood in principle but not applied
Impact: teams bypass lifecycle gates, documentation varies, and control evidence is difficult to review.
Response: workflow-based learning using the organisation's intake, assessment, approval, and monitoring processes.
Limitation: training cannot compensate for missing processes or unavailable control owners.
Shadow AIEmployees adopt tools without appropriate review
Impact: confidential data may be exposed, contracts may be breached, and outputs may be used without adequate human review.
Response: acceptable-use learning, practical red-flag scenarios, approved-tool guidance, and incident escalation.
Dependency: the organisation needs a usable approved-use and exception process.
Technical-control inconsistencyAI teams interpret testing and documentation differently
Impact: evaluation coverage, model records, monitoring, and release evidence vary across products.
Response: practitioner pathways covering risk-based evaluation, lifecycle documentation, quality gates, and monitoring decisions.
Limitation: specialist technical validation may require a separate assurance engagement.
Leadership knowledge gapExecutives receive AI proposals without a common challenge framework
Impact: value, risk, accountability, and investment decisions are difficult to compare.
Response: executive briefings, case-based decision simulations, oversight questions, and governance dashboards.
Dependency: leadership participation and access to relevant portfolio information.
Assurance fragmentationRisk, legal, privacy, security, and audit teams work from different assumptions
Impact: duplicated reviews, late-stage objections, conflicting control requests, and delayed deployment.
Response: cross-functional workshops, shared terminology, integrated scenarios, and control-boundary clarification.
Limitation: final interpretations remain with authorised specialists.