Assessment FAQ · the ownership deliverable
AI controls fail quietly in the gaps between organisations.
Your app calls an orchestrator, the orchestrator calls a model, the model runs on someone else’s cloud — and a control everyone assumes “the platform” handles is owned by no one. The Shared Security Responsibility Model map makes the chain explicit.
No control without a named owner. The gaps between the boxes are where breaches live.
The failure it prevents
“The provider handles that” is the most expensive assumption in an AI supply chain. The map turns it into a named seat and a clause — or a gap you now own.
“For each control in this chain — who, exactly, is accountable?”
The answer
One named owner for every in-scope control.
The deliverable is a matrix: control by control, the accountable seat — yours, your provider’s, or shared — with the chain mismatches and the justified NAs that become due-diligence questions and contract language.
The live ownership view maps every AI Controls Matrix (AICM) control to its accountable seat. This is the long-form intro to the same artefact.