ai · security · skills

Assessment FAQ · the ownership deliverable

AI controls fail quietly in the gaps between organisations.

Your app calls an orchestrator, the orchestrator calls a model, the model runs on someone else’s cloud — and a control everyone assumes “the platform” handles is owned by no one. The Shared Security Responsibility Model map makes the chain explicit.

Youthe AI customerAppthe deployerOrchestratorthe integratorModelthe providerCloudthe platformEach in-scope control is assigned to exactly one seat — owned, shared, or inherited — with justified NAs that become contract clauses.The map surfaces the controls you believed someone else was doing.

No control without a named owner. The gaps between the boxes are where breaches live.

The failure it prevents

“The provider handles that” is the most expensive assumption in an AI supply chain. The map turns it into a named seat and a clause — or a gap you now own.

“For each control in this chain — who, exactly, is accountable?”

The answer

One named owner for every in-scope control.

The deliverable is a matrix: control by control, the accountable seat — yours, your provider’s, or shared — with the chain mismatches and the justified NAs that become due-diligence questions and contract language.

The live ownership view maps every AI Controls Matrix (AICM) control to its accountable seat. This is the long-form intro to the same artefact.

The ownership view, control by control →

See where the line falls →
← Back to Insights

Subscribe for the next essay.