Decision Authority Beyond Artefacts

Decision Authority Beyond Artefacts

Audio Commentary
Decision authority is often treated as something that can be secured through policies, frameworks, approval structures and formal accountability. But AI implementation reveals the limits of what these governance artefacts can achieve on their own. This commentary explores what happens when authority has been documented but remains difficult to exercise: when system recommendations are challenged, new evidence emerges and responsibility is clearer than permission. It considers why effective governance depends not only on what has been designed, but on whether people possess usable decision authority at the moment a consequential choice must be made.

Decision authority is often treated as though it can be secured through documentation. Organisations produce policies, approval matrices, committee terms of reference, escalation routes, model risk standards and lines of accountability.

These artefacts are necessary because complex institutions cannot operate through instinct alone. They create a common language, preserve institutional intent and provide evidence that a control environment has been designed. Yet they also encourage a dangerous assumption: that because authority has been described, it has therefore been made usable. AI implementation exposes the weakness of that assumption.

Once a system begins recommending, prioritising or shaping consequential decisions, the question is no longer whether governance exists on paper. The question is whether people can identify, exercise and defend their authority at the precise moment when the system’s output is incomplete, contested or wrong.

This distinction matters most in regulated and operationally complex environments. A bank may have a model governance framework, an insurer may have claims protocols, and a healthcare provider may have clinical escalation procedures.

Each formal design may appear coherent. Yet governance artefacts describe an intended order, not what happens when commercial pressure, incomplete information, professional judgement and fear of accountability converge. AI does not create this gap; it makes it visible.

It introduces a new source of confidence into the decision environment, often with the appearance of analytical neutrality. When that confidence collides with human experience or emerging evidence, the organisation discovers whether its governance supports judgement under pressure or merely documents compliance.

The limits of governance become apparent because artefacts usually define roles more easily than they define permission. A policy may state that a relationship manager can challenge a lending recommendation, that a claims handler can refer a case, or that a clinician remains responsible for the final decision.

Yet none of these statements answers the practical question: what can that person actually do without waiting for further approval? Can they override the recommendation, suspend the process, request new evidence or change the classification?

Must they justify the challenge before acting, or only afterwards? What happens if the system is usually right but appears wrong in this case? Governance artefacts may allocate responsibility while leaving the conditions of authority uncertain.

This is where decision ownership becomes more than a line on a chart. Ownership requires clarity about who is entitled to change the course of action, what evidence they may rely upon and what consequences they are expected to carry.

Without that clarity, people borrow confidence from the system, from senior colleagues or from committees. The result is often a form of distributed participation combined with concentrated accountability.

Many people contribute, review and advise, but no one is entirely certain who is authorised to decide. When the outcome is favourable, the ambiguity remains hidden. When the outcome is challenged, the organisation reconstructs the decision retrospectively and searches for the individual who should have known better.

AI implementation intensifies this pattern because algorithmic recommendations acquire institutional weight before their authority has been explicitly defined. A model may technically provide advice, yet operationally function as a default decision.

Staff learn that departures attract scrutiny, require extra evidence or slow the process. Managers may insist that human judgement remains central while performance targets reward agreement with the system.

Over time, the recommendation becomes difficult to challenge, not because policy prohibits challenge, but because the surrounding environment makes challenge costly. The authority of the system is therefore produced socially and operationally, even when it has no formal decision rights. This is one reason governance execution cannot be assessed by reading policy alone.

The crucial issue is not whether humans remain “in the loop”. That phrase is too weak for the demands of consequential decision-making.

A person can be present in a process without possessing meaningful authority. They may review the output, add contextual information or record a concern, yet still lack the permission to alter the result.

Human involvement can therefore become ceremonial: a visible layer of oversight that reassures boards and regulators while leaving the practical balance of power unchanged. What matters is whether the human participant has defined decision rights, sufficient information, protected routes for challenge and the confidence that a reasonable departure will be supported. Presence is not authority, and review is not control.

This is also why accountability structures often fail at the point of use. They tend to be designed backwards from the undesirable event.

Organisations ask who should answer if a customer is harmed, a loan defaults, a claim is mishandled or a regulatory obligation is breached. They are less precise about what authority that person needs beforehand.

Accountability without usable authority creates defensive behaviour. People escalate unnecessarily, delay decisions, seek consensus or follow the system because deviation feels personally dangerous. The organisation may interpret this as risk aversion or resistance to innovation. In reality, it is frequently a rational response to an environment in which responsibility is visible but authority is fragmented.

At the centre of this problem is decision authority itself. It cannot be reduced to a job title, a RACI chart or a committee mandate.

It is the practical capacity to make or alter a consequential choice within recognised boundaries. It includes permission, evidence, judgement, timing and answerability.

In an AI-enabled process, that capacity must remain clear when the recommendation is challenged, when new information emerges and when two legitimate forms of expertise disagree. A data scientist may trust the model’s performance, a frontline professional may recognise an unusual context, and a risk leader may see a wider exposure. The governance question is not which voice is universally superior. It is how the organisation determines whose judgement governs this decision, under these conditions, at this moment.

Governance artefacts struggle with this because they freeze what is inherently dynamic. They capture the approved process, expected thresholds and formal routes of escalation.

Real decisions unfold through changing information. A customer provides new documents. A supplier failure alters an operational assumption. A medical symptom changes. A fraud indicator has an innocent explanation.

An AI recommendation may have been reasonable when generated and less reasonable twenty minutes later. Operational governance must therefore account for movement: who can reopen a decision, what new evidence is material, when the original recommendation loses force and whether the person closest to the change can act without restarting the entire governance chain.

The quality of AI implementation will increasingly depend on how organisations manage this movement. Technical controls remain essential: validation, monitoring, data quality, explainability, bias testing and performance review.

But those controls cannot resolve every live case. They can indicate whether the system is reliable in aggregate; they cannot determine whether its recommendation should govern a particular exception.

Exceptions are not simply noise around a well-designed process. They are moments in which the organisation’s values, risk appetite and allocation of judgement become operational. A mature control environment does not attempt to eliminate discretion. It makes discretion visible, bounded and defensible.

That requires a different understanding of governance execution. The test is not whether the organisation can produce the relevant document.

The test is whether the people involved can answer a small number of difficult questions under pressure. Who has the final decision? What may they do without further approval? On what grounds may the AI output be challenged? What evidence must be preserved? Who is accountable for the consequences, including the consequences of following the system?

These questions sound elementary, yet many organisations cannot answer them consistently across functions. The absence of clarity is then absorbed by meetings, workarounds and repeated escalation.

For a CRO, the concern should be wider than model risk. Unclear authority creates conduct risk, operational risk, compliance risk and strategic risk at the same time.

It can produce inconsistent customer outcomes, delayed action and an inability to explain why one case was treated differently from another. For a COO, the same problem appears as friction: increased handling time, duplicated reviews, queues around senior decision-makers and teams that cannot move without permission.

The organisation may invest heavily in automation and still experience slower execution because the technology has entered an unresolved decision environment. Efficiency is lost not through system failure, but through authority failure.

The appropriate response is not to create another layer of governance artefacts. More documentation may improve coverage while leaving the live problem untouched.

Organisations need to examine decisions as they are actually performed. That means tracing a consequential decision from trigger to outcome, identifying every person and system that can influence it, and distinguishing recommendation, approval, veto, override and escalation.

It means observing where staff hesitate, where exceptions accumulate and where formal routes differ from operational practice. It also means asking whether the evidence required to challenge the system is realistically available at the moment of decision, rather than only discoverable during a later review.

Such analysis changes the role of governance. Instead of operating mainly as a protective layer around technology, it becomes an architecture for responsible action.

Good governance should make it easier for a competent person to act when the situation requires it, while preserving the evidence needed to explain that action later. It should prevent arbitrary override without turning the model into an unquestionable authority.

It should protect challenge without romanticising human judgement. Most importantly, it should align accountability structures with the real distribution of power. Where a person is expected to answer for an outcome, they must possess authority proportionate to that responsibility.

There is a deeper institutional issue here. Organisations often prefer artefacts because artefacts are visible, auditable and controllable.

They allow boards to see that something has been approved and regulators to see that a process exists. Decision authority is harder to govern because it resides partly in behaviour, confidence, relationships and organisational permission.

It can be diluted by culture even when it is clear in policy. It can be concentrated informally in senior figures who are absent from the documented process. It can also be surrendered voluntarily by people who no longer believe the organisation will support their judgement. These realities are uncomfortable, but AI makes them increasingly difficult to ignore.

The task, then, is not to move beyond artefacts by abandoning them. It is to place them in their proper role.

Policies, frameworks and records should support the decision environment, not substitute for it. They should clarify the boundaries within which judgement can be exercised and preserve the reasoning that makes a decision defensible.

They should also be tested against actual cases, especially those involving conflict between system output and professional judgement. A governance framework that works only when everyone agrees with the AI is not a framework for decision-making. It is a framework for conformity.

As AI becomes embedded in lending, claims, healthcare, public services, employment and critical operations, organisations will be judged not only by the quality of their systems but by the quality of the authority surrounding them.

The decisive question will be whether they can act responsibly when the model is uncertain, when evidence changes and when a human challenge is both necessary and difficult.

The organisations that answer this well will not be those with the most elaborate documentation. They will be those that have made authority usable, accountability proportionate and judgement defensible. AI implementation is therefore not merely a test of technology or governance design. It is a test of whether the organisation truly understands its own decision authority.

Why Decision Frameworks Cannot Guarantee Responsibility

You can now listen to The Decision Environment on Spotify and Apple Podcasts.

When Decision Authority Is Unclear, Strategy Slows

Understand how decisions actually move in your organisation. Explore the Decision Authority Diagnostic.

Explore the Decision Authority Diagnostic

Continue the conversation


    Add a comment

    *Please complete all fields correctly

    Related Posts

    Bess Obarotimi reflecting on leadership judgement and Interior Accountability as a Governance Variable while reviewing governance insights over coffee