Accountability
Section 9 of Agentic Banking Architecture: A Practitioner's Guide
Every conversation about agentic AI governance eventually arrives at the same question: who's accountable when the agent gets it wrong?
The instinct is to find one person — one throat to choke. But banking has never actually worked that way for automated systems, and regulators already accept that. The pattern exists. We just haven't recognised it.
The accountability structure
Accountability for autonomous agents distributes across three domains, each answering a different question:
The business domain owner answers: "Should we deploy this agent, and within what operating envelope?" They own the decision to use an autonomous agent for a given business process, define its boundaries, and are accountable for the outcomes within those boundaries.
The CRO function answers: "Is this safe enough?" They set the risk appetite, define the guardrails, and validate that the agent's operating envelope falls within acceptable risk parameters. They don't own the agent — they own the constraint framework the agent operates within.
The CTO / platform function answers: "Does this work as designed?" They're accountable for the platform's reliability, the control plane's enforcement, and the integrity of the technical infrastructure that agents run on. They don't make business or risk decisions — they ensure the infrastructure faithfully executes them.
The integrating layer
Above all three sits a designated senior executive who answers a different question entirely: "Does the governance framework hold together?" This person isn't accountable for individual agent decisions. They're accountable for ensuring that the three domains don't leave gaps between them — that the accountability boundaries are explicit, tested, and auditable.
Many banks have appointed Chief AI Officers. In my view, the CAIO's most important job isn't AI strategy — it's owning the seams.
Where accountability breaks down
The failure in autonomous agent governance may not be that nobody is accountable. It's that the boundaries between the three domains are ambiguous. Each can legitimately say "I did my part" and things can still go wrong.
Consider: the business domain defines an operating envelope for a lending agent. The CRO function approves the risk parameters. The platform enforces the guardrails correctly. But the envelope definition and the risk parameters don't quite align — there's a gap where the agent can make decisions that none of the three owners explicitly authorised or prohibited. That gap is the actual risk.
Ambiguity between domains is the actual risk — not distributed accountability.
This is what the control plane and governance architecture from Section 3 are designed to address: making the boundaries between domains explicit, machine-readable, and continuously validated rather than relying on periodic committee reviews to catch gaps.
This isn't new
Banking already distributes accountability exactly this way across several established domains:
Model risk (SR 11-7 / FEAT): Model owner accountable for use, validation function for independent challenge, technology for infrastructure. A designated model risk officer oversees the framework.
Algorithmic trading: A named responsible person accountable for the algorithm's behaviour, with kill switches and surveillance infrastructure operated by a separate function.
Outsourcing (MAS TRM / EBA guidelines): You can delegate the activity, but not the risk. The business owner remains accountable for outcomes even when a third party performs the work.
Automated credit decisioning: The policy owner is accountable for the system, not each individual decision. The system executes within defined parameters; accountability attaches to the parameters and the monitoring, not to every credit decision the system makes.
The common pattern across all of these: accountable for the system, not each decision. That's exactly the right framing for autonomous agents. Nobody reviews every transaction an algo trading system executes. Instead, the responsible person is accountable for the system's design, its operating envelope, and the surveillance that monitors it. The same logic applies to agents.
This section is based on Part 8 in the LinkedIn series on agentic banking architecture. The accountability question came up in the comments of earlier posts in the series, particularly around governance and the control plane.