The Authority is a small, senior, cross-functional body with clear decision rights. It owns the standards and runs the reviews. It operates as the AI-specialist complement to the Group Industrialization Design Authority (IDA), applying Group and Business Line policy to AI product work. See Foundations.
Standing members hold the bar and the cadence, with regional tech leaders connecting the Authority to delivery on the ground.
Etienne Grass. Mandates the Authority, unblocks resourcing, and represents it to the wider practice and to the IDA.
Ian Davies. Accountable for the Authority. Owns the cadence, breaks ties, and holds the final decision on delivery escalations.
Regional owners connecting the Authority to delivery: TBD (UK), Ben Farcy (France), Markus Jahn (Germany), Wouter Plukkel (North America).
Rekha Bhatia. Owns cybersecurity approval and exceptions; coordinates with the Authority via Group Exception Management.
Siddarth Singh. Owner of AI for Us globally and the arbiteur of quality.
TBD. Connects the Authority to the AI Asset Product Owner community and the asset creation process. See Asset Lifecycle.
Clear ownership prevents both bottlenecks and quiet gaps. Every decision has one accountable role.
| Decision | Accountable | Notes |
|---|---|---|
| Asset technology approval | AI Design Authority | The technology lens at Step 4 of the asset process |
| Risk class of a product | Reviewer, confirmed by domain lead | Set at Gate 0; re-classified on material change |
| Gate Pass or Hold decision | Assigned reviewer | Escalates to Lead if contested |
| Responsible AI sign-off | Responsible AI lead | Independent; not overridable by the Lead |
| Cybersecurity approval & exceptions | CISO | Group Exception Management process; Authority coordinates |
| Data protection sign-off | DPO | Required for sensitive or live personal data |
| Investment docking (>€1M) | Group Investment Committee (GIC) | Per ASLM; aligns Group IT, Cyber, Legal, Portfolio |
| Adding or changing a standard | Authority, by consensus | Lead decides if consensus is not reached |
| Delivery escalation | Lead | Final within the Authority; sponsor beyond |
Scheduled gate reviews run continuously and form the working heartbeat of the Authority.
Standing members meet to decide contested gates and standards changes.
The full library is reviewed against new regulation, tooling, and lessons from live products.
The sponsor reviews the Authority's mandate, membership, and measured impact.
The library is version-controlled and dated, and structured as an AI management system aligned to ISO/IEC 42001. Anyone can propose a change; the Authority ratifies it. A standard that no longer earns its place is retired before it rots.
Any practitioner raises a gap or a change, with the problem and evidence behind it.
The relevant domain lead drafts or refines the standard and tests it against real builds.
The Authority agrees the wording and level, versions it, and communicates the change with a lead time.
Standards overtaken by regulation or practice are deprecated and archived, with the reason recorded.
Start at the same intake. Bring the problem and the evidence. We will take it from there.