Section 3 of the template

Roles, responsibilities & oversight

Governance only works when every responsibility has a name against it. Treat this list of roles as a menu, and cut it to the ones you have.

Home › Roles, responsibilities & oversight

Governance only works when every responsibility has somebody’s name against it. Section 3 sets out who owns what, so nothing important falls into the gap between roles.

What it is

A list of roles and what each one owns. Delete the roles you don’t have, merge them where one person carries several, and reassign anything left over to whoever will pick it up. The usual owners are:

  • Trustees or the governing board — strategic oversight and assurance; making sure AI is on the risk register; receiving regular reporting on adoption, incidents, breaches and changes to the approved list.
  • Senior leadership — approving the policy and any material changes; approving tools where named as the approver; commissioning the periodic AI risk review.
  • AI or digital lead — owning the approved list and the approval process; keeping the policy and staff guidance current; being the first point of contact for questions.
  • Data protection officer or lead — coordinating impact assessments; advising on lawful basis and processing agreements; receiving reports of data entered in error.
  • Designated safeguarding lead — receiving safeguarding and Prevent concerns that involve AI; advising on the safeguarding implications of proposed uses.
  • Filtering and monitoring lead — the senior named owner of your filtering and monitoring arrangements.
  • IT or network lead — running access, security, filtering and monitoring controls; blocking unapproved services; including AI in cyber reviews.

Why it’s important

The DfE governance standards expect clear lines of accountability, and the ICO’s edtech audits found, time and again, responsibilities that everyone assumed somebody else was holding. Putting a name against each line means you can assure it properly, and report on it to your board with confidence.

What you decide here

  • A named owner for every responsibility you keep.
  • Your reporting cycle to trustees or governors, for example each term.
  • Where the AI or digital lead and the DPO sit, and how they hand work over to each other.

Guidance it speaks to

Working on your AI policy?

Support with writing or refining it, and with training your staff, is exactly the work I do. And if the template or the screening tool has helped in your school or trust, I’d love to hear about it.