Escalation and Ownership: Who Owns What, and When to Escalate
Deliberate Academy Editorial Team
Reviewed for accuracy and professional relevance
You're 8 lessons in — don't lose your progress.
Sign up free to save where you are and earn a verified certificate when you pass.
- Map the compliance-function roles most commonly involved in AI governance work and the piece of the work each typically owns
- Identify the handoff points between roles where gaps most often appear
- Recognize three specific situations from this course that should trigger escalation to specialist expertise, rather than being handled at a foundational level
- Apply this course's foundation to recognize the boundary of your own current expertise honestly, as a professional strength rather than a weakness
A newly hired compliance analyst is asked to "handle the AI governance question" for a new marketing tool that processes customer purchase history to generate personalized offers. Handled well, this is a two-minute conversation: recognize that this touches personal data, flag it to the data protection function whose existing remit covers exactly this kind of question, and confirm the handoff happened. Handled poorly, the analyst either tries to resolve the data protection question alone without the relevant expertise, or assumes someone else has already covered it and never follows up. This lesson is about getting that handoff right.
Who Typically Owns What
The compliance officer typically owns the overall program: maintaining the AI system inventory, tracking regulatory obligations against it, and reporting status upward. The AI governance lead — sometimes a dedicated role, sometimes layered onto an existing model risk or data governance function — typically owns the classification methodology and technical documentation standard. Legal and risk teams interpret how a specific regulatory obligation applies to an ambiguous or novel use case and advise on vendor contract exposure. Enterprise IT risk functions typically own the technical controls layer — access logging, system security, and infrastructure. The data protection officer, where one exists, extends their remit to cover the data governance dimension of AI systems specifically — training data provenance and personal data use in AI processing.
You do not need to personally hold the expertise every one of these roles carries. You need to recognize, from the foundation this course has built, which category a given question falls into and who is positioned to answer it — and to make sure the handoff to that person actually happens, rather than assuming it will.
A compliance analyst discovers that a new marketing AI tool processes customer purchase history to generate personalized offers. Whose responsibility is it to assess whether this specific use of customer data is compatible with the organization's data protection obligations?
Select one answer.
Three Moments From This Course That Should Trigger Escalation
Looking back across this course, three specific situations should reliably prompt escalation to deeper specialist expertise rather than a foundational-level resolution: when an AI system's orientation-level EU AI Act classification suggests it is plausibly high-risk (Lesson 5) — this needs the formal classification methodology and conformity gap analysis a dedicated governance course covers, not a first-pass orientation judgment treated as final; when a GDPR Article 22 analysis is genuinely ambiguous, particularly around whether a human review step is substantive (Lesson 4) — legal counsel should confirm a borderline case; and when a vendor relationship touches a consequential, individual-level decision and the vendor's own due-diligence answers are incomplete or evasive (Lesson 6) — this warrants full legal and risk team involvement before contract signature, not just a compliance analyst's initial screen.
A Clean Handoff That Prevented a Delay — Enterprise SaaS Company
Context
A compliance analyst, three months into the role, was asked to review a new AI-powered candidate-ranking feature the company's own product team was building for an HR-tech product line.
Action
Applying the orientation framework from this course, she recognized the feature plausibly fell into the EU AI Act's high-risk employment domain and that its automated ranking output likely raised a GDPR Article 22 question given how thin the proposed human review step was. Rather than attempting to resolve either question herself, she escalated both specifically — the risk classification to the company's AI governance lead, and the Article 22 human-review-adequacy question to legal counsel — with a clear, written summary of what she had found and why each question needed their expertise.
Outcome
Both specialists were able to move quickly because her summary was specific and well-scoped rather than a vague 'can someone look at this AI thing.' The AI governance lead confirmed the high-risk classification and began the formal conformity process; legal counsel identified that the proposed review step needed to be redesigned before launch. The analyst's manager specifically credited the clarity of the escalation — not just the fact that she escalated — for how quickly both issues moved to resolution.
What does this lesson identify as the key skill this course has built, with respect to situations beyond a foundational level of expertise?
Select one answer.
Exercise
Your Task
Think of an AI-related question currently open in your organization (or a plausible one). Identify which of the roles from this lesson — compliance officer, AI governance lead, legal/risk, IT risk, or DPO — is best positioned to resolve it, and draft the two- or three-sentence escalation summary you would send them, specific enough that they could act on it without needing to ask you clarifying questions first.
Your reflection
Did you complete this exercise? What did you find? (Saved locally in your browser)
- AI governance work typically splits across five roles — compliance officer, AI governance lead, legal/risk, IT risk, and DPO — each owning a distinct piece, with gaps most often appearing at the handoffs between them.
- Recognizing which category a question falls into, and making sure the right person actually receives it, is more valuable at a foundational level than attempting to resolve every question personally.
- Three specific moments from this course should reliably trigger escalation: a plausibly high-risk EU AI Act classification, a genuinely ambiguous Article 22 human-review question, and an incomplete or evasive vendor due-diligence answer on a consequential use case.
- A clear, specific escalation summary — not just the fact of escalating — is what lets a specialist move quickly on a handed-off question.
- Recognizing the boundary of your own current expertise honestly is a professional strength this course is specifically designed to build, not a gap to be embarrassed about.