The Accountability Gap™ (TAG™) is the framework that names who owns a decision when an AI system shapes it. It defines two seats, a Governance Owner who carries institutional accountability for putting the system into use and a Decision Owner who carries accountability for the individual call the system informs, connected by a required handoff that specifies what crosses between them. The Governance Owner holds Charter, Commission, and Cover. The Decision Owner holds Decide, Document, and Defend. The gap closes only when all six functions are named and the handoff is defined. This brief states the framework in sector neutral terms and shows it holding without modification in two live rooms, clinical AI at the bedside and financial AI at the alert queue. Same seats, same handoff, different room.
The Accountability Gap™ (TAG™) is the framework that names who owns a decision when an AI system shapes it. It defines two seats. A Governance Owner carries institutional accountability for putting the system into use. A Decision Owner carries accountability for the individual call the system informs. A required handoff connects the two, and it specifies what crosses from the institution that authorized the system to the person who acts on its output. The framework does not change by sector. Only the room does.
This brief is the definitional statement of that framework. The papers published alongside it assume the reader already understands the gap from context, which held while clinical AI was the only room in use. It is no longer the only room. Financial AI is live, and two separate practices now reference the same underlying structure. This is the page each of them points to. The Handoff That Isn’t, Named Owner, and the applied clinical instruments all sit underneath the framework stated here.
A framework earns the right to be called canonical by being stated once, plainly, in terms that do not depend on the room it started in. That is the work of this brief. It does not argue for the framework, which the papers beneath it already do in their own settings. It states what the framework is, so that any paper, any deployment, and any reader in any regulated sector has a single definition to point to.
The problem TAG™ names
Every regulated institution running AI faces the same structural failure. An AI system produces an output. A person acts on it. Between those two moments, in most institutions, no one is named as owning the resulting decision. The output carries the authority of the system that produced it and the reasoning of the person who acted, and the record rarely shows who was accountable for the two together.
This is not a technology problem. The model can be accurate, validated, and monitored, and the gap remains open, because the gap is a question of accountability rather than performance. It is also not a documentation problem that a better template solves. It is structural. When the system shapes a decision and no one is named on both sides of it, the institution cannot answer the one question every regulator, board, and court eventually asks, which is who owned this.
The clinical version and the financial version of this failure are the same failure wearing different clothes. In a health system, an AI system recommends and a clinician acts, and the chart records the clinician alone, with nothing about the system that shaped the recommendation or the authority that approved it. In a financial institution, an automated system triages an alert and a compliance officer is presumed to have reviewed it, and the record often cannot show whether a person looked at all. The room differs. The gap does not.
The gap is quiet until it is expensive. A deployment that looks complete on paper produces output after output with no owner named on both sides, and nothing announces the omission. It surfaces at the worst possible moment, when an outcome is questioned and the institution reaches for a record that was never built to answer.
Institutions do not catch the gap on their own, and the reason is structural rather than careless. Governance for AI is usually built at the enterprise level, where it governs how models are selected, validated, and monitored. That governance is real and necessary, and it stops one step short of the decision. It governs the system as an asset. It does not name who owns the moment the system’s output becomes an institutional act. The layer where that naming has to happen is the one most institutions have not built, and its absence produces no error at the time, only a hole in the record that opens later.
The cost of the open gap is not hypothetical. The parties whose business is pricing risk have begun to act on the exposure an unowned AI decision creates, and the institutions holding those decisions increasingly find the question of ownership arriving from outside, from an underwriter, an examiner, or a court, before they have asked it of themselves. An unowned decision is an exposure the institution has not measured and cannot yet defend.
The gap also resists the instinct to solve it by naming a single accountable person. The institutional decision to deploy and the individual decision to act are different decisions, made by different people, at different times, against different information. One person cannot answer both. An executive cannot speak to the specific call made at the far end of the workflow, and the person who made that call did not approve the system or set its boundaries. The gap has two sides because the decision has two owners, and any attempt to collapse them into one recreates the failure under a single name.
The two seats
The framework places accountability in two named seats. Each seat holds three functions, and the functions are what make a seat real. A name on an org chart with none of the functions behind it is a label, not an owner. The two seats sit at different levels of the institution and answer different questions, which is why neither can stand in for the other.
The Governance Owner
The Governance Owner carries institutional accountability for the system entering use. This is the executive who put the institution’s authority behind the deployment, and who answers to the board, to counsel, and to the regulator when the deployment is questioned. The seat holds three functions.
Charter. Names what the AI system is authorized to do, and what it is not. The charter is the boundary. It states the decisions the system may shape and the ones it may not touch.
Commission. Approves the system for deployment inside a specific institutional context. A charter in the abstract is not a commission. The commission places the system into a named workflow, for a named population, under named conditions.
Cover. Holds institutional accountability for the system operating as chartered. When the deployment is challenged, cover is the function that answers for it on the institution’s behalf, rather than letting the challenge fall onto the person who acted at the far end.
The Decision Owner
The Decision Owner carries accountability for the individual decision the system informs. This is the person at the point of action, whose name already lands on the record when the call is made. The role is not new. It is the existing structure of professional accountability, now carrying a call that a system the person did not build has shaped. The seat holds three functions.
Decide. Makes the call the AI system cannot make on its own. The system produces an output. The Decision Owner acts on it, overrides it, or sets it aside, and owns that choice.
Document. Records the decision and the reasoning in a form that survives audit. Not the action alone, but what the system offered, what the person did with it, and why.
Defend. Stands behind the decision when it is reviewed, challenged, or investigated. The Decision Owner is the person who answers for the specific call, with the institutional charter and cover standing behind them rather than absent.
Between the two seats runs the audit trail, the record that carries both names from the decision to deploy through to the decision to act. A complete trail shows the charter, the commission, the output, the call, and the reasoning behind it. An incomplete trail shows the person who acted and nothing about the system that shaped the call or the authority that approved it. The trail is where the framework is either visible or absent, and it is the first thing a reviewer reaches for.
One seat is not enough
Naming only one seat does not close the gap. A Governance Owner without a named Decision Owner has authorized a system that no one is accountable for using. The institution has approved a tool and left every decision it shapes unowned. A Decision Owner without a named Governance Owner is personally exposed for a system they did not charter, cannot fully inspect, and were never positioned to approve. Full accountability lands on the person with the least control over the system that produced the output.
Both seats must be named for the framework to function. The gap closes across the two seats or it does not close at all. This is the failure the framework exists to prevent, and it is the most common one in practice, because filling one seat and leaving the other implicit feels like accountability until the moment it is tested.
The six functions are also the test of whether a seat is genuinely filled. An institution can point to a name in each seat and still hold an open gap if the functions behind the names are not actually held. A Governance Owner who signed an approval but set no charter has named a boundary that does not exist. A Decision Owner who acts but does not document has made a call the record cannot reconstruct. The framework asks for the functions, not the titles, because the functions are what an audit can see.
The Handoff
Naming both seats is necessary and still not sufficient. What activates the framework is the handoff between them.
The Handoff is a mechanism, not a moment that passes on its own. It specifies what crosses from the Governance Owner’s charter into the Decision Owner’s hands, and what the Decision Owner is expected to send back into the institutional record. Without it, two seats can be named and the decision can still fall through the space between them, because nothing states what the institution authorized, what reached the person, and what the person returned.
A real handoff in any accountable profession transfers responsibility along with information. The sending side is named. The receiving side is named. What crossed is recorded, and the transfer is legible to anyone who reviews it later. An AI system, left ungoverned, transfers the information and drops the owner. The output arrives, the person acts, and no named sender travels with it. The handoff completes on one side only, which is the structural signature of the gap.
A defined handoff records three things at minimum. What the institution authorized, so the boundary the system operated within is legible. What reached the person, so the output they acted on is fixed rather than reconstructed after the fact. What the person returned, so the decision and its reasoning enter the institutional record rather than living only in one individual’s memory. When those three are present, a reviewer can trace the decision from the charter through the output to the call and back into the record without guessing.
Defined does not mean elaborate. A handoff can be a single documented step, provided it names the sending authority, the receiving person, and what crossed between them. The failure is not insufficient process. The failure is a transfer that names no one on the sending side, so that the output arrives carrying the weight of the institution and none of its accountability. Defining the handoff is the act of putting a name back on the side the AI system left empty.
TAG closes when all six functions are named and the handoff between the two seats is defined. There is no third category. The gap is not closed by adding a third role, standing up a committee, or publishing a general accountability statement. A committee cannot be deposed and cannot stand behind a specific decision, and a general statement names no one. Two seats, one handoff, six functions. That is the whole of the framework, and it is deliberately small, because a framework that must be rebuilt for every case is not a standard.
The handoff also has to stay current, because the seats do not hold still. Executives move and titles are restructured, so a Governance Owner named at approval may no longer hold the role. People at the point of action rotate, so a Decision Owner named once may not be the person on duty when the system next produces an output. A framework named at launch and never revisited describes an accountability that has quietly expired. Naming the seats is the first act. Keeping them current is the standing one.
Two rooms, one framework
The framework earns its claim by holding in more than one sector without modification. What follows are two live rooms, clinical AI and financial AI, walked through the same six functions in the same order.
The two rooms are not analogies for each other. They are two instances of one structure. The point of setting them side by side is not to argue that finance is like medicine, but to show that the framework does not bend to fit either. The same six words name the functions in both. The same handoff sits between the same two seats. What follows should read as one framework observed twice, not two frameworks compared.
Clinical AI, at the bedside
This is the point where a recommendation reaches a patient decision, the layer of governance that sits at the bedside rather than in the enterprise.
The Governance Owner is typically a Chief Medical Officer or a Chief Medical Information Officer. Charter names what the clinical AI system is authorized to recommend. Commission approves the system for a specific clinical workflow. Cover holds institutional accountability when the system is used as chartered.
The Decision Owner is the clinician at the point of care. Decide is the moment the clinician acts on or overrides the recommendation. Document is the record of that decision and its reasoning in the chart. Defend is the clinician standing behind the call when it is reviewed.
The Handoff is the moment the recommendation reaches the clinician, when something has to be named about what crossed and who now holds it. In most deployments nothing is named, and the chart later shows a clinician acting alone on a recommendation whose origin and approval have vanished.
Financial AI, at the alert queue
The Governance Owner is typically a Chief Risk Officer or a Chief Compliance Officer. Charter names what the automated triage or monitoring system is authorized to close, escalate, or flag. Commission approves the system for a specific deployment, such as transaction monitoring or alert triage. Cover holds institutional accountability when the system operates as chartered. The shape of this failure is already on the regulatory record. In the pattern behind recent enforcement, an institution let an automated system close alerts at thresholds that were never tuned to real transaction volume, and no one was named as accountable for what the system closed unseen. The full evidentiary treatment of that pattern belongs to the forthcoming FinVigilance™ working paper and is only referenced here.
The Decision Owner is the compliance or risk officer reviewing an escalated alert. Decide is the judgment on whether the alert warrants action. Document is the record of that judgment and its basis. Defend is the officer standing behind it under examination.
The Handoff is the moment an alert clears the automated system, when something has to be named about whether a person actually reviewed it or the system closed it unseen. Where the handoff is undefined, the institution cannot later distinguish an alert a person cleared from one the system closed on its own.
The comparison
Read the table down each column and the framework holds as a whole. Read it across each row and the same function appears in both rooms, phrased for the setting and identical in what it demands.
| Function | Clinical AI, the bedside | Financial AI, the alert queue |
|---|---|---|
| Charter | What the system may recommend | What the system may close, escalate, or flag |
| Commission | Approval for a specific clinical workflow | Approval for a monitoring or triage deployment |
| Cover | Institutional accountability for clinical use | Institutional accountability for the alert program |
| Decide | Clinician acts on or overrides the recommendation | Officer acts on the escalated alert |
| Document | The decision recorded in the chart | The judgment recorded in the case file |
| Defend | The clinician under clinical review | The officer under examination |
Same seats, same handoff, different room.
The mapping is one to one, and nothing in it is forced. The clinician and the compliance officer are doing structurally the same thing, acting on an output a system produced and owning the result. The Chief Medical Officer and the Chief Risk Officer are doing structurally the same thing, chartering a system and carrying the institution’s accountability for it. The evidence behind each room differs. The law behind each room differs. The framework between them does not.
Why the framework generalizes
The two rooms above use the same two seats and the same six functions with no structural change. That is the point. The framework does not need rebuilding for each sector it enters. The seats and the functions are abstract enough to hold anywhere a regulated institution runs an AI system that produces an output a person is expected to act on.
The two live rooms are clinical AI and financial AI. The portability of the framework beyond them is a structural property being described here, not a business claim being made. Where an AI system shapes a decision that a regulator, a board, or a court can later question, the same two seats and the same handoff apply. What changes from room to room is the title of the Governance Owner, the setting of the Decision Owner, and the point at which the handoff occurs. What does not change is that both seats must be named and the handoff must be defined.
The boundary of the framework is worth stating as plainly as its reach. TAG applies where an AI system shapes a decision and a person is expected to act on it inside an institution that can be called to account. Where no person is in the loop, there is no Decision Owner to name, and the framework does not describe that case. Where the decision carries no institutional accountability, there is no charter to write. Within those bounds, which cover the regulated sectors where the stakes make ownership matter, the two seats and the handoff hold.
The practical consequence is that an institution which adopts the framework in one room already holds what it needs in the next. The vocabulary is built to travel. A health system that has named its two seats at the bedside and a financial institution that has named its two seats at the alert queue are running the same framework, and each can read the other’s deployment without translation.
A framework that holds across rooms becomes a shared language. When a health system and a financial institution describe their AI accountability in the same terms, a regulator can read both against one standard, a board that oversees more than one kind of risk can ask one set of questions, and the field gains a vocabulary it did not have. That is the reason to state the framework at this level. A standard more than one sector can adopt without translation.
Framework glossary
The Accountability Gap™ (TAG™). The framework that names who owns a decision when an AI system shapes it, defined by two seats and a required handoff between them.
Governance Owner. The institutional seat accountable for authorizing an AI system into use, holding Charter, Commission, and Cover.
Decision Owner. The seat accountable for the individual decision the system informs, holding Decide, Document, and Defend.
The Handoff. The mechanism that specifies what crosses from the Governance Owner to the Decision Owner and what returns to the institutional record.
Charter, Commission, Cover. The three functions of the Governance Owner: what the system is authorized to do, approval into a specific context, and institutional accountability for its chartered operation.
Decide, Document, Defend. The three functions of the Decision Owner: making the call the system cannot make alone, recording it in a form that survives audit, and standing behind it under review.
The named owner. The general term for a person carrying accountability in the audit trail, in either seat, used across the wider body of this work.
Frequently asked questions
- What is the difference between TAG and a general AI governance policy?
- A general AI governance policy sets rules for how AI is selected, validated, and monitored across an institution. The Accountability Gap™ names who is accountable for a specific decision the AI shapes. A policy can be complete and the gap can still be open, because a policy governs the system while TAG governs the decision. TAG names two seats and the handoff between them for each deployment, which a general policy does not reach.
- Does TAG apply outside clinical and financial AI?
- The two live rooms are clinical AI and financial AI. The two seats and six functions are abstract enough to hold in any regulated sector where an AI system produces an output and a person acts on it. That portability is a structural property of the framework, not a claim that other sectors are active or planned.
- What happens if only one seat is named?
- The gap stays open. A Governance Owner with no named Decision Owner has authorized a system that no one is accountable for using. A Decision Owner with no named Governance Owner is personally exposed for a system they did not charter. The framework closes across both seats or not at all.
- Who should hold the Governance Owner seat at our institution?
- The person with the authority to charter the system and the standing to answer for it. In health systems that is typically a Chief Medical Officer or Chief Medical Information Officer. In financial institutions it is typically a Chief Risk Officer or Chief Compliance Officer. The title matters less than the authority to approve the deployment and the accountability for it operating as chartered.
- Is TAG a compliance requirement or a voluntary framework?
- TAG is a framework, not a statute. It describes the accountability structure that regulators, boards, and courts already expect an institution to be able to show. Adopting it is voluntary. Being asked who owned a decision is not. The institution that has named both seats and defined the handoff can answer that question. The institution that has not cannot.
- How does TAG relate to the Clinical AI Accountability Canvas™ and Mind the 9 Blocks™?
- TAG is the parent framework. Mind the 9 Blocks™ and the Clinical AI Accountability Canvas™ are the applied clinical instruments that operationalize it inside a health system, arranging the accountability requirements into nine blocks and scoring readiness with the Gap Score™. TAG defines the two seats and the handoff. Those instruments put them to work at the bedside.
- How does TAG relate to a FinVigilance™ deployment?
- FinVigilance™ is the financial application of the same framework. A FinVigilance™ deployment names the Governance Owner and the Decision Owner for an automated monitoring or triage program and defines the handoff at the alert queue. The seats and functions are identical to the clinical case. The room is the financial institution rather than the health system.
Funding
None declared.
Conflicts of interest
Mo Johnson, MD MBA is the founder of GPe Research. The Accountability Gap™ (TAG™), the Clinical AI Accountability Canvas™, Mind the 9 Blocks™, the Gap Score™, the Named Owner Principle, MedicoVigilance™, and FinVigilance™ are works and marks of GPe Research. The author has a commercial interest in the adoption of the frameworks described in this brief.
How to cite
@techreport{johnson2026accountabilitygap,
author = {Johnson, Mo},
title = {The Accountability Gap: Two Seats, One Handoff, Any Regulated Sector},
institution = {GPe Research Publications},
type = {Framework Brief},
number = {№02},
year = {2026},
month = {7},
url = {https://publications.gperesearch.com/papers/the-accountability-gap}
}
Version history
Version 2 — September 8, 2026
The NOHARM benchmark was published in December 2025, not January 2026 as this paper stated, and was developed by a multi-institutional study team led from Stanford University and Harvard Medical School rather than by the ARISE Network. The severe-harm figure of up to 22.2% is drawn from the December 2025 version, now superseded, and the citation is to that version specifically. That paper also evaluated a hypothetical no-intervention comparator carrying potential for severe harm in 37% of cases, higher than any model tested, which this paper did not report. The MedAgentBench task success rate of approximately 70% is the score of the best-performing model of eleven evaluated, in a range beginning at 4.0%.
Version 1 — July 26, 2026
Original publication.