What an auditor, or Sekit's evidence engine, asks for.
AI responsibility allocation with partners and customers
The written agreements that split AI responsibilities where the company works with providers, partners or customers: who decides what, who handles incidents, who controls changes, and what each customer is promised about the AI-powered product.
From the Sekit evidence catalog
In practice
In a small company buying a vendor chatbot or copilot, this control means writing down, before you sign, who owns what: the vendor patches the model and the platform, you own how staff use it and what data goes in, and someone specific calls the vendor when the tool misbehaves. An auditor asks for the AI responsibility allocation record and checks it names an incident contact, a change-notification commitment, and what the company tells its own customers about the AI-powered feature. The common failure is a verbal agreement nobody wrote down, so the first incident becomes a finger-pointing exercise instead of a five-minute lookup.
Common gaps
A team adopts an AI copilot through a vendor's free trial and nobody documents who is responsible when it gives a customer a wrong answer.
The responsibility record lists the vendor's obligations but never states what the company itself owns, so incident response stalls on the first call.
Responsibility splits are agreed verbally with an account manager and never written into the contract or a document an auditor can read.
Questions your auditor will ask
Who is responsible for an AI vendor's outage or bad output that reaches a customer?
The AI responsibility allocation record names an internal incident owner and the vendor's contractual incident contact for each AI-powered feature.
How do you decide which AI security duties are yours versus the provider's?
The record splits duties by feature, following the same shared responsibility logic used for cloud providers, so nothing defaults to being assumed handled.
What do customers get told about AI-powered parts of your product?
The responsibility agreement records the specific promise made to customers about the AI feature, including who they contact if it fails.
Who controls changes when the AI vendor updates or retires a model version?
The written agreement assigns change-control rights and requires the vendor to notify the company before a version change reaches production.
Where regulation demands it
NIS2 art. 5.1 (Supply chain security policy) expects a documented policy, and GDPR Article 32.1.b ties confidentiality and resilience duties to whoever controls the AI system.