Skip to content
iclock 7 Minutes - Read Now
idate

What a Room Full of AI Practitioners Revealed About Accountability

Ethisphere’s recent webinar with EY, Compliance in a World of AI: Using AI in Practice While Managing Risks, set out […]

Bill Coffin
Bill Coffin Editor-in-Chief, Ethisphere Magazine, Ethisphere
What a Room Full of AI Practitioners Revealed About Accountability

Ethisphere’s recent webinar with EY, Compliance in a World of AI: Using AI in Practice While Managing Risks, set out to cover a lot of ground on efficiency: where AI saves time, where it catches what a tired human eye would miss, where a three-person compliance team gets to operate like a team of six. Ebony Yeboah-Amankwah of Signet Jewelers, Susie Wagner of Kohler, and Sue Maiolli of EY delivered plenty of that. But the part of the conversation that stood out most had less to do with what AI can do than with who has to answer for it when something goes wrong, and how little that question has to do with the technology itself.

The Efficiency Case Is Already Closed

Nobody on the panel needed convincing that AI works. Ebony pulls code of conduct results, training completion, and HR data into a single view and lets AI draft the first pass, then checks whether the combined picture actually holds up. Susie’s team feeds 65 to more than 100 investigation documents into AI and gets a timeline back, including a detail buried in one document that AI surfaced and Susie later confirmed by going back and reading it herself. Sue, who watches this play out across many of client organizations rather than just one, has seen enough successful builds to know the shape of a good one: name the actual bottleneck, design around it, pilot small, then scale.

That part of the conversation moved fast, because there wasn’t much left to argue. AI’s usefulness in compliance work is no longer really in question. The harder question, one the panel spent most of its remaining time circling without ever quite naming outright, is where responsibility sits once the tool is doing real work inside a compliance program.

For the full conversation, including the audience questions this piece doesn’t have room for, watch the on-demand replay.

Structure Isn’t the Same Thing as Accountability

Signet and Kohler have both built something to govern AI. Ebony described how AI went from a subset of some other risk conversation to its own line on Signet’s audit committee agenda, with a dedicated council and an intake form that asks business units to name the risks before compliance ever sees the request. Susie described Kohler folding AI into the same enterprise risk framework it uses for everything else, with ownership split deliberately across the business, technology, and compliance so no single function can either bottleneck it or wave it through unchecked.

But structure answers a different question than accountability does. A council can review a use case and approve it. A framework can assign a business unit as the owner of a given risk. Neither one determines what happens the day an employee sits down at their desk, opens an AI tool, and has to decide in that exact moment whether to paste in something they probably shouldn’t. That decision doesn’t happen in a council meeting, and no framework makes it on an employee’s behalf.

Accountability Lives at the Point of Use

Susie’s team has shifted its focus here, and it’s the most useful idea to come out of the entire hour. Most AI risk at Kohler, in her experience, doesn’t trace back to a missing policy. It traces back to a moment: an employee decides what to upload, or how much to trust an AI-drafted analysis, without a policy document anywhere in sight. So her team stopped grading training on completion rates and started asking a different question. Are policy violations actually going down? Are employees escalating legitimate concerns more often? Can a manager describe a specific time someone caught an AI output that was wrong? That’s a much harder thing to measure than a completion percentage, and it’s also the only measurement that means anything.

Ebony’s version of the same instinct is a test worth sitting with. If the honest answer to “where did this come from” is “ChatGPT,” that citation doesn’t hold up, and most people would be a little embarrassed to say it out loud. A human still has to be able to defend the work, and that’s closer to a professional instinct than a policy requirement, one every compliance program depends on whether or not it’s written down anywhere.

Sue connected this back to something organizations still haven’t built well: employee monitoring that is designed specifically for AI, rather than borrowed from everything else. Her point was that most monitoring today looks at what AI produces (a report, a summary, a flagged item) and very little of it looks at the AI itself. Is there even an inventory of every AI tool being used across the business? Nothing gets governed if nobody knows it exists in the first place, and that gap is still wide open at most organizations, not just the ones on this panel.

The Lines People Draw on Purpose

The most convincing panelists weren’t the ones with the most AI use cases. They were the ones who could say, without hesitating, what they’d decided not to do. Signet uses AI heavily for internal efficiency, and Ebony was just as clear about where it stops: no AI in hiring, firing, promotion, or performance decisions, and none touching customer data. The technology could almost certainly handle it. Signet decided, on purpose, that certain decisions still need to run through a person who can be held accountable for them.

Kohler draws its lines differently, shaped by the fact that it operates in more than 30 countries: data privacy exposure, bias in employment-adjacent decisions, and intellectual property tied to Kohler’s own product designs. Susie’s team ranks information itself, from public to highly sensitive, so an employee has an actual answer to “can I put this into AI” instead of a policy they have to interpret under pressure. Both approaches work for the same reason. The line isn’t an accident of what the tool happens to be good at, someone decided where it goes and can explain why.

That same instinct showed up when the panel talked about disclosure, and all three of them arrived at nearly the same test using different language. Ebony draws the line at how much AI actually contributed to a given piece of work. Sue ties it to whether an approved tool was used the way it was meant to be used, a distinction that carries real weight in EY’s client engagements. Susie’s version was the simplest: would a customer reasonably want to know AI played a role here? If the answer is yes, disclose it. If AI just tightened up something a person had already written, none of them thought disclosure was necessary. Three different people, three different organizations, one shared judgment call about where honesty actually matters.

The Same Question Will Keep Showing Up in New Places

Sue spent part of the hour walking through where AI misuse is already showing up: deepfake audio used to fake an executive’s authorization on a wire transfer, AI-generated damage claims in retail and insurance, forged expense receipts, synthetic identities built from real social data. None of that is theoretical. It’s happening now, and it’s a preview of what third-party risk management will have to catch up to next. Sue and Susie both talked about using AI to move third-party monitoring from a point-in-time review to something closer to continuous, whether that’s tracking payments tied to a high-risk vendor or tracing a vague screening hit back to its actual source before deciding whether it means anything.

None of that changes the underlying question, however. Wherever AI shows up next inside a compliance program, the question worth asking is who stands behind the answer when someone asks why.

That’s what makes this moment in the field encouraging. The organizations getting this right aren’t necessarily the ones with the most sophisticated technology, they’re the ones that never stopped asking who’s accountable and built everything else around getting that answer right.

The full hour covered more ground than this piece can capture, including audience questions on training for early-career employees and how AI is starting to show up in third-party due diligence. Watch the entire conversation with Ebony, Sue, and Susie on demand.