This isn’t a joke. It’s how many AI deployment decisions actually happen in enterprises, and it ends the same way: with nobody being entirely clear about who made the call.
The CFO’s concern is straightforward: if this fails, how much does it cost us? They want to understand the financial consequences. They’re thinking about downside risk, capital allocation, shareholder communication if something goes wrong.
The VP of AI is thinking about capability and execution. Can we actually build this? Will it work? What will we learn? They’re thinking about staying competitive, building the team’s skills, proving value. They want to move.
The Compliance Officer is thinking about exposure. What if a regulator asks about this? What if a customer complains? Can we defend this decision? They’re thinking about policies, documentation, the audit trail. They want to be careful.
These aren’t contradictory perspectives. But they’re different perspectives, and they weight risks differently. The CFO is most concerned about economic risk. The VP is most concerned about execution risk. The Compliance Officer is most concerned about regulatory risk. When you put them in a room to decide whether to deploy an AI system, someone has to make the call. And often, nobody actually does.
What usually happens instead is consensus seeking that masks disagreement. You leave the meeting with implicit agreement that “we’re moving forward,” but the CFO is thinking “we’re moving forward if the economic model works out,” the VP is thinking “we’re moving forward and we’ll figure out the details,” and the Compliance Officer is thinking “we’re moving forward and we’ll handle the risks.” These statements sound like agreement. They’re not. They’re three different decisions that will conflict the moment execution requires actual tradeoffs.
Then something happens—the model drifts, a customer complains, a regulator asks a question—and suddenly it’s clear that you never actually resolved the disagreement. You just deferred it.
The Three Types of Risk These People Actually Represent
To understand why this happens, start with what each person is actually accountable for.
The CFO is accountable for financial performance. If the AI system costs more than it saves, they answer to the board. If it creates unexpected costs, they’re explaining variance to investors. Economic risk is their domain.
The VP of AI is accountable for delivering on the AI roadmap. Building capabilities, shipping systems, enabling the business. Execution risk is their domain. They’re being evaluated on delivery and impact, not on managing risk.
The Compliance Officer is accountable for regulatory compliance and risk management. If something goes wrong and there’s no documented governance, they’re explaining to auditors and regulators. Governance and procedural risk is their domain.
These aren’t competing priorities. They’re different dimensions of risk. The problem is that your governance structure probably treats them as competing. It probably puts them in the same meeting, assumes they’ll reach consensus, and then acts surprised when they don’t.
The real issue is that nobody is explicitly accountable for integrating these perspectives and making the actual decision. The CFO can’t decide alone because they don’t understand execution risk. The VP can’t decide alone because they’re not responsible for financial outcomes. The Compliance Officer can’t decide alone because they’re not responsible for business outcomes. So you have three people none of whom is empowered to make the call.
This is a different governance problem than the ones in previous pieces. In Days 1-2, I was focused on the structural problem: nobody owns the decision. Here we’re looking at the substantive problem: when you have multiple valid perspectives and they don’t align, how do you actually decide?
What Happens When You Pretend Consensus Exists
Most organizations try to solve this through consensus. The theory is: if everyone agrees it’s a good decision, it’s a good decision. If people disagree, talk until they agree.
This works for some decisions. It doesn’t work for decisions where people have legitimately different risk appetites.
Say the AI system will cost $500K to build and maintain, and it will save $1.5M annually if it performs as modeled. The CFO looks at this and says: “If performance is as modeled, great. If it underperforms by 20%, we still have positive ROI, so I can support this.” That’s a CFO’s way of agreeing.
The VP of AI looks at the same numbers and says: “I can build this, and I believe the model will work well.” That’s a VP’s way of committing to execution.
The Compliance Officer looks at the same numbers and says: “I need to see the governance around this, but the financial case looks sound.” That’s a Compliance Officer’s way of saying they’ll proceed carefully.
All three have “agreed.” But the CFO agreed subject to financial performance. The VP agreed subject to being able to execute. The Compliance Officer agreed subject to governance being in place. If any of those conditions isn’t met, the agreement falls apart. But nobody documented the conditions. So everyone walks out of the meeting thinking they’ve committed to moving forward, when what they’ve actually committed to is moving forward if certain things happen.
Then execution reveals that governance isn’t as clear as the Compliance Officer wanted, or execution is harder than the VP expected, or the financial model is too optimistic. Now you have a decision you thought was made, coming apart under the stress of reality.
The Actual Decision-Making Process That Works
The organizations I’ve seen navigate this successfully have a structure that acknowledges this complexity rather than hiding from it.
They explicitly assign decision authority to one person. Often this is a business leader—a VP of Product, a business unit leader, a Chief Operating Officer. Someone who’s accountable for outcomes, not just for process. That person is explicitly accountable for the deployment decision.
They structure the input so that person gets clear perspective from all angles. Not consensus—perspective. The CFO provides financial analysis and financial risk tolerance. “Here’s what happens if the model underperforms by 10%, 20%, 30%. Here’s the financial exposure.” The VP of AI provides execution assessment. “Here’s our confidence in our ability to build this. Here’s what could go wrong technically. Here’s how we’d mitigate it.” The Compliance Officer provides governance and regulatory assessment. “Here’s what we need to document. Here’s what regulators might ask. Here’s what we can defend.”
The decision-maker’s job is to integrate these inputs, understand the tradeoffs, and make a call. Not “do we all agree?” but “given what we know, should we move forward?”
They document the decision explicitly. Not “we decided to deploy,” but “we decided to deploy this system, accepting these financial risks, with this mitigation plan, having documented this governance, knowing that these scenarios could happen and here’s how we’ll handle them.” That decision document becomes the reference point when things change. If something goes wrong, you can point to what you understood and accepted at the time.
They assign someone to own ongoing accountability. Usually the same person who made the deployment decision. That person is accountable not just for the decision being made, but for it being monitored and for adjustments when things change. They’re the person who can actually pull the system if something goes wrong.
The Specific Governance Moments Where This Breaks
In my experience, this breaks down in specific places:
The decision meeting that doesn’t resolve anything. You’re in a room. Three perspectives. No explicit decision authority. You talk until everyone is tired, and then you say “okay, sounds like we’re aligned on moving forward.” You’re not aligned. You’re just tired. Write down what you’ve agreed to. Document the conditions and assumptions. Have the decision-maker say explicitly: “Here’s what I’m deciding, and here’s what I’m accepting by making that decision.”
The governance framework that exists but doesn’t actually gate anything. You have a checklist. Model validation: check. Fairness assessment: check. Compliance review: check. And now you’re automatically approved to deploy. This is governance theater. Someone has to actually make a decision based on the checklist. Not “has the checklist been completed,” but “given what the checklist shows, should we deploy?” If the answer is always “yes,” you don’t have governance. You have a process.
The risk discussion that’s all upside and no downside. You’re talking about how much value this will create. Nobody’s talking about what happens if it doesn’t. The CFO should be laying out financial downside. The VP should be laying out execution risk. The Compliance Officer should be laying out governance and regulatory risk. If everyone is only talking about upside, you haven’t actually thought about risk. You’ve just decided you like the idea.
The monitoring plan that nobody actually monitors. You’re going to “track accuracy” and “monitor for bias” and you’ve assigned it to a team. That team has other priorities. Months later, nobody’s looking at the metrics. And the first time something goes wrong is the first time anyone actually paid attention. Assign actual, prioritized monitoring to someone. Not “the data science team will keep an eye on it,” but “person X is responsible for checking this metric weekly, and person Y is responsible for deciding what to do if the metric moves.”
The escalation that doesn’t actually escalate. Something unexpected happens with the model. The monitoring team sees it. They send an email. It gets lost. Or it goes to a stakeholder who doesn’t have the authority to make decisions. Or it gets escalated to a committee that meets quarterly. By then it’s late. Build an escalation path where an observation actually reaches someone with authority to act, and with enough urgency to matter.
How This Looks in Practice
Here’s a real-world example of what I mean (composite, not a specific case):
You’re deploying an AI system for credit decisions. The CFO looks at the model and says: “If this achieves 85% approval rate with a default rate of 4%, I can fund this. If default rate goes above 5%, we need to recalibrate or stop.” That’s the financial decision rule.
The VP of Risk (who owns credit) says: “I can defend these decisions if I can explain them. If we’re using a black-box model and regulators ask why we denied someone credit, I need an explanation. I need model documentation and decision-level traceability.” That’s the governance decision rule.
The Compliance Officer says: “Fair Lending is a regulatory focus. We need to demonstrate that our approval rate is not substantially different across demographic groups, or if it is different, we need to explain why based on credit risk factors, not demographic factors.” That’s the regulatory decision rule.
The decision-maker’s job is to say: “We’re deploying this system. The target is 85% approval with 4% default. We’re committing to documenting decisions and having explainability. We’re targeting demographic parity adjusted for credit risk. If either of the first two gets violated, we recalibrate. If the third gets violated, we stop. Person A monitors the approval rate and default rate weekly; person B monitors the decision documentation and explainability; person C monitors the demographic parity. If any metric moves outside acceptable range, person A/B/C escalates to me for decision.”
That’s a decision. Not a consensus that hides disagreement. A decision that integrates different perspectives and lays out what happens next.
The Board Question
When the board asks “why did you deploy that AI system?” the answer should be specific:
“We evaluated the deployment against financial risk, execution risk, and governance risk. The financial model showed positive ROI with acceptable downside. We had sufficient technical capability to execute. We had governance and regulatory framework in place to defend the decision. We assigned clear ownership and escalation. We made the decision deliberately, documenting what we understood and accepted.”
That’s what a governance decision sounds like. Not “everyone agreed,” not “the model was validated,” not “it was on the roadmap.” But “we thought through the decision, we integrated perspectives from across the organization, and we were willing to own the consequences.”
When you have that clarity—about who decides, what they’re deciding, what they’re accepting, what happens if things change—the CFO, the VP, and the Compliance Officer stop needing to reach consensus on something they never fully agreed about in the first place. They each provide clear perspective on their domain, someone integrated that perspective into a decision, and they all know what was decided and why.
That’s how you actually handle multi-stakeholder AI deployment decisions. Not perfectly. But deliberately.