Assign ownership after handover

An automation keeps running long after the engagement that produced it has closed. Suppliers change invoice formats, staff move on, platforms update their interfaces. Governance is the plain question of who notices, who decides and who fixes things when that happens, answered in writing before the consultant leaves rather than after the first failure.

Handover transfers responsibility

Handover is often treated as a meeting. It is better treated as a transfer: from the moment of sign-off, a named person inside the firm answers for the automation's behaviour. That person need not be technical, but they should know what the automation does, how to tell whether it is working and whom to call when it is not. If support continues under a separate agreement, that agreement should say what it covers and what remains with the firm.

Contents of a handover pack

Deliverable

Run book

Daily and weekly checks, how to pause and restart, and what to do with items in the review queue.

Deliverable

Current diagram

The future-state BPMN map as built, not as first designed, stored with its source file.

Deliverable

Access register

Every account, credential and connection the automation uses, held in the firm's name.

Deliverable

Change log

A dated list of changes, starting with the accepted version and its sign-off record.

Rows of unlabelled ring binders on archive shelving in low, shadowed light
Illustrative image: records kept where the next owner can find them.

Review on a Plan-Do-Check-Act cycle

The PDCA cycle traces back to Walter Shewhart's work on quality control and was popularised by W. Edwards Deming, who later preferred the term Plan-Do-Study-Act. It suits automation reviews because it is short and repeatable:

  1. Plan: set the review date and the questions, such as error volumes, queue sizes and complaints.
  2. Do: gather the evidence from logs, the review queue and the people affected.
  3. Check: compare it with the acceptance criteria and the previous review.
  4. Act: record decisions — leave as is, adjust, retrain staff or retire the automation.

The review frequency is a business decision. A process touching payments or personal data usually warrants closer attention than an internal reminder.

Control changes without bureaucracy

ITIL, the IT service management framework, describes change enablement as balancing speed against risk. An SME can borrow the principle without the apparatus: classify changes as routine (a new supplier added to a lookup list) or significant (a new data source, a new decision rule), let the process owner approve routine changes, and send significant ones back through acceptance testing. Firms certified to ISO/IEC 27001 will already have change-management controls that an automation should sit within.

Frameworks worth knowing by name

NIST AI Risk Management Framework
Published by the US National Institute of Standards and Technology as AI RMF 1.0 in January 2023. Voluntary and usable outside the US; its Govern function covers roles, policies and accountability for AI systems.
NIST Cybersecurity Framework
A widely used structure for managing cyber risk; version 2.0 added Govern as a core function alongside Identify, Protect, Detect, Respond and Recover.
ICO guidance on AI and data protection
The UK regulator's guidance on fairness, transparency, accountability and individual rights where AI processes personal data.
ISO/IEC 42001
An international standard for AI management systems, aimed at organisations that want a certifiable structure for governing AI.
Cyber Essentials
The UK government-backed baseline security scheme associated with the National Cyber Security Centre.

None of these is mandatory for every SME; they are reference points for deciding how much structure a given automation needs. This is general information rather than compliance advice.

Plan for the owner leaving

Every named owner should have a named deputy who has run the daily checks at least once. When ownership changes, the handover pack, change log and open review actions move with it, and the RACI is updated. If nobody can be found to take ownership, that is itself a finding for the next PDCA review: an automation without an owner is a candidate for retirement.