Jay Hawkinson is a board-certified (NACD.DC) data and digital leader turning data into margin through AI, analytics and strategy.
I’ve sat through a lot of PE diligence conversations over the years, and lately, I’ve noticed a pattern: Buyers are asking about AI systems as part of quality-of-earnings and operational review. Who is responsible for that system? What happens if it makes a wrong call?
The problem is that many organizations can’t answer those questions. The company being acquired often uses AI to do things like set prices, forecast revenue or control product quality. These are systems that sit inside the numbers. But no one ever formally documented who owns the system or how decisions it makes get reviewed.
To a buyer, an undocumented authority is a liability. If something goes wrong after the acquisition, they’ve inherited a system with no accountable owner and no audit trail. So they either discount the purchase price or flag it as a risk. That’s why organizations need to have a clear understanding of what’s going on and how to avoid it.
Why This Is Happening Now
Ongoing regulatory developments and lawsuits are driving the shift in expectations. The EU AI Act, Fannie Mae lender letters and a growing body of state-level laws all place the documentation and ownership burden on the company running the system, not the company that built it. Look at what happened with UnitedHealthcare: An AI system was making decisions about which claims should and shouldn’t be approved, leading to the critical question of whether people had any authority to override them.
PE firms are getting smarter about all of this because they’re the ones taking on the liability. They don’t want to buy a company whose entire forecast is built on an AI projection that nobody truly understands. Once a system influences pricing, forecasting or batch disposition, it falls under the quality-of-earnings review.
The Named Owner Framework
The most important step a company can take is designating a named owner for every consequential AI system. In many companies, ownership is distributed across three roles: a model owner in data or IT, a process owner in the business and a budget owner above both. Each owns a piece, and none of them can stop the system alone. We designed it that way deliberately, to avoid a blame culture, but the result is a consensus structure that’s too slow for what AI requires.
A named owner has to meet four criteria. First, the person can stop the system without asking anyone for permission. Second, their name appears in a document others can reference, so anyone who notices a problem knows exactly who to go to.
Third, they have to actually know they are the owner. I’ve seen cases where a CIO was assigned as owner and didn’t find out until it came up in a meeting. Last, the authority must be operational, not just a title. This means someone has to be willing to stand up and say, “That’s my number, and I’m responsible for it.”
Pre-Diligence Priorities
Once an owner is named, there are a few more things CEOs should focus on, depending on how much time is available. First, inventory every AI or model-driven system that touches a number in the model. Even an incomplete list is better than no list. If a buyer finds a system that isn’t on your inventory, that’s a serious problem.
Next, build in an override process. If an AI system isn’t producing the right results, someone needs to be able to stop it and have a plan. Write down the override process that already exists informally, ideally one page per system, describing what people actually do, in the real world. This is no different from disaster recovery in IT: If your ERP goes down, you don’t want production to stop. The same thinking has to apply to AI.
Pull together whatever kind of evidence trail you can. PE firms want to see that the operating team knows what they have and is managing it. A CFO who can walk into a room and demonstrate familiarity with their systems, their owners and their processes is in a far stronger position than one who can’t.
Don’t try to build a full evidence trail retroactively from scratch, and don’t seek board approval on a policy that never existed or was just drafted the week before. Both of these are clearly evident on close inspection.
Your AI will make a bad decision at some point. The question is whether you can do anything about it. With many companies I see coming into these conversations, the honest answer is “no,” and that’s not good enough. The regulatory environment isn’t going away. The good news is that doing the governance work right is the perfect foundation for everything else you’re trying to accomplish.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

