Accountability answers the question no organisation can dodge: who answers for this outcome. It exists because oversight is impossible when results belong to everyone in general and no one in particular. The rule that makes the concept work is strict: accountability sits with one named person and cannot be delegated, even when all the work is. For a board, mapping accountabilities is the fastest way to find out whether the organisation is governable.
Accountability is fixed in charters, delegations of authority, policies and RACI matrices, where the A is assigned to exactly one role per outcome. It survives reorganisations only if someone maintains these documents. Example: for recovery of the payments service, the COO is accountable; IT restores the systems and vendors support them, but when the board asks why recovery took nine hours instead of two, one person answers. Gulf regulators increasingly expect critical services to carry this kind of named executive accountability.
The classic confusion is with responsibility: many people can be responsible for doing the work, only one can be accountable for the result. Shared accountability is the polite name for no accountability, and committees are where it usually hides. When a RACI shows two As on one line, the matrix is documenting a future dispute. The distinction is developed in ERGP module M1, Resilience governance and the board.
Accountability becomes real through three mechanical steps. First, single-point assignment: every outcome that matters — a service, a risk, a plan — carries exactly one name, recorded where charters and delegations live, not in someone's memory. Second, matching authority: a person accountable for an outcome without the budget, information and decision rights to influence it has been assigned blame, not accountability. Third, a consequence loop: the accountable person reports on the outcome at a set rhythm, and the report has consequences — questions, decisions, resources. Remove any one of the three and the word returns to being decorative.
In resilience programmes the accountability map is short and must be explicit: an executive owner for the continuity programme as a whole, a named owner for each critical service and its recovery objectives, a risk owner for each entry in the risk register, and a crisis leader with pre-agreed authority to declare and to spend. The chain is tested in exercises — an exercise that never asks «who had the authority to decide this?» has not tested governance, only logistics. How the assignment is verified is the province of the three lines model, and how it reaches the board is described in reporting.
This term is part of the working language of ERGP — the first resilience governance certification fully available in Arabic, also in English. 94 chapters, six modules, a verifiable certificate.
Explore the ERGP programme