There is a question that produces the same silence in serious organisations across different sectors and countries. The question is this · who is leading this implementation. The first answers come quickly and always in the same order. The IT department. The external consultant. The compliance team.
I ask again · the board? The person who signs when something goes wrong? That is when the silence comes. Sometimes, a nervous smile. Sometimes, the honest phrase · I don't know. That silence is the subject of this criterion.
The political clause
Management system standards place leadership before operations. The order matters · management defines purpose, integrates the system into the business and provides resources; the team executes within that decision.
ISO 9001:2015 and ISO/IEC 42001:2023 require top management to demonstrate leadership and commitment to the system. Evidence is sought in verifiable decisions · objectives consistent with the organisation's direction, requirements integrated into processes, allocated resources, monitoring of results and support for the responsible functions. This list is an operational interpretation; for a conformity assessment, the text of the applicable standard governs.
Appointing someone with operational responsibility is necessary. Using that appointment to remove management from decisions on scope, resources and risk is another matter.
The two hands · and the boundary with Criterion 06
In every organisation with real responsibilities, there are two hands. The hand that operates — the technical team that executes, records, adjusts. And the hand that signs — the person who, when an incident occurs, is identified as responsible. Contemporary institutional culture has spent years trying to separate them · let the technical hand operate, let the signing hand delegate. The result of that separation already has a name in this series (Criterion 06) · institutional opacity with the appearance of governance.
The two criteria look at the same signature from opposite sides. Criterion 06 is forensic · it traces back to the actor behind a decision already made. This criterion is political · it demands, looking ahead, that power be exercised before the decision is needed. Traceability reconstructs. Leadership prevents.
Four patterns of delegating compliance
Audit practice encounters the delegation of leadership in four recurring forms. The phantom committee · it appears on the organisation chart, its minutes are five lines long and its decisions shift no budget. The non-existent sponsor · the system has a nominal sponsor who has never attended a review. Resources without a budget · the policy promises what the budget allocation does not recognise. Delegated communication · the importance of the system is communicated by the technical team; in other words, the technical team talks to itself. When top management delegates compliance — no longer just execution — it loses control of the organisation it leads.
The gap that this delegation creates can be measured. After 250 interviews, a panel of experts convened by the FAA documented a disconnect at Boeing between management's message on safety and what frontline staff actually hear and believe, with 27 findings (FAA expert panel, 2024). Leadership delegated to statements leaves a measurable distance between what the top says and how the frontline operates. And the Swiss parliamentary commission of inquiry attributed primary responsibility for the collapse of Credit Suisse to its board and executive management, which ignored years of supervisory interventions (PUK, 2024). No external supervision can compensate for management that has decided not to manage.
The three non-negotiable moments
Moment one · the initial decision. When it is determined which system will be implemented and why. The decision is strategic · if it is signed by the IT department or a consultant, the system is born without political backing.
Moment two · the operational conflict. When the team needs to escalate something and needs political permission to do so without personal cost. If management is absent, the conflict is handled in corridors and the system accumulates silent debt.
Moment three · the external audit. When the auditor asks a question and the answer must come from management. If management delegates the interview, the auditor already knows how much real backing the system has.
The three moments seem different. They are the same · the moment when the system needs to know it has a real signatory.
Delegation in the intelligent era
A Chief AI Officer can govern day-to-day technical work. The role does not absorb decisions on scope, risk tolerance or resource allocation that belong to management. Article 4 of the European AI Act requires providers and deployers to take measures to ensure a sufficient level of AI literacy among their staff and those acting on their behalf; it does not create an obligation exclusive to a particular management role.
The counterexample
The criterion is also met, and it shows. I have seen a chief executive preside over every ceremony in his quality programme, pin on the team's badge and personally open the management review. The entire organisation knew who signed. That visibility shaped more behaviour than the entire manual · leadership exercised well is an observable fact, with witnesses.
The criterion test
Three checks with a written record, each with an expected response.
Check one · ask top management to explain recent material findings and what it decided in response. It may consult the person with technical responsibility; what it must be able to explain is the decision, its reasons and its date.
Check two · review who participated in the last management review and what decisions were recorded. The format may vary; the evidence must show real involvement by top management in results, resources and changes.
Check three · observe how top management responds during the audit. There is no universal rule requiring the same person to attend every meeting; there must, however, be sufficient access to assess leadership and responsibility.
These checks do not replace the audit criterion. They serve to distinguish a sound operational assignment from an effective withdrawal by management.