This paper aims to build a responsibility model based on accountability, capability, and commitment. The model's objectives are to help organizations verify their structure and detect policy problems. It also provides a framework for organizations to define corporate, security, and access control policies. The paper reviews previous research and proposes a responsibility model using UML and a formal representation using logic. It analyzes whether responsibility is perceived at the user or company level.