Patient-safety regulation in pharmacy commonly places substantial responsibility on individual pharmacists while many conditions that shape safe practice are determined elsewhere. Staffing establishments, skill mix, workload allocation, performance targets, workflow design, information access, and the practical room to exercise professional judgment may be controlled by owners, corporate structures, managers, regulators, or combinations of these actors. This article develops a Regulatory-Governance Model of Control and Accountability for examining that mismatch. Drawing on contemporary evidence concerning community-pharmacy safety climate, workforce conditions, workload, professional autonomy, organizational governance, and regulation, the analysis distinguishes legal responsibility from practical control, resource authority, target-setting power, professional discretion, oversight, and sanction capacity. The central claim is conditional: organizational scrutiny becomes necessary when an actor is held responsible for preventing a safety problem but lacks realistic authority or resources to alter the conditions producing it. The model consequently directs regulatory attention upstream from isolated practitioner conduct toward the distribution of decision rights that configure pharmacy work. It also preserves countervailing explanations, including individual competence, professional agency, local adaptation, and role negotiation. Regulatory accountability is strongest when responsibility is aligned with demonstrable capacity to change the safety-relevant condition.