AI Risk and AI Risk Governance Manager
Listed on 2026-09-28
-
IT/Tech
AI Evaluation, Information Security & Data Protection
Description
The AI Risk and AI Risk Governance Manager is a Second Line of Defense individual contributor role within Risk Management responsible for providing independent oversight, challenge, and risk governance support for enterprise-wide artificial intelligence activities, with emphasis on generative AI, agentic AI, and AI-enabled applications. This role will report to the AI Risk and Digital Assets Risk Director and help ensure AI use across the enterprise is governed in alignment with risk appetite, internal policy, regulatory expectations, and responsible AI principles.
This role partners closely with first-line business, technology, data, model risk, compliance, privacy, information security, audit, and other risk stakeholders to provide credible challenge over AI risk identification, assessment, monitoring, control design, and governance processes. The role will also support development and oversight of risk governance expectations specific to AI agents and agentic AI systems, including autonomy, tool use, human oversight, escalation, testing, monitoring, change management, and incident response considerations.
- Provide independent Second Line of Defense oversight and credible challenge of enterprise AI governance activities, including AI risk identification, risk assessment, control expectations, monitoring, reporting, issue management, and escalation.
- Assess whether first-line AI governance, control, testing, validation, and monitoring practices are appropriately designed and operating in alignment with enterprise risk appetite, AI policy, risk management standards, and applicable regulatory expectations.
- Support risk governance program expectations for AI agents and agentic AI systems, including requirements related to autonomy, delegated decision‑making, tool and API access, task boundaries, auditability, and kill‑switch or deactivation protocols.
- Establish and maintain oversight expectations for material changes to AI systems, including changes to models, data sources, prompts, tools, permissions, integrations, autonomy, and intended use, and challenge whether reassessment, retesting, approval, restriction, or deactivation is required.
- Evaluate risks associated with generative AI and agentic AI use cases, including inaccurate or misleading outputs, inappropriate system actions, prompt injection, data leakage, privacy concerns, bias, explainability, security vulnerabilities, third‑party dependencies, operational resiliency, and model or system drift.
- Provide oversight and challenge of AI use case intake, classification, approval, monitoring, inventory, and material change processes to ensure appropriate governance coverage across the AI lifecycle and visibility into aggregate enterprise exposure, common dependencies, and concentration risk.
- Review AI risk assessment and ongoing monitoring outputs and challenge whether risks, controls, testing evidence, residual risk conclusions, limitations, compensating controls, risk acceptances, and continued‑use decisions are sufficiently documented and supported.
- Partner with Model Risk Management, Technology Risk, Operational Risk, Compliance, Privacy, Information Security, Legal, Internal Audit, and business risk teams to ensure AI governance expectations are consistently interpreted and applied across the enterprise.
- Monitor emerging AI and agentic AI risks, industry practices, regulatory developments, and internal control themes; translate relevant developments into actionable oversight considerations.
- Support governance reporting for senior management and risk committees by developing concise insights on the enterprise AI risk posture, alignment with risk appetite, material exposures, concentration and dependency…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).