Governance, risk and compliance

SmartSuite for the AI Governance Lead

The AI Governance Lead monitors enterprise AI posture, identifies systemic issues and ensures AI use aligns with laws, regulations and internal standards. They run the governance programme: inventory coverage, exceptions, framework mapping and maturity, linking models to obligations, controls and evidence.

What you own

  • Operate the AI governance programme and its policies
  • Maintain inventory coverage and risk tiering of AI use cases
  • Map models to obligations, controls and standards
  • Track exceptions, systemic issues and governance maturity
  • Coordinate reviews with model owners, validators, privacy and security
  • Report AI governance posture to the Chief Data and AI Officer

Where the role sits

Each name opens that role's page.

Reports to

Chief Data and AI Officer

Chief Data and AI Officer

See the role

Direct reports

Works closely with

AI Risk Officer

AI Risk Officer

See the role
Model Risk Manager

Model Risk Manager

See the role
Model Owner

Model Owner

See the role
Privacy Program Manager

Privacy Program Manager

See the role
IT Compliance Manager

IT Compliance Manager

See the role

GRC processes

The shared GRC process map, highlighted for this role.

Owns

accountable for the process

ai-governance

Touches

contributes or approves

compliance, issues-actions, reporting, privacy

Depends on

consumes its output

risk, audit

How SmartSuite helps, suite by suite

Each card is the persona record from that suite's Users tab.

How they use the AI Governance suite

Program monitoring

Tracks coverage, exceptions, and governance maturity.

Compliance alignment

Maps models to obligations, controls, and standards.

Systemic insight

Identifies repeat issues and enterprise risk themes.

Suites that serve this role

How SmartSuite supports this role

AI governance. Provides a connected governance ecosystem linking models, risks, controls, obligations and evidence, with framework mapping and issue management.

Compliance management. Maps models to obligations, controls and standards and tracks evidence per requirement.

Issues and actions. Tracks exceptions and repeat issues to identify enterprise risk themes.

Reporting. Reports coverage, exceptions and governance maturity.

Industry reference

The NIST AI RMF's Govern function and ISO/IEC 42001:2023 define the programme: policies, an inventory of AI systems, roles, impact assessments and monitoring, with the Generative AI Profile (2024) covering foundation-model use. The EU AI Act (2024/1689) makes inventory, risk classification and documentation legal duties for providers and deployers of high-risk systems.

Sector rules add detail. US federal agencies must inventory AI use cases under OMB guidance; insurers follow the NAIC's 2023 model bulletin and Colorado's AI law; healthcare organisations meet HHS transparency rules for decision support and FDA device guidance; financial firms fold AI into SR 11-7 model governance.

In their words

Related roles

Chief Data and AI Officer

Chief Data and AI Officer

See the role

See SmartSuite for your role

Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.