Governance, risk and compliance

SmartSuite for the AI Risk Officer

The AI Risk Officer owns the risk view of artificial intelligence: the AI risk taxonomy, tiering of use cases, assessment of harms such as bias, safety, security and drift, and the controls that keep high-risk systems within tolerance. They report AI risk to the CRO.

What you own

  • Maintain the AI risk taxonomy and tiering criteria
  • Assess AI use cases for bias, safety, security, privacy and drift risk
  • Define required controls and monitoring by risk tier
  • Review high-risk system approvals and conditions
  • Track AI incidents and near misses
  • Report AI risk posture to the CRO and risk committee

Where the role sits

Each name opens that role's page.

Reports to

Chief Risk Officer

Chief Risk Officer

See the role
Chief Data and AI Officer

Chief Data and AI Officer

See the role

GRC processes

The shared GRC process map, highlighted for this role.

Owns

accountable for the process

ai-governance

Touches

contributes or approves

risk, issues-actions, reporting, privacy

Depends on

consumes its output

compliance, audit

How SmartSuite helps, suite by suite

Each card is the persona record from that suite's Users tab.

No items found.

Suites that serve this role

How SmartSuite supports this role

AI governance. Scores AI use cases against the risk taxonomy and records required controls and monitoring by tier.

Risk management. Links AI risks to the enterprise register so they roll up with other risk.

Issues and actions. Tracks AI incidents, near misses and remediation to closure.

Reporting. Reports AI risk posture, high-risk systems and open actions to the risk committee.

Industry reference

The NIST AI RMF's Map, Measure and Manage functions and ISO/IEC 23894:2023 describe AI risk assessment: identifying harms such as bias, safety, security and drift and setting controls by tier. The EU AI Act defines the tiers in law, with prohibited, high-risk and limited-risk categories and obligations phased in from 2025.

In financial services AI risk sits inside model risk management under SR 11-7 and the PRA's SS1/23; in insurance the NAIC model bulletin and Colorado's AI law govern consumer-facing decisions; in healthcare FDA guidance and HHS rules on decision-support tools apply; US federal agencies manage rights- and safety-impacting AI under OMB guidance.

In their words

Related roles

Chief Risk Officer

Chief Risk Officer

See the role
Chief Data and AI Officer

Chief Data and AI Officer

See the role

See SmartSuite for your role

Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.