Governance, risk and compliance

SmartSuite for the Chief Data and AI Officer

The Chief Data and AI Officer is accountable for how the organisation governs data and artificial intelligence: the AI inventory, the risk tiering of use cases, the approval gates and the policies that keep models lawful, fair and safe. They report AI posture to the board.

What you own

  • Set the data and AI governance strategy, policies and operating model
  • Maintain the enterprise AI and model inventory with risk tiers
  • Approve high-risk AI use cases and their controls
  • Align AI governance with NIST AI RMF, ISO/IEC 42001 and the EU AI Act
  • Oversee data quality, lineage and stewardship
  • Report AI risk posture and governance maturity to executives and the board

Where the role sits

Each name opens that role's page.

Reports to

Chief Executive Officer

Chief Executive Officer

See the role
Chief Information Officer

Chief Information Officer

See the role

Direct reports

AI Governance Lead

AI Governance Lead

See the role
AI Risk Officer

AI Risk Officer

See the role
Model Risk Manager

Model Risk Manager

See the role
Data Governance Analyst

Data Governance Analyst

See the role

Works closely with

Chief Risk Officer

Chief Risk Officer

See the role
Chief Privacy Officer

Chief Privacy Officer

See the role
Chief Information Security Officer

Chief Information Security Officer

See the role
Chief Compliance Officer

Chief Compliance Officer

See the role

GRC processes

The shared GRC process map, highlighted for this role.

Owns

accountable for the process

ai-governance, reporting

Touches

contributes or approves

risk, compliance, privacy, policy

Depends on

consumes its output

audit, third-party

How SmartSuite helps, suite by suite

Each card is the persona record from that suite's Users tab.

How they use SmartSuite

How they use SmartSuite

How they use SmartSuite

Suites that serve this role

How SmartSuite supports this role

AI governance. Provides an AI model registry with risk tiering, assessment workflows and approval decisions, so every model's status and governance steps are visible.

Risk management. Monitors material AI risk themes, drift, bias and safety signals with mitigation progress alongside other enterprise risk.

Compliance management. Maps AI systems to obligations such as the EU AI Act and internal standards with linked evidence.

Privacy. Connects AI use cases that process personal data to privacy assessments.

Reporting. Delivers board-ready AI governance posture and exception reporting from live data.

Industry reference

The NIST AI Risk Management Framework 1.0 (2023) and ISO/IEC 42001:2023 describe the governance system this role owns: an AI inventory, risk tiering, documented controls and accountable approval. The EU AI Act (Regulation 2024/1689) turns that into law for providers and deployers of high-risk systems, with obligations phased in from 2025.

In financial services the Federal Reserve's SR 11-7 model risk guidance already governs statistical and AI models, and the NAIC's 2023 model bulletin sets expectations for insurers. US federal agencies must appoint a Chief AI Officer under OMB guidance. In healthcare, HHS rules on patient care decision support tools and FDA guidance on AI-enabled devices apply.

In their words

Related roles

Chief Executive Officer

Chief Executive Officer

See the role
Chief Information Officer

Chief Information Officer

See the role

See SmartSuite for your role

Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.