•This role is involved in supporting the execution of the Bank’s AI-amplified risk management agenda and assisting with the coordination of activities across existing risk domains impacted by AI. Reporting to the Lead, Risk Management - AI, the primary roles is focused on:
•Supporting AI-amplified risk discovery, baselines assessment, control gap analysis, control uplift tracking, and BAU monitoring activities.
•Assisting domain teams in documenting AI-related risk impacts, controls, actions, issues, dependencies, and evidence.
•Supporting governance routines, workstream coordination, progress reporting, and committee material preparation.
•Maintaining accurate trackers, logs, repositories, management information, and evidence packs for AI risk activities.
•Supporting RCSA, control testing, assurance, audit, regulatory, and RFI related activities relating to AI-amplified risks.
•Helping ensure that AI-related risk information is complete, consistent, timely, and escalated where required.
Processes
•Embed AI-amplified risk considerations into existing domain processes, standards, and control routines.
•Assess were AI adoption changes processes and relevant control expectations, ownership, evidence, or escalation requirements.
•Support process owners in uplifting controls, and procedures for AI-impacted activities
•Coordinate dependencies between AI Governance, Technology, Cyber, Data, Compliance, and Third-Party risk teams.
•Track delivery of agreed process and control uplift actions
Risk Management
•Identify, assess, and challenge AI-amplified risks across existing risk domains.
•Support materiality assessments, control gap reviews, and residual risk assessments for AI-impacted processes, tools, platforms, vendors, and use cases.
•Provide clear risk opinions and recommendations to support control uplift, risk acceptance, remediation, and escalation decisions.
•Monitor AI-related issues, control gaps, incidents, risk acceptances, and management actions.
•Support integration of AI-amplified risks into RCSA, control testing, MI, KRIs, KCIs, and BAU risk reporting.
Governance
•Manage AI risk workstreams and ensure delivery remains aligned to agreed scope, timelines, and governance expectations in partnership with central AI Risk governance teams.
•Prepare governance updates, executive summaries, committee materials, and decision papers on AI-amplified risk topics.
•Escalate material risks, blockers, dependencies, and unresolved control gaps through appropriate governance forums.
•Support clear ownership across domain teams, control owners, AI governance, and Risk Management.
•Maintain auditable records of key decisions, actions, issues, and escalations.
Regulatory & Business Conduct
•Ensure activities are aligned to Group policies, AI standards, regulatory expectations, and applicable conduct requirements.
•Support mapping of AI-amplified risks to relevant regulatory, policy, and control obligations.
•Promote responsible AI adoption by escalating risks of unfair, inappropriate, opaque, or poorly controlled outcomes.
•Support audit, assurance, regulatory, and RFI responses relating to AI-amplified risks.
•Display exemplary conduct and uphold the Group’s Values, Code of Conduct, and risk management standards.
Key Stakeholders
•AI Leadership Team
•T&O Management Team
•Central AI Governance and AI Enablement Teams
•2nd Line of Defence functions
•Governance & Optimisation teams
•Group Internal Audit
•T&O Risk Management Teams
•T&O Technology Process Owners
•Regulators and their appointed auditors (where applicable)
Other Responsibilities
•Support ad-hoc tactical and strategic risk initiatives to meet business and operational demands through thoughtful partnership.