Back to jobs
AI Governance & Controls Lead
Successfully
Req. VR-124257
The AI Governance & Controls Lead is the senior individual contributor responsible for operationalizing M&T's AI governance framework: authoring and maintaining AI standards and controls, executing the policy exception and deviation processes, and producing the examiner-ready evidence that demonstrates our controls are enforced mechanically rather than attested annually. This role partners closely with Technology Risk Management, Model Risk Management, Compliance, Cybersecurity, Enterprise Architecture, and the enterprise AI platform team to ensure every AI use case at the bank operates within a defensible, testable control framework.
This is a hands-on, technically fluent governance role. The Lead works directly with platform-enforced controls (gateway policies, entitlements, quotas, audit logging), translates regulatory obligations (e.g., SR 26-2, NYDFS guidance) into implementable standards, and validates that evidence generated by the platform satisfies second-line and examiner expectations. The role serves as a key contributor to policy refresh cycles, regulatory response efforts, and the continuous-monitoring design that replaces point-in-time annual review
Standards, Controls & Policy Execution
Author, maintain, and version the bank's AI standards library: model selection and approval, human oversight tiers, prompt/response logging and retention, agentic guardrails, and acceptable-use requirements.
Build and maintain the obligation-to-control-to-evidence mapping against applicable regulatory guidance (SR 26-2, NYDFS, and evolving supervisory expectations).
Operate the AI policy exception and TRM deviation processes: draft time-bound deviation requests, define compensating controls, track expiries and remediation paths to closure.
Support annual policy refresh cycles and translate policy principles into testable, enforceable requirements in partnership with policy owners.
Platform-Enforced Governance & Evidence
Partner with the AI platform team to ensure governance requirements are enforced mechanically at the enterprise AI gateway (entitlements, model allowlists, quotas, audit logging) and that enforcement produces native evidence.
Define evidence requirements and validate audit artifacts as queryable, export-ready, and sufficient for internal audit, second-line review, and examiner requests.
Design and operate continuous-monitoring practices: monitoring boundaries, event-based review triggers, and evidence expectations for AI systems that change frequently.
Maintain the AI use case and agent registry as the system of record, integrated with platform onboarding and entitlement workflows.
Provide governance ownership of the AI use-case intake framework in partnership with the AI Use Case Intake & Value Lead.
Risk Partnership & Regulatory Readiness
Serve as the primary working-level interface to Technology Risk Management, Model Risk Management, Compliance, and Internal Audit for AI governance matters.
Assemble examiner-readiness packages: control mappings, evidence samples from the live platform, and documented rationale for the standards the bank has defined.
Monitor the regulatory and industry landscape (agency guidance, FSB/trade-group developments) and assess impact to standards and controls.
Support AI Control Group and AI Ethics Working Group activities with documented assessments and control recommendations.
Must have
Bachelor's degree and a minimum of 5 years' experience in technology risk, IT governance, information security governance, or technology compliance within a regulated environment, or in lieu of a degree, a combined minimum of 9 years' education and/or relevant work experience.
Demonstrated experience authoring technology standards, controls, or policies and mapping them to regulatory obligations.
Working technical fluency with modern AI systems: LLM-based applications, API gateways, model access patterns, RBAC/entitlements, logging and monitoring architectures.
Experience preparing for or responding to internal audit, second-line review, or regulatory examination.
Strong analytical writing: able to produce standards, deviation requests, and evidence narratives that survive challenge.
Strong communication and stakeholder management skills across risk, technology, and business partners
Nice to have
Experience with AI/ML governance frameworks (NIST AI RMF, model risk management guidance, SR 11-7/SR 26-2 lineage).
Familiarity with Azure services relevant to AI workloads (API Management, Entra ID, Key Vault, Azure Monitor) and with policy-as-code or controls-automation concepts.
Financial services or other highly regulated industry experience.
Experience with GRC tooling and evidence management.
Experience supporting AI, data, or technology committees and governance forums
Languages
English: C1 Advanced
Seniority
Lead
Wilmington, US, Delaware, United States of America
Req. VR-124257
Enterprise Architecture
BCM Industry
29/07/2026
Req. VR-124257
Apply for AI Governance & Controls Lead in Wilmington, US, Delaware
*Indicates a required field