Lead Mashreq’s enterprise-wide AI Governance program to ensure AI and ML (including GenAI/LLMs) are responsible, compliant, secure, fair, explainable, and well-controlled across their lifecycle. Establish policies, standards, and controls; oversee model risk governance; and enable safe, value-creating AI adoption aligned to Mashreq’s strategy, regulatory expectations, and customer trust.
- AI Policy & Standards
- Define, publish, and maintain Mashreq’s AI Governance Policy, standards, and procedures (Responsible AI, model lifecycle, GenAI safety, human-in-the-loop, data & privacy, monitoring).
- Embed policy into SDLC/MLOps, change management, and risk frameworks.
- GenAI / LLM Controls
- Define guardrails for prompt security, data leakage prevention, content safety, output evaluation, and usage logging.
- Regulatory & Assurance
- Interpret applicable regulations and guidance; evidence compliance and audit readiness.
- Risk Management & Security Integration
- Align AI controls with Cybersecurity, Data Protection, Operational Risk, and Third‑Party Risk.
- Implement access controls, encryption, privacy-by-design, and incident response for AI systems.
- Governance Operating Model
- Design RACI and governance workflows, from use‑case intake to go‑live and sunset.
- Drive adoption of tools (model registry, monitoring dashboards, policy attestations).
- Stakeholder Enablement & Culture
- Train teams on Responsible AI; run awareness campaigns; publish guidance/playbooks.
- Partner with Business, Technology, Data, Risk, Compliance, Legal, and Audit to enable safe innovation.
- Metrics & Reporting
- Define KPIs/KRIs (policy adherence, coverage, validation backlog, incidents, bias and drift metrics).
- Provide executive dashboards and regular reporting to leadership committees.
- Portfolio Oversight & Prioritization
- Triage and prioritize AI use cases; ensure value vs. risk trade-offs and timely approvals.
- Escalate material risks and recommend risk treatment or go/no‑go decisions.
- Continuous Improvement
- Benchmark against leading frameworks (e.g., risk management, AI RMF, ISO standards).
- Industrialize governance processes and automate controls.
Operates within Mashreq policies, risk appetite, IT standards, data protection requirements, and applicable regulatory guidance.
Works cross‑functionally with
Technology (AI/ML Engineering, Data Platform, Cybersecurity),
Risk,
Compliance,
Legal,
Audit, and
Business Units; engages external vendors/partners under third‑party risk controls.
Boundaries include approval mandates defined by Risk Committees, budget authority, and change governance.
Knowledge & Experience
Risk & Compliance: Familiar with model risk management concepts, Responsible AI principles, and audit practices.
Leadership & Communication: Executive stakeholder management, committee engagement, policy writing, training and change management.
Education & Certifications: Bachelor’s/Master’s in Computer Science, Data Science, Engineering, or related. Relevant certifications in risk, audit, or AI governance are advantageous.