Director, AI Risk Governance & Validation Lead

SUMITOMO MITSUI BANKING CORPORATION Singapore BranchSingaporemycareersfuturepublished 10/05/2026
Must-have:AzureDataQA/TestAIFinTechSecuritySeniorLead

Responsibilities:

  1. Lead the DMO AI Risk Governance & Validation Team
  • Lead a four-member specialist team covering AI model governance, model validation, AI testing / QA / evaluations, and AI engineering for governance validation.
  • Set the operating cadence, work allocation, review standards, escalation protocols and evidence-quality expectations for the team.
  • Build a practical Line 1.5 AI governance capability that supports AI use case intake coordination, preliminary risk triage, evidence completeness checking, control effectiveness challenge and post-deployment governance.
  • Ensure the team remains a technical assurance and evidence-review function, not an AI delivery owner, model owner or final risk approval owner.
  • Develop team capabilities across AI governance, model risk, model validation, testing, data governance, GenAI, agentic AI, MLOps and regulatory expectations.
  1. Operate Line 1.5 AI Governance Review and Challenge
  • Review AI use cases from data governance, data risk, model lifecycle and practical control perspectives before escalation to independent risk and compliance stakeholders.
  • Challenge the completeness and quality of AI review submissions, including business purpose, data sources, model / agent design, preliminary risk classification, validation evidence, control evidence and monitoring plans.
  • Review whether AI controls are operationally workable, evidenced and sustainable, rather than policy-level only.
  • Coordinate with Business / Use Case Owners, Data Owners, AI delivery teams, Technology / Security teams, Risk Management Department, Compliance Department, Legal Department, local data protection officers and other relevant control functions.
  • Provide clear review conclusions, challenge points and remediation recommendations to support independent risk review and governance committee decision-making.
  1. Data Governance for AI
  • Review AI input data sources, data ownership, data classification, personal data / PII treatment, data access controls, cross-border considerations, data quality, lineage, metadata and evidence readiness.
  • Confirm whether data used for AI use cases is appropriately approved, fit for purpose, traceable and subject to adequate controls.
  • Challenge whether data access, storage location, output retention, SharePoint / platform access and downstream use are consistent with applicable data governance and privacy requirements.
  • Work with Data Governance, Data Owners and control functions to establish a unified evidence layer covering data classification, data access, cross-border sharing, data protection, data quality, lineage, metadata and AI data risk assessment.
  • Support AI-ready data governance standards, evidence templates and review checklists.
  1. Model / Agent Validation Challenge
  • Oversee review and challenge of model / agent validation evidence, including methodology, assumptions, feature logic, data inputs, limitations, performance, stability, robustness, explainability and monitoring design.
  • Ensure validation evidence is appropriate for use case risk level, intended use and AI lifecycle stage.
  • Challenge model / agent performance metrics, drift monitoring, bias / fairness assessment, robustness testing, output accuracy testing and human-in-the-loop controls.
  • Work with model developers, AI engineers, data scientists and independent risk reviewers to ensure validation artefacts are clear, complete and decision-useful.
  • Ensure validation evidence clearly identifies limitations, residual risks, control gaps and remediation actions where required.
  1. AI Testing, QA and Evaluation Oversight
  • Oversee testing approaches for statistical models, ML models, LLM applications and agentic AI systems.
  • Ensure coverage of functional testing, regression testing, scenario-based testing, edge cases, adverse / irregular scenarios, bias / fairness evaluation, robustness analysis, drift detection and workflow reliability.
  • Review end-to-end AI workflows, including data inputs, feature transformations, task completion, tool-use accuracy, API / connector behaviour, multi-step reasoning and output quality.
  • Promote test logs, evaluation results, benchmarking, traceability and observability evidence to support AI risk review.
  • Ensure testing findings are documented clearly and translated into remediation actions, risk caveats or acceptance considerations for governance forums.
  1. AI Engineering and MLOps Governance
  • Provide leadership oversight over technical review of AI engineering, agentic workflows, RAG, API integration, tool-use orchestration, Copilot Studio / Power Automate-type workflows, logging and monitoring controls.
  • Challenge whether AI systems have appropriate MLOps / lifecycle controls, including model registry, version control, deployment controls, monitoring, retirement triggers and change management.
  • Review whether AI / GenAI solutions disable inappropriate model training or data leakage pathways where required.
  • Assess whether technical architecture and workflow design support auditability, explainability, resilience and responsible AI expectations.
  • Partner with Technology, Security and AI delivery teams to embed technical controls early enough in the lifecycle.
  1. Governance Framework, Procedures and Evidence Standards
  • Translate AI governance policy, risk appetite and regulatory expectations into practical review procedures, templates, evidence packs and operating standards.
  • Maintain AI review checklists and evidence standards covering lifecycle governance, data handling, access control, validation, testing, monitoring and control effectiveness.
  • Ensure DMO review outputs are structured, audit-ready and reusable for independent risk review and committee escalation.
  • Develop reporting on review pipeline, common evidence gaps, key control weaknesses, review turnaround, remediation status and recurring AI risk themes.
  • Support continuous improvement of the AI Risk Governance operating model, including workflow tooling, intake process, inventory integration and review status tracking.
  1. Senior Stakeholder Management and Regulatory Readiness
  • Act as the senior DMO point of contact for AI risk governance matters with Risk Management Department, Compliance Department, Technology / Security teams, AI delivery teams, business use case owners and senior management.
  • Explain complex AI, data and model-control issues in a clear, practical and decision-oriented manner for senior stakeholders.
  • Support management discussions on AI governance, Line 1.5 operating model, staffing, capability build-out and APAC implementation roadmap.
  • Contribute to regulator-ready documentation and evidence where AI governance, data handling, model validation or control effectiveness needs to be demonstrated.
  • Bring external market awareness of AI governance practices in regulated financial services and adapt them to the APAC DMO operating model.

Requirements

Education

  • Bachelor's degree in Data Science, Computer Science, Artificial Intelligence, Information Systems, Mathematics, Statistics, Engineering, Risk Management, Finance, or a related discipline.
  • Master's degree in AI, Machine Learning, Data Science, Analytics, Risk Management, Business Administration, or a related field preferred.

Experience

  • 15+ years of experience spanning AI/ML, data governance, model risk management, data management, technology risk, analytics, or related disciplines.
  • Minimum 7+ years of leadership experience managing specialist teams within data, analytics, AI governance, model risk, validation, or technology risk functions.
  • Proven experience designing and operating governance, risk, validation, or assurance frameworks for AI, machine learning, advanced analytics, and GenAI solutions.
  • Demonstrated experience reviewing and challenging AI, machine learning, statistical, and predictive models in a regulated environment.
  • Experience establishing or operating Line 1, Line 1.5, Line 2, or Model Risk Management functions within banking, financial services, or other highly regulated industries.
  • Strong track record engaging senior executives, governance committees, regulators, auditors, and control functions.
  • Experience building governance capabilities, operating models, review workflows, evidence standards, and control assessment frameworks from the ground up.
  • Banking, financial services, or regulatory experience is strongly preferred.

Preferred Certifications

One or more of the following certifications would be advantageous:

  • Certified Model Risk Manager (CMRM)
  • Certified Data Management Professional (CDMP)
  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Systems Auditor (CISA)
  • Certified in Risk and Information Systems Control (CRISC)
  • PMI Project Management Professional (PMP)
  • Microsoft Certified: Azure AI Engineer Associate
  • Databricks Machine Learning Professional
  • Certified AI Governance Professional (AIGP)
  • Relevant AI Ethics, Responsible AI, or Model Risk certifications