Role Summary
Own the design and execution of the enterprise AI governance program. Build the standards, policies, and procedures that govern how AI use cases and models move from idea to production. Structure the governance roadmap across intake, classification, value assessment, and control design. Stand up use case governance and model governance functions, define the target state for AI governance across the organization, and drive an implementation plan with clear monitoring, prioritized against engineering delivery timelines.
Key Responsibilities
Governance Framework Design
- Author and maintain AI governance standards, policies, and procedures covering the full lifecycle of AI use cases and models
- Design the governance roadmap organized into intake, classification, value assessment, and control design stages
- Define risk tiers and controls proportional to use case risk (e.g., low/medium/high risk classification tied to required controls)
Use Case Governance
- Build the intake process for new AI use cases: how requests enter the pipeline, what information is captured, who reviews them
- Establish classification criteria (risk level, data sensitivity, regulatory exposure, business criticality)
- Design value assessment methodology to prioritize use cases against cost, risk, and business impact
- Define control requirements per classification tier (documentation, testing, sign-off, monitoring)
Model Governance
- Establish model risk management practices: validation, documentation, versioning, approval gates
- Define requirements for model cards, testing evidence, bias/fairness checks, and performance monitoring
- Set standards for third-party and open-source model vetting
Target State & Team Build
- Define the target state for AI governance: what "good" looks like, what the organization should expect from the function
- Design the governance team structure, roles, and operating model
- Set RACI across governance, engineering, legal, risk, and business stakeholders
Implementation & Monitoring
- Build a phased implementation plan with milestones and owners
- Prioritize governance rollout in sequence with engineering platform and architecture delivery
- Establish monitoring and reporting: KPIs, compliance tracking, exception handling, escalation paths
- Run periodic reviews of the governance program's effectiveness and adjust as needed
Required Qualifications
- Combined minimum of 10 years' higher education and/or operational/business analytics/systems development experience
- Demonstrated experience building a governance framework or program from the ground up in a large or complex organization
- Working knowledge of model risk management practices (e.g., SR 11-7 or equivalent) and how they extend to AI/ML systems
- Experience designing intake, classification, and risk assessment processes for technology or data initiatives
- Experience working cross-functionally with engineering, legal, compliance, and business teams
- Strong written communication skills; able to produce policy documents, standards, and executive-level reporting
- Bachelor's degree in a relevant field (risk, business, computer science, law, or similar); advanced degree a plus but not required in place of experience
Preferred Qualifications
- Direct experience with AI-specific regulatory frameworks (EU AI Act, NIST AI RMF, ISO/IEC 42001) and applying them practically
- Prior experience standing up or scaling a governance team, including hiring and role design
- Familiarity with MLOps and model deployment pipelines, enough to design controls that don't bottleneck engineering
- Experience with generative AI governance specifically (prompt/data leakage risk, hallucination controls, third-party LLM vendor risk)
- Certifications such as CRISC, CISA, or AI governance-specific credentials
- Experience in a regulated industry (financial services, healthcare, insurance)
Skills Required
- Policy and standards writing
- Risk classification and control design
- Stakeholder management across technical and non-technical audiences
- Program/project management (roadmap building, milestone tracking, prioritization)
- Working knowledge of ML lifecycle and model development practices
- Data literacy: able to read model documentation, validation reports, and technical risk assessments
- Facilitation and negotiation, particularly balancing governance rigor against engineering velocity
#LI-JB3
M&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $123,600.00 - $206,000.00 Annual (USD). The successful candidate’s particular combination of knowledge, skills, and experience will inform their specific compensation.Location
Buffalo, New York, United States of AmericaLearn more about this Employer on their Career Site
