New Roles: Chief AI Officer, Model-Risk-AI, Fair-Lending-AI Leads
The following scenario is a composite illustration. In the spring of 2026, the board of a mid-sized regional bank approved three new positions simultaneously: a Chief AI Officer (CAO), a Model-Risk-AI Lead, and a Fair-Lending-AI Lead. The chief executive presented the org chart at the annual strategy offsite. Two rows of executives studied it in silence. The chief risk officer (CRO) broke the quiet: "So who owns the AI model that denied a large share of mortgage applications last quarter?" The answer, under the old structure, had been nobody in particular. Under the new one, it was the Model-Risk-AI Lead, whose mandate included OCC Bulletin 2026-13 compliance, validation oversight, and a direct reporting line to the CRO and the board's risk committee. That structural answer, simple as it sounds on an org chart, was the transformation.
Enterprise AI transformation in banking does not fail because the technology is wrong. It fails because accountability is diffuse. A model that produces discriminatory outcomes, a vendor contract that transfers none of the governance obligation, a GenAI tool adopted by a business line without model-risk review: these are not technology failures. They are organizational design failures. The lessons of 2024 and 2025, now encoded in OCC Bulletin 2026-13, are that banks need AI to be someone's actual job, with a defined scope, a reporting line, a budget, and the authority to say no to a business line that wants to deploy an ungoverned model.
This lesson maps the three AI governance roles that 2026 requires: the Chief AI Officer who owns the enterprise AI strategy and the board relationship; the Model-Risk-AI Lead who runs the validation program, the vendor due-diligence pipeline, and the OCC 2026-13 compliance posture; and the Fair-Lending-AI Lead who owns disparate-impact testing, the less-discriminatory-alternative search process, and the adverse-action quality program across all AI-touched credit decisions. Together, these three roles close the accountability gap that regulators are finding in examinations across the industry.
Why the Old Org Chart Cannot Govern AI
The pre-2026 banking org chart was built around functional silos. Lending owned origination. Risk owned underwriting policy. Compliance owned regulatory reporting. Technology owned systems. This structure worked when AI was a statistical credit score sitting inside the loan origination system (LOS) with a documented methodology and a periodic validation cycle. It stopped working when AI became a dynamic capability embedded across the loan lifecycle: pre-screening applicants, extracting income from documents, drafting credit memos, summarizing adverse action reasons, flagging suspicious transactions, and generating borrower communications.
The problem is not that any of those use cases is inherently ungovernable. The problem is that each use case, under the old structure, belonged to a different function. Lending owned the LOS pre-screening. Compliance owned adverse action. BSA/AML (Bank Secrecy Act and Anti-Money Laundering, the combined federal framework requiring banks to detect and report suspicious financial activity) owned transaction monitoring. Technology owned vendor contracts. Risk owned the model inventory. With five functions each owning a piece of the AI governance picture, the fundamental questions fell through the seams: Who reviewed the vendor's fair-lending testing before signing the contract? Who validated the GenAI drafting tool before loan officers started using it? Who ran the disparate-impact analysis on the pre-screening model's 2025 outcomes?
OCC Bulletin 2026-13, the April 2026 interagency guidance issued jointly by the OCC, the Federal Reserve, and the FDIC that superseded OCC 2011-12 and pulled AI and GenAI explicitly under model-risk management (MRM), fair-lending, third-party risk, and board governance expectations, crystallized the problem. The bulletin does not describe functions. It describes accountabilities. Someone must validate models. Someone must test for disparate impact. Someone must maintain the model inventory. Someone must brief the board. When each of those accountabilities belongs to a different function with different priorities and different reporting lines, none of them is consistently met.
The structural solution is a small, high-authority AI governance team whose scope spans functions and whose mandate is to close those seams. The CAO owns the strategy and the board relationship. The Model-Risk-AI Lead owns the technical governance posture. The Fair-Lending-AI Lead owns the fair-lending thread that runs through every AI-touched credit decision. Each role requires a different skill profile, a different set of relationships, and a different set of deliverables. Together, they create a governance architecture that a regulator can examine and find whole.
AI governance fails when accountability is distributed across functions by default; the CAO structure creates explicit, concentrated accountability that regulators can examine and find whole.
The Chief AI Officer: Scope, Authority, and the Board Relationship
The Chief AI Officer (CAO) is the most visible and most misunderstood of the three roles. In technology companies and fintech startups, the title often maps to an applied AI researcher or an engineering leader. In a regulated bank, the CAO is something different: a strategic, governance-oriented executive whose primary accountability is ensuring that the bank's AI program is enterprise-coherent, regulatory-defensible, and board-reportable. The CAO is not primarily a technologist. The CAO is an executive who knows enough technology to ask the right questions of technologists, and enough regulatory compliance to know what questions an examiner will ask of the institution.
The CAO's scope has four components. First, enterprise AI strategy: the CAO owns the institution's AI roadmap, including which use cases the bank pursues, in what order, with what governance requirements attached, and with what resourcing. The CAO's roadmap decision-making is informed by the Model-Risk-AI Lead's capacity for validation and the Fair-Lending-AI Lead's capacity for disparate-impact testing, so the bank does not commit to deploying models faster than it can govern them.
Second, cross-functional governance: the CAO chairs or co-chairs the AI governance committee, which includes the chief risk officer, the chief compliance officer, the chief lending officer, and the technology lead. The CAO's role in that committee is not to be the technical expert. It is to own the agenda, ensure that every AI deployment decision goes through a consistent governance gate, and maintain the enterprise view of AI risk exposure that no single function can see from its own seat.
Third, vendor and third-party AI oversight: the CAO owns the institution's relationship with AI vendors at the strategic level. When a fintech AI vendor pitches an underwriting model or a document extraction platform, the CAO's office sets the due diligence requirements, including the explainability review, the fair-lending testing obligation, and the model-risk documentation requirement, before a commercial conversation advances. OCC Bulletin 2026-13 is explicit that banks cannot outsource model-risk obligations to vendors; the CAO is the executive whose signature reflects that principle.
Fourth, board relationship: the CAO presents to the board's risk committee on a quarterly basis, providing a view of the AI model inventory, significant model changes, fair-lending testing results, material incidents, and the forward roadmap. The board oversight section of OCC Bulletin 2026-13 expects board members to receive regular reporting on AI model risk and to ask substantive questions in response. The CAO's job is to make that reporting legible to a board that may have limited AI technical background, while ensuring that the reporting is substantive enough to satisfy an examiner reviewing board governance records.
The CAO reporting line matters significantly. In the most defensible structures, the CAO reports to the chief executive or the chief operating officer, with a dotted line to the chief risk officer. This placement gives the CAO enough authority to push back on business lines that want to deploy ungoverned models, without subordinating the AI strategy function to risk in a way that could slow legitimate AI investment. Some institutions house the CAO inside risk; the advantage is tighter integration with MRM and compliance, but the risk is that the role becomes purely defensive rather than strategically enabling. Neither is universally right. What matters is that the reporting line is high enough in the organization to give the CAO genuine authority.
The skill profile for a CAO in a regulated bank is hybrid: five to ten years of financial-services experience including exposure to model risk, fair lending, or regulatory compliance; genuine familiarity with AI and machine learning concepts at a level that allows substantive dialogue with data scientists and vendors; executive communication and board-presentation skills; and the professional credibility to represent the institution in regulatory examination conversations about AI governance. This profile is genuinely scarce, which is why many banks are building the role by elevating an internal candidate with deep regulatory expertise and investing in AI technical fluency, rather than importing a pure technologist and hoping the compliance knowledge develops.
The Model-Risk-AI Lead: Owning the Validation Program Under OCC 2026-13
Model risk management (MRM) has existed in banking since the 2011 OCC guidance established the framework for model inventory, validation, and ongoing monitoring. What OCC Bulletin 2026-13 added was the explicit inclusion of AI and GenAI tools under that framework, with specific attention to the governance challenges those tools present: opacity of model logic, dynamic model updating, vendor black boxes, and generative outputs that cannot be validated against a finite output space. The Model-Risk-AI Lead is the role that operationalizes MRM for the AI era.
The Model-Risk-AI Lead's core responsibilities organize around four domains. The first is the model inventory: maintaining a complete, current inventory of every AI model in production, in pilot, and in development, with documentation of each model's inputs, outputs, intended use, risk tier, validation status, and last-review date. The model inventory is not a technology asset list. It is a governance record that an OCC examiner will review to confirm the institution has comprehensive visibility into its AI exposure. In 2026, that inventory needs to include third-party vendor models, which many banks have historically omitted from their MRM programs on the theory that validation is the vendor's job. OCC Bulletin 2026-13 is clear: the bank's model-risk obligations extend to models it licenses, not just models it builds.
The second domain is validation oversight: the Model-Risk-AI Lead owns the validation program, including the validation methodology, the validation team (internal validators and external validators for high-risk models), the validation schedule, and the findings-remediation process. For AI models, validation has expanded beyond the statistical performance testing that characterized OCC 2011-12-era MRM. Validation now includes explainability testing (can the model's outputs be explained in terms that support adverse-action reason generation?), stability testing (does the model's performance degrade over time or in different demographic subpopulations?), and GenAI-specific validation (for models that generate text, does the output stay within compliant boundaries, or does it introduce hallucinated or inaccurate content?).
The third domain is vendor due diligence and ongoing monitoring: when a business line wants to license an AI tool from a vendor, the Model-Risk-AI Lead's team performs the technical governance review. This review covers the vendor's model documentation (is the methodology disclosed at sufficient depth to allow an independent assessment?), the vendor's validation history (has the model been independently validated, by whom, and when?), the vendor's data practices (what training data was used, are there known disparate-impact findings, and how does the vendor handle model updates?), and the contract terms that govern the bank's access to model information and audit rights. Many AI vendor contracts are structured to protect intellectual property in ways that limit the bank's ability to perform its OCC-required model oversight. The Model-Risk-AI Lead needs the technical knowledge to identify those limitations and the authority to condition commercial progress on contract terms that enable compliance.
The fourth domain is ongoing monitoring and model governance reporting: the Model-Risk-AI Lead produces regular reporting on model performance, validation status, findings, and material model changes for the AI governance committee and the board. This reporting creates the audit trail that an OCC examiner will review. A well-constructed monitoring report shows that the institution is tracking the metrics it committed to tracking in the model's validation documentation, that it is responding to performance degradation before it becomes a compliance problem, and that it is keeping the board informed at a level of substance that reflects genuine board oversight rather than passive acknowledgment.
The organizational positioning of the Model-Risk-AI Lead should be inside the MRM function or, at large institutions, as a dedicated AI sub-function within MRM that reports to the Chief Model Risk Officer or equivalent. The crucial requirement is independence from the business lines that use the models: the same structural independence that OCC 2011-12 established for model validators generally applies with particular urgency to AI models, because business-line pressure to deploy fast is exactly the force that degrades AI governance.
The skill profile for this role combines deep MRM knowledge (model inventory management, validation methodology, findings-remediation processes, OCC examination experience), technical AI literacy (understanding model architectures, training data, feature engineering, and the specific failure modes of ML and GenAI systems), and vendor risk management expertise. Many institutions have promoted senior model validators into this role as AI became the dominant modeling paradigm; the best candidates have also sought AI technical education, either through certification programs or through structured collaboration with the institution's data science team.
The Fair-Lending-AI Lead: Owning the Disparate-Impact and Adverse-Action Thread
The Fair-Lending-AI Lead is the role that closes the gap between fair-lending compliance and AI governance. In the pre-AI bank, fair-lending oversight focused on human underwriting patterns, pricing disparities, geographic redlining risk, and adverse-action reason code quality. Those concerns remain. What AI adds is a new layer of fair-lending risk: models that do not use protected characteristics as inputs can still produce disparate outcomes if their training data, their features, or their optimization targets correlate with protected class. The Fair-Lending-AI Lead owns the program that detects, documents, and remediates those disparities.
The Equal Credit Opportunity Act (ECOA, the federal statute that prohibits discrimination in any aspect of a credit transaction on the basis of race, color, religion, national origin, sex, marital status, age, or receipt of public assistance) and Regulation B (Reg B, the CFPB's implementing regulation for ECOA at 12 CFR Part 1002 that governs adverse-action notice requirements, prohibits discriminatory lending practices, and establishes the specific reason-code standards for credit denials) together define the legal framework the Fair-Lending-AI Lead is working within. The Community Reinvestment Act (CRA, the statute requiring federally insured depository institutions to help meet the credit needs of their communities, including low-and-moderate income neighborhoods) adds a geographic dimension. The Office of the Comptroller of the Currency (OCC), the primary federal regulator for national banks, expects both proactive testing and documented remediation under OCC Bulletin 2026-13.
The Fair-Lending-AI Lead's responsibilities organize around four areas. The first is the disparate-impact testing program: designing and executing regular statistical analyses of AI-touched credit decisions to identify disparities in approval rates, pricing, terms, and adverse-action rates across protected classes. The testing program uses approved proxy methods (BISG, Bayesian Improved Surname and Geocoding, is the most widely accepted method for estimating race and ethnicity when applicants have not self-reported demographic data) to construct the demographic dataset that makes the analysis possible, and uses statistical measures that regulators recognize, including adverse action rate ratios and regression-adjusted disparities, to quantify whether a disparity exists and whether it is statistically significant.
The second area is the less-discriminatory-alternative (LDA) search: when the disparate-impact testing program identifies a statistically significant disparity, the institution is not automatically in violation of ECOA. The legal defense requires demonstrating a business necessity for the practice and establishing that no less-discriminatory alternative achieves comparable business performance. The Fair-Lending-AI Lead owns the LDA search methodology: testing alternative feature sets, alternative model architectures, or alternative decision thresholds to identify whether a modification could reduce the disparity without meaningfully degrading the model's predictive performance. The documentation of the LDA search is the primary fair-lending defense in an examination.
The third area is adverse-action quality: AI-assisted lending creates a new adverse-action risk. When a model contributes to a denial, the adverse-action notice must cite specific, accurate reasons that are grounded in the applicant's actual file data, not vague references to model outputs. The Fair-Lending-AI Lead owns the adverse-action quality review program: sampling AI-assisted denial files on a regular basis, reviewing the reason codes against the actual file data, and confirming that the reasons are accurate, specific, and sufficient. Files where the AI-suggested reason does not match the actual basis for the denial are a compliance finding and a potential ECOA violation. Files where the reason code is too generic to constitute specific notice are similarly deficient.
The fourth area is exam preparation: when a fair-lending examination is scheduled, the Fair-Lending-AI Lead is the primary internal resource for preparing the AI fair-lending record. This includes assembling the testing documentation, the LDA search records, the adverse-action quality review logs, and the model-risk documentation that is relevant to fair-lending analysis. The Fair-Lending-AI Lead also trains business-line staff on fair-lending concepts specific to AI, so that underwriters and loan officers can recognize file-level fair-lending concerns and escalate appropriately.
The organizational placement of the Fair-Lending-AI Lead is typically inside the compliance or fair-lending function, with a strong working relationship with the Model-Risk-AI Lead. The two roles need to share data and findings regularly: the Model-Risk-AI Lead's validation results often inform the Fair-Lending-AI Lead's testing program, and the Fair-Lending-AI Lead's disparate-impact findings often generate Model-Risk-AI Lead action items. At institutions large enough to have separate compliance and model-risk teams, a joint working group led by the CAO creates the coordination mechanism.
How the Three Roles Work Together in Practice
The three roles create an enterprise AI governance posture only when they function as a coordinated system rather than independent silos. The coordination mechanism is the AI governance committee, which the CAO chairs and which the Model-Risk-AI Lead and Fair-Lending-AI Lead both attend and contribute to. But the coordination extends well beyond committee meetings.
Consider how the three roles interact through a single AI deployment lifecycle. A business line proposes using a new vendor AI model for mortgage pre-screening. The CAO's office sets the governance requirements: the model must be reviewed by the Model-Risk-AI Lead before pilot, the Fair-Lending-AI Lead must conduct a pre-pilot disparate-impact assessment using the vendor's testing data, and the deployment cannot advance to full production without a live-pilot fair-lending monitoring result. The Model-Risk-AI Lead performs the technical due diligence on the vendor's methodology, validation history, and contract terms. If the vendor's model documentation is insufficient to perform the required validation, the Model-Risk-AI Lead elevates the concern to the CAO, who conditions commercial progress on additional vendor disclosure. The Fair-Lending-AI Lead reviews the vendor's fair-lending testing results and, if the vendor did not perform testing on a comparable population, designs and executes a supplemental test on the bank's own historical application data.
At the pilot stage, the three roles create a shared monitoring framework. The Model-Risk-AI Lead defines the performance metrics and the thresholds that would trigger a model review or suspension. The Fair-Lending-AI Lead defines the fair-lending monitoring cadence and the disparity thresholds that would trigger an LDA search. The CAO's office establishes the escalation protocol: if a threshold is breached, who is notified, within what timeframe, and what decision authority does the governance committee have relative to the business line.
At the board reporting stage, the CAO presents the integrated view: the model is in production, performing within the defined parameters, and the fair-lending monitoring is current. The Model-Risk-AI Lead and Fair-Lending-AI Lead provide the underlying data for that presentation. If there is a finding, the CAO presents it with the remediation plan. The board's role, as OCC Bulletin 2026-13 defines it, is to ask substantive questions and confirm that the executive team is managing AI risk with rigor. The three-role structure creates the information foundation that makes board oversight substantive rather than ceremonial.
A related benefit of the three-role structure is its effect on vendor relationships. When a vendor knows that a bank has a Model-Risk-AI Lead with validation authority and a Fair-Lending-AI Lead with disparate-impact testing authority, the commercial dynamic shifts. Vendors who have invested in explainability and fair-lending testing welcome that scrutiny because it differentiates them from vendors who have not. Vendors who have not invested in those areas face a choice: invest, negotiate terms that give the bank sufficient oversight access, or lose the deal. The three-role structure, by creating a credible and consistent governance review, raises the floor of vendor quality across the industry.
Titles and reporting lines create the structural accountability, but they do not by themselves create operational accountability. Operational accountability requires defined deliverables, clear authority, and a governance infrastructure that makes the accountability visible and measurable. Each of the three roles needs this infrastructure to function.
For the CAO, the primary accountability mechanism is the board reporting calendar and the AI governance committee charter. The board reporting calendar specifies what the CAO delivers to the risk committee at each meeting: the current model inventory summary, the validation status by risk tier, the most recent fair-lending testing results, any material model incidents, and the forward deployment pipeline with governance status. The AI governance committee charter specifies the CAO's authority: the CAO can pause a deployment pending governance review, can commission an independent validation at the CAO's discretion, and can require a fair-lending gate before any AI model that touches credit decisions advances to production. Authority that is not documented in governance policy is not authority in an examination.
For the Model-Risk-AI Lead, the primary accountability mechanism is the MRM policy framework and the model inventory record. The MRM policy specifies validation standards, including the documentation requirements for each risk tier, the independence requirements for validators, and the finding-severity taxonomy that determines whether a model can remain in production while remediation proceeds. The model inventory record is updated on a defined schedule (at minimum quarterly) and reviewed by the AI governance committee. If a model is in production without a current validation, the record reflects that fact and the Model-Risk-AI Lead owns the remediation timeline.
For the Fair-Lending-AI Lead, the primary accountability mechanism is the fair-lending testing calendar and the adverse-action quality review log. The testing calendar specifies which models are tested for disparate impact in which quarter, at what sample size, using what methodology, and with what threshold for a material finding. The adverse-action quality review log is updated monthly and reviewed by the compliance committee and the AI governance committee. If the quality review identifies a pattern of deficient reason codes on AI-assisted denials, the Fair-Lending-AI Lead owns the remediation plan and the timeline for confirming the pattern is resolved.
A common governance failure is creating the three roles but not connecting them to the institution's existing governance infrastructure. The MRM policy, the fair-lending compliance program, and the board reporting framework were designed before these roles existed. Inserting the three roles requires amending those existing frameworks: adding the CAO to the board-reporting mandate, specifying the Model-Risk-AI Lead's obligations in the MRM policy, and defining the Fair-Lending-AI Lead's testing calendar in the fair-lending compliance program. These amendments are not cosmetic. They are the mechanism by which the three roles generate the governance record that an OCC examination expects to find.
The Talent and Succession Challenge
Each of these three roles requires a hybrid skill profile that was rare in 2025 and remains scarce in 2026. The CAO needs regulatory credibility plus AI strategic fluency. The Model-Risk-AI Lead needs deep MRM expertise plus AI technical literacy. The Fair-Lending-AI Lead needs fair-lending compliance expertise plus quantitative testing capability. None of these profiles can be filled by promoting a strong performer from a single-domain background without a deliberate development investment.
The most common talent pathway for each role reflects where the hybrid skill gap typically appears. For the CAO: most successful early hires are former chief risk officers or chief compliance officers who made a serious investment in AI literacy through education and structured exposure to data science teams, or former technology leaders who spent several years in a highly regulated bank environment developing genuine regulatory knowledge. Promoting from within is preferred where the candidate is credible to regulators and can learn the AI strategy dimension on the job. Hiring externally risks a candidate who has the title vocabulary without the regulatory grounding that the OCC will probe in examination.
For the Model-Risk-AI Lead: the natural development path runs through senior model validation, where the candidate developed the MRM framework knowledge and the examination experience, and then invested in AI technical education, either through a graduate program, a professional certification in machine learning, or a structured rotation through the bank's data science function. The candidate who spent four years as a senior model validator and then spent eighteen months as a technical partner to the data science team building AI models is far better prepared for this role than a candidate with deep AI research credentials who has never run a model-validation review or prepared for an OCC model-risk examination.
For the Fair-Lending-AI Lead: the natural development path runs through fair-lending compliance, where the candidate developed ECOA and Reg B expertise and the analytical skills to conduct disparate-impact testing, and then developed quantitative testing skills either through direct collaboration with the data science team on fair-lending analytics or through a graduate-level statistics or data analysis program. Increasingly, banks are finding candidates with both profiles: former fair-lending analysts who took on quantitative testing responsibilities as AI underwriting expanded and who now have genuine proficiency in both the regulatory and the analytical dimensions of the role.
Succession planning for all three roles should begin the day the roles are filled. The accountability these roles represent does not stop when the incumbent departs, and an examination is not scheduled around a bank's leadership transitions. Each role should have an identified successor or developmental candidate who is receiving structured exposure to the role's core deliverables, so that a transition does not create a governance gap of more than ninety days.
Key Takeaways
- The old functional org chart cannot govern enterprise AI: when AI accountability is distributed across lending, risk, compliance, and technology by default, the questions that matter for OCC Bulletin 2026-13 fall through the seams between functions.
- The Chief AI Officer (CAO) owns the enterprise AI strategy, the cross-functional governance committee, vendor oversight at the strategic level, and the board risk committee relationship; the CAO reporting line must be high enough to give genuine authority to push back on ungoverned deployments.
- The Model-Risk-AI Lead owns the model inventory, the validation program (including third-party models under OCC Bulletin 2026-13), vendor technical due diligence, and the ongoing monitoring and board reporting on model performance and validation status.
- The Fair-Lending-AI Lead owns the disparate-impact testing program using accepted proxy methods such as BISG, the less-discriminatory-alternative (LDA) search process, the adverse-action quality review program, and exam preparation for AI fair-lending records.
- The three roles generate value as a coordinated system through the AI governance committee: the CAO sets deployment gates, the Model-Risk-AI Lead performs technical validation, and the Fair-Lending-AI Lead performs fair-lending testing at each stage of the deployment lifecycle.
- Operational accountability requires more than titles: each role needs documented deliverables, defined authority, and connection to existing governance frameworks including the MRM policy, the fair-lending compliance program, and the board reporting mandate.
- All three roles require hybrid skill profiles that are currently scarce; the most defensible talent pathway promotes domain experts (senior model validators, fair-lending analysts, chief risk officers) who have made a serious and structured investment in AI technical fluency rather than importing pure technologists who must develop regulatory knowledge from scratch.
- Succession planning for all three roles must begin at hire; the accountability cannot tolerate governance gaps of more than ninety days when a role transitions, and examiners do not schedule around leadership changes.
Skill.re