A global asset manager with $300B AUM is establishing a formal AI Governance Committee for the first time. The General Counsel and CTO are co-sponsoring the initiative. The committee must approve new AI models entering production, manage model risk inventory, and respond to regulatory inquiries about AI use. Which committee composition and charter structure best satisfies both regulatory expectations under SR 11-7 and operational effectiveness for a complex investment firm?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Good governance committees are like a well-designed airplane cockpit — each person has a distinct role, field of view, and set of controls that together cover the whole flight envelope. A tech-only committee can't see regulatory risk; a compliance-only committee can't evaluate model validity. The cross-functional structure with CRO, CTO, Compliance, and an independent validator covers all the flight instruments, while the Board escalation path ensures there's a captain who can take the controls when it matters most.
Full explanation below image
Full Explanation
SR 11-7, the Federal Reserve and OCC's model risk management guidance, provides the most widely adopted framework for AI governance committee structure in financial services. It explicitly requires that model risk management include independent validation (separation of model development from model review), senior management accountability, and Board-level visibility into material model risks. A committee composed solely of technologists (Option A) violates the independence requirement — developers cannot objectively validate their own models — and lacks the investment risk and compliance perspectives needed to assess whether AI model outputs meet fiduciary and regulatory standards.
The correct structure (B) satisfies SR 11-7's requirements across four dimensions: independence (the model validation lead must be organizationally separate from model developers), cross-domain risk coverage (CRO covers investment risk, Head of Compliance covers regulatory risk, CTO covers technical risk), pre-deployment authority (the committee must approve before models go live, not review them after), and Board escalation (SR 11-7 requires the Board or Board Risk Committee to be informed of material model risk). The ongoing monitoring mandate addresses SR 11-7's requirement for model performance tracking after deployment.
Option C (quant-chaired, alpha-focused) is a model performance committee, not a governance committee — it cannot address compliance, legal, or operational model risks. Option D (outsourced annual review) fails on two counts: annual cadence is insufficient for models that may drift or be materially changed on a monthly basis, and third-party certificates do not substitute for internal accountability. Regulators expect the firm's own senior management to own model risk — it cannot be contracted away. The NIST AI RMF 'Govern' function reinforces that AI governance must be embedded in organizational structure with clear accountability chains, not delegated externally.