Live 20 practitioner certifications live · First lesson free on every course Back to main site →

The named AI Governance Officer role, and why your organisation must create one in 2026

The role at the centre of your organisation's AI governance programme. What the MeitY Guidelines expect, how the role differs from DPO and CISO, what the Board resolution must contain, and what personal liability looks like when the regime is still voluntary but the forcing functions are already here.

Free preview 12 min read Verified

A friend of mine was appointed Head of AI Risk at a Mumbai broker last March. The Managing Director had read the SEBI Advisory of 5 May 2026 [L1-C1] on a Sunday evening and decided by Monday morning that someone needed to own this. The decision was quick. The role definition was not.

By the time my friend walked into my office six weeks later he had three contradictory job descriptions, two reporting lines (one solid to the Chief Risk Officer and one dotted to the CTO), no written authority to pull a model out of production, and a confused Board that still thought AI governance was the same thing as data protection. He had a title. He did not have a role. The programme stalled.

If you are being considered for an AI governance seat, or you are the person asked to create one, this is the first lesson you must read. The seat is not the DPO seat renamed. It is not the CISO seat extended. It is a new seat with its own authority chain, and the Indian regulators have begun to converge on what it must look like even though the MeitY Guidelines of 5 November 2025 [L1-C2] stop short of naming the role.

The role sits between four existing seats and takes authority from each

The AI Governance Officer draws from four existing roles. From the DPO comes the authority to invoke DPDP Section 10(2)(c) proviso [L1-C3], which requires a Significant Data Fiduciary to observe due diligence to verify that algorithmic software it deploys is not likely to pose a risk to Data Principal rights. This proviso is the single clearest AI-governance hook in Indian statutory law today. The AI Governance Officer runs the diligence; the DPO carries the Section 10 signature.

From the CISO comes the authority to run the SEBI AI Advisory of 5 May 2026 on an active footing. The Advisory expects a Software Bill of Materials for every critical AI application including the open-source stack, Market SOC onboarding and the long-term plan for agentic mitigation. The CISO scopes the perimeter; the AI Governance Officer owns the model-specific items.

From the Chief Risk Officer comes model risk ownership. If the organisation is a bank or NBFC in the eleven categories covered by the RBI Draft on Model Risk [L1-C4], the Board policy on model risk management will name the AI Governance Officer as the custodian for AI and ML models within the policy perimeter.

From the Compliance Head comes regulatory interface authority. When MeitY, SEBI, RBI, IRDAI, DPDP Board or the Ministry of Information and Broadcasting asks a question about an AI system, the AI Governance Officer is the person who answers in the first instance.

This four-way draw explains why the role cannot be absorbed into any one of the existing seats. The DPO cannot answer SEBI\'s SBOM question. The CISO cannot sign a DPDP Section 10 attestation on algorithmic due diligence. The CRO cannot interpret the MeitY 7 Sutras [L1-C5] as a transparency obligation. The Compliance Head cannot run a pre-deployment bias test. One role owns the integration.

What the Board resolution must say

The Board resolution appointing the AI Governance Officer is the single document a MeitY review, a SEBI inspector or a DPDP Board officer will ask for first. It must set out five things.

One, the name, designation and employee identifier of the AI Governance Officer and the reporting line. The reporting line should be a solid line to the Managing Director or an executive director, and a dotted line to the Chairman of the Audit Committee or the Risk Management Committee. Avoid a pure functional reporting line to the CTO. The AI Governance Officer must be able to escalate over the CTO when a model needs to come out of production.

Two, the authority to maintain the AI inventory and the model register. Every AI system in use by the organisation, whether built in-house, procured from a vendor or embedded in a third-party product, enters the register. The AI Governance Officer has the standing authority to inspect each entry.

Three, the authority to require a Data Protection Impact Assessment under DPDP Section 10(2)(c) [L1-C6] and Rule 13 [L1-C7] on any AI system before go-live, and to halt go-live until the DPIA is signed off.

Four, the authority to pull a model out of production on a confirmed incident. This is the kill-switch authority that the RBI FREE-AI Report of 13 August 2025 flags as a committee expectation for banks. Even if your organisation is not a bank, write the authority in. It is the single-most consequential operational power the role carries.

Five, the independence protections. The AI Governance Officer cannot be removed or his authority diluted except by a Board resolution recorded in minutes. His compensation is not linked to the deployment velocity of any business line. He has a direct right of access to the Chairman and to the Audit Committee at any time.

Personal liability exists even in a voluntary regime

The MeitY Guidelines are voluntary. There is no standalone AI penalty regime. But the forcing functions that bite the role are not voluntary. DPDP Section 10 obligations on a Significant Data Fiduciary carry penalties up to Rs 150 crore under the Schedule. SEBI penalty powers for compliance failures under the AML/CFT Framework and the CSCRF are already in force. RBI Section 13 PMLA-style powers do not apply here, but RBI directions under the Banking Regulation Act and the Payment and Settlement Systems Act do. The IT Rules 2026 amendment of 10 February 2026 creates fresh obligations on intermediaries that touch AI-generated content, and failure attracts safe-harbour loss under Section 79 of the IT Act 2000.

The practical consequence is that the AI Governance Officer must create a documented decision trail for every judgment call. Model approved for production. Model held back for bias testing. Model deployed with human-in-the-loop guardrails. Model withdrawn after post-deployment drift. Each decision gets a dated entry in the Board decision log with the specific reasoning. The due-diligence defence lives in these files.

Five failure modes practitioners repeat

Treating the role as "DPO renamed". The DPO owns personal data processing. The AI Governance Officer owns AI systems, which touch personal data in some use cases and do not touch it at all in others. If your mental model is DPO, you will miss model-risk, bias testing and the SEBI SBOM obligation entirely.

Reporting purely to the CTO. The AI Governance Officer must be able to tell the CTO that a model is coming out of production. If the reporting line runs through the CTO, that conversation becomes a negotiation. The dotted line to the Audit Committee is non-negotiable.

No written policy. The internal AI governance policy is the artifact a MeitY review will ask for before the resolution. Without a policy, every decision is undefended. Draft the policy in Week 1, approve it by Board resolution by Week 3.

No AI inventory. If you cannot list every AI system in use in the organisation on one page in under thirty minutes, you do not have a programme. You have a hope.

Hiring the role as a part-time add-on. The role requires full-time attention in the first six months. Treating it as 20 percent of someone\'s week guarantees that neither the model risk nor the DPDP obligation nor the SEBI SBOM gets done.

Your artifact from Lesson 1

Draft the Board resolution appointing the AI Governance Officer for your organisation with the five contents above. Save it in your capstone workbook under Artifact 1. If you are running on Aarti Capital Markets as the course case study, the resolution is already pre-populated. If you are running on your real organisation, write it from a blank. The exercise forces you to put the authority chain in plain English, and that discipline is the muscle every later module will build on.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 11 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 11 paid modules (55 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Lifetime access plus every future update
Inclusive of 18% GST. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
SEBI AI, SEBI AI Advisory HO/13/19/12 (5 May 2026) (SEBI AI Advisory 2026) L1-C1
SEBI Advisory on Emerging Advanced AI Tools for Vulnerability Detection dated 5 May 2026. Applies to over 10,000 regulated entities.
MeitY AI Governance Guidelines 2025, PIB PRID 2186639 (5 November 2025) (MeitY Guidelines announcement) L1-C2
PIB Press Release 5 November 2025 announcing the India AI Governance Guidelines under the IndiaAI Mission.
DPDP x AI, DPDP Act 2023 Section 10(2)(c) proviso (DPDP S.10(2)(c) proviso) L1-C3
Observe due diligence to verify algorithmic software deployed is not likely to pose a risk to Data Principal rights. The single clearest AI-governance hook in Indian law today.
RBI AI, RBI Draft Model Risk Circular (5 August 2024) (RBI Model Risk 2024 draft) L1-C4
RBI draft on Regulatory Principles for Management of Model Risks in Credit, press release 5 August 2024, comments closed 4 September 2024.
MeitY AI Governance Guidelines 2025, Sutra 5 Accountability (Sutra 5) L1-C5
Accountability follows function. Developer, deployer and data provider each answer for their own choices.
DPDP x AI, DPDP Act 2023 Section 10(2)(c) (DPDP S.10(2)(c)) L1-C6
SDF must undertake periodic Data Protection Impact Assessment and audit.
DPDP x AI, DPDP Rules 2025 Rule 13 (DPDP Rule 13) L1-C7
Additional obligations for Significant Data Fiduciary including DPIA every twelve months and periodic independent audit.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: The India AI Governance Perimeter and Why You Are Reading This
Module 2: The MeitY Guidelines, Section by Section
  • The 7 Sutras, one by one, with the Indian context behind each
  • The 6 Pillars across Enablement, Regulation and Oversight, and the two Pillars where you actually spend time
  • Developer, deployer, data provider. Three functions, three parallel sets of duties documented, signed and defended
  • Transparency reporting under Sutra 6, aligned to DPDP, and what a disclosure a regulator can understand actually looks like
  • AIGG, TPEC and AISI. The three institutions, the current state on 9 October 2026 and how to track
Module 3: RBI FREE-AI and Financial-Sector AI
  • The FREE-AI Committee, the Report of 13 August 2025 and the 26 Recommendations that preceded MeitY
  • The Model Risk Management Framework. RBI Draft of 5 August 2024 and the expanded 2026 cycle
  • AI in credit underwriting. Borrower scoring, bias testing and challenger models at an NBFC gold-loan and personal-loan book
  • The AI kill-switch and incident reporting. FREE-AI expectations, the Chapter 5 form and the CERT-In six-hour interface
  • The Bank and NBFC Board policy on AI. The twelve-clause specimen outline
Module 4: SEBI AI Vulnerability Advisory and Market Infrastructure
  • The SEBI AI Vulnerability Advisory of 5 May 2026. HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026
  • Annexure A, ten items. The deep walk through items 2, 6c, 9 and 10
  • Market SOC onboarding. What M-SOC is, what it ingests and how an entity integrates
  • How the AI Advisory expands CSCRF audit scope. project-cyber-suraksha.ai and advisor obligations
  • Running the SEBI AI programme end-to-end on Aarti Capital Markets
Module 5: DPDP x AI
  • Section 10 Significant Data Fiduciary. The six-factor test and why nobody has been notified yet
  • Section 10(2)(c) proviso. Algorithmic due diligence, verbatim text and operational meaning
  • Rule 13. Twelve-month DPIA, independent audit and the Board reporting cadence
  • Rule 7 breach notification. AI incidents, the DPB clock, the MeitY expectation and the CERT-In six-hour window
  • Why DPDP has no Article 22. India chose a de facto automated decision regime through Section 10(2)(c)
Module 6: The AI Governance Officer's Playbook
  • The appointment Board resolution in detail. Five authorities, eleven paragraphs, one specimen
  • The AI inventory and model register. Columns, worked rows, and the "one-page in thirty minutes" test
  • The twelve-clause AI governance policy. Scope to third-party management, one clause at a time
  • The Board reporting cadence and the five KPIs that matter
  • Personal liability and the due-diligence defence. DPDP Schedule, sectoral penalties, Section 79 safe harbour
Module 7: Risk Assessment, DPIA and the Model Lifecycle
  • High-impact decision classification. The method MeitY left to you
  • The AI-specific DPIA. Ten sections that satisfy DPDP Section 10(2)(c) and Rule 13
  • Pre-deployment testing. Bias, robustness and security batteries that satisfy a regulator
  • Post-deployment monitoring. Drift, feedback loops, shadow mode and the thresholds that trigger review
  • Change control, retraining and incident response. Closing the lifecycle loop
Module 8: Transparency, Explainability and Human Oversight
  • User-facing transparency notices. Operationalising Sutra 6 for Aarti Capital's three AI use cases
  • Model cards and datasheets for datasets. The two documents a regulator will ask for first
  • Explainability for high-impact decisions. What SHAP, LIME and counterfactuals buy you, and where they fail
  • Human-in-the-loop oversight. Three stages, one SOP, and how to document that a human actually reviewed
  • Audit trail and immutable logging. Reconstructing a specific AI decision three years later
Module 9: Synthetic Media and the IT Rules 2026 Amendment
  • The new Synthetically Generated Information category under the IT Rules 2026 amendment
  • Labelling and provenance metadata. Watermarks, C2PA and metadata that survives re-encoding
  • The three-hour takedown and the two-hour non-consensual sexual imagery window
  • Deepfake case law. Rashmika Mandanna, Lok Sabha 2024 and Images Bazaar PIL
  • The MeitY advisories of 1 March and 15 March 2024. How India iterates fast
Module 10: Sectoral Deep-Dives: IRDAI, Telecom, Health and Public Services
  • IRDAI AI Working Group and the framework insurers should pre-build
  • The IRDAI 2026 Cyber Security Guidelines and AI as a threat vector
  • The Telecom Cyber Security Rules 2024 and where AI sits in a silent framework
  • TRAI's AIDAI proposal and why MeitY picked AIGG, TPEC and AISI instead
  • Healthcare, education and public-services AI: the gaps and the practitioner playbook
Module 11: The International Reference Layer
  • EU AI Act. The four risk tiers and the phased timeline that quietly binds Indian GCCs
  • NIST AI RMF 1.0 and the GenAI Profile. Four functions and twelve generative risks
  • OECD AI Principles. The common vocabulary that lets a Mumbai team talk to a Munich team
  • ISO/IEC 42001. The voluntary conformity path and the clause-by-clause map to the MeitY 7 Sutras
  • The GCC compliance architecture. One baseline plus two overlays, when EU plus India plus US arrives at once
Module 12: Capstone and Final Exam
  • Build your ten-week AI governance programme. The scope document and the stakeholder map
  • Weeks 1-10 Gantt and the twelve artifacts of the capstone workbook
  • The Board briefing deck and the year-1 operating calendar
  • The 25-anchor exam reference card
  • The final exam. 45 questions from a 70-item pool, 90 minutes, 75 percent pass