Talent Radar · Cybersecurity — India needs 250K+ security pros by 2028; supply covers about a third.

Get the report
AI in the workplace

BFSI GCCs are hiring an ‘AI risk’ layer no one budgeted for

A new seat between the model and the regulator. Where it reports, and why it’s hard to fill.

By Sachith Rai 7 min read
Colleagues reviewing a laptop by a large window

Draft. Figures marked like this are illustrative and pending verification against Recruise placement data & Sachith sign-off before publication.

Key takeaways

  1. A new seat is opening in BFSI GCCs: an ‘AI risk’ layer that sits between the model and the regulator — and almost no one budgeted for it.
  2. It’s hard to fill because it needs model fluency and regulatory credibility at once — two profiles that rarely live in one person.
  3. Where it reports decides whether it works: too close to the builders and it’s captured, too far and it’s ignored.
01

The seat between the model and the regulator.

As BFSI GCCs move AI into workflows that touch decisions a regulator cares about, a gap opens that the existing structure doesn’t cover. The model risk team understands models but not always the way this generation of them behaves. The compliance function understands the regulator but not the internals of the system. Between them sits a decision no one currently owns: is this AI use defensible, and who says so.

That gap is becoming a seat. We’re seeing BFSI centres stand up an ‘AI risk’ role — the person accountable for how AI is used against the standard a regulator will hold them to. It’s appearing quietly, often before there’s a budget line for it, because the need showed up faster than the annual plan could.

“Every BFSI centre scaling AI eventually discovers it needs a person between the model and the regulator. The ones that discover it in an audit paid the most to learn it.”

Sachith Rai · MD & Founder, Recruise

02

Why it’s so hard to fill.

The role is difficult because it demands two things that rarely coexist in one candidate. It needs enough model fluency to genuinely understand what the system is doing — not a slide-deck understanding, but a working one. And it needs enough regulatory scar tissue to know what will and won’t survive scrutiny. The pool of people who have both, at the seniority to be credible with both sides, is thin.

The failure mode is hiring for one half. A pure risk-and-compliance profile can’t challenge the model on its own terms; a pure technical profile doesn’t carry weight with the regulator or the board. The centres that fill the seat well tend to accept a longer, more selective search rather than compromise on one side of the requirement.

03

Where it reports is the whole design.

Reporting line makes or breaks this role. Place it under the team building the models and it gets captured — its independence is compromised the moment it’s judging its own colleagues’ work. Place it too far from the build, buried deep in a control function, and it’s out of the loop until decisions are already made. Either way, the seat exists on paper and does nothing in practice.

The centres that get it right give the role real independence and real proximity at once — close enough to the work to see it early, structurally separate enough to say no. Getting that line right is as much a part of the hire as the candidate, and it’s the part that’s easiest to get wrong under time pressure.

The Signal · Weekly

One pattern worth knowing, every week.

The Signal is our weekly read on the senior GCC talent market — one chart, one pattern, no noise. Written from live placement data.