Confidential mandate
Interim Chief Data Officer — Bank Consent and Lineage Repair
Urgent / Replacement
A bank requires an interim data chief after an audit escalation to repair customer-consent controls, establish regulatory lineage and install a permanent-ready data accountability model within ten months.
The mandate
An internal audit traced conflicting customer-consent states across the lakehouse, campaign engine and service channels, prompting the former data head to step aside during the investigation. Regulatory returns also depend on manual reconciliations whose source-to-report lineage is incomplete, leaving the board without a defensible view of data control.
The interim is required in Bengaluru within four weeks for a fixed ten-month term. Recruitment for a permanent data chief begins once the target ownership model is approved in month three, and the contract will end on schedule after a structured five-week transfer regardless of search delays.
Success at handover means priority regulatory reports have field-level lineage and named owners, consent discrepancies have been reconciled to a verified golden source, critical-data quality rules run with evidenced escalation, and the permanent CDO has accepted the control catalogue. The audit committee must also receive an independent effectiveness opinion.
The interim may set enterprise data standards, quarantine unreliable datasets, reassign stewardship duties and direct up to ₹12 crore within the approved repair envelope. Any change to privacy policy, analytics monetisation, permanent organisation grades or spend beyond that ceiling needs executive committee approval; statutory breach notification remains with Legal and the Data Protection Officer.
Building new customer propensity models, replacing the bank's cloud provider and redesigning management information outside the cited regulatory returns are excluded. The seat repairs governed data foundations and must resist being absorbed into every analytics backlog.
Why this seat is open
The audit escalation made continuation of the previous reporting line untenable while facts are established. No internal leader spans consent operations, lineage engineering and executive governance without a conflict in the current design. The CEO wants a fixed-term operator to resolve the defects and create a clean role for permanent appointment.
What you will own
- Establish the authoritative consent record and approve reconciliation logic for channel, campaign and third-party processing states.
- Map field-level lineage for the twelve highest-risk regulatory returns and certify accountable owners at every transformation boundary.
- Issue a critical-data-element standard with thresholds, breach routing, remediation clocks and evidence retained for audit inspection.
- Decide which datasets must be quarantined, corrected at source or retired after quantifying their regulatory and customer impact.
- Reconstitute the Data Council with explicit decision logs, unresolved ownership escalations and monthly control-effectiveness measures.
- Commission an independent test of lineage and consent controls and close every severe exception before the final committee review.
- Package the metadata inventory, stewardship charters, remediation economics and ninety-day successor agenda into an accepted handover.
Candidate qualifications
- Held a chief data, enterprise data governance or data risk director role in a regulated bank or systemically important financial institution.
- Remediated consent or privacy data across multiple customer channels with demonstrable source-system reconciliation.
- Delivered traceable regulatory reporting lineage using business glossaries, metadata tooling and accountable data ownership.
- Led data engineers, governance specialists, privacy operators and business stewards through a board-visible control programme.
- Can distinguish data-control repair from analytics modernisation and defend scope under competing executive demands.
- Brings working knowledge of Indian privacy obligations, banking outsourcing controls and audit evidence expectations.
Non-negotiables
- Can be Bengaluru-based for at least four days a week from the agreed start.
- Has personally signed data-control attestations presented to audit, risk or technology committees.
- No active commercial relationship with the bank's metadata, cloud or campaign-platform suppliers.
- Accepts a fixed ten-month exit and will not condition handover on permanent conversion.
- 49 words maximum. What is the earliest date you can start, and which current commitment must conclude first?
- 49 words maximum. Describe the most complex source-to-report lineage defect you fixed and the control that prevented recurrence.
- 49 words maximum. How would you identify the authoritative consent state when three operational systems disagree?
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.