The DPO: the one role here that isn't even in the banking rulebook.
Every other role on this roster exists because of the SM&CR. The DPO exists because of a completely different regime (UK GDPR), which makes it a genuinely different kind of entry: not a Senior Management Function, but a role a digital-only, continuously-monitoring retail bank is highly likely to need in practice regardless.
Last reviewed: 2026-07-24
Independent oversight of data protection, not operation of it.
UK GDPR Article 37 requires a DPO wherever core activities involve large-scale, regular and systematic monitoring, or large-scale special-category processing. A bank running continuous AI-driven transaction monitoring and profiling sits squarely in that territory, even though the precise legal trigger depends on the exact processing design. The DPO advises on and challenges Data Protection Impact Assessments for high-risk automated systems, acts as the contact point for the ICO and data subjects, and monitors UK GDPR/Data Protection Act 2018 compliance, independently of the systems doing the actual processing, for the same conflict-of-interest reason Internal Audit can't audit itself.
The processing itself, not the independent check on it.
The profiling, monitoring, and automated decisioning systems the DPO oversees can be highly automated. What can't move to the system being overseen is the independent assessment of whether that system's processing is lawful, proportionate, and safeguarded. The DPO has to sit outside it, structurally, the same way Internal Audit can't check the function it's embedded in.
The artefacts that prove independent oversight happened.
- Data Protection Impact Assessments for significant automated-decision systems.
- The Article 30 record of processing activities.
- Breach notification decisions and the 72-hour ICO notification clock.
Article 37(6) explicitly allows a service-contract DPO.
Unlike the MLRO, UK GDPR doesn't require this to be an employee: a firm can appoint a DPO "on the basis of a service contract." That's why this role sits in the control architecture's outsourceable-function tier alongside Internal Audit, not the mandatory tier: the independent oversight has to exist, but the specific human providing it doesn't have to be on the payroll.
Sources
[20] Guidance on AI and data protection (automated decision-making), ICO. [23] Data protection officers: accountability and governance guidance, ICO. Neither citation has been independently re-confirmed by Axiom Verity this session. See the hub's What's Still Open section.
One of nine role perspectives.
CEO, CRO, COO, Head of Internal Audit, Compliance Oversight, and the NEDs each get the same treatment as research progresses.