Last updated: September 27, 2026
By Tom Kenaley, President and Senior Partner, KORE1
A chief data officer job description should state the year-one goal, the reporting line, any duties a regulator expects someone to be named for, what the CIO, CISO, and AI leader keep, and a real pay range. Responsibilities come after that. Most CDO postings flip the order. Strong candidates notice.
A regional bank in Grand Rapids sent us its CDO posting last winter before we started the search. Twenty-three responsibility bullets. I counted. Governance, privacy, architecture, analytics, data literacy, “AI enablement,” vendor management, a data catalog, a data quality program, a data culture. It read like a table of contents for a textbook. A thick one.
The first finalist we put in front of them asked a question on the second call that I still think about. “Which of these twenty-three do I actually get to decide?”
Nobody had an answer ready. Fair enough. So we did the exercise together, on a shared screen, line by line. Next to every bullet we typed the name of whoever owned that thing today. The CISO owned access control. The CIO owned the warehouse contract and the platform team. Compliance owned the privacy program, and a vice president in risk ran the regulatory reporting data that the examiners actually looked at. When we were done, four of the twenty-three bullets had no other name next to them.
Four.
Now, that posting wasn’t dishonest. Not really. It was a list of topics the new executive would care about, written by a committee, and a senior candidate reads a list like that as a warning. The job that exists inside the building was a lot smaller than the job on the page, and good CDOs have usually been burned by exactly that gap once already. Our CDO hiring guide covers the mandate decisions that sit upstream of the posting. This piece is about the document itself, the one a candidate reads before they ever talk to you, and the template near the bottom is built so the page and the building match.
Bias check before we go further. KORE1 is paid when a CDO is hired through our chief data officer staffing practice. You don’t need us to use anything here. Plenty of companies rewrite their own spec with it and never call. That’s fine.

The Name Next to Each Line
The chief data officer answers for whether an organization’s data can be trusted, protected, and put to use. In practice the seat covers data strategy, governance and quality, privacy and regulatory data obligations, the data platform and the team that runs it, and the data that analytics and AI programs depend on. The job description’s job is to say which of those this CDO owns outright.
Run the Grand Rapids test on your own draft before anything else. Put every responsibility in a list, and next to each one type the name or title of whoever owns it right now. Then sort. Three piles.
- Moves to the CDO on day one. Budget, people, and authority come with it. All three.
- Shared. The CDO sets the standard and someone else still runs the thing. Say that in the posting, in those words, because it is how most governance really works.
- Stays put. Delete the bullet, or turn it into a sentence about who the CDO works with.
The third pile is usually the biggest. Awkward. It’s uncomfortable to see, and I’d rather you find that out before posting than in month nine. A candidate who reads “partners with the CISO on access policy” knows what the relationship is. A candidate who reads “owns data security” and then meets a CISO with a board mandate knows they were misled, and they’ll remember who wrote it.
The exercise surfaces one more thing. Money. If none of the day-one bullets carries a dollar figure or a headcount, the posting is describing an advisor. That can be exactly what you want. Plenty of companies need a senior data strategist and not an executive with a P&L, and our CDO salary guide shows how the pay should drop to match. Just title it and price it that way. Honestly.
Which Duties Are Designated, Not Just Assigned
Most CDO duties are assigned. Some aren’t. The CEO decides the CDO runs the data catalog, and next year a new CEO can decide otherwise. A few duties are different. In some industries a law or a supervisor expects the organization to name a specific person or group as accountable, and when that name goes on a document, an examiner or an auditor may ask that person to explain it.
Those are the lines a serious candidate looks for first. They’re also the lines companies most often leave vague. Why? Mostly because nobody wants to decide in writing whether the new CDO or the existing compliance officer is the one on the hook.
| Setting | What the rule expects | The line your posting has to settle |
|---|---|---|
| U.S. federal agency | 44 U.S.C. 3520 requires each agency to designate a nonpolitical employee as its Chief Data Officer, chosen for demonstrated training and experience in data management and governance | Whether this hire is the statutory CDO, and how the seat works with the agency’s evaluation officer and statistical official |
| HIPAA covered entity | 45 CFR 164.530(a)(1) requires a designated privacy official responsible for the entity’s privacy policies and procedures | Whether the CDO is that privacy official, or works alongside a separate one |
| Bank under BCBS 239 | The board and senior management review and approve the risk data aggregation and risk reporting framework and make sure it has adequate resources | Whether the CDO owns that framework and presents it to the board, or supports a chief risk officer who does |
| Provider of a high-risk AI system in the EU | EU AI Act Article 10 sets data governance and quality requirements for training, validation, and testing data | Whether the CDO’s governance program covers training and test data, or only operational data |
A few notes on that table. Each row hides a detail.
In the federal row, and only there, the title itself is written into law. The statute behind the federal CDO role came in with the Foundations for Evidence-Based Policymaking Act of 2018, and it lists the functions too, from lifecycle data management to acting as the agency’s liaison on statistical data use. Hiring for an agency? Then much of your job description is already written. Copy the statute’s list and then say which parts are real priorities this year.
Next row. HIPAA’s privacy official requirement is one sentence long. It’s also the row we see botched most often. A health system in Nashville we worked with had a privacy officer in compliance, a CDO in the operations org, and a posting for the CDO that said “owns patient data privacy.” Two people believed they owned the same thing. Neither was wrong, exactly. The fix took one sentence in the revised spec. The CDO sets data standards and access patterns and partners with the privacy officer, who stays the designated privacy official.
BCBS 239 is the Basel Committee’s set of principles for risk data aggregation and risk reporting, published in January 2013 and aimed first at the largest, globally systemic banks, though plenty of regional banks borrow the language. The principles put the approval with the board and senior management, not with a named title. So the posting has to say where the CDO sits in that chain. Plainly. At a bank, a CDO who presents the framework to the risk committee is a very different hire from one who maintains the data behind a chief risk officer’s presentation.
The EU row is newer. Its timing is later than most people assume. Under the current text, Article 10’s data governance requirements apply to the Annex III high-risk systems from December 2, 2027. If your company sells AI systems into the EU that could land in that category, a CDO who has never governed a training data set is going to be learning on your time.
None of the four rows apply to you? Good. Leave them out. Don’t pad the posting with regulations the role won’t touch.

What the CDO Doesn’t Own
Every CDO posting needs a short paragraph that says what the role does not own. It’s the most useful paragraph on the page. Almost nobody writes it.
Start with the CIO. That line is the familiar one, and our CIO job description template draws it from the other side. The CIO usually keeps infrastructure, enterprise applications, and the IT operating budget, and the CDO usually owns data standards, data quality, and the data platform’s roadmap even when IT runs the servers under it. Write down which of those two runs the warehouse contract. That one line settles more arguments than any org chart does.
The CISO line is different. It’s about control versus policy. Security owns how access is enforced, monitored, and investigated. The CDO usually owns classification, meaning which data is sensitive and who ought to see it. If your posting says the CDO “owns data security,” expect your CISO to have opinions about that before the finalist does.
Then there’s AI, and here I’d push back on a lot of the 2026 postings I’ve read. Companies that don’t have a separate chief AI officer seat tend to write “own the AI strategy” into the CDO job and move on. Companies that do have one tend to leave AI out of the CDO posting entirely. Both miss. Same direction, too. A CDO almost always owns the data side of AI whether the title says so or not: where training and evaluation data came from, whether the company has the right to use it that way, how long it’s kept, and whether the data a retrieval system pulls from is current and permitted. Models, model risk, and AI product decisions can sit elsewhere. Usually they do.
Say that in two or three sentences and you’ve drawn the line. The NIST AI Risk Management Framework, a voluntary framework released in January 2023, is a reasonable shared vocabulary if your two executives need one, because its Map and Measure functions lean heavily on knowing the data.
One company got this right. A software firm in Tucson we talked to earlier this year had it worked out. Their CDO spec said, roughly, “you own the data our models are trained and evaluated on, including its provenance, consent terms, and retention, and our head of AI owns the models.” The candidates who read that asked much better questions in the first call. One of them told us it was the first CDO posting she’d seen that year that didn’t secretly want two people.
Two Documents: the Search Spec and the Posting
Here’s something the free template sites skip. Most CDO searches produce two documents. They do different jobs.
The search spec, sometimes called a position specification, is the long one. It goes to a short list of targeted candidates, often under NDA, and to the board or the search committee. It can name the reporting line, the team size, the budget, the problems the last CDO left behind, and what the first year is supposed to fix. It can be honest in ways a public page can’t. You chose every reader.
The public posting is another animal. It’s shorter, and it gets read by everyone, including your current data team, your competitors, and the recruiters who call your executives. Plenty of CDO searches never produce one at all. When they do, it needs to be accurate without being revealing. Nothing about the predecessor, no internal politics, and no budget figure you wouldn’t want quoted back to you.
Pay is where the two split hardest. The spec can lay out the whole package. If you post publicly and a state pay-transparency law applies, the posting needs a range too, and in California, Labor Code 432.3 requires employers with 15 or more employees to include a pay scale, meaning a good-faith salary or hourly range, in any job posting. Executive roles don’t get a pass. None. Check the rules in every state where the role could be filled, which for a remote-eligible CDO can be most of them.
Now the numbers. Work from real bands, not from what the last posting said. Our salary guide places base pay at $172,000 to $245,000 for a mid-market CDO, $245,000 to $400,000 at the enterprise tier, and $400,000 to $700,000 at Fortune 500 and heavily regulated employers, before bonus and equity. The federal number sits lower. It’s also broader. In May 2025, BLS data showed a $175,140 median wage for the computer and information systems manager category, which lumps CDOs in with a lot of IT directors, and the agency expects that group to grow 16% between 2025 and 2035. For one metro and level, our salary benchmarking tool is quicker than reading any of this.
The template below is written as a search spec. Trim the bracketed sections marked “spec only” to turn it into a posting. Filling more than one executive seat this year? The CFO version of this template and the chief AI officer job spec follow the same logic for those roles.

Chief Data Officer Job Description Template
Fill in anything inside [brackets]. Parenthetical notes are guidance and come out before anything goes live. Sections marked (spec only) belong in the confidential version and can be cut or shortened for a public posting.
Job Title
[Chief Data Officer / Chief Data and Analytics Officer / Chief Data Officer, Enterprise Data and Governance] (Keep “Chief Data Officer” somewhere in the title so candidates searching for it find the role. Add “and Analytics” only if analytics and BI actually report to this person.)
About the Role
[Company] is a [one line: industry, size, ownership, and where data sits in the business]. We’re hiring our [first / next] Chief Data Officer to [one sentence naming the year-one outcome, such as “put one governed definition of customer, revenue, and claim behind every report the board sees by the end of next fiscal year”]. This role reports to [CEO / COO / CFO / CIO] and is a member of [the executive team / the operating committee / the technology leadership team].
What You’ll Own From Day One
- The enterprise data strategy and its budget of [amount], covering [people, platform contracts, and governance tooling]
- A team of [N] across [data engineering / analytics / data governance / master data / ML platform], with [N] direct reports
- Data governance: data ownership and stewardship, data quality standards, the business glossary, and data classification
- The data platform roadmap on [Snowflake / Databricks / BigQuery / Microsoft Fabric], including the vendor relationship and renewal
- The data used to train, evaluate, and ground our AI systems, including its provenance, usage rights, and retention
- [One or two company-specific items, such as a data product sold to customers, or a pending migration]
Designated Duties
[Delete this section if none apply.] In this role you will [serve as the agency’s Chief Data Officer under 44 U.S.C. 3520 / own the risk data aggregation and risk reporting framework and present it to the board risk committee / work with our designated HIPAA privacy official, who remains in compliance / lead data governance for training and test data in our high-risk AI systems].
Shared Work and Boundaries
You’ll set standards and partner with [the CIO, who owns infrastructure and enterprise applications], [the CISO, who owns access enforcement and security monitoring], and [the chief AI officer / head of AI, who owns models and model risk]. [Name any function you considered giving to this role and decided not to, such as BI reporting staying with finance.]
Year-One Priorities (spec only)
- [Priority one, with a date, such as “retire the three competing customer counts before the Q3 board meeting”]
- [Priority two, such as “renegotiate the warehouse contract, up for renewal in (month)”]
- [Priority three, such as “stand up data classification ahead of the (audit or exam) in (quarter)”]
What You Bring
- [10 to 15+] years in data leadership, including [N] years running a data organization of [size] or larger
- A governance program you built or rebuilt, and the business result it produced
- Experience with [the regulations that apply: HIPAA / GLBA / GDPR / CCPA / BCBS 239 / the EU AI Act]
- Hands-on familiarity with [your platform and tools, such as Snowflake, dbt, and Collibra], enough to make vendor and architecture calls
- A record of working with a [CFO / CRO / general counsel / business-unit president] as a peer, not a requester
Nice to Have
- [Industry experience, such as regional banking or payer-side healthcare]
- [Experience governing AI training and evaluation data]
- [Board presentation experience]
Compensation and Location
Base: [$X to $Y] a year, with a target bonus of [X]% and [equity or long-term incentive]. [Benefits.] Location: [city, with (N) days a week on site / remote in (states)]. (Where a pay-transparency law applies, the public posting needs the range. Work from the bands in the section above.)
Adjust It for Your Setting
The template is general on purpose. Deliberately bland. These are the lines that change most by setting, and none of the edits takes more than a sentence.
| Setting | Lines to change |
|---|---|
| Bank or credit union | Designated Duties names the BCBS 239 framework or your regulator’s equivalent. Shared Work names the chief risk officer. |
| Health system or payer | Designated Duties settles the HIPAA privacy official question. What You Bring asks for clinical or claims data experience. |
| Federal agency | Copy the statute’s CDO functions into What You’ll Own and cut the equity line. |
| Software company with data products | What You’ll Own adds the data product and its revenue. Shared Work draws the line with the CTO and head of AI. |
| Mid-market, first data executive | Year-One Priorities gets shorter and more concrete. Consider whether the seat is full-time at all. |
About that last row. If the honest year-one list is three items and a team of four, you may be writing a posting for a part-time role. Fractional CDO services exist for exactly that stage, and a fractional leader is often the person who writes the permanent spec later, with a lot more information than you have now.
Questions We Get About CDO Postings
What responsibilities belong in a chief data officer job description?
List data strategy and its budget, governance and data quality, the platform roadmap, the team, and the data behind AI systems, but only the pieces this CDO actually owns.
Add any duty a regulator expects someone to be named for, and a short paragraph on what stays with the CIO, CISO, and AI leader. Twenty responsibilities with no owner behind them read as a wish list.
How much experience should the posting ask for?
Ten to fifteen years in data leadership is the common ask, with several of those years spent running a data organization rather than contributing to one.
Years matter less than evidence. Ask for a governance program the person built and the result it produced. A candidate with twelve years and one clear turnaround usually beats one with twenty years of steady maintenance. On degrees, most of the CDOs we place have one, and very few searches actually turn on which one it was.
Our CDO will work at a federal agency. Is the posting different?
Federal law already defines the role, since 44 U.S.C. 3520 requires a nonpolitical Chief Data Officer at each agency and lists that officer’s functions.
Start from that list, then say which functions matter most this year. Federal postings also run through their own hiring rules and pay scales, so the compensation section looks nothing like a private-sector spec.
Is a pay range required on an executive posting?
Often, if the role is posted publicly in a state with a pay-transparency law. California, for one, requires a good-faith pay range in any job posting from an employer with 15 or more employees.
A confidential search spec that goes only to targeted candidates isn’t a job posting in the everyday sense, but ask your employment counsel before relying on that. Most companies we work with share the range early anyway. At this level, hiding it mostly wastes a month.
How long should a CDO job description be?
A public posting runs about 600 to 900 words, and a confidential search spec often runs two to four pages.
Length isn’t the problem. Vagueness is. A three-page spec that names the budget, the team, and the first-year priorities gets read to the end. A one-page posting full of “drive a data-driven culture” doesn’t.
Who should write it, HR or the CEO?
The executive the CDO reports to should write the first draft of the mandate, and HR should shape it into the final document.
When HR writes it alone, you get a competent posting that describes the category. When the CEO writes it alone, you get a vision statement with no budget. The version that works has the hiring executive’s own sentence about year one near the top, and it sounds like a person wrote it. Then the peers named in the Shared Work paragraph read it before it goes anywhere. If the CISO objects to a line, better now. Much better.

Before It Goes Out
One last pass. Go back to the Grand Rapids exercise with the finished draft. Every line in What You’ll Own should have one name next to it, and the name should be the new CDO’s. The designated duties should be settled in writing. The paragraph on what the CDO doesn’t own should be something your CIO and CISO would read without reaching for a pen.
If it passes, the posting is describing a job that actually exists, and that’s most of what a strong candidate checks for. Most, not all. The rest shows up in the interview loop, where our interview questions for CDO finalists pick up where the spec leaves off.
Permanent CDO searches run through our direct hire practice, and KORE1 has recruited technology executives since 2005. Of the people we seat, 92% are still employed by that client twelve months on. For a role with this much turnover, I’d put a good share of that on getting the spec right before anyone applies.
If you have a CDO spec in draft, send it to our executive search team. We’ll mark up the lines with no name next to them. Then it comes back to you.

