EXPOSED
The daily work — pulling exposure data, running VaR and stress scenarios, writing model documentation, assembling regulatory reporting packages for Basel/CCAR/CECL — is screen-based quantitative and narrative production that current AI already drafts at usable quality with a reviewer. What survives is the accountable layer: defining scenarios that matter, challenging model assumptions in front of a risk committee, and owning the judgment call when the model and the market disagree. Licensure is institutional rather than personal (FRM/CFA help but aren't legally required), so the regulatory shield protects the bank's process, not your specific seat.
Headcount grew steadily across the period.
This line is counted by the Bureau of Labor Statistics — the one figure on this page that isn't a judgement of ours. Headcount moves on demand, offshoring, demographics and the business cycle, and automation is one term among several, often not the loudest.
So a falling line is not evidence that AI did it, and a rising one is not evidence that it won't. Both happen in this register: some occupations resist automation and shrink anyway, others are highly automatable and keep growing.
BLS projection, 2024–2034
+6.5% 60,500 → 64,400 on the projections basis
Exposed, but growing
AI can already do a lot of these tasks, and the BLS still expects +6.5% more of these jobs by 2034. Demand for the output is growing faster than the work is being automated away — the mechanism BLS gives for software developers, and the combination people most often misread as an error.
Different clocks. The score is what current AI could do to this work today. The projection is how many of these jobs will exist in 2034. Everything between the two — how fast employers actually adopt, whether demand grows in the meantime — is why they can point opposite ways without either being wrong.
~4,800 openings a year on average, including replacing people who leave.
AnalystBond AnalystRisk AnalystRisk ManagerEstate ExecutorRisk SpecialistModel Risk ManagerSecurities AnalystCredit Risk AnalystMarket Risk AnalystSecurity ConsultantBusiness Risk ManagerSecurities ConsultantFinancial Risk AnalystLoss Control InspectorMarket Risk SpecialistCompliance Risk ManagerEnterprise Risk ManagerEquity Research AnalystLoss Control ConsultantRisk Adjustment AnalystRisk Control ConsultantRisk Management AnalystRisk Management Manager
Holding it up: judgment & accountability . Weakest point: embodiment .
Mixed — a routine tier and a judgment tier At 7 the split is real but lopsided: backtesting, limit monitoring, counterparty exposure aggregation, sensitivity tables and the SR 11-7 model documentation boilerplate are all rules-plus-prose work that tooling handles end-to-end, and only scenario design and the effective-challenge conversation with model risk management resist — enough to keep you above the 6 line, not enough to reach mixed territory.
Fully desk- and screen-based A 1 reflects that everything you touch is a data warehouse query, a Python or SAS job, a Bloomberg terminal and a committee deck; the only physical requirement is being in the room for the quarterly risk committee, and that room is increasingly a Zoom call.
Certification preferred, not legally required FRM, PRM or CFA are hiring signals rather than legal prerequisites, and when a CCAR submission or CECL reserve is wrong it is the CFO and CRO who attest under Sarbanes-Oxley and to the Fed — a 6 rather than 3 because model owner sign-off and the OCC's expectation of a named independent validator do put your name in an examinable file.
Meaningful discretion 13 sits at the top of real discretion because you decide which tail scenarios enter the stress suite, when to override a model that is mispricing a regime shift, and how to word a material weakness — high-stakes ambiguous calls, but ones ratified by a committee and a board risk charter rather than owned alone.
The verdict above describes this occupation as a whole. Almost nobody does the typical version of a job — tick what's actually in your week and see how your own mix sits.
Your task mix speaks to task resistance (7/20 here) — how much of the day's work current AI already does. That is the dimension the boxes above are about.
It cannot move the other three. Liability shield (6/20) is whether the law requires a licensed human to sign. Trust premium (8/20) is whether buyers specifically pay for a person. Judgment and accountability (13/20) is whether the role exists to own consequential calls. Those are facts about the occupation's standing, not about which tasks are in your week — a paralegal who does only trial exhibits still holds no licence. Together they are 27 of this occupation's 35 points (77%).
Embodiment (1/20) is also a property of the work rather than the worker, but we don't tag individual tasks as physical or not, so the picker can't tell you anything about it. That's a limit of this tool, not a claim.
Did we get the list right? Tell us what's missing — the tasks are written from the outside, and you're reading this from the inside.
No occupation passed every test: close enough to financial risk specialists on skills and subject matter, at least 10 points more resistant, no big jump in training, no new licence, no pay cut, and not shrinking on its own. That happens for 223 of the 654 occupations here that aren't SAFE, and it is worth stating plainly rather than leaving the section off.
The usual reason is that exposure travels with the skill profile. The jobs most similar to yours tend to be exposed for the same reasons yours is, so the near neighbours don't clear the gap — and the ones that do are a different kind of work, not a transfer of what you already know. Read that as a limit of this method, not a verdict that you're stuck: it only compares whole occupations, and it cannot see specialisation, industry, or anything you'd bring that isn't in a federal skill survey.
The moves above are yours to make. This is the other half: what would have to change in the world for the occupation itself to score higher. None of it is in any one person's gift, but it is where the floor actually comes from. Scores here are not a one-way ratchet. Only two of the five dimensions — task resistance and embodiment — track what machines can do. The other three track law, what buyers will pay for, and who is answerable, and those move in both directions, often in response to the same pressure AI creates. If every lever below landed, this occupation would score around 52/100, still EXPOSED.
Task-mix shift is genuine here: the occupation has a clear routine tier (data pull, VaR runs, CECL reporting packages, documentation drafting) and a judgment tier (scenario design, effective challenge, breaching-limit escalation). If the routine tier is absorbed and headcount contracts to the challenge-and-attest function, the remaining role's measured resistance rises even as total jobs fall
If SR 11-7 model risk guidance is amended (or Fed/OCC exam manuals updated) to require a NAMED individual model owner and independent validator to personally attest to AI-generated model documentation and validation findings — analogous to the named-officer attestation in CCAR capital plan submissions or the EU AI Act's high-risk 'human oversight' role for creditworthiness models — the sign-off becomes seat-specific rather than institutional
If banking regulators extend a Senior Managers & Certification Regime-style personal accountability rule (UK FCA SMCR already assigns a prescribed responsibility for risk management functions) to US bank risk officers, with enforceable individual sanctions for inadequate challenge of model output
If supervisory findings increasingly cite failure of 'effective challenge' by name — as post-SVB 2023 Fed reviews did for interest-rate risk oversight — and banks respond by making a specific risk specialist the documented owner of limit breaches and scenario-severity calls presented to the risk committee
Narrow route only: if GARP (FRM) or CFA Institute institutes a mandatory continuing-attestation credential that regulators or counterparties begin naming in due-diligence questionnaires for third-party risk validation engagements, external validation buyers may specify a credentialed human. Internal bank employment shows no comparable mechanism
The limit. Embodiment has no route — this is entirely screen work. The structural ceiling is that risk-management liability in the US attaches to the institution and its board, not to a licensed individual seat; without a statutory personal-attestation regime the shield stays weak no matter how consequential the judgment. Even with every lever above, the occupation likely tops out in the 50s, and rising per-seat resistance is compatible with sharply fewer seats.
| New York-Newark-Jersey City, NY-NJ | 12,770 | $139,670 +19% |
| Chicago-Naperville-Elgin, IL-IN | 2,360 | $105,370 -10% |
| Philadelphia-Camden-Wilmington, PA-NJ-DE-MD | 2,340 | $130,880 +12% |
| Dallas-Fort Worth-Arlington, TX | 2,320 | $103,760 -12% |
| Charlotte-Concord-Gastonia, NC-SC | 1,880 | $133,530 +14% |
| Los Angeles-Long Beach-Anaheim, CA | 1,540 | $113,230 -3% |
| Atlanta-Sandy Springs-Roswell, GA | 1,400 | $104,850 -11% |
| Washington-Arlington-Alexandria, DC-VA-MD-WV | 1,400 | $126,510 +8% |
| San Francisco-Oakland-Fremont, CA | 1,380 | $167,440 +43% |
| San Jose-Sunnyvale-Santa Clara, CA | 480 | $166,240 +42% |
| New York-Newark-Jersey City, NY-NJ | 12,770 | $139,670 +19% |
We have no reported case of a named organisation automating this occupation. Not one deployment, not one announcement.
That is worth saying out loud next to a score of 35. The verdict above is about what the work exposes — what current AI could do to these tasks. It is not a claim that anyone has done it. For this occupation those two things have come apart completely: the capability argument is on this page, and the evidence column is empty.
Has AI actually changed your work? One tap, anonymous, and the running tally is public. Nothing else is asked of you.
Rather than check back: get the digest and we'll tell you what changed — or watch a single occupation from its own page.