Almost nobody working in AI governance today has a degree in it. In most places the degree does not exist. The field went from a handful of jobs to widespread hiring in about two years, which means everyone doing it now came from somewhere else.
That is the opening, and it will not stay open. Right now the people hiring cannot demand a credential nobody has had time to earn. In five years they will.
So the useful question is not whether you are qualified. It is which parts of what you have already done transfer, and what you have to add. That holds whether you are working now or between things. This page answers that, and every resource it points at is free with no account.
What the work actually is
Strip away the language and AI governance is three jobs braided together.
Somebody decides what the organization will and will not do with these systems, and writes it down so it can be followed. That is policy. Somebody checks whether what was written down is what is actually happening. That is audit. Somebody catches the problem before it becomes a headline, a regulator's letter or a lawsuit. That is risk.
None of it is new work. It is what compliance, audit, privacy and risk people have done for decades, pointed at a new object. The object is unfamiliar. The discipline is not. If you want the longer version first, start with what an AI governance career actually involves.
The control environment does not change because the thing being controlled is a model. You still ask who owns this, what happens when it fails, who is watching, and how would we know. An auditor who cannot yet explain a transformer can still find the control nobody owns, and that is most of the job.
Louise Bertrand, who ran institutional risk and internal audit strategy at Harvard University
Where you are coming from, and what carries over
This is the part people get wrong. They assume they are starting at zero. Almost nobody is.
Compliance or regulatory affairs
You already read a regulation and turn it into something an operating team can follow. That is the scarcest skill in this field right now, because the EU AI Act and the NIST AI RMF are long, new, and nobody has finished translating them into practice. You need the vocabulary of machine learning, not a new profession. Start with the EU AI Act readiness companion and the NIST AI RMF companion.
Internal audit
You have the hardest part already: sampling, evidence, and testing a control rather than accepting an assertion. ISO/IEC 42001 is an auditable management system standard and it will look familiar within an afternoon.
The first AI audit I sat in on, the framework was new and the questions were the ones I had been asking for ten years. What changed was that I had to learn to ask them about training data.
Stephan Pochet, a decade in internal audit and risk advisory
Privacy
You are the closest of anyone. Data minimization, purpose limitation, lawful basis, impact assessments. AI governance is largely a privacy program with model behavior added. CIPM and CIPP holders move fastest, and AIGP was built for this transition. The privacy career guides map the rest.
Security
You know threat modeling and how to think about an adversary. Model security, prompt injection, data poisoning and supply chain risk in model provenance are live problems with too few people on them. CISSP and GSEC both carry over directly, and the cybersecurity career guides connect the two fields.
Law and policy
The drafting skill is the transferable asset. Most organizations have an AI policy copied from somewhere that cannot survive contact with a regulator. Someone who can write a policy that is both defensible and actually followable is worth a great deal, and there are not many of them.
Karen Alphonse, JD, Columbia Law School
Data governance and information management
Lineage, cataloging, retention, quality. Every model failure traces back to data nobody governed. You know where the bodies are buried.
Project and program management in a regulated business
You can run the thing most governance programs die for lack of: someone who coordinates legal, security, data and the business without the whole thing stalling.
If you are not working right now
Nothing above requires you to hold a job today. Read it again as past tense if you need to. The skills you built are still yours whether or not you are currently being paid for them, and an employer is going to ask what you can do, not what your status was last month.
Three things are in your control, and they are the same three whether you are employed or not.
Lean on the work you already did. Whatever you have done, some of it transfers. Look at the section above that matches your old field, not your current situation. Nobody interviewing you will care that there was a gap if you can explain a control you owned.
Get certified. This is the piece you can finish on your own schedule with no employer's permission and no budget. Everything in the Academy is free, the practice questions are free, and the five-question quiz will tell you which one to sit. A credential is the one line on a résumé that does not depend on anyone hiring you first.
Volunteer, and be specific about it. Nonprofits need governance help badly and almost none of them can pay for it. Offer to write a data handling policy, review an AI tool a program team started using, or sit on a board committee looking at risk. They will say yes, because nobody else is offering. You get the thing employers say they want and cannot explain how you are meant to acquire: evidence you have done the work on something real.
If you want to find those organizations, ExecSearches has listed nonprofit roles since 1999, and board and committee openings turn up there too.
The certification plus one piece of real volunteer work beats a year of waiting for somebody to give you a chance in a field that does not have enough people in it.
You do not have to start with a full-time job
Most people picture one route in: apply for a permanent role, get it, start. That is the slowest door and the most crowded one. There are several others, and in a field this short of people they are wide open.
Consulting and advisory work. The largest category by far right now. Consulting roles in GRC and AI governance is where organizations put the work they need done but have not built a permanent job around yet. It is also the fastest way to see several control environments instead of one, which is worth more than a title.
Contract and project work. Fixed-term and project engagements run six or twelve months against a defined piece of work, often a readiness assessment or a remediation. You finish with something specific you can point at.
Fractional and interim. Fractional and interim roles are an organization buying two days a week of someone senior instead of five days of someone they cannot afford. If you have depth from a previous career, this is often the most direct way to be taken seriously quickly.
Remote. Remote GRC and AI governance roles are a large share of what gets posted, which matters if you are not sitting in one of the handful of metros where these jobs cluster.
Fellowships. AI governance and policy fellowships usually carry a stipend and sometimes carry benefits. They are built for exactly the person this page is written for: someone with real experience in another field who needs a structured year inside this one. We are still building that hub out, so check back.
Part-time. Part-time GRC roles exist and are badly under-advertised, which is why that page is thin. If you want part-time, say so in your first email rather than waiting to be offered it.
If you already consult, look at the RFPs. A lot of this work never appears as a job at all. It goes out as a request for proposal. Our RFP hub exists for scoped engagements, and if you run your own practice that is often the better door.
Be clear-eyed about the trade. Some of these carry benefits and some do not, and the posting should say which. If a listing on this board does not tell you what it pays and what comes with it, that is a fault on our side, and telling us about it is a favor.
If you are still in school
You are in a better position than any of the above, and worse in one specific way.
Better, because you can walk in with a credential the people hiring you do not have. Nobody currently senior in this field studied it. Arrive with a governance certification and a working understanding of how these systems fail and you are not junior in the usual way.
Worse, because governance is a judgment discipline and judgment comes from having watched something go wrong. You cannot shortcut that. You can get close to it: an internship in internal audit, compliance, privacy or risk at an organization with a real control environment teaches more in a summer than another course will. Start with Career Readiness and the first résumé bullet builder, which is built for people who do not yet have the experience the posting asks for.
I read these postings every day. The requirements sections are aspirational and the hiring managers know it. They ask for five years in a field that is three years old. What they will actually take is somebody who can show they understand the risk, has a credential that proves they did the reading, and comes from a discipline where being careful is the whole job.
F. Jay Hall, founder, ExecSearches and GRC Careers
What to do this week
- Take the five-question quiz first. If you are not sure which credential fits where you are coming from, Which GRC Certification Is Right for You? asks five questions and tells you. It takes a minute and it is the fastest way to stop guessing.
- Pick the framework closest to what you already do. Everything in the Academy is free with no account, and the certifications guide compares them side by side.
- Play the practice game until you stop guessing. 652 practice questions and 372 flashcards across eleven certifications, free permanently. Try the free practice questions first.
- Read real job postings for the role you want, not summaries. Note every phrase you cannot explain. That list is your syllabus. Use Super Search to filter by function, industry, state and credential.
- Rehearse the interview before you need to. We publish 22 role-by-role interview question sets.
- Check what the work pays with the salary benchmark, and what a credential is worth over time with the career growth calculator.
Interview questions, by the role you are aiming at
Each set is the questions actually asked for that title, with what a strong answer contains.
The certification guides
What each credential covers, what it costs, who it is for, and whether it is worth your time. The full comparison, plus:
If you are coming from security: the reference library
116 free one-page reference sheets, written for people studying for a security certification or crossing into governance from a technical role. No account, no download wall. The full library, or jump straight in:
Where the jobs are, by state
41 state pages, each with the live roles in that state.
Where the jobs are, by role and sector
223 pages crossing job title with industry and metro. If you are staying in your current sector and changing discipline, this is the fastest way to see what exists.
The part nobody says out loud
There is a shortage and it is not resolving on its own. These roles sit open for months. That is not good news for anyone, because governance failures do not stay inside the company that had them.
That is why all of this is free and always will be. Not as a marketing gesture. The profession needs people faster than the usual pipeline produces them, and the fastest available supply is the people already doing adjacent work who have not been told they qualify.
You probably qualify. Start with the framework closest to your desk.
- Founder of ExecSearches, listing executive roles since 1999
- Executive search across nonprofit, higher education and financial services
- Reads the AI governance job market daily
- Ran institutional risk management and internal audit strategy at Harvard University
- Office of Internal Audit at Columbia University; outsourced internal audit lead at KPMG
- CISA, CIA, CHC, CRMC
- JD, International and Comparative Law, Columbia Law School
- AB, Harvard University
- Policy, regulatory compliance and candidate development
- More than a decade in internal audit and risk advisory in financial services
- SOX and regulatory compliance programs
- Public Accounting Certification, Cornell University