| Title | AI Assurance Manager |
|---|---|
| Department | Internal Audit / AI Governance / Assurance |
| Reports to | [Chief Audit Executive / Head of AI Governance / Director of Assurance] |
| Location | [Remote / Hybrid / On-site] |
| Employment type | Full-time |
| Salary | [Salary range. Postings with a range perform significantly better, and several states require one.] |
Position overview
The AI Assurance Manager leads independent assurance over [Company]'s AI systems and AI management system, giving management and the board confidence that AI is governed, controlled, and compliant. This role designs and runs AI audits, conformity assessments, and controls testing across the AI lifecycle.
Working with AI governance, risk, security, data, and business teams, the AI Assurance Manager evaluates whether AI controls are designed well and operating effectively, and whether the organization meets emerging AI standards and regulation. The role provides an objective view that complements first and second line governance.
This is a leadership role for an assurance professional who understands both structured audit methodology and how AI systems create risk.
Key responsibilities
AI assurance strategy
- Define the AI assurance approach and risk-based audit plan.
- Set the scope and methodology for AI audits and reviews.
- Coordinate assurance with first and second line governance.
- Report AI assurance results to leadership and the audit committee.
AI audit and controls testing
Plan and execute audits of AI systems and controls across the model lifecycle. Evaluate:
- Governance, accountability, and human oversight
- Data quality, bias, and fairness controls
- Model validation, testing, and monitoring
- Security, privacy, and third-party AI controls
Conformity and standards assessment
Assess conformity against recognized AI standards and frameworks, including ISO/IEC 42001 management system requirements and the NIST AI Risk Management Framework, and support readiness for external certification or regulatory review.
Management system oversight
- Evaluate the AI management system for effectiveness.
- Assess policies, roles, and lifecycle controls.
- Test evidence that governance processes operate as intended.
- Support continual improvement of the AI program.
Findings and remediation
Document findings clearly, quantify AI risk, agree remediation with owners, and track corrective action to closure.
Advisory and enablement
Advise the organization on strengthening AI controls and prepare it for evolving assurance expectations, while preserving audit independence.
Required qualifications
- Bachelor's degree in Information Systems, Data Science, Computer Science, Accounting, or a related discipline. Advanced degree a plus.
- 7 to 10 years of experience in audit, assurance, risk, or controls, including exposure to AI or model risk.
- Strong understanding of AI systems, the model lifecycle, and related risks.
- Experience designing and executing audits or conformity assessments.
- Familiarity with AI standards and frameworks such as ISO/IEC 42001 and NIST AI RMF.
- Ability to work independently and brief senior stakeholders.
Preferred certifications
One or more of: CISA, AIGP, ISO/IEC 42001 Lead Auditor, CIA, CRISC, or equivalent audit or AI governance certification.
Technical knowledge
AI audit and controls testing, conformity assessment, AI management system evaluation, model lifecycle risk, bias and fairness testing, model validation and monitoring, AI security and privacy controls, third-party AI risk, and audit methodology.
Essential competencies
Independent judgment, audit rigor, executive communication, program management, stakeholder influence, and the ability to reason about both controls and AI system behavior.
Success measures: first 12 months
- Define the AI assurance approach and risk-based audit plan.
- Complete a baseline audit of high-risk AI systems.
- Assess conformity against ISO/IEC 42001 and NIST AI RMF.
- Evaluate the effectiveness of the AI management system.
- Establish AI controls testing and reporting.
- Close priority AI control findings.
- Build AI assurance reporting for the audit committee.
- Prepare the organization for external AI certification or review.
About [Company]
[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]
Post this role on GRC Careers
Reach professionals who specialize in AI assurance and audit rather than hoping they find you in a general feed. Hand reviewed, live within one business day.
See how others are hiring
Review live GRC jobs postings to benchmark scope, level, and posted salary before you publish yours.
Stay close to the market
Job alerts
Get new GRC jobs roles sent to you as they post.
Newsletter
Hiring trends, salary signals, and new templates from GRC Careers.
Frequently asked questions
What does an AI Assurance Manager do?
An AI Assurance Manager provides independent assurance that AI systems and the AI management system are governed, controlled, and compliant. They design and run AI audits, conformity assessments, and controls testing across the model lifecycle and report results to leadership.
What qualifications and certifications does an AI Assurance Manager need?
Most bring 7 to 10 years in audit, assurance, or risk, including exposure to AI or model risk. Common certifications include CISA, AIGP, ISO/IEC 42001 Lead Auditor, CIA, and CRISC.
What frameworks does an AI Assurance Manager use?
Common references include the NIST AI Risk Management Framework, ISO/IEC 42001 for AI management systems, ISO/IEC 42006 for bodies auditing those systems, ISO 27001, and the IIA International Standards.
How does AI assurance differ from AI governance?
AI governance sets the policies, roles, and controls for AI, while AI assurance independently tests whether those controls are designed well and operating effectively. Assurance provides an objective view that complements the governance function.