| Title | AI Auditor |
|---|---|
| Department | Internal Audit / Risk Assurance / AI Governance |
| Reports to | [Chief Audit Executive / Audit Director / Head of AI Governance] |
| Location | [Remote / Hybrid / On-site] |
| Employment type | Full-time |
| Salary | [Salary range. Postings with a range perform significantly better, and several states require one.] |
Position overview
The AI Auditor provides independent, objective assurance over [Company]'s use of artificial intelligence. This role plans and executes audits of AI systems, models, and the governance processes that surround them, testing whether controls operate as intended across the model lifecycle.
Working closely with internal audit, risk, compliance, data science, and technology teams, the AI Auditor evaluates AI systems against recognized frameworks and regulatory requirements, then reports findings and corrective actions to management.
As AI regulation and conformity expectations mature, the AI Auditor helps the organization demonstrate that its AI is trustworthy, well governed, and audit ready.
Key responsibilities
AI audit planning
- Build a risk-based AI audit plan aligned to the enterprise audit universe.
- Maintain an inventory of AI systems and prioritize audits by risk and regulatory exposure.
- Define audit scope, objectives, and testing approaches for each engagement.
- Coordinate audit timing with model owners and control owners.
Control testing
Design and execute tests over AI governance and technical controls, including:
- Model documentation, approval gates, and change management
- Data quality, lineage, bias testing, and model monitoring
- Access, security, logging, and human oversight controls
- Third-party AI vendor controls and contractual safeguards
Framework and regulatory conformity
Assess AI systems and processes against the NIST AI Risk Management Framework, ISO/IEC 42001, ISO/IEC 42006, the EU AI Act, and internal AI policies, and evaluate readiness for external certification and conformity assessment.
Findings and reporting
- Document findings, root causes, and risk ratings clearly and factually.
- Recommend practical remediation and control improvements.
- Present results to management and the Audit Committee.
- Track corrective actions to closure and validate remediation.
Advisory and standards support
- Advise control owners on effective AI governance controls.
- Support the design of AI conformity and certification programs.
- Contribute to AI audit methodology and testing tools.
- Share lessons learned across audit and risk teams.
Continuous monitoring
Use data analytics and continuous auditing techniques to monitor model performance, drift, incidents, and control health between full audit cycles.
Required qualifications
- Bachelor's degree in Accounting, Information Systems, Computer Science, Data Science, or a related discipline.
- 5 to 8+ years of experience in internal audit, IT audit, technology risk, or assurance, including exposure to AI, machine learning, or data-intensive systems.
- Working knowledge of AI governance frameworks and control testing methods.
- Ability to translate technical AI concepts into clear audit findings.
- Strong analytical, documentation, and stakeholder communication skills.
Preferred certifications
One or more of: CISA, CIA, AIGP, CISM, CRISC, ISO/IEC 42001 Lead Auditor.
Technical knowledge
AI audit and assurance, IT general controls, model risk and model documentation review, bias and fairness testing, data lineage and quality, AI security controls, continuous auditing and data analytics, third-party AI risk, and GRC and audit management platforms.
About [Company]
[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]
Post this role on GRC Careers
Reach professionals who specialize in AI audit and assurance rather than hoping they find you in a general feed. Hand reviewed, live within one business day.
See how others are hiring
Review live AI governance jobs postings to benchmark scope, level, and posted salary before you publish yours.
Stay close to the market
Job alerts
Get new AI governance jobs roles sent to you as they post.
Newsletter
Hiring trends, salary signals, and new templates from GRC Careers.
Frequently asked questions
What does an AI Auditor do?
An AI Auditor provides independent assurance over an organization's AI systems and governance. They plan risk-based audits, test AI controls across the model lifecycle, and report findings and remediation to management and the Audit Committee.
What qualifications and certifications does an AI Auditor need?
Most AI Auditors bring 5 to 8 or more years in internal audit, IT audit, or technology risk, with exposure to AI and data-intensive systems. Common certifications include CISA, CIA, and AIGP, and ISO/IEC 42001 Lead Auditor for conformity work.
What frameworks does an AI Auditor use?
Common reference points include the NIST AI Risk Management Framework, ISO/IEC 42001, ISO/IEC 42006, and the EU AI Act, alongside the organization's own AI policies and control standards.
How is an AI Auditor different from an AI Risk Manager?
The AI Risk Manager owns and manages AI risk within the business, while the AI Auditor independently tests whether risk and governance controls actually operate as intended and reports the results objectively.