Skip to content
AGJ, the AI governance job board
Menu

Job description template

AI Auditor

The AI Auditor gives your organization independent assurance that its AI systems are governed, controlled, and compliant. This template reflects how the role is scoped at enterprises building AI audit and conformity programs today. Replace the [highlighted fields] with your specifics, trim what does not apply, and post.

Download PDF Download reference sheet

TitleAI Auditor
DepartmentInternal Audit / Risk Assurance / AI Governance
Reports to[Chief Audit Executive / Audit Director / Head of AI Governance]
Location[Remote / Hybrid / On-site]
Employment typeFull-time
Salary[Salary range. Postings with a range perform significantly better, and several states require one.]

Position overview

The AI Auditor provides independent, objective assurance over [Company]'s use of artificial intelligence. This role plans and executes audits of AI systems, models, and the governance processes that surround them, testing whether controls operate as intended across the model lifecycle.

Working closely with internal audit, risk, compliance, data science, and technology teams, the AI Auditor evaluates AI systems against recognized frameworks and regulatory requirements, then reports findings and corrective actions to management.

As AI regulation and conformity expectations mature, the AI Auditor helps the organization demonstrate that its AI is trustworthy, well governed, and audit ready.

Key responsibilities

AI audit planning

Control testing

Design and execute tests over AI governance and technical controls, including:

Framework and regulatory conformity

Assess AI systems and processes against the NIST AI Risk Management Framework, ISO/IEC 42001, ISO/IEC 42006, the EU AI Act, and internal AI policies, and evaluate readiness for external certification and conformity assessment.

Findings and reporting

Advisory and standards support

Continuous monitoring

Use data analytics and continuous auditing techniques to monitor model performance, drift, incidents, and control health between full audit cycles.

Required qualifications

Preferred certifications

One or more of: CISA, CIA, AIGP, CISM, CRISC, ISO/IEC 42001 Lead Auditor.

Technical knowledge

AI audit and assurance, IT general controls, model risk and model documentation review, bias and fairness testing, data lineage and quality, AI security controls, continuous auditing and data analytics, third-party AI risk, and GRC and audit management platforms.

About [Company]

[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]

Post this role on GRC Careers

Reach professionals who specialize in AI audit and assurance rather than hoping they find you in a general feed. Hand reviewed, live within one business day.

Post this role

See how others are hiring

Review live AI governance jobs postings to benchmark scope, level, and posted salary before you publish yours.

Browse AI governance jobs

Stay close to the market

Frequently asked questions

What does an AI Auditor do?

An AI Auditor provides independent assurance over an organization's AI systems and governance. They plan risk-based audits, test AI controls across the model lifecycle, and report findings and remediation to management and the Audit Committee.

What qualifications and certifications does an AI Auditor need?

Most AI Auditors bring 5 to 8 or more years in internal audit, IT audit, or technology risk, with exposure to AI and data-intensive systems. Common certifications include CISA, CIA, and AIGP, and ISO/IEC 42001 Lead Auditor for conformity work.

What frameworks does an AI Auditor use?

Common reference points include the NIST AI Risk Management Framework, ISO/IEC 42001, ISO/IEC 42006, and the EU AI Act, alongside the organization's own AI policies and control standards.

How is an AI Auditor different from an AI Risk Manager?

The AI Risk Manager owns and manages AI risk within the business, while the AI Auditor independently tests whether risk and governance controls actually operate as intended and reports the results objectively.