| Title | AI Risk Manager |
|---|---|
| Department | Risk Management / AI Governance |
| Reports to | [Chief Risk Officer / Head of AI Risk] |
| Location | [Remote / Hybrid / On-site] |
| Employment type | Full-time |
| Salary | [Salary range. Postings with a range perform significantly better, and several states require one.] |
Position overview
The AI Risk Manager leads the assessment and management of AI risk across [Company]. This role identifies, evaluates, mitigates, and monitors risks arising from AI and machine learning systems throughout their lifecycle.
Working with data science, technology, compliance, security, privacy, and business teams, the AI Risk Manager runs AI risk assessments, maintains the AI risk register, and drives control implementation and remediation.
As AI moves deeper into decision-making, the AI Risk Manager ensures AI risk is understood, measured, and managed within the organization's risk appetite.
Key responsibilities
AI risk assessment
Lead risk assessments across AI and machine learning systems, evaluating risks such as:
- Bias, fairness, and harmful or unintended outcomes
- Model performance, drift, hallucination, and reliability
- Data quality, privacy, and intellectual property
- Security, third-party, and operational resilience risk
Risk framework and register
- Maintain the AI risk register and risk classifications.
- Apply the enterprise AI risk methodology consistently.
- Align AI risk decisions to risk appetite and tolerance.
- Track risks, treatments, and residual risk over time.
Controls and mitigation
- Define and validate controls for prioritized AI risks.
- Partner with model owners on mitigation and remediation.
- Monitor control effectiveness and model health in production.
- Escalate issues that exceed tolerance to leadership.
Regulatory compliance
Support compliance with the EU AI Act, the NIST AI Risk Management Framework, ISO/IEC 42001, and emerging AI regulation by mapping requirements to AI risks and controls.
Third-party AI risk
- Assess AI vendors, tools, and externally sourced models.
- Support due diligence and contractual risk provisions.
- Monitor concentration and dependency risk.
Reporting and monitoring
Produce AI risk reporting, including Key Risk Indicators, incidents, and emerging risks, for leadership and governance committees.
Required qualifications
- Bachelor's degree in Risk Management, Information Systems, Computer Science, Data Science, Business, or a related discipline.
- 7 to 10+ years of experience in risk management, technology risk, model risk, compliance, or governance, including AI or data-intensive systems.
- Experience running risk assessments and managing risk registers and controls.
- Working knowledge of AI and machine learning concepts and lifecycle.
- Strong analytical, stakeholder management, and communication skills.
Preferred certifications
One or more of: CRISC, AIGP, CISM, FRM, PRM, ISO/IEC 42001 Lead Implementer.
Technical knowledge
AI risk management, AI risk assessment, model risk management, risk classification and quantification, control design and testing, third-party AI risk, regulatory mapping, and GRC platforms.
Essential competencies
Risk-based judgment, stakeholder influence, clear communication of risk, structured problem solving, and program discipline.
Success measures: first 12 months
- Implement an AI risk assessment methodology and register.
- Complete baseline risk assessments across priority AI use cases.
- Define and validate controls for high-priority AI risks.
- Align AI risk decisions to risk appetite and tolerance.
- Establish AI risk reporting and Key Risk Indicators.
- Map key AI regulations to risks and controls.
- Stand up third-party AI risk review.
- Improve measured AI risk management maturity.
About [Company]
[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]
Post this role on GRC Careers
Reach professionals who specialize in AI risk management rather than hoping they find you in a general feed. Hand reviewed, live within one business day.
See how others are hiring
Review live AI governance jobs postings to benchmark scope, level, and posted salary before you publish yours.
Stay close to the market
Job alerts
Get new AI governance jobs roles sent to you as they post.
Newsletter
Hiring trends, salary signals, and new templates from GRC Careers.
Frequently asked questions
What does an AI Risk Manager do?
An AI Risk Manager identifies, assesses, mitigates, and monitors AI risk across an organization's models and use cases. They run AI risk assessments, maintain the AI risk register, drive control implementation, and report risk to leadership and governance committees.
What qualifications and certifications does an AI Risk Manager need?
Most AI Risk Managers bring 7 to 10 or more years in risk management, technology risk, model risk, compliance, or governance, including AI or data-intensive systems. Common certifications include CRISC, AIGP, CISM, and FRM.
Who does an AI Risk Manager report to?
The role commonly reports to a Chief Risk Officer, Head of AI Governance, or Chief AI Risk Officer, and works closely with the AI Governance Committee and model owners.
What frameworks does an AI Risk Manager use?
Common reference frameworks include the EU AI Act, the NIST AI Risk Management Framework, ISO/IEC 42001, and ISO 31000, mapped to internal AI risks and controls.