Skip to content
AGJ, the AI governance job board
Menu

Executive job description template

Chief AI Risk Officer (CAIRO)

The Chief AI Risk Officer is the organization's senior authority on AI risk governance, owning enterprise AI risk across the full model lifecycle. This template reflects how the role is scoped at regulated enterprises standing up AI oversight today. Replace the highlighted fields with your specifics, trim what does not apply, and post.

Download PDF Download reference sheet View & download on Scribd

TitleChief AI Risk Officer (CAIRO)
DepartmentEnterprise Risk Management / AI Governance / Executive Leadership
Reports to[Chief Executive Officer / Chief Risk Officer / Board Risk Committee]
Location[Remote / Hybrid / On-site]
Employment typeFull-time
Salary[Salary range. Postings with a range perform significantly better, and several states require one.]

Position overview

The Chief AI Risk Officer (CAIRO) provides executive leadership for [Company]'s enterprise AI risk management program. This role is responsible for identifying, assessing, mitigating, monitoring, and reporting risks associated with artificial intelligence systems throughout their lifecycle.

The CAIRO partners closely with executive leadership, legal, compliance, cybersecurity, privacy, data governance, technology, internal audit, and business leaders to ensure AI technologies are deployed responsibly, ethically, securely, and in alignment with organizational objectives and regulatory requirements.

As AI becomes increasingly integrated into business operations, the Chief AI Risk Officer serves as the organization's senior authority on AI risk governance and helps build a culture of responsible innovation.

Key responsibilities

Enterprise AI risk strategy

AI risk assessments

Lead enterprise assessments involving generative AI, machine learning models, autonomous systems, third-party AI vendors, foundation models, large language models (LLMs), AI agents, and decision automation systems. Evaluate risks including:

Governance

Regulatory compliance

Monitor and implement requirements related to the EU AI Act, NIST AI Risk Management Framework, ISO/IEC 42001, ISO 31000, ISO 27001, OECD AI Principles, state AI legislation, and emerging global AI regulations.

Cross-functional leadership

Partner with Information Security, Privacy, Legal, Compliance, Internal Audit, Enterprise Risk, Technology, Procurement, Data Governance, Human Resources, and business unit leaders.

Third-party AI risk

Monitoring and reporting

Develop enterprise reporting covering Key Risk Indicators (KRIs), AI incidents, model performance, emerging threats, regulatory developments, executive dashboards, Board reporting, audit findings, and corrective action tracking.

Incident response

Lead response efforts involving AI failures, unauthorized AI usage, model compromise, data leakage, ethical concerns, high-risk AI incidents, and regulatory inquiries.

Program development

Build and maintain the AI Risk Register, AI Controls Library, AI Risk Taxonomy, AI Governance Framework, risk assessment methodology, risk scoring models, AI approval workflow, AI risk metrics, and AI policy library.

Required qualifications

Preferred certifications

One or more of the following: Certified in Risk and Information Systems Control (CRISC), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Internal Auditor (CIA), Certified Information Systems Auditor (CISA), Project Management Professional (PMP), Certified Data Privacy Solutions Engineer (CDPSE), Artificial Intelligence Governance Professional (AIGP), ISO/IEC 42001 Lead Implementer or Lead Auditor, Professional Risk Manager (PRM), Financial Risk Manager (FRM).

Technical knowledge

Strong familiarity with AI governance, enterprise risk management, AI risk assessments, model risk management, responsible AI, AI security, AI privacy, data governance, LLM governance, AI agent governance, model lifecycle management, vendor risk management, regulatory compliance, AI controls testing, risk quantification, and governance, risk, and compliance (GRC) platforms.

Essential competencies

Strategic leadership, executive communication, Board presentation skills, risk-based decision making, critical thinking, ethical judgment, collaboration, change leadership, program management, regulatory interpretation, analytical problem solving, and negotiation and influence.

Success measures: first 12 months

Why join us

This is an opportunity to shape how artificial intelligence is governed across the enterprise. As Chief AI Risk Officer, you will help ensure AI is deployed responsibly while enabling innovation, protecting stakeholders, and strengthening organizational resilience in an evolving regulatory landscape.

About [Company]

[Two or three sentences about your organization, the maturity of your AI program, and what the first year looks like. Executive candidates in this field respond to honesty about whether they are joining a build or an established function.]

Post this role on GRC Careers

Reach executives who specialize in AI risk and governance rather than hoping they find you in a general feed. Hand reviewed, live within one business day.

Post this role

See how others are hiring

Review live AI governance and risk leadership postings to benchmark scope, level, and posted salary before you publish yours.

Browse GRC leadership jobs

Stay close to the market

Frequently asked questions

What does a Chief AI Risk Officer (CAIRO) do?

The Chief AI Risk Officer is an organization's senior authority on AI risk governance. They own the enterprise AI risk management framework and identify, assess, mitigate, monitor, and report risks across the full AI lifecycle, from generative AI and large language models to third-party and autonomous systems.

What qualifications and certifications does a Chief AI Risk Officer need?

Most CAIROs bring 12 to 15 or more years in enterprise risk, technology risk, cybersecurity, model risk management, or governance, including at least 5 years leading programs. Common certifications include CRISC, CISSP, CISM, CISA, AIGP, and ISO/IEC 42001 Lead Implementer or Lead Auditor.

Who does a Chief AI Risk Officer report to?

The CAIRO typically reports to the Chief Executive Officer, the Chief Risk Officer, or the Board Risk Committee, and usually chairs or co-chairs the AI Governance Committee.

What frameworks does a Chief AI Risk Officer use?

Common reference frameworks include the EU AI Act, the NIST AI Risk Management Framework, ISO/IEC 42001, ISO 31000, ISO 27001, and the OECD AI Principles, alongside emerging state and global AI regulation.