AI talent
AI Governance, Risk and Ethics Lead
Owns policy, risk classification, documentation and audit for AI in production, against the regulation that applies.
The role
What the job actually is.
This role decides what a use case is, under whichever framework the organisation is held to, and what that classification obliges. It covers the documentation that has to exist before a system is allowed near a customer, the register of what is running and who owns it, and the audit trail that proves the controls were real. The useful version of the role works with the engineers rather than at them, because a control that cannot be implemented is a control that will be quietly skipped. The screening question that separates the field is whether they have ever stopped a launch.
What we screen for
The questions that separate the field.
Asked by someone who has built the thing, and designed to catch this role's specific failure rather than to confirm a general impression.
- Whether they can classify a use case under a real framework and say precisely what that classification obliges.
- Whether they have said no to a launch, and what happened next.
- Whether they work with engineers or only produce documents. Ask them to read a system diagram.
- How they keep a register current once the first wave of enthusiasm has passed.
The common mis-hire
The one you have probably already made.
A compliance generalist who can cite frameworks and cannot read a system diagram. The policy is written, the register is accurate on the day it is published, and nothing in engineering changes as a result.
In the estate
Where this role works, and what we screen it against.
The layers this family works at, lit. These are the tools we screen against. Naming one says we can test for it, not that we have delivered on it.
Evaluation and observability
Spans every layer. Without it a system is shipped on impressions.
Experience and delivery
Copilots and agents inside a business process, and the interaction design that makes an uncertain system usable.
Orchestration and agents
Where an agent's steps, tools and state are defined, and where its failures are caught before a user meets them.
Models
The models themselves, and the platforms an enterprise hosts them through.
Data and grounding
What the model is grounded in, and the integration work that gets enterprise data to where it can reach it.
Systems you already run
The seven platform desks Yallo staffs. Almost no AI work is greenfield; it lands here.
Governance, risk and safety
Spans every layer. Named as what governance roles are screened against; what any of them obliges is your counsel's call.
- EU AI Act
- ISO/IEC 42001
- ISO/IEC 23894
- NIST AI Risk Management Framework
- OWASP Top 10 for LLM Applications
Seniority
What changes between mid, senior and lead.
The grade is a description of what the person owns, not a band. Rates come with the shortlist.
- Mid
- Maintains the register and the documentation against an agreed classification method.
- Senior
- Owns the classification method and the control set, and holds the gate on individual launches.
- Lead
- Owns the governance operating model across the portfolio and is accountable to the board for it.
In a programme
When this role is needed, and what blocks it.
Engaged at design, not at deployment. Classification changes what has to be built, so a governance lead appointed after build produces rework rather than assurance. This is the role most often bolted on late, and the cost lands on the engineering team rather than on the function that was late.
Adjacent
The roles this one is confused with.
Ask
Send the brief, get a screened AI Governance Lead shortlist.
Tell us the programme, the stack and the timeline.