Skip to content

AI talent

AI Governance, Risk and Ethics Lead

Owns policy, risk classification, documentation and audit for AI in production, against the regulation that applies.

The role

What the job actually is.

This role decides what a use case is, under whichever framework the organisation is held to, and what that classification obliges. It covers the documentation that has to exist before a system is allowed near a customer, the register of what is running and who owns it, and the audit trail that proves the controls were real. The useful version of the role works with the engineers rather than at them, because a control that cannot be implemented is a control that will be quietly skipped. The screening question that separates the field is whether they have ever stopped a launch.

What we screen for

The questions that separate the field.

Asked by someone who has built the thing, and designed to catch this role's specific failure rather than to confirm a general impression.

  1. Whether they can classify a use case under a real framework and say precisely what that classification obliges.
  2. Whether they have said no to a launch, and what happened next.
  3. Whether they work with engineers or only produce documents. Ask them to read a system diagram.
  4. How they keep a register current once the first wave of enthusiasm has passed.

The common mis-hire

The one you have probably already made.

A compliance generalist who can cite frameworks and cannot read a system diagram. The policy is written, the register is accurate on the day it is published, and nothing in engineering changes as a result.

In the estate

Where this role works, and what we screen it against.

The layers this family works at, lit. These are the tools we screen against. Naming one says we can test for it, not that we have delivered on it.

Evaluation and observability

Spans every layer. Without it a system is shipped on impressions.

Experience and delivery

Copilots and agents inside a business process, and the interaction design that makes an uncertain system usable.

Orchestration and agents

Where an agent's steps, tools and state are defined, and where its failures are caught before a user meets them.

Models

The models themselves, and the platforms an enterprise hosts them through.

Data and grounding

What the model is grounded in, and the integration work that gets enterprise data to where it can reach it.

Systems you already run

The seven platform desks Yallo staffs. Almost no AI work is greenfield; it lands here.

Role families we place here

Governance, risk and safety

Spans every layer. Named as what governance roles are screened against; what any of them obliges is your counsel's call.

  • EU AI Act
  • ISO/IEC 42001
  • ISO/IEC 23894
  • NIST AI Risk Management Framework
  • OWASP Top 10 for LLM Applications
Role families we place here
Naming a technology here says we screen against it, not that we have delivered on it. The role families on each layer are the ones we place there.

Seniority

What changes between mid, senior and lead.

The grade is a description of what the person owns, not a band. Rates come with the shortlist.

Mid
Maintains the register and the documentation against an agreed classification method.
Senior
Owns the classification method and the control set, and holds the gate on individual launches.
Lead
Owns the governance operating model across the portfolio and is accountable to the board for it.

In a programme

When this role is needed, and what blocks it.

Engaged at design, not at deployment. Classification changes what has to be built, so a governance lead appointed after build produces rework rather than assurance. This is the role most often bolted on late, and the cost lands on the engineering team rather than on the function that was late.

Ask

Send the brief, get a screened AI Governance Lead shortlist.

Tell us the programme, the stack and the timeline.