Hiring · August 2, 2026 · 10 min read
AI governance lead job description template (2026)
A free AI governance lead job description template to copy and adapt: responsibilities, requirements, the AI fluency section nobody else writes, and what to test.
← Part of The five pillars of hiring: what assessments measure
On this page
This page is for the hiring manager, talent lead or General Counsel who has been handed a requisition for an AI governance lead — a role that owns one deceptively simple question: where does this organisation use AI, and can we prove we use it responsibly and lawfully? You are writing this job description now because the rules acquired teeth. The EU AI Act placed employment-related AI in its high-risk tier, and the compliance wave that follows is what turned 'someone should track this' into a named, accountable job. The description is hard to write for three reasons: the title is new and unstable, the market boilerplate is thin, and the role attracts a specific impostor — the candidate who can quote the Act chapter and verse but has never run a model evaluation in their life. This page gives you a copy-paste template plus the sections every competing template leaves out: the AI fluency expectations, and the requirements mapped to what you can actually test.
This is a hiring template, not legal advice. Where it references the EU AI Act, New York City's Local Law 144 or other regimes, it stays at the level our compliance coverage already establishes and adds no legal specifics. For anything binding on your organisation, take proper counsel in the relevant jurisdiction.
The AI governance lead job description template
Copy the sections below, replace the bracketed placeholders, and cut anything that does not apply to your surface area. Keep the title consistent everywhere — if you advertise for an AI governance lead, do not switch to a different label halfway through the loop. The template is written in employer voice so you can paste it almost verbatim.
About the role
[Company] is hiring an AI governance lead to own how we use AI responsibly and lawfully as we deploy it across [hiring / customer operations / product]. You will maintain the inventory of AI systems in use, classify each by risk against the regimes we operate under, run our human-oversight and impact-assessment processes, and keep the audit trails a regulator or customer can query. You will report to [legal / the CTO / the Chief AI Officer] and coordinate legal, engineering and [HR / operations] so obligations become process rather than a slide deck.
Responsibilities
- Maintain a live inventory of every AI system in use — bought, built, or quietly bolted on by a team that never told anyone.
- Classify each system by risk against the EU AI Act and any other regimes we operate under, and re-classify when a tool's use changes.
- Own impact assessments and the human-oversight process: the review step where a person can understand, question and override an automated output.
- Read evaluation reports for the AI systems we deploy, interrogate the results, and flag where a vendor's claims do not survive scrutiny.
- Keep audit trails a regulator or auditor can actually query — what was decided, by whom, on what basis, and when.
- Run intake for new AI tools: the awkward vendor questions asked before anything goes near a candidate, customer or employee.
- Coordinate legal, engineering and [HR] — translating each obligation into a workflow those teams will follow, then checking it holds.
- Field external scrutiny — customer due-diligence questionnaires, auditor requests, board questions — with evidence, not assurances.
- Own the process, not just the policy: success is a governance step teams run because it helps, not one they route around.
Requirements
- Demonstrated experience turning a regulatory or policy obligation into a working process a technical team actually followed.
- Enough regulatory literacy to know what an obligation such as the EU AI Act's high-risk duties requires, and enough judgement to know when to defer to counsel.
- Evaluation literacy: able to read a model-evaluation or bias-audit report critically and distinguish a real signal from a small-sample artefact.
- Cross-functional credibility — engineers, lawyers and [recruiters] take you seriously, which means speaking all three dialects.
- Risk judgement under ambiguity: comfortable deciding whether a use is high-risk when the mapping is genuinely unclear, and defending the call.
- Clear written and spoken communication — able to brief a sceptical executive without hiding behind acronyms.
- A bias toward evidence: you reach for the record that proves a decision because you have been on the receiving end of an audit.
Nice to have
- Experience governing AI in a high-stakes decision context such as hiring, lending or access.
- Familiarity with more than one regulatory regime — for example the EU AI Act alongside New York City's Local Law 144 or a US state law.
- A hands-on background in data, machine learning or engineering that lets you challenge an evaluation rather than take it on trust.
- Experience standing up a governance function from scratch rather than inheriting a mature one.
AI fluency expectations
This is the section every competing template omits, and for this role it is the one that separates the operator from the policy writer. Paste these expectations verbatim:
- Read evaluation reports critically — able to open a model-evaluation or bias-audit result, question the methodology, and say what the numbers do and do not support.
- Hands-on testing of the AI systems you govern — you probe tools yourself rather than governing them from a document, and you have opinions grounded in use.
- Translate between regulator language and engineering reality — turning 'ensure human oversight' into a specific review step engineering agrees to build.
- Work fluently with AI tools to move through a review backlog, while knowing what to delegate to them and where their confident output needs checking.
- Enough technical fluency to hold a working conversation with the people who build the systems, without pretending to be one of them.
The AI fluency section above is the part no competing job description template includes — we checked the ranking templates and not one has it. For an AI governance lead it is not decoration. A person who governs AI systems they cannot read or test is governing a document, not a system. If you copy one section from this page, copy that one.
What we offer
[Company] offers [salary range or 'a competitive, benchmarked package'], [equity / bonus], [remote / hybrid / location] working, and the mandate to build this function properly rather than inherit someone else's shelved policy. You will have the authority to convene legal, engineering and [HR], and a leadership team that treats governance as a design input rather than a box-tick. [Add benefits, learning budget, and anything specific to your organisation.]
How do you adapt this template?
Turn the seniority dial with the responsibilities, not the adjectives. A startup deploying one or two AI tools wants a hands-on senior individual contributor who can own the inventory and still read an evaluation; an enterprise across several jurisdictions wants a manager who can convene teams and defend a classification to an auditor. Cut what your surface area does not justify, and delete the boilerplate below outright — it filters out your strongest candidates.
- Degree requirements — a law degree is not the job. Demanding one screens out the operators who learned governance by shipping it.
- Years-of-a-named-tool — the tooling in this field is a year old; 'five years of AI governance platform X' describes almost nobody real.
- A wall of framework acronyms — listing every standard as a hard requirement rewards the candidate who collects certifications, which is exactly the wrong signal.
For scope and reporting-line decisions, and for the full interview loop, read our companion guide on how to hire an AI governance lead — this page is the artefact; that one is the process. If you are writing the advert from scratch, how to write a job description covers the mechanics that apply to any role.
What should you assess instead of trusting the CV?
Map each requirement to something observable, then test that rather than reading it back off a résumé. The template's bullets line up cleanly with the five capability pillars — cognitive, domain, situational judgement, behavioural, and AI fluency — which is a better spine for this role than a keyword filter. A CV tells you a candidate has heard of the EU AI Act; it cannot tell you whether they would catch a flawed evaluation before it reached production.
- Domain and evaluation literacy → have them read a real evaluation or bias-audit report and tell you what it does and does not support.
- Situational judgement → hand them an ambiguous risk-classification call and watch how they reason to a defensible answer.
- Behavioural signals → probe how they behaved when a launch they governed went wrong, using structured interviews so the scoring holds across panels.
- AI fluency → observe how they work with AI tools directly, scored against the 4D framework of AI fluency — Delegation, Description, Discernment, Diligence.
- Cognitive → the whole loop is a reasoning test; keep the tasks job-shaped so you measure applied judgement, not abstract puzzles.
Illustrative weights — configurable per role, locked at the first candidate for comparability.
The most predictive move is a job-shaped work sample: draft an AI-tool intake questionnaire, triage a bias-audit finding, brief a sceptical executive. Score every candidate on one rubric — work sample tests explains why this beats interview polish, and how to assess AI fluency covers reading that signal specifically. You can run the tasks in a realistic AI Sandbox where the tools are genuinely available, or book a demo to see the candidate evaluation built from a job description like the one above.

How do you spot the policy-only impostor?
Every version of this title attracts the same candidate: a CV that is a catalogue of frameworks authored, principles published and committees chaired, with no evidence any of it changed how a single system got built. Policy writing is the visible, photogenic half of governance and the half that fools interviewers. It reads as authority in a deck. It has no operational teeth — a document engineers have never read governs nothing, and a person who can recite the EU AI Act but has never opened an evaluation report is guessing about the systems they are meant to oversee.
The demand your job description should make — and your assessment should verify — is hands-on evidence. Look for the person who can point to a control they designed that a team adopted willingly, walk you through an evaluation they interrogated, and describe an incident post-mortem they ran after a governed system misbehaved. Watch for these red flags in applications:
- Fluent on the letter of the regulation, blank when asked what an evaluation report actually measures.
- Every achievement is a document produced or a framework adopted; none is a process still running a year later.
- Cannot describe a single time they worked shoulder-to-shoulder with engineering on a control, only times they handed one over.
- Talks about AI systems entirely in the abstract, with no sign they have ever tested or used the tools they would govern.
- Reaches for acronyms under pressure instead of a plain-language answer a sceptical VP could follow.
You may not need this role yet. If you run one or two AI tools in a single jurisdiction and your General Counsel or Head of People can hold the whole picture in their head, a dedicated AI governance lead is premature — name a part-time owner and revisit when the surface area grows. Hire too early and you get a governance function with nothing to govern, and someone who justifies the seat by generating process nobody needs.
The compliance calendar is the honest forcing function here. Article 50 transparency obligations under the EU AI Act apply from 2 August 2026, and the high-risk employment obligations from 2 December 2027 under the Digital Omnibus deferral. Those dates, layered on New York City's Local Law 144 and a widening state patchwork, are why the role exists — read the EU AI Act and hiring and Local Law 144 for what the obligations mean in practice, and compliance-first hiring AI for why we treat hiring AI as high-risk AI by design. Write the job description ahead of the deadline, not after the regulator's letter.
A good AI governance lead job description is a spec you can test against, not a wish-list of frameworks. Name the systems the person will govern, demand they can read and test those systems, and assess for the process they shipped rather than the policy they wrote. Do that, and you screen out the impostor who can quote the Act but has never watched a model fail.
Written by
Aayesha Patel · Co-founder, Hanzomon Inc
Co-founder of Hanzomon. Writes about skills-based hiring, fair assessment and building a better candidate experience.