Sourcing by role
How to find an AI governance specialist.
The title is younger than the work. Almost nobody has held it for long, and the genuinely experienced people are working under privacy, model risk, and audit titles instead.
AI governance is the clearest example of a role where searching the job title actively misleads you. The title appeared when regulation created demand, which means adverts arrived faster than careers could form. Anyone claiming ten years in AI governance is describing work they called something else at the time.
That is the opportunity. The people who can do this job have been doing it for years under other names — data protection officers translating GDPR into technical controls, model risk managers validating models under SR 11-7 since 2011, IT auditors testing algorithmic systems. They are more experienced than the title-holders and dramatically less contested.
Job titles worth searching
Grouped by what the person actually does, because searching all46 at once produces a result set you cannot triage. Decide which group you need first — that decision does more for the search than any string below.
Emerging governance titles
The titles job adverts now use, and the ones fewest people actually hold with meaningful tenure. Searching only these returns a very small pool, heavily weighted toward people who adopted the title recently. Treat them as a starting point rather than the search.
- AI Governance Specialist
- AI Governance Lead
- Responsible AI Lead
- AI Ethics Officer
- AI Policy Manager
- AI Compliance Manager
- Head of AI Governance
- AI Risk Manager
- Algorithmic Accountability Lead
Privacy and data protection
The single richest source of genuinely qualified candidates. GDPR built a profession of people who translate regulation into technical controls, run impact assessments, and argue with engineering teams — which is exactly the AI governance job with a different regulation attached. Most transition well.
- Data Protection Officer
- DPO
- Privacy Counsel
- Privacy Engineer
- Privacy Programme Manager
- Data Governance Manager
- Information Governance Lead
- Chief Privacy Officer
Model risk and financial services
Banking has governed models under SR 11-7 since 2011, which means this sector has a decade-plus head start and a genuine professional discipline around model validation. These candidates are the most underrated group in the market and rarely think of themselves as AI governance people.
- Model Risk Manager
- Model Validation Analyst
- Model Risk Officer
- Quantitative Risk Analyst
- Model Governance Lead
- Credit Model Validator
- SR 11-7 Specialist
Audit and assurance
Algorithmic audit is becoming a defined practice, and the people doing it come from IT audit and assurance backgrounds. Where a role is genuinely about verification and evidence rather than policy authorship, this group is a better fit than the ethics-titled candidates.
- Algorithmic Auditor
- AI Auditor
- IT Auditor
- Technology Risk Auditor
- Assurance Manager
- Controls Assurance Lead
- Third Party Risk Manager
Research and technical
People who work on fairness, interpretability, and evaluation from the technical side. A genuinely technical governance role — one that requires reading model cards critically or designing evaluations — needs this group rather than a policy background. They are usually in research organisations rather than compliance functions.
- Responsible AI Researcher
- ML Fairness Researcher
- AI Safety Researcher
- Model Evaluation Scientist
- Interpretability Researcher
- Trustworthy AI Engineer
- AI Assurance Engineer
- Red Team Lead (AI)
Policy and legal
Where the regulatory expertise sits. Technology policy specialists and regulatory counsel understand how legislation is drafted and interpreted, which matters enormously when the rules are new and untested. Weaker on technical implementation, so pair accordingly.
- Technology Policy Manager
- Regulatory Affairs Manager
- Tech Policy Analyst
- Digital Regulation Specialist
- Public Policy Manager
- Regulatory Counsel
- Compliance Counsel
Frameworks and credentials that signal capability
AI-specific certifications are new and thinly held, so the useful signals are mostly borrowed from adjacent disciplines — privacy credentials, framework implementation experience, and in US banking, model validation under SR 11-7.
| Credential | Full name | Region | What it tells you |
|---|---|---|---|
| AIGP | Artificial Intelligence Governance Professional | International (IAPP) | The first widely recognised AI governance certification, launched recently. Holding it signals current commitment to the field, though the population is small and nobody has held it long. |
| CIPP/E | Certified Information Privacy Professional, Europe | Europe (IAPP) | The established privacy credential. A strong proxy for regulatory literacy, and far more common than any AI-specific certification. |
| CIPM / CIPT | Privacy Programme Management / Privacy Technologist | International (IAPP) | CIPM covers running a programme, CIPT the technical side. CIPT holders in particular translate well to AI governance work. |
| EU AI Act | EU AI Act familiarity | European Union | Not a certification but the single most valuable knowledge area. Risk categorisation, prohibited practices, and conformity assessment obligations are what most hiring is actually about. |
| ISO 42001 | AI management system standard | International | The AI equivalent of ISO 27001. Lead auditor and lead implementer qualifications exist and are becoming a practical differentiator. |
| NIST AI RMF | NIST AI Risk Management Framework | United States | The dominant voluntary US framework. Experience applying it is the closest US equivalent to EU AI Act familiarity. |
| SR 11-7 | Federal Reserve model risk guidance | United States, banking | The reason financial services has a mature model governance discipline. Candidates with SR 11-7 validation experience have been doing this work since long before it was called AI governance. |
| CISA | Certified Information Systems Auditor | International (ISACA) | Relevant where the role is genuinely audit-shaped. Signals evidence-gathering and controls testing discipline rather than policy authorship. |
Where AI governance people actually are
IAPP is the centre of gravity. Its conferences, certification directories, and publications identify practitioners with real standing in privacy and increasingly in AI governance, and the community is unusually willing to be found — the field is new enough that people are actively building reputation.
For technical governance roles, the research literature is the better source. FAccT and the responsible AI workshops attached to major machine learning conferences publish work on fairness, interpretability, and evaluation, with author affiliations attached. Someone with papers in this area understands model behaviour in a way a policy background does not supply.
Two underused sources deserve mention. Financial services model risk functions have run genuine model governance for over a decade under SR 11-7, and those candidates almost never appear in AI governance searches. And people leaving data protection authorities and regulators understand enforcement from the inside — a small population, rarely approached, and disproportionately valuable when regulation is new and untested.
Boolean search strings
Written to be pasted as-is. Each one is built around an intent rather than a platform, since the useful question is what you are trying to find, not which site you happen to be on.
LinkedIn profiles, direct X-ray
Google (LinkedIn)site:linkedin.com/in/ ("AI governance" OR "responsible AI" OR "AI ethics") ("EU AI Act" OR "NIST AI" OR CIPP) "{city}"More useful here than for most roles, because people who have adopted these emerging titles tend to be deliberately visible about it — the field is new enough that practitioners are building reputation publicly. Still subject to LinkedIn no longer indexing titles and locations, so pair it with the framework terms rather than relying on the title alone.
Privacy professionals as the adjacent pool
Google("data protection officer" OR "privacy counsel" OR CIPP OR CIPM) ("AI" OR "automated decision" OR "algorithmic") -jobs -courseThe highest-yield search on this page. GDPR built a profession of people who translate regulation into technical controls — the same job with a different regulation. Requiring the AI framing filters for those already making the transition.
Model risk specialists from financial services
Google("model risk" OR "model validation" OR "SR 11-7" OR "model governance") ("machine learning" OR "AI") -jobs -hiringBanking has governed models under SR 11-7 since 2011. These people have a decade of genuine validation experience and are consistently overlooked because they do not use AI governance vocabulary.
EU AI Act practitioners
Google("EU AI Act" OR "AI Act" OR "high-risk AI system" OR "conformity assessment") ("implementation" OR "readiness" OR "compliance") -jobs -webinarThe Act created most of the current demand. Excluding 'webinar' matters — the topic is saturated with marketing content from consultancies and law firms selling readiness services.
Responsible AI researchers
Google(site:arxiv.org OR site:scholar.google.com) ("algorithmic fairness" OR "model interpretability" OR "AI evaluation" OR "model cards")For technically demanding governance roles, published research is the strongest signal. FAccT and NeurIPS workshop papers identify people who understand evaluation rather than only policy.
Conference speakers on AI policy
Google("speaker" OR "panelist") ("AI governance" OR "responsible AI" OR "AI policy") (IAPP OR FAccT OR "AI Safety") 2024..2026 -jobsIAPP events and FAccT are where this community gathers. Speaker lists identify people with genuine standing in a field where standing is otherwise hard to assess.
ISO 42001 and framework implementers
Google("ISO 42001" OR "ISO/IEC 42001" OR "NIST AI RMF" OR "AI management system") ("lead implementer" OR "lead auditor" OR "certified") -jobs -trainingFramework implementation experience is concrete and verifiable, unlike a general claim to AI ethics interest. ISO 42001 is new enough that holders are demonstrably current.
Regulators and public sector movers
Google("data protection authority" OR "ICO" OR "CNIL" OR "regulator") ("AI" OR "algorithmic") ("former" OR "previously" OR "ex-") -jobsPeople leaving regulatory bodies understand enforcement from the inside, which is rare and valuable. A small population, and one almost nobody sources deliberately.
Mistakes that cost the most time
Searching only for the title
AI governance barely existed as a job title five years ago, so almost nobody holds it with meaningful tenure. Searching the title alone returns a small pool dominated by recent adopters. The qualified people are working under privacy, model risk, audit, and policy titles, and they are considerably more experienced than the title-holders.
Overlooking the privacy profession
GDPR created a whole profession of people who translate regulation into technical controls, run impact assessments, and hold their ground with engineering teams. That is the AI governance job with a different regulation attached. Data protection officers and privacy engineers are the highest-yield adjacent pool, and most recruiters filling these roles never look at them.
Ignoring financial services model risk
Banks have validated models under SR 11-7 since 2011, with documented methodology, independent challenge, and ongoing monitoring. That is a decade-plus head start on everyone else. These candidates rarely describe themselves in AI governance terms, which is exactly why they remain available.
Conflating ethics interest with governance capability
A great many candidates express genuine interest in AI ethics. Far fewer have implemented a control framework, run an audit, or argued a risk categorisation with a regulator. The role is usually operational rather than philosophical, and screening on stated interest rather than delivered work produces shortlists that cannot do the job.
Not deciding whether the role is technical or policy
These are different hires. A role requiring critical reading of model cards, evaluation design, or bias testing needs a technical background. A role focused on regulatory interpretation, policy authorship, and regulator engagement needs a legal or policy one. Very few people do both well, and adverts that ask for both attract neither.
Underestimating how fast the regulatory picture moves
EU AI Act obligations phase in on a staged timeline, and national implementations vary. A candidate whose knowledge dates from a year ago may be materially out of date. Ask what they have read recently and what they think is still unsettled — the answer separates current practitioners from people who took a course once.
Common questions
- What job titles should I search for when hiring an AI governance specialist?
- Search well beyond the emerging titles, because almost nobody holds AI Governance Specialist or AI Ethics Officer with meaningful tenure. The strongest adjacent pool is privacy: Data Protection Officer, Privacy Counsel, Privacy Engineer, and CIPP holders already translate regulation into technical controls. Financial services model risk is the second: Model Risk Manager and Model Validation Analyst have governed models under SR 11-7 since 2011. Add algorithmic audit titles such as IT Auditor and Technology Risk Auditor, and for technical roles, Responsible AI Researcher and ML Fairness Researcher.
- Why is it so hard to find experienced AI governance candidates?
- Because the title is younger than the work. Demand was created largely by the EU AI Act and similar regulation, which means job adverts appeared faster than careers could form. Anyone claiming a decade in AI governance is describing something they called by another name at the time — most often privacy, model risk, or algorithmic audit. The practical consequence is that title-based searching returns a small pool of recent adopters while the genuinely experienced people sit under adjacent titles and are far less contested.
- Should an AI governance hire be technical or policy focused?
- Decide before sourcing, because they are different hires and few people do both well. A technical governance role — designing evaluations, reading model cards critically, running bias testing, building assurance tooling — needs someone from a machine learning or engineering background. A policy-focused role — interpreting regulation, authoring internal policy, engaging with regulators, running conformity assessments — needs legal, privacy, or policy experience. Adverts asking for deep expertise in both tend to attract neither, and produce long searches that end in a compromise hire.
- Which AI governance certifications are worth anything?
- The IAPP's AIGP is the first widely recognised AI-specific credential, though the population holding it is small and nobody has held it long. More telling in practice are the established privacy certifications — CIPP/E, CIPM, and especially CIPT for the technical side — because they indicate regulatory literacy built over years. ISO 42001 lead implementer or auditor qualifications are becoming a genuine differentiator, as is documented experience applying the NIST AI Risk Management Framework. For US financial services, SR 11-7 model validation experience outweighs any certification.
- Where can I find AI governance professionals outside LinkedIn?
- IAPP is the centre of gravity for this community — its events, publications, and certification directories identify practitioners with genuine standing. For technically oriented roles, FAccT and the responsible AI workshops at major machine learning conferences publish papers and speaker lists that show who actually works on fairness, interpretability, and evaluation. Regulatory bodies are an underused source: people leaving data protection authorities understand enforcement from the inside. Finally, ISO 42001 and NIST AI RMF implementation work is concrete enough to search for directly.
The method behind the strings
Sourcing, in full.
Full Stack Recruiter devotes its first seven chapters to search: Boolean fundamentals, search engines beyond Google, research sources, contact discovery, and responsible public-source research. The titles change by role; the method under them does not.