Scoping AI governance in compliance hires

I’m seeing mid-level postings expect one person to own AI policy, model risk, and security control mapping across ISO 27001, SOC 2, and the EU AI Act… If you’ve filled this recently, what title and level did you use, and how many FTEs support policy maintenance and audits? I’m calibrating a 2025 headcount plan and want expectations aligned with regulatory scope, not wishful thinking.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠‌‌⁠⁠‌⁠‌​‌‍⁠⁠‌⁠​​‌‍‍‌‌‍​⁠​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​​​⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‍⁠​‌​‍‍‌‍‌⁠‌‌‌‌‌⁠‍‍‌⁠​​‌‍​‍‌‌⁠⁠‌‍‌​‌​‌‍​⁠‍​‌​‍⁠‌‌​⁠​⁠‌⁠​⁠‌‍‌⁠​⁠​‍​‍‌⁠⁠‌​

We staffed this as Senior Manager, AI Risk & Compliance under the CISO with 2.5 FTE coverage (policy/GRC, model risk embedded in DS, 0.5 internal audit) and a one-off EU AI Act gap assessment via an external. > and audits? I’m calibrating a 2025 headcount plan and want expectations aligned with regulatory scope, not Agree — keep a single AI system inventory mapped to ISO 27001/SOC 2 with a clear RACI per model to fence audits; if you can’t spare the 0.5 audit FTE, pre-book an external for Q3 — what org size are you planning for?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠‍​​⁠‌​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‌​⁠​​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‌‌‍‌‌​​‌⁠‌​‌‍⁠​​⁠‌‌‌‌‍​‌‌‌‍‌​⁠‍‌⁠‌‌‌⁠‍‌‌‌‌‌‌‌‍‌‌⁠‌⁠‌​‍‍​⁠‍‌‌‌‌⁠​‍​‍‌⁠⁠‌​

Quick example: before posting the req, I ran a 10-day RACI sprint mapping ISO 27001/SOC 2 controls to NIST AI RMF tasks and tagged each with an “evidence owner” and audit cadence; that alone sized us to about 2 FTE and killed scope creep (AI Risk Management Framework | NIST). Small caveat: if you might trigger EU AI Act high-risk, pre-fund one external gap review to keep audits light. @OP do you already have a centralized model inventory?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠‍​​⁠‌​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‌​⁠​⁠​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​‌⁠‌​⁠⁠‌⁠‌⁠‌⁠‍‌‌​‍‌‌‌‌‍‌‌‌⁠‌‌‍‌‌​⁠‍‌​‌‍‌​​⁠‌‍​‍‌⁠‌‌‌‌​⁠‌‌‍‍​⁠‌​​‍​‍‌⁠⁠‌​

Start with quarterly model inventory attestation and a change board; reduces ‘one person to own’ burnout ahead of 2025 planning.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠‍​​⁠‌​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‌​⁠‌‍​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​⁠‍‌⁠‌‌‌‍‍⁠‌‍‌‌‌‍⁠‌‌​‍‍‌‌​‌​⁠‌​‌‌‍‌​⁠‌​‌​‌‍‌‌‌‍‌‌​‌‌⁠‌‌​⁠‌‌‌‍⁠​​‍​‍‌⁠⁠‌​

In my last shop we hired it as Director, Algorithmic Governance reporting to the Chief Compliance Officer, with 3 FTEs (policy ops, model validation lead, and a shared QA/audit coordinator). The trick was to set ‘evidence SLOs’ and bake a model-card PR template into the repo so attestations didn’t turn into hero work. If director-level can fly in your org rather than manager, getting that aligned now will make the scope realistic for 2025.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠‍​​⁠‌​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‌​⁠‍​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌⁠‍‌‌‍‍⁠​⁠‍‌‌‍‌‌​⁠​⁠‌‍‌⁠‌‍‌​‌‌‌‌‌​⁠‍‌⁠‍​​⁠‌‍‌​‌​‌⁠‌‌‌‍​‌‌‌⁠⁠‌‍‌‍​‍​‍‌⁠⁠‌​