Compliance Analyst - AI Governance
Skills
About the Role
You will be central to building and operating AlphaSense's AI governance program, helping ensure that the way AI systems are deployed, built, and procured is well-governed, well-documented, and defensible to regulators, auditors, and enterprise clients. Sitting within the Strategic Risk team, you will own the day-to-day execution of AI risk assessments — intake, classification, evaluation, and documentation — that keep the program running at scale. You will act as the operational backbone of the program, turning frameworks such as the EU AI Act, NIST AI RMF, and ISO/IEC 42001 into repeatable, auditable processes that grow with the business, including supporting the rollout of a dedicated GRC platform to automate assessment workflows. This is a risk and governance role, not a hands-on AI engineering role, well-suited to someone who understands how AI systems create risk and knows how to manage it. You will coordinate with engineering, product, security, legal and privacy, and procurement contacts to collect details needed for assessments, assist with third-party and vendor AI risk reviews, draft clear summaries from completed assessments, and track the status of assessments and follow-ups so nothing slips through.
Requirements
- IAPP AIGP certification with strong knowledge of the AI governance landscape and major frameworks
- 2-4 years of experience in risk management, GRC, compliance, audit, or data privacy, with exposure to AI governance, technology risk, or third-party risk
- Familiarity with the EU AI Act, NIST AI RMF, ISO/IEC 42001, and ISO/IEC 27001, and ability to apply their requirements to real use cases
- Comfortable working with GRC or governance tooling, configuring workflows, managing inventories, and generating reporting
- AI-literate at a conceptual level, understanding how AI and ML systems work and the risks they introduce such as bias, hallucination, data leakage, and model drift
- Highly organized and detail-oriented, capable of managing a high volume of assessments, inventory records, and deadlines
- Strong written and verbal communication skills in English
- Collaborative, self-directed, and comfortable with ambiguity and evolving priorities
Responsibilities
- Complete AI risk assessments using established templates and criteria, gathering details on AI use cases and preparing draft assessments for senior review
- Maintain the accuracy of the AI system inventory by adding and updating records of AI/ML systems, vendors, and use cases
- Leverage the AI governance platform to enter assessment data, follow set workflows, and organize supporting evidence and documentation
- Gather information and evidence to map use cases against frameworks such as the EU AI Act, NIST AI RMF, and ISO/IEC 42001
- Coordinate with engineering, product, security, legal and privacy, and procurement contacts to collect details needed for assessments
- Assist with third-party and vendor AI risk reviews by collecting vendor documentation and completing initial reviews
- Draft clear, well-organized summaries and notes from completed assessments and flag higher-risk or unclear items to senior reviewers
- Track the status of assessments and follow-ups, keeping records and trackers up to date
