AI Auditor
Risk, audit and assurance, a mid-level role
What does AI Auditor do?
Independently evaluates whether the controls governing AI systems are designed well and operating consistently, and whether the organization can support its claims with reliable evidence.
What it decides: Whether the evidence supports management's conclusions, and what the findings and their severity are.
The competencies employers name
- AI audit and independent assurancecore, depth expected
Scopes an AI audit, sets criteria, samples, interviews, tests, writes findings with condition, criteria, cause, effect and recommendation, and tracks remediation.
6 graded topics teach this
- Control design and operating-effectiveness testingcore, depth expected
Maps risks to preventive, detective and corrective controls, then tests design and operation with samples, evidence and defensible findings.
12 graded topics teach this
- Evidence collection and audit-ready documentationcore, depth expected
Collects, labels and preserves the evidence that a control operated, a decision was made, and a claim can be defended to an auditor or regulator.
20 graded topics teach this
- AI inventory and use-case intakerequired, working knowledge
Finds every AI system in use, records owner, purpose, data and risk tier, and keeps the record alive as tools change.
13 graded topics teach this
- Data lineage and provenancerequired, working knowledge
Traces where data came from, what transformed it, who owns each hop and where it flows downstream, so a number can be defended.
6 graded topics teach this
- Post-deployment monitoring and drift detectionrequired, working knowledge
Sets performance metrics, thresholds and review triggers after launch, and treats a model change, a vendor update or new data as a reason to re-check.
12 graded topics teach this
- Human oversight designrequired, working knowledge
Defines who reviews AI outputs, what they check, when they can override, and how to keep review from becoming a rubber stamp.
9 graded topics teach this
- AI incident response and recoverypreferred, working knowledge
Classifies AI incidents by severity, runs containment, preserves evidence, manages notification, and closes the loop with lessons learned.
3 graded topics teach this
- How models work, at a governance depthrequired, working knowledge
Explains training, tokens, context windows, embeddings, retrieval and fine-tuning well enough to ask an engineer a precise question and spot weak evidence.
18 graded topics teach this
- NIST AI RMF in practicerequired, working knowledge
Runs GOVERN, MAP, MEASURE and MANAGE as a cycle with evidence, builds current and target profiles, and applies the generative AI profile.
3 graded topics teach this
- ISO/IEC 42001 management systemsrequired, working knowledge
Builds and audits an AI management system: context, leadership, planning, support, operation, performance evaluation, improvement and the Annex A controls.
3 graded topics teach this
- AI vendor due diligence and third-party riskpreferred, working knowledge
Tiers vendors by use and impact, requests evidence instead of promises, tests in the customer's context, and plans monitoring and exit.
5 graded topics teach this
- Cross-functional facilitation and influencerequired, working knowledge
Interviews, facilitates, challenges and secures action across legal, security, product and business teams without owning every decision.
20 graded topics teach this
Where it is taught
Counted from the graded topics that teach this role's competencies. Your own path is shorter: it skips what you already cover.
- Certified AI Governance Professional (CAIGP)28 topics
- The AI Lobbyist: Certified AI Policy Strategist19 topics
- Certified AI Practitioner: Workplace Foundations17 topics
- Certified AI Data Governance Professional (CADGP)16 topics
- Certified Agentic AI Governance Professional (CAAGP)15 topics
- EU AI Act Implementation Expert14 topics
- Certified AI Transformation Professional (CATP)11 topics
Check your readiness for this role
Add what you already have (optional)
Roles that feed into it
- IT Auditor
- Internal Auditor
- Model Validator
- Compliance Testing Analyst
- Privacy Auditor
- AI Controls Analyst
Where it leads
- Lead AI Auditor
- AI Assurance Manager
- Chief Audit Executive, AI audit edition
Backgrounds that reach it fastest
What postings tend to name
Frameworks: Global Internal Audit Standards, NIST AI RMF, ISO/IEC 42001, SOC reporting.
Credentials often listed: CISA, CIA, CPA, CISSP, AIGP, ISO/IEC 42001 Lead Auditor. GAGE does not issue these and does not prepare for their exams; the record you earn here is your own graded evidence, which stands beside them.
Questions
- What is the difference between an AI audit and an AI risk assessment?
- Management owns risk decisions and controls. The auditor evaluates that work independently and reports whether the evidence supports management's conclusions. Same system, different seat.
- Do AI Auditors need to be machine-learning engineers?
- No. They need to understand the AI lifecycle well enough to recognize weak evidence and to bring in a specialist when the question is technical.