AI Controls Analyst
Risk, audit and assurance, an entry-level role
What does AI Controls Analyst do?
Helps the organization show that AI risks are covered by controls that actually operate: maps risks to controls, finds owners and evidence, tests design and operation, records findings and follows remediation. One of the most accessible doors into the field.
What it decides: Whether a control passed or failed its test, and how the exception is rated.
The competencies employers name
- Control design and operating-effectiveness testingcore, working knowledge
Maps risks to preventive, detective and corrective controls, then tests design and operation with samples, evidence and defensible findings.
12 graded topics teach this
- Evidence collection and audit-ready documentationcore, working knowledge
Collects, labels and preserves the evidence that a control operated, a decision was made, and a claim can be defended to an auditor or regulator.
20 graded topics teach this
- Framework crosswalking without false equivalencerequired, working knowledge
Compares the EU AI Act, NIST AI RMF, ISO/IEC 42001 and sector rules by intent and control objective, and says where they do not overlap.
5 graded topics teach this
- AI risk register and treatment trackingrequired, working knowledge
Keeps the living record: each risk with a named owner, rating, treatment, residual risk, monitoring metric, threshold and review date.
12 graded topics teach this
- Working AI fluencyrequired, working knowledge
Uses generative AI tools daily, knows what a model can and cannot do, and can say where an output should not be trusted.
21 graded topics teach this
- AI inventory and use-case intakerequired, working knowledge
Finds every AI system in use, records owner, purpose, data and risk tier, and keeps the record alive as tools change.
13 graded topics teach this
- Human oversight designpreferred, working knowledge
Defines who reviews AI outputs, what they check, when they can override, and how to keep review from becoming a rubber stamp.
9 graded topics teach this
- AI vendor due diligence and third-party riskpreferred, working knowledge
Tiers vendors by use and impact, requests evidence instead of promises, tests in the customer's context, and plans monitoring and exit.
5 graded topics teach this
- Cross-functional facilitation and influencerequired, working knowledge
Interviews, facilitates, challenges and secures action across legal, security, product and business teams without owning every decision.
20 graded topics teach this
Where it is taught
Counted from the graded topics that teach this role's competencies. Your own path is shorter: it skips what you already cover.
- The AI Lobbyist: Certified AI Policy Strategist25 topics
- Certified AI Governance Professional (CAIGP)17 topics
- Certified Agentic AI Governance Professional (CAAGP)17 topics
- Certified AI Practitioner: Workplace Foundations16 topics
- EU AI Act Implementation Expert15 topics
- Certified AI Transformation Professional (CATP)12 topics
- Certified AI Data Governance Professional (CADGP)8 topics
Check your readiness for this role
Add what you already have (optional)
Roles that feed into it
- GRC Analyst
- Internal Audit Associate
- Security Compliance Analyst
- Quality Analyst
- Operational Risk Analyst
- Claims or operations analyst with process-control experience
Where it leads
- Senior Controls Analyst
- AI Auditor
- AI Risk Manager
- AI Governance Manager
Backgrounds that reach it fastest
What postings tend to name
Frameworks: COSO, ISO/IEC 42001, NIST AI RMF.
Credentials often listed: CRISC, CGRC, CISA, CIA, AIGP. GAGE does not issue these and does not prepare for their exams; the record you earn here is your own graded evidence, which stands beside them.
Questions
- Is AI Controls Analyst a good entry point?
- Yes. It draws on risk-and-control thinking that people from audit, quality, operations and compliance already have, and adds enough AI literacy to understand the system under test.
- What does a strong analyst distinguish that a weak one does not?
- A policy statement from a control, a screenshot from reliable evidence, and a one-time activity from a repeatable process.