Skip to main content

AI Governance Manager

Governance and compliance, a mid-level role

What does AI Governance Manager do?

The person who builds and runs the governance program: framework, policies, committees, inventory, risk assessments, vendor reviews and the reporting that tells leadership it is working.

What it decides: How a new AI use case enters review, what it must show, and when it may proceed.

The competencies employers name

  • AI governance operating model designcore, depth expected

    Designs decision rights, committees, intake, approval tiers and escalation so routine uses move and consequential uses get reviewed.

    20 graded topics teach this

  • AI inventory and use-case intakecore, depth expected

    Finds every AI system in use, records owner, purpose, data and risk tier, and keeps the record alive as tools change.

    13 graded topics teach this

  • AI policy and standards writingcore, depth expected

    Writes policies with scope, responsibilities, requirements, exceptions and evidence, so people can follow them and auditors can test them.

    10 graded topics teach this

  • AI risk and impact assessmentcore, depth expected

    Reviews purpose, data, affected people, accuracy, bias, security, oversight, vendors and law for a use case, scores likelihood and impact, and documents residual risk.

    14 graded topics teach this

  • AI risk register and treatment trackingrequired, working knowledge

    Keeps the living record: each risk with a named owner, rating, treatment, residual risk, monitoring metric, threshold and review date.

    12 graded topics teach this

  • AI vendor due diligence and third-party riskrequired, working knowledge

    Tiers vendors by use and impact, requests evidence instead of promises, tests in the customer's context, and plans monitoring and exit.

    5 graded topics teach this

  • NIST AI RMF in practicerequired, working knowledge

    Runs GOVERN, MAP, MEASURE and MANAGE as a cycle with evidence, builds current and target profiles, and applies the generative AI profile.

    3 graded topics teach this

  • ISO/IEC 42001 management systemsrequired, working knowledge

    Builds and audits an AI management system: context, leadership, planning, support, operation, performance evaluation, improvement and the Annex A controls.

    3 graded topics teach this

  • EU AI Act obligations and timelinesrequired, working knowledge

    Classifies a system by role and risk tier, knows which obligations bind on which date after the Digital Omnibus, and what evidence conformity needs.

    24 graded topics teach this

  • Governance metrics and program measurementrequired, working knowledge

    Measures whether governance works: inventory coverage, owners named, overdue reviews, incidents, approval times, not how busy the committee is.

    16 graded topics teach this

  • Executive and board communication on AI riskrequired, working knowledge

    Turns technical uncertainty into a one-page decision: material risks, trends, exceptions, remediation, and what the board is being asked to accept.

    10 graded topics teach this

  • Cross-functional facilitation and influencerequired, working knowledge

    Interviews, facilitates, challenges and secures action across legal, security, product and business teams without owning every decision.

    20 graded topics teach this

  • AI literacy training and enablement designpreferred, working knowledge

    Designs role-based AI training that measures skill, not attendance, with approved-use guidance, office hours and communities of practice.

    20 graded topics teach this

  • How models work, at a governance depthpreferred, working knowledge

    Explains training, tokens, context windows, embeddings, retrieval and fine-tuning well enough to ask an engineer a precise question and spot weak evidence.

    18 graded topics teach this

Where it is taught

Counted from the graded topics that teach this role's competencies. Your own path is shorter: it skips what you already cover.

Check your readiness for this role

Add what you already have (optional)
Signed in? Every topic you have passed already counts as proof.

Roles that feed into it

Where it leads

Backgrounds that reach it fastest

What postings tend to name

Frameworks: NIST AI RMF, ISO/IEC 42001, EU AI Act.

Credentials often listed: AIGP, CRISC, CISA, CGEIT, CIPM, ISO/IEC 42001 Lead Implementer. GAGE does not issue these and does not prepare for their exams; the record you earn here is your own graded evidence, which stands beside them.

Questions

What does an AI Governance Manager do all week?
Reviews new use cases, keeps the inventory and the risk register current, drafts and updates policy, prepares the committee's decision packages, runs vendor reviews and reports to leadership on whether the program is working.
What is the usual path into the role?
Governance Analyst, then AI Governance Analyst or AI Risk Analyst, then manager. People also arrive from compliance, privacy, internal audit and risk with the same underlying discipline.