Skip to main content

AI Risk Manager

Risk, audit and assurance, a mid-level role

What does AI Risk Manager do?

Builds and runs the processes that identify, assess, treat, monitor and communicate AI risk across the lifecycle, and helps decision-makers choose proportionate safeguards.

What it decides: Which risks need strong controls, which can be accepted, and when a use case should pause.

The competencies employers name

  • AI risk and impact assessmentcore, depth expected

    Reviews purpose, data, affected people, accuracy, bias, security, oversight, vendors and law for a use case, scores likelihood and impact, and documents residual risk.

    14 graded topics teach this

  • AI risk register and treatment trackingcore, depth expected

    Keeps the living record: each risk with a named owner, rating, treatment, residual risk, monitoring metric, threshold and review date.

    12 graded topics teach this

  • AI inventory and use-case intakerequired, working knowledge

    Finds every AI system in use, records owner, purpose, data and risk tier, and keeps the record alive as tools change.

    13 graded topics teach this

  • Control design and operating-effectiveness testingrequired, working knowledge

    Maps risks to preventive, detective and corrective controls, then tests design and operation with samples, evidence and defensible findings.

    12 graded topics teach this

  • AI vendor due diligence and third-party riskrequired, working knowledge

    Tiers vendors by use and impact, requests evidence instead of promises, tests in the customer's context, and plans monitoring and exit.

    5 graded topics teach this

  • Post-deployment monitoring and drift detectionrequired, working knowledge

    Sets performance metrics, thresholds and review triggers after launch, and treats a model change, a vendor update or new data as a reason to re-check.

    12 graded topics teach this

  • AI incident response and recoveryrequired, working knowledge

    Classifies AI incidents by severity, runs containment, preserves evidence, manages notification, and closes the loop with lessons learned.

    3 graded topics teach this

  • NIST AI RMF in practicerequired, working knowledge

    Runs GOVERN, MAP, MEASURE and MANAGE as a cycle with evidence, builds current and target profiles, and applies the generative AI profile.

    3 graded topics teach this

  • Model failure modes and bias recognitionrequired, working knowledge

    Recognizes hallucination, drift, skew, brittleness and biased outcomes, and knows how each one enters a system.

    10 graded topics teach this

  • Executive and board communication on AI riskrequired, working knowledge

    Turns technical uncertainty into a one-page decision: material risks, trends, exceptions, remediation, and what the board is being asked to accept.

    10 graded topics teach this

  • Cross-functional facilitation and influencerequired, working knowledge

    Interviews, facilitates, challenges and secures action across legal, security, product and business teams without owning every decision.

    20 graded topics teach this

  • US federal and state AI regulationpreferred, working knowledge

    Tracks executive orders, OMB guidance, agency rules and the state patchwork, and knows which state laws reach hiring, insurance and consumer decisions.

    17 graded topics teach this

  • Privacy law applied to AIpreferred, working knowledge

    Applies GDPR, CCPA and sector rules to training data, inference, automated decisions, lawful basis, individual rights and cross-border transfer.

    7 graded topics teach this

Where it is taught

Counted from the graded topics that teach this role's competencies. Your own path is shorter: it skips what you already cover.

Check your readiness for this role

Add what you already have (optional)
Signed in? Every topic you have passed already counts as proof.

Roles that feed into it

  • Enterprise Risk Analyst
  • Technology Risk Manager
  • Model Risk Analyst
  • Privacy Manager
  • GRC Analyst
  • Internal Auditor

Where it leads

Backgrounds that reach it fastest

What postings tend to name

Frameworks: NIST AI RMF, ISO/IEC 42001, ISO 31000, COSO.

Credentials often listed: CRISC, AIGP, CIPM, CISA. GAGE does not issue these and does not prepare for their exams; the record you earn here is your own graded evidence, which stands beside them.

Questions

Is the AI Risk Manager's job to eliminate risk?
No. It is to help decision-makers understand uncertainty, choose proportionate safeguards, and decide whether the benefit justifies the exposure that remains.