OmDev Logo
GetYourJob
0
Publié il y a 66 jours

AI Compliance Manager - Freelance

Entreprise
Localisation
Paris, France
Sur site
Type de contrat
Freelance
Niveau
0vues
0clics

Description du poste

Location: Paris, on site with partial remote
Contract: Freelance mission, independent contractor status
Client: Large organisation in a regulated sector.
Start: September / October
Duration and daily rate: Discussed based on scope and seniority

The mission

The client operates AI systems in a regulated environment governed by evolving requirements: the EU AI Act, GDPR, and the sector rules enforced by its supervisor. Reference frameworks exist, but the organisation has no version adapted to its context, applied by the teams building and buying AI, and supported by evidence available on demand. The role covers three pillars: adapt the framework, implement it, and audit the AI systems against it.

The scope goes beyond policy writing. The framework must be implemented and evidenced so it can be demonstrated to a regulator, a certification body, or a corporate client on request. The mission concludes when an internal owner can operate the system independently, so preparing that handover is included in the role.

What you will do

1. Adapt the governance framework

  • Translate the applicable frameworks (mainly EU AI Act into a single internal control framework calibrated to its risk profile, systems, and way of working.

  • Define the classification logic: which AI systems are in scope, at what obligation level, and on which axes (role in the value chain, risk tier, deployment geography, criticality to the regulated activity).

  • Map obligations to concrete controls. Give each control an owner and specify what evidence proves it. Remove duplicate and unenforceable controls rather than stacking them.

  • Make it hold across the group's entities and jurisdictions

2. Implement it

  • Build the AI system inventory and make it trustworthy: use cases, models, data, vendors, owners, lifecycle stage, current risk classification.

  • Roll controls out with the teams that live with them (engineering, data, product, procurement, legal, security, business lines), turning each into a workable procedure, template, or gate.

  • Stand up the operating cadence: intake and triage of new AI use cases, risk assessments, model and vendor reviews, human oversight arrangements, incident and serious malfunction handling, post-market monitoring.

  • Set up the tooling that carries the evidence (an existing GRC platform or a dedicated AI governance solution) and drive adoption.

  • Run third-party AI governance: due diligence on model, data and platform providers, contractual clauses, and ongoing vendor monitoring.

  • Train and coach the first line so governance is run by the teams, not by you alone. That is what makes the handover possible.

3. Audit AI systems against the framework

  • Design and execute a risk-based audit programme covering the AI systems in scope, across their lifecycle.

  • Test control design and operating effectiveness. Gather evidence, document findings with a defensible severity rating, and agree remediation plans with the owners.

  • Track remediation to closure, re-test, and escalate what does not move.

  • Produce the conformity documentation and technical files that will withstand a supervisor, an external auditor, a certification body, or a corporate client's assessment.

  • Report to the governance committee and executive stakeholders on portfolio posture, control coverage, open gaps, and trend.

Deliverables

  1. AI system inventory, complete and classified against the agreed criteria.

  2. Gap analysis of the current state against the target framework, with a prioritised remediation backlog agreed with the owners.

  3. Adapted control framework, approved by the client's governance body, with named control owners and defined evidence requirements.

  4. Operating procedures: use case intake and triage, risk assessment method, vendor review, incident handling, post-market monitoring.

  5. Audit programme, and its first cycle executed on the highest-risk systems, with a documented findings file and agreed remediation plans.

  6. Conformity documentation pack, ready to be produced on request.

  7. Handover: an internal owner trained and operational, with the documentation to keep the system running.

Exigences du poste

Stack technique :

Artificial Intelligence

Plan d'action

Un plan personnalisé pour postuler intelligemment à cette offre.

Publié par

Recruteur
Recruteur

Intéressé par cette offre ?

Cliquez sur "Postuler" pour accéder à l'offre.