AI Governance & Compliance Analyst
Also posted as: AI Governance Analyst · AI Governance Specialist · Responsible AI Analyst · AI Risk and Compliance Analyst · Model Governance Analyst · Compliance Analyst - AI Governance · Data and AI Governance Compliance Analyst · AI Governance & Responsible AI Consultant
An AI Governance & Compliance Analyst decides whether an AI system is allowed to go live and on what conditions: keeping the AI use-case inventory, running risk assessments against the EU AI Act, NIST AI RMF and ISO/IEC 42001, writing the policies, control templates and playbooks other teams must follow, reviewing third-party AI vendors, and reporting residual risk to leadership. In India the hiring splits across Big-4 and IT-services consulting arms (EY, Deloitte, PwC AC India, TCS, Wipro, Infosys, Accenture), BFSI and GCC risk functions (Barclays, State Street, Nomura, Booking Holdings, Amgen), industrials and transport (Bosch, Alstom, thyssenkrupp), aviation tech (SITA) and a couple of product companies (AlphaSense, LeadSquared) — 22 India postings collected in a 60-day window. It is the clearest switcher role on this site: employers recruit from compliance, GRC, audit, risk and privacy rather than engineering — AlphaSense asks for someone 'AI-literate without being a developer' and only 1 of the 22 postings (Infosys' Sr. Responsible AI Analyst) wants Python — but two things are true and worth knowing before you start: certifications are a stated gate here, with IAPP AIGP named as mandatory or required in three postings, and no posting in this collection is open to 0 years, the lowest bars being 1 year (Booking Holdings) and 2 years (PwC AC India) while 16 of 22 sit at 5+ years at Manager, AVP, VP or Partner grade.
- Across 88 AI Governance & Compliance Analyst job postings in India, the most-requested capabilities are Apply responsible-AI and data-protection basics (100%), Communicate AI trade-offs to stakeholders (65%) and Translate business requirements into an AI solution design (47%).
- Pay at 0–2 yrs averages about ₹5.5 LPA (based on GRC Analyst pay · verified across 2 salary sites: AmbitionBox, Glassdoor); most earn ₹4–7 LPA (base pay).
- At least 1,000 open roles in India — no portal could be counted in full, checked 04-10-2026.
- Hiring is concentrated in Bengaluru, Delhi NCR and Hyderabad.
- Postings read from LinkedIn 91% and company career pages 9% — one portal supplies most of this sample, so the shares lean to the employers that post there.
Hire for this role? Add your read to this page — what decides the offer, what it closes at. An email to Ajeet, ten minutes, credited or not as you choose. How that read is shown.
Capabilities employers ask for
How often employers ask for each capability, measured across the job descriptions behind this page. Click one to see what "knowing it" means, how to learn it, and how to prove it.
Have a posting open? Check it against this map →
Apply responsible-AI and data-protection basics
This is the job itself, so every posting asks for it in some form. State Street wants AI services evaluated "against enterprise governance, security, compliance requirements", Infosys wants fairness and explainability tools like Fairlearn and SHAP, and Macquarie wants data ownership, lineage and "emerging AI governance expectations". You must be able to take an AI use case, map it to a framework and the relevant privacy rules, and write down what controls it needs.
Explore 3 practice tools →Communicate AI trade-offs to stakeholders
Governance is mostly persuading people who would rather ship. Societe Generale wants "senior stakeholder engagement skills across business, technology, risk, compliance", Citi says you will negotiate internally "often at a senior level", and Prasanz wants writing good enough to draft compliance policies. You need to explain an AI risk and its fix in plain language to a lawyer, an engineer and an executive, sometimes in the same meeting.
Explore 3 practice tools →Translate business requirements into an AI solution design
Governance analysts sit between the policy and the build. thyssenkrupp wants regulatory and policy requirements translated with legal, privacy and architecture teams, Wipro wants secure AI design reviews covering data flows and API permissions, and Northern Trust wants inherent and residual risk assessed with AI architecture teams. You should be able to read a proposed AI system's design and say what has to change before it can ship.
Explore 4 practice tools →Apply guardrails, safety and privacy controls
Red teaming and guardrails have become a governance chore, not just an engineering one. Bosch wants guidelines for "prompt injection, jailbreaks, insecure tool use", EY and McCain Foods want red-team and adversarial testing, and Citi wants output guardrails and content filters tested for unsafe behaviour. You should be able to probe a model for jailbreaks and leaks, and specify the controls that would stop them.
Explore 3 practice tools →Define quality metrics and eval plans for AI features
Governance teams are expected to measure, not just opine. Citi wants faithfulness and groundedness scored with RAGAS, TruLens or DeepEval, the National e-Governance Division wants fairness audits using demographic parity and equalised odds, and ANSR wants Responsible AI KPIs tracked and reported. You should be able to pick the metrics for an AI feature, run them, and report what they say to people who decide.
Explore 4 practice tools →Explain how LLMs work and where they fail
You can't govern what you don't understand. Bajaj Broking wants you to attack-test its LLMs against prompt injection and data poisoning, the Data Security Council of India wants a working grasp of fine-tuning, RAG and agentic systems, and Infosys Consulting wants LLM-based architectures understood. You should be able to explain how an LLM produces an answer and the specific ways it fails.
Explore 4 practice tools →Evaluate AI outputs as a domain expert
Domain knowledge is what makes your review worth having. Nomura and Tata Consultancy Services want BFSI or other regulated-industry experience, Prasanz wants AI outputs audited for "hallucination, bias, and context safety", and Albemarle runs an ethics review board that judges use cases for privacy and reputational harm. You need to read an AI's output with an expert's eye for your field and say, with reasons, whether it is safe to use.
Explore 3 practice tools →Evaluate and rank model responses (RLHF / preference data)
Someone has to look at what the model actually said. Prasanz lists "quality review / QA of AI outputs", Cognizant wants hallucination detection and groundedness validation, and Ecolab wants LLM evaluation and tracing with tools like LangSmith or DeepEval. You should be able to judge and compare model responses consistently, and turn those judgments into evidence a risk committee can use.
Explore 3 practice tools →Map a process and quantify automation ROI
The process work here is mapping, not ROI spreadsheets. AlphaSense wants use cases mapped against frameworks, LeadSquared wants an inventory of AI use cases with their risks, and ANSR wants risk-tiering criteria that decide how deep each review goes. You should be able to document how an AI use case flows through a business and where its risks sit.
Explore 4 practice tools →Write labeling guidelines and evaluation rubrics
No posting in this sample names rubrics or labeling guidelines outright. The nearest asks are FNZ wanting safety requirements turned into "practical evaluation criteria", McCain Foods maintaining golden datasets, and Bosch creating Responsible AI assessment templates. Being able to write a clear scoring guide that two reviewers apply the same way is what those tasks quietly depend on.
Explore 3 practice tools →Families: Product, business & communication · Evaluation, safety & observability · Annotation, quality & human feedback · AI automation & no-code
"AWS" on a JD is not "learn AWS"
The words employers write, translated into what they want you to be able to do for this role.
Skip, for now
- Python, PyTorch and fairness libraries (Fairlearn, AIF360, SHAP, LIME) — Named in exactly 1 of 22 postings — Infosys' Sr. Responsible AI Analyst, which is a genuinely technical evaluation role. Nomura is the only other posting that mentions Python at all, and asks for 'basic scripting capabilities (Python, SQL) for automation'. AlphaSense states the actual bar for the other 20: 'AI-literate without being a developer'. Learn what SHAP output means well enough to challenge it; do not spend six months on PyTorch.
- Building data pipelines (Airflow, dbt, Spark) — Data-quality and data-governance language shows up in 18 of 22 postings, which is misleading: it means catalogs, lineage, stewardship and DQ rules, not moving data. Only Accenture names tooling (Collibra, Alation, Informatica, Talend, SAP MDG) and only for a strategy-consulting seat. You govern pipelines here, you never build one.
- LLM observability tooling, RAG and agent building — RAG is named in 2 of 22 postings and AI agents in 4, always as things to govern — thyssenkrupp wants governance processes for AI agents (inventory, ownership, approval gates), not agents built. LangSmith/Langfuse-style observability appears once, in the Infosys technical role. Understand the failure modes; skip the frameworks.
- Cloud engineering and hyperscaler certifications — Azure appears in 6 of 22 postings, AWS in 5 and GCP in 3, essentially always as platforms whose AI services you review (Accenture's Responsible AI Tech Lead wants Azure AI Foundry familiarity; State Street asks for 'demonstrated interest' in cloud providers and FinOps). The certifications that are actually named as required here are IAPP AIGP, IAPP CIPP/E, ISO 42001 Lead Auditor/Implementer and NIST AI RMF training — spend the money there, not on a cloud architect badge.
- SQL and BI dashboard building — SQL is named in 2 of 22 postings and BI tools in 3 (EY, Nomura, and Booking's compliance dashboards). Enough Excel and Power BI to read and maintain a compliance dashboard is useful; a full analytics-engineering track is not what gets you hired for this role.
AI use-case register and a full risk assessment pack for one real organisation
Pick an organisation you can actually see inside — your current employer, a college, an NGO, or a public-sector body with published AI use — and do the work an AI governance analyst does in their first month. Build an AI use-case inventory for at least three real systems (a support chatbot, a resume screener, a document summariser), risk-tier each one against the EU AI Act with your reasoning written down, then run one full assessment on the riskiest against NIST AI RMF or ISO/IEC 42001, ending in an approve / approve-with-conditions / reject recommendation. Test the system by hand rather than trusting the vendor's claims, and review the vendor as a third party. Nothing here needs code; everything here is what the postings describe.
- An AI inventory register covering at least 3 real systems with owner, purpose, data categories, model or vendor, EU AI Act risk tier and the written reason for that tier
- One completed assessment mapped item by item to NIST AI RMF (Govern / Map / Measure / Manage) or ISO/IEC 42001, with each control written as a testable requirement rather than an aspiration
- A manual test log of 50+ prompts against the live system, sorted into a failure taxonomy (hallucination, bias, PII leakage, prompt injection, out-of-scope use) with severity ratings and evidence
- A third-party review of one bought AI tool: what you asked the vendor for (DPA, model card, sub-processors, training-data claims, ISO 27001/42001 certificates) and what actually came back
- A two-page decision memo for a non-technical approver stating residual risk, conditions of use, the monitoring plan and the trigger that would switch the system off
What the interviews look like
The rounds you'll actually face, in the order they usually come.
- 1
Screening
Background and credentials first, and be ready for the certification question early: SITA states IAPP privacy and AI qualifications are 'a mandatory requirement of this role', AlphaSense wants an IAPP AIGP holder, thyssenkrupp names AIGP, CIPP/E and PECB ISO/IEC 42001 Lead Implementer. Then the experience bar — 16 of 22 postings want 5+ years and the lowest bars in the whole collection are 1 year (Booking Holdings) and 2 years (PwC AC India). Prior compliance, GRC, audit, risk or privacy experience is what they are checking for, not engineering.
- 2
Frameworks and regulation
A working-knowledge round on the EU AI Act (risk tiers, prohibited practices, obligations on deployers vs providers), the NIST AI RMF functions, and ISO/IEC 42001 as a management system — plus how they overlap with what you already know from ISO 27001, GDPR or the DPDP Act. Expect 'where does this AI use case land and why', not recitation.
- 3
Risk assessment case or take-home
You are handed a use case (a hiring screener, a credit decision assistant, a customer-facing GenAI bot) and asked to run the assessment: classify the risk, name the specific failure modes (bias, hallucination, drift, data leakage, prompt injection), specify controls and evidence, and give an approve / approve-with-conditions / reject call you can defend. Bring your entry project — it is the same artefact.
- 4
AI depth without code
A conversation to check you can hold your own with data scientists: what explainability actually gives you on a deep model, what a fairness metric does and does not prove, what drift monitoring detects, how RAG and agents change the risk picture. AlphaSense's 'AI-literate without being a developer' is the standard in 21 of the 22 postings; only the Infosys Sr. Responsible AI Analyst loop goes into Python, Fairlearn, SHAP and evaluation pipelines.
- 5
Stakeholder or client round
For the Big-4 and IT-services seats (EY, Deloitte, PwC, TCS, Accenture, Infosys, Wipro) expect a client-workshop simulation and a look at your report writing. For in-house seats (Barclays, State Street, Nomura, Bosch, Alstom, thyssenkrupp, Amgen, Booking Holdings) the question is how you say no to a business team without stopping the business — and how you escalate when they ship anyway.
What people ask before choosing this role
Can a fresher get an AI Governance & Compliance Analyst job in India?
Realistically, no — not straight away. Only 1 of the 88 job postings behind this page accept 0–2 years; most want people who have already shipped software or run projects. It is a strong second move rather than a first job.
What is the salary of an AI Governance & Compliance Analyst in India?
Pay at 0–2 yrs averages about ₹5.5 LPA (based on GRC Analyst pay · verified across 2 salary sites: AmbitionBox, Glassdoor); most earn ₹4–7 LPA (base pay). Not every posting states pay, and pay varies widely by city and by whether the employer is an IT-services firm, a global capability centre or a product startup.
How long does it take to become an AI Governance & Compliance Analyst?
The six capabilities employers ask for most add up to roughly 55 focused hours — about 7 weeks at 8 hours a week, if you are starting from zero on all of them. Most people are not: the self-check on this page works out what you can skip, which is usually a large part of it.
What skills do you need for an AI Governance & Compliance Analyst role?
Across the 88 job postings behind this page, the most-requested capabilities are Apply responsible-AI and data-protection basics (100% of postings), Communicate AI trade-offs to stakeholders (65% of postings) and Translate business requirements into an AI solution design (47% of postings). Note these are capabilities, not tools — employers write tool names, but what they are buying is the ability to do the work.
Which cities in India post the most AI Governance & Compliance Analyst jobs?
Bengaluru (33), Delhi NCR (20), Hyderabad (13) and Mumbai (7) — counted across the 88 job postings behind this page. Remote-India roles are counted separately where the posting said so.
Is demand for AI Governance & Compliance Analyst roles in India growing?
Still mostly a senior role — 19 of the 25 India postings added in early September ask for 5+ years — but analyst-level doors are opening in BFSI GCCs: AllianceBernstein's AI Governance Coordinator asks for 2-5 years in compliance, risk or governance, and the Data Security Council of India is hiring AI safety staff at 2-3 years. The pressure behind the hiring is a governance gap: ServiceNow's 2026 index found only 22% of Indian enterprises have AI testing, auditing and risk-assessment processes in place, while enterprise AI investment grew 119% in a year.
Do I need a degree or a paid certificate for this?
Nothing on this page requires a paid certificate, and none of the 88 job postings behind it asked for one by name. What they ask for is evidence you can do the work — a public repo, a deployed project, something a hiring manager can open. That is what the path on this page is built to produce.
Companies with this role open in India
A sample of employers we saw hiring for this role — IT services, global capability centres, product companies and startups. Each links to one of the company's postings for this role, checked open on 04-10-2026; where none is open, to its current openings instead.
What it pays
most earn ₹4–7 LPA (base pay) · based on GRC Analyst pay · verified across 2 salary sites: AmbitionBox, Glassdoor
Not enough salary data yet for Mid · 2–5 yrs or Senior · 5+ yrs.
Across all levels: the middle half earns ₹4.2–15 LPA · Glassdoor · GRC Analyst pay
How much demand
What each job portal shows for this role's title — the readings behind the openings figure above.
Where this role is heading
- Still mostly a senior role — 19 of the 25 India postings added in early September ask for 5+ years — but analyst-level doors are opening in BFSI GCCs: AllianceBernstein's AI Governance Coordinator asks for 2-5 years in compliance, risk or governance, and the Data Security Council of India is hiring AI safety staff at 2-3 years.
- The pressure behind the hiring is a governance gap: ServiceNow's 2026 index found only 22% of Indian enterprises have AI testing, auditing and risk-assessment processes in place, while enterprise AI investment grew 119% in a year.
Capability percentages come from 88 job descriptions read in full on 02-10-2026. How we do this