Full-Time

AI Risk and Governance Technical Expert

Workstream Lead Support

Posted on 8/19/2026

Ernst & Young

Ernst & Young

5,001-10,000 employees

Global professional services: consulting, assurance, tax

No salary listed

Gurugram, Haryana, India

In Person

Master's

Category
Legal & Compliance (1)
Required Skills
LLM
Power BI
Microsoft Office
Python
SQL
Machine Learning
RAG
Risk Management
Excel/Numbers/Sheets

Get referred to Ernst & Young

See people who can refer or advise you

Requirements
  • Working knowledge of AI risk, Responsible AI principles, AI governance processes and the AI system lifecycle.
  • Understanding of data protection, information security, third-party AI risk, evidence management, issue tracking and governance reporting.
  • Familiarity with AI risk assessments, control frameworks, system or model documentation, evidence packs and audit-readiness expectations.
  • Exposure to AI regulatory expectations, including the EU AI Act or similar governance frameworks.
  • Strong understanding of AI and machine learning concepts, including generative AI, large language models, foundation models, retrieval-augmented generation and the end-to-end AI system lifecycle.
  • Ability to understand and critically review AI solution architecture, data flows, system integrations, model or system documentation, evaluation results, technical limitations and control design.
  • Knowledge of key AI risks, including bias and fairness, explainability, inaccurate or unreliable outputs, robustness, privacy, data leakage, prompt injection, adversarial threats, performance drift and human overreliance.
  • Practical experience conducting or supporting AI, technology, data, information security, model or algorithmic risk assessments.
  • Understanding of AI testing and evaluation approaches, including performance assessment, robustness testing, bias and fairness evaluation, security testing, red teaming and post-deployment monitoring.
  • Familiarity with AI regulatory and governance frameworks, including the EU AI Act, NIST AI Risk Management Framework, ISO/IEC 42001 or comparable frameworks.
  • Understanding of data protection, information security, third-party technology risk, secure development, evidence management, issue management and audit-readiness expectations.
  • Ability to translate technical findings into clear risk statements, control requirements, remediation recommendations and concise leadership reporting.
  • Strong drafting and documentation capability, including preparation of guidance, templates, decision notes, status updates, metrics and review observations.
  • Proficient in using digital tools such as generative AI platforms, Microsoft Excel and PowerPoint for research, analysis, reporting and presentations.
  • Strong analytical and problem-solving skills, with the ability to identify gaps, clarify requirements, assess implications and propose practical next steps.
  • Ability to manage multiple activities, deadlines and provide timely progress updates to leadership and stakeholders.
  • Effective stakeholder management and relationship-building skills, with the confidence to work with business owners, technology owners and risk or compliance subject-matter professionals.
  • Clear written and verbal communication skills, with the ability to present complex topics in a concise, practical and audience-appropriate manner.
  • Ability to work through ambiguity, respond to evolving requirements and exercise sound judgment while seeking guidance on material or sensitive matters.
  • Collaborative and service-oriented approach, with attention to detail, accountability and action closure.
  • A post-graduate degree or equivalent professional qualification in risk management, governance, compliance, technology, computer science, artificial intelligence, machine learning, data science, information systems, engineering, cybersecurity, technology risk or a related discipline.
  • Approximately 10 years of relevant experience in risk management, governance, compliance, technology risk, Responsible AI or related areas.
  • Demonstrable experience reviewing or assessing AI-enabled systems, technology solutions, solution architecture, data flows, technical controls or model-related documentation.
  • Experience working with Risk Management, technical subject-matter experts and cross-geography stakeholders.
  • Strong drafting, research, communication and Microsoft Office skills.
  • Experience applying AI regulations, governance frameworks or technical standards in an enterprise environment.
Responsibilities
  • Support the workstream lead in planning and delivering assigned AI Risk and Governance workstreams while maintaining visibility of milestones, dependencies, risks and upcoming decisions.
  • Coordinate cross-functional reviews involving Global Risk Management, Service Lines, EY Technology, Global Functions, Regions and enabling teams such as Legal/GCO, Data Protection, Information Security, Procurement/Supply Chain and Quality.
  • Prepare, review and maintain workstream drafts, guidance, control requirements, templates, action trackers, decision logs and other governance artefacts for review and approval.
  • Assist in developing practical implementation plans for new or updated AI guidance and controls, and support communication and adoption across service lines, functions and geographies.
  • Support activities across the AI governance lifecycle, including intake, risk assessment, QRM review, validation, release or go-live conditions, evidence readiness and post-deployment monitoring.
  • Prepare materials for AI governance forums and leadership reporting, including status updates, decision papers, metrics, risk summaries, meeting notes and follow-up trackers.
  • Perform or support risk-based technical assessments of AI systems and tools that are built, bought, deployed or used by EY, evaluating alignment with Responsible AI principles and relevant data protection, information security, AI security, third-party risk, technology risk and quality requirements.
  • Identify and assess technical risks such as inaccurate or unreliable outputs, bias, lack of explainability, data leakage, prompt injection, insecure integrations, insufficient human oversight and model or performance drift.
  • Review whether proposed technical and procedural controls are appropriately designed to manage identified risks across the AI lifecycle, including testing, approval, deployment, monitoring, change management and incident management.
  • Work with technology owners, developers, architects, data professionals and risk subject-matter experts to translate technical findings into clear risk statements, proportionate control requirements and practical remediation actions.
  • Conduct research on emerging regulatory expectations, market developments and Responsible AI practices, and summarize potential implications for workstream activities and stakeholder guidance.
  • Support development and maintenance of enablement materials such as playbooks, checklists, FAQs and templates to help teams apply governance requirements.
Desired Qualifications
  • Familiarity with technical or analytical tools such as Python, SQL, Power BI, Azure AI services, source-code repositories or AI testing and monitoring tools.
  • Working in a Risk Management domain.
  • Project or program management, risk, compliance or legal certifications.
  • Relevant certifications in AI, cloud, cybersecurity, privacy, technology risk, audit or project management.

EY (Ernst & Young) provides professional services at a global scale, offering consulting, assurance, tax, and transaction advisory services. It serves clients across industries such as technology, media, real estate, hospitality, and construction. Instead of selling a single product, EY works with clients through tailored engagements where cross-disciplinary teams analyze challenges, design strategies, perform audits, help with tax planning, and assist with mergers or divestitures. What sets EY apart is its worldwide reach and integrated service model, industry-specific expertise, and focus on responsible business practices like sustainability, cybersecurity, and workforce flexibility. EY’s goal is to help organizations improve performance, manage risk, and achieve sustainable growth while building a better working world.

Company Size

5,001-10,000

Company Stage

N/A

Total Funding

N/A

Headquarters

Boston, Massachusetts

Founded

1991

Get referred to Ernst & Young

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • EY.ai Agentic for Sales launched March 2, 2026, broadening AI-led revenue opportunities.
  • EY's Copilot rollout reached 150,000 users, boosting productivity 15 percent for client delivery.
  • EY's Snowflake Innovation Center, launched February 10, 2026, deepens cloud-data transformation partnerships.

What critics are saying

  • EY paid £105.5 million to settle NMC Health claims on May 18, 2026.
  • EY faces Shell audit probes; four partners left after December 2025 rotation breaches.
  • EY cut 3,000 U.S. jobs in 2025, signaling overcapacity and partner-client pressure.

What makes Ernst & Young unique

  • EY Canvas now embeds agentic AI across 160,000 audits in 150 countries.
  • EY and Microsoft invested over $1 billion on May 21, 2026, for enterprise AI.
  • EY bought Supply Nexus on May 12, 2026, strengthening supply-chain automation and AI consulting.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Professional Development Budget

Flexible Work Hours

Remote Work Options

Company News

Business Insider
Jul 30th, 2026
EY's 'invisible' AI router cuts token costs by 60% by directing queries to cheaper models

EY has introduced an "invisible" AI router to manage internal AI spending, helping cut token consumption by up to 60% since its April rollout. The router sits behind specialised AI tools and directs employee queries to the most appropriate model for each task, rather than defaulting to the most powerful option. Token costs have become a growing concern as AI providers increasingly charge based on usage. EY's AI Pulse survey found that 82% of senior leaders at companies investing in AI were worried about token usage. The router has been deployed on department-specific platforms, including tax and risk functions, though not on the general Microsoft Copilot chatbot available to all staff. EY has also implemented token budgets based on employees' roles and departments. The firm's global consulting AI leader Dan Diasio said companies should focus AI investment on areas with the deepest impact rather than spreading resources thinly.

Yahoo Finance
Jul 29th, 2026
FRC fines EY $1.5M over Made.com audit failures before 2022 collapse

The UK's Financial Reporting Council has fined EY nearly £1.2m and audit partner Julie Carlyle £49,000 for failings in their 2021 audit of Made.com. Both received severe reprimands for breaching international auditing standards regarding going concern and deferred tax assets. The FRC said the auditors relied on management forecasts without sufficient challenge or adequate testing. Made.com, an online furniture retailer that listed on the London Stock Exchange in June 2021, entered administration in November 2022 after reporting a £35.3m loss. EY later disclaimed its opinion on Made.com's 2022 interim statements due to material uncertainty about the company's ability to continue operating.

Yahoo Finance
Jul 16th, 2026
Australia and New Zealand apply pressure on Big Four over misconduct and workforce concerns

Australia's securities regulator is reviewing internal and whistleblower complaints about audit conduct at all Big Four accounting firms. The Australian Securities and Investments Commission will examine allegations of misuse or sharing of confidential information at PwC, Deloitte, EY and KPMG. The review follows multiple scandals, including PwC Australia's 2023 tax leaks case, where a former partner disclosed confidential government information about multinational tax avoidance laws. KPMG Australia recently revealed that more than two dozen employees, including one partner fined A$10,000, used AI to cheat on internal training exams. Meanwhile, Deloitte's latest workforce survey in New Zealand indicates younger professionals are becoming more selective about careers in public accounting.

Associated Press
Jul 11th, 2026
Trinidad and Tobago signs agreements for 450MW US data centers amid environmental concerns

Trinidad and Tobago has signed agreements with two US companies to develop data centres in the Caribbean nation. The memorandums of understanding with Florida-based Hummingbird AI Holdings and New York's Ernst and Young were signed on Friday, marking the first such deals with a Caribbean country. Ernst and Young will develop a 300-megawatt data centre, whilst Hummingbird AI Holdings plans a 150MW AI infrastructure facility. The government said the initiatives could generate over 5,000 jobs. However, the deals have sparked environmental concerns. Social activist Dr Wayne Kublalsingh criticised the energy consumption plans, whilst water-intensive data centres could strain Trinidad and Tobago's already stretched water supply system.

The Register
Jul 6th, 2026
EY sacks staff for allegedly accessing Australian PM's bank account

EY has sacked two staff members who allegedly accessed Australian Prime Minister Anthony Albanese's bank account details whilst working on a contract for Commonwealth Bank. The bank has not commented on how the contractors accessed such sensitive information. The incident means all Big Four consultancies now face scrutiny in Australia. KPMG's chair recently departed after inappropriate use of client data, whilst Deloitte repaid fees for submitting an AI-generated report. PWC faced the most serious scandal, using knowledge gained from tax policy consultations to advise tech companies on reducing tax payments. EY, formerly Ernst and Young, has not disclosed further details about the alleged breach or the circumstances surrounding the access to the Prime Minister's banking information.