Summer 2026

Product Marketing Intern

Posted on 3/12/2026

Diligent

Diligent

1,001-5,000 employees

SaaS GRC platform for board management

Compensation Overview

$20/hr

New York, NY, USA

Hybrid

Hybrid role; onsite at least 50% of the time for NY office.

Category
Product (1)

Get referred to Diligent

See people who can refer or advise you

Requirements
  • Turn complex information into clear, structured, and usable insights, with strong written communication skills.
  • Conduct research and analysis across qualitative sources (interviews, deal notes, call summaries) and basic quantitative/data sets (spreadsheets).
  • Apply strong organizational skills and attention to information structure to create repeatable, easy-to-use outputs.
  • Leverage AI tools to support research, synthesis, and knowledge management workflows.
Responsibilities
  • Support core go-to-market initiatives for the Board product through research, analysis, and development of clear, sales-ready messaging and positioning.
  • Build and maintain foundational assets (Messaging House, personas, value narratives) by synthesizing product capabilities, target audiences, pain points, and competitive context into usable insights for commercial teams.
  • Conduct persona and customer research, including creating and refining a Director persona, mapping challenges and buying drivers to product capabilities and value propositions.
  • Own ongoing win/loss analysis, performing weekly qualitative reviews of key deals and delivering concise insights and an end-of-internship quantitative and qualitative summary.
  • Analyze pricing and packaging performance, assessing adoption trends, deal feedback, and customer signals to identify what’s working, what’s not, and why.
  • Maintain and enhance competitive intelligence, monitoring competitor messaging, positioning, and product changes to surface implications and recommendations for sales and marketing.
Desired Qualifications
  • (Nice to have) Prior experience in product marketing, strategy, consulting, or sales operations, especially within B2B SaaS or enterprise software.
  • (Nice to have) Familiarity with competitive analysis, pricing research, CRM data, or BI tools.

Diligent provides governance, risk, and compliance (GRC) software as a service to organizations that need robust governance structures. It offers a subscription-based suite focused on board management, regulatory compliance, and ESG initiatives. The product is a cloud platform that lets clients securely manage board activities, track compliance requirements, assess risk, and support ESG commitments through integrated tools and workflows. What sets Diligent apart from competitors is its emphasis on data security and privacy, a user-friendly interface, and a comprehensive, scalable platform that serves diverse customers — from large enterprises to government entities and nonprofits — enabling leaders to make informed decisions and oversee governance effectively. The company’s goal is to help organizations navigate complex regulations, strengthen governance practices, mitigate risks, and achieve ESG objectives through secure, accessible GRC software.

Company Size

1,001-5,000

Company Stage

Acquired

Total Funding

$22.2M

Headquarters

New York City, New York

Founded

1994

Get referred to Diligent

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Forrester named Diligent a Q2 2026 GRC Leader on May 27.
  • AuditAI cut audit administration roughly 70%, from 120 hours to 35.
  • Third-Party Risk Intel and Cyber Risk Management expand attach rates across compliance teams.

What critics are saying

  • Judge orders in AML Global Eclipse cost Diligent $82,067.54 on March 3, 2026.
  • Diligent's 2022 breach settlement still signals security exposure and reputation drag through 2026.
  • AI Board Member's fall 2026 rollout faces explainability scrutiny from audit committees.

What makes Diligent unique

  • Diligent One unifies board, audit, cyber, and third-party workflows across 25,000 organizations.
  • AI Board Member and agentic GRC agents embed governed automation directly into boardrooms.
  • Thirty-plus years in governance and 700,000 board members give unmatched board-specific data.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Flexible Work Hours

Health Insurance

Paid Vacation

Wellness Program

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
DSG.AI
Jul 29th, 2026
How to govern an AI audit agent: the explainability gap no one is solving.

How to govern an AI audit agent: the explainability gap no one is solving. Editorial team. EY deployed enterprise-scale AI audit agents in early 2026. Diligent unveiled AuditAI at the IIA GAM conference in March 2026, then followed with an "Agentic GRC Workforce" announcement at its Elevate conference in April. The category has landed. What no vendor is discussing clearly is how internal audit functions should govern the AI systems they are about to deploy to perform their work. This is not the question of how to govern AI risk in the organization (a CISO question). It is the question of how a CAE governs the AI systems running the internal audit function itself, where the outputs are audit findings, control assessments, and assurance opinions delivered to the board. The governance requirements are different, and most existing AI governance frameworks were not written with audit independence in mind. Why AI audit agent governance is different. Most enterprise AI governance frameworks address how the organization manages AI systems it deploys to customers or uses in operational processes. The key concerns are fairness, accuracy, safety, and regulatory compliance. AI audit agents introduce a different set of concerns. The audit function is an independent assurance provider. Its outputs are formal opinions about the organization's control environment. If an AI system performs audit procedures, generates findings, or classifies control failures, the audit function's independence and professional judgment requirements extend to the AI performing that work. The IIA's International Standards for the Professional Practice of Internal Auditing (the Standards) require that internal audit findings be based on sufficient, reliable, relevant, and useful evidence. The 2024 Standards update introduced explicit language on AI tool use. The CAE bears accountability for whether evidence gathered by an AI system meets those criteria, regardless of the vendor's marketing claims. The explainability gap is specific: most AI audit agent vendors describe their systems in terms of what the agent does (collects evidence, tests controls, classifies findings). Fewer describe how the system reached a specific finding conclusion in a specific engagement, and fewer still provide the CAE with a documented audit trail that would satisfy an external review. The three risks most CAEs are not accounting for. Risk 1: The agent produces findings the auditor cannot explain. AI systems that classify control test results into "pass," "fail," or "exception" categories are making what is legally and professionally a judgment call. If an agent classifies a segregation of duties exception as "low risk" based on a pattern-matching model and that classification is wrong, the CAE is accountable for the conclusion, but the agent has no documentation of how it reached it. Ask your vendor: for a specific finding generated by the AI agent in a past engagement, can you produce a document that explains why the system reached that conclusion and what evidence it relied on? If the answer is "the model produces a confidence score but not an explanation," you have an explainability problem that will matter in the next external quality assessment. Risk 2: Model drift changes what "pass" means over time. AI agents trained on control testing data learn patterns from prior audit cycles. As the organization's control environment changes (new systems, new controls, staff turnover, process changes), an agent trained on prior-period data may apply outdated pass/fail thresholds without alerting the audit team that its reference frame has shifted. Auditor judgment is calibrated to the current environment. An AI model is calibrated to its training period. Continuous retraining is a technical requirement, not a feature. Risk 3: The agent's decisions are outside the audit committee's visibility. Audit committees receive findings and conclusions. If those conclusions were generated by an AI agent rather than a trained auditor, the audit committee has a legitimate question about the independence and professional judgment applied. Most CAEs deploying AI audit agents are not proactively disclosing this in their audit committee communications. The IIA's guidance on the Chief Audit Executive role requires transparency with the board about significant changes in the audit approach. Shifting 30-40% of control testing to AI agents is a significant change in approach. The absence of disclosure is a governance gap. Twelve questions to ask before deploying an AI audit agent. | # | Question | What it reveals | | 1 | Can the agent produce a finding-level explanation (not just a confidence score) for each audit conclusion? Explainability for external review | | 2 | Is the agent's decision logic documented in a technical specification the audit function owns? Independence of the audit trail | | 3 | How often is the model retrained, and who decides when retraining is triggered? Drift management | | 4 | What is the agent's false negative rate on control testing (failing to detect a real failure)? Audit risk quantification | | 5 | How does the agent handle novel control environments it was not trained on? Boundary behavior | | 6 | Does the agent's output satisfy the IIA's criteria for sufficient, reliable evidence? Standards compliance | | 7 | Is the agent's activity logged in a way that supports an external quality assessment? QA readiness | | 8 | What human review step occurs before an AI-generated finding enters the formal audit report? Oversight architecture | | 9 | How are the agent's errors tracked and fed back into model improvement? Learning mechanism | | 10 | Who has access to the agent's audit trail, and is it stored separately from the vendor's system? Data sovereignty | | 11 | Does the vendor's contract address what happens to the agent's trained model if the contract ends? IP and continuity risk | | 12 | Has the AI system itself been audited against an AI management framework (ISO 42001 or equivalent)? AI-of-AI governance | Question 12 is the one most vendors will avoid. The ISO 42001 standard for AI management systems was designed exactly for this situation: an organization deploying an AI system in a high-stakes assurance context needs documentation of how that AI system is managed, monitored, and controlled. A vendor whose AI audit agent is not documented to ISO 42001 or equivalent is asking the CAE to run audit procedures through a system that has not been audited. What good governance looks like in Practice. A well-governed AI audit agent deployment includes: Before deployment: A documented decision about which audit procedures the agent will and will not perform. The agent tests controls; a human auditor reviews exceptions and forms the audit opinion. Clear delineation of what "the agent does" versus "the auditor concludes." During operation: A finding review protocol where every AI-generated exception is reviewed by a credentialed auditor before it is included in a final report. The review should be documented: auditor name, review date, and any modification to the agent's initial classification. At audit committee reporting: Disclosure that AI-augmented procedures were used in the audit cycle, the scope of those procedures, and the human oversight applied. Most audit committees will welcome this transparency; the ones that don't are telling you something about their tolerance for novelty in the assurance function. Annually: An independent assessment of the agent's performance against the prior year's false negative rate benchmark, with results reported to the audit committee alongside the internal audit quality metrics. The AI agents for internal audit piece covers what agents currently do well and where human judgment remains necessary. This piece is about the governance layer on top: who is accountable when the agent is wrong, and how you know. The CAE's accountability does not transfer to the vendor. The final point is the one that matters most. Vendor contracts for AI audit agent software do not and cannot transfer professional accountability for audit conclusions to the vendor. The CAE is the responsible party under the IIA Standards and under the organization's governance framework. Deploying an AI audit agent shifts the operational burden of evidence collection and control testing to the system. It does not shift the professional judgment burden. The CAE who deploys an AI agent that generates a false negative on a material control failure is accountable for that finding under the same standards that apply to any audit quality failure. The practical implication: govern the agent like you govern a junior auditor. Review its work. Document your review. Correct its errors. Report its performance. That governance framework is not glamorous, but it is what the Standards require, and it is what an external quality assessment will look for. Diligent's "Agentic GRC Workforce" framing positions AI agents as headcount replacement. That framing is not a governance framework. A CAE who governs an AI agent like headcount will pass external review. One who does not will not. <!- related-links:start (auto-managed by seo/sync-internal-links.mjs) -> <!- related-links:end ->

Revival Holdings
Jul 23rd, 2026
5 new AI tools for audit and Risk teams.

5 new AI tools for audit and Risk teams. Stay compliant with regulations, anticipate potential issues, and provide clarity through assurance - what aren't audit and risk teams expected to do these days? Fortunately, AI tools designed for audit and risk purposes have exploded onto the market, helping teams manage their responsibilities and meet deadlines more easily. With numerous solutions available in the market, it's time to highlight some effective tools for modern audit and risk professionals. Here are the 5 essential tools Revival Holdings will be exploring: AI tools for risk: * AI Risk Essentials for ERM * Diligent Issue Manager * Risk Rating Aggregation AI tools for audit: * AI Request Agent * ACL Analytics AI Studio Three AI tools for risk teams. Here are the latest AI tools for risk teams. 1. Launch ERM faster with AI. Even as risks multiply, many organizations still rely on spreadsheets and ad hoc processes that make ERM slow and reactive. Diligent's new product, AI Risk Essentials, gives risk professionals a practical, defensible way to identify, assess, and mitigate enterprise risks with AI-powered benchmarking, all without a complex implementation. Rather than starting from scratch, teams can use AI-powered benchmarking to surface relevant risks from a library of 200,000+ real-world risks sourced from external data, building a consistent foundation for assessment, oversight, and governance in days, not months. How this helps risk teams: * Identify potential enterprise risks earlier using AI-powered risk identification and benchmarking * Establish a consistent approach to assessing and documenting risks with a guided, three-step workflow * Strengthen governance and regulatory readiness with a centralized risk library and interactive heatmaps for clearer visibility 2. Resolve what matters: Issue Manager. Across audits, risk assessments, and compliance reviews, issues can easily fall through the cracks. Diligent's Issue Manager brings everything together in one place, giving teams a unified way to track, prioritize, and resolve issues - no matter where they originate. With standardized workflows and real-time visibility, risk and audit leaders can be confident that issues are being addressed consistently and on time. How this helps risk & audit teams: * Centralize issues from audits, risk assessments, and controls testing * Define ownership, priorities, and timelines with configurable workflows * Track progress with dashboards showing overdue items and bottlenecks * Strengthen accountability and accelerate remediation 3. Clearer risk insight: Risk Rating Aggregation. When risks are assessed repeatedly, clarity can quickly fade. Risk Rating Aggregation, a solution from Diligent, provides risk professionals with a transparent, standardized way to consolidate assessment results into a single, meaningful risk score. No spreadsheets. No workarounds. Just a clearer, more defensible view of risk. How this helps risk teams: * Combine multiple assessments into one consistent risk rating * Choose aggregation methods such as Average, Minimum, Maximum, or Median * Preview results before applying them to ensure accuracy * Improve comparability and confidence in risk reporting 2 AI tools for audit teams. Read more to explore two new AI tools for audit teams. 1. Cut audit admin, not corners: AI Request Agent for internal audit. Evidence collection is essential, but it shouldn't consume weeks of an audit cycle. The AI Request Agent was built to remove the manual friction that slows audit teams down, without sacrificing control or traceability. By automating the creation, tracking, and follow-up of evidence requests, internal audit teams can spend less time chasing documents and more time delivering assurance. How this helps audit teams: * Automatically draft clear, context-aware evidence requests * Route requests to the right owners and track responses in real time * Handle reminders, overdue follow-ups, and escalations automatically * Maintain a complete, auditable trail of requests and responses 2. AI-Powered audit analytics, without the complexity: ACL AI Studio. Advanced analytics have long been powerful - but often limited to specialists with scripting skills. ACL AI Studio changes that, bringing sophisticated audit, risk, and compliance analytics within reach of every professional, no coding required. By combining natural-language querying, AI-guided test recommendations, and full compatibility with existing ACL Analytics scripts, ACL AI Studio removes technical barriers while preserving organizations' existing investments in analytics. Teams can analyze millions of records, surface anomalies quickly, and produce audit-ready results with confidence. It's AI-powered GRC analytics - without the complexity. How this helps audit, risk & compliance teams: * Run advanced analytics using natural-language queries - no scripting required * Analyze large, complex datasets and surface anomalies faster * Get AI-guided recommendations for relevant tests and procedures * Preserve and extend existing ACL Analytics scripts and investments * Maintain complete, audit-ready documentation of all analytics activity The results of AI tools for audit and Risk teams. Taken together, these innovations are designed to solve real, everyday challenges for audit and risk teams: * Less manual work, more time for analysis and insight * Earlier visibility into emerging and AI-driven risks * Stronger assurance through consistency, traceability, and clarity AI isn't replacing judgment - it's helping professionals apply it where it matters most. The next steps. After exploring how these tools are purpose-made for audit and risk teams, the only thing left is to explore them for your organization. Whether you're daydreaming or ready to harness these tools, its team can show you exactly how they can work in your organization's environment. Book a pressure-free demo to learn more today. Frequently asked questions. What are the AI tools for audit teams are available? For audit teams, the AI tools are AI Request Agent and ACL Analytics AI Studio. The AI Request Agent automates evidence requests, tracks responses, and maintains an auditable trail, reducing admin time. ACL Analytics AI Studio brings AI-guided analytics and natural-language querying to analyze large datasets without scripting, preserving existing investments and delivering audit-ready results. What is Risk Rating Aggregation and why is it beneficial? Risk Rating Aggregation provides a transparent, standardized way to consolidate assessment results into a single, meaningful risk score. It avoids spreadsheets and workarounds, allows different aggregation methods like Average, Minimum, Maximum, or Median, and lets users preview results before applying them to improve comparability and confidence in reporting. What problems does Diligent Issue Manager solve for audit and risk teams? Diligent Issue Manager centralizes issues from audits, risk assessments, and controls testing, defines ownership and timelines with configurable workflows, provides dashboards to track overdue items and bottlenecks, and strengthens accountability to accelerate remediation. How does AI Risk Essentials accelerate ERM deployment without a complex implementation? AI Risk Essentials accelerates ERM by using AI-powered benchmarking to surface relevant risks from a library of 200,000+ real-world risks, enabling a consistent foundation for assessment, oversight, and governance in days rather than months. What are the AI tools for risk and how do they help risk teams? The AI tools for risk include AI Risk Essentials for ERM, Diligent Issue Manager, and Risk Rating Aggregation. They help risk teams identify, assess, and monitor risks more efficiently, centralize issues, standardize workflows, provide governance-ready insights with heatmaps, and consolidate multiple assessments into a clear risk rating.

IT Security News
Jun 2nd, 2026
Diligent automates cyber risk assessments and reporting.

Diligent automates cyber risk assessments and reporting. 2026-06-02 14:06 Read the original article: Hacking & Cracking Diligent launched of Third-Party Risk Intel, an agentic due diligence and intelligence solution that automates the most time-consuming steps of third-party reviews, delivering up to 80% time savings for compliance, legal, and procurement teams. The launch builds on the company's recent acquisition of 3rdRisk, an AI-native third-party risk management solution... March 30, 2026 Diligent announced Diligent One, a platform that provides leadership, boards and practitioners with a single source for all their governance, risk and compliance (GRC) needs. Over the last six months Diligent has launched board and leadership reporting dashboards for ESG, Audit, Cyber Risk and Investor Engagement to bring clear and... September 14, 2023 In "Help Net Security" Diligent launched its Network and Information Security Directive (NIS2) Compliance Toolkit, designed to help organizations navigate the complexities of the European Union (EU) NIS2 Directive and bolster their cybersecurity resilience. The toolkit maps cybersecurity risk management obligations mandated by NIS2 against Cyber Risk Management Group's (CRMG) leading controls library, which... August 28, 2024

Associated Press
Jun 2nd, 2026
Diligent launches AI-powered cyber risk management to link security threats to business impact

Diligent has launched Diligent Cyber Risk Management, an AI-powered solution that helps organisations manage cybersecurity risk within their business context. Available summer 2026, the platform reduces manual cyber risk work from weeks to hours by connecting cyber threats to strategic objectives and critical processes. The solution features AI-powered risk assessments, automated asset-level risk scoring, centralised remediation tracking and board-ready reporting dashboards. It integrates technical security data with business intelligence on the Diligent One Platform, providing a unified view across enterprise risk management, audit and cyber functions. The platform aims to help security teams prioritise mitigation efforts by business impact rather than technical severity alone, cutting board preparation time from days to hours. Diligent has been recognised as a leader in seven major GRC evaluations.

Business Wire
Jun 2nd, 2026
Diligent launches ai-powered Cyber Risk Management to put business impact at the center of security decisions.

Diligent launches ai-powered Cyber Risk Management to put business impact at the center of security decisions. New AI-driven solution unifies cyber, risk and compliance so leaders can reduce manual work and focus on the risks that matter most NEW YORK-(BUSINESS WIRE)-Diligent, the AI leader in governance, risk and compliance (GRC), today announced Diligent Cyber Risk Management, its latest agentic solution that helps organizations manage cybersecurity risk within the context of their business. Available in summer 2026, Diligent Cyber Risk Management reduces manual cyber risk work from weeks to hours and connects cyber threats directly to strategic objectives, critical processes and board-level oversight, so leaders can focus security investments where they have the greatest business impact. Most security teams are drowning in vulnerability scans, threat feeds and control data, yet lacking the one thing the board keeps asking for: a clear picture of what is truly at risk for the business. Share "Municipal security teams don't have the luxury of piecing together risk from scattered scans and spreadsheets. We need up-to-date insight into how cybersecurity can best protect the services our community depends on," said Dave Schultz, Risk Manager, Risk and Controls, City of Lethbridge. "An agentic solution that accelerates assessments and clearly connects threats and vulnerabilities to strategic priorities would be transformative in helping us make credible recommendations to leadership." Diligent Cyber Risk Management brings together technical security data and business context in a single platform to support end-to-end cyber risk workflows: * AI-powered cyber risk assessments - Connects threat, vulnerability, asset and control data, and uses AI to generate risk scenarios, scores and rationales so teams prioritize mitigation by business impact, not just technical severity. * Risk scoring tied to critical assets and processes - Automated, asset-level risk scores pinpoint where the business and critical processes are most exposed, guiding patching, investment and remediation to what matters most. * Centralized risk remediation and IT compliance - A single workspace to define and track treatment plans, assign owners and monitor progress, combined with AI-powered IT compliance that maps controls across frameworks and automates testing. * Board-ready cyber risk reporting - Auto-updating dashboards connect cybersecurity threats to strategic objectives and critical processes, giving boards clear line of sight into cyber posture and cutting CISO board prep from days to hours. * Unified GRC view across ERM, Audit and Cyber - Delivered through the Diligent One Platform, so organizations can now manage cyber, enterprise and audit risk together, avoid conflicting risk narratives and provide a single source of truth for the C-suite and the board. "Most security teams are drowning in vulnerability scans, threat feeds and control data, yet lacking the one thing the board keeps asking for: a clear picture of what is truly at risk for the business," said Scott Bridgen, General Manager, Risk & Audit at Diligent. "Diligent Cyber Risk Management turns static risk registers and checkbox compliance into an AI-powered system of action, helping organizations prioritize the security decisions that matter and clarify the impact of AI, IT and cyber risk to management and the board." Building on innovations like AI Board Member, AI Risk Essentials, AuditAI, ACL AI, GovernAI and 3rdRisk, Diligent is weaving AI into every stage of the GRC lifecycle - helping organizations surface risks earlier, prioritize the right actions, and embed intelligent automation into day-to-day workflows. This growing portfolio of AI-first solutions has earned Diligent recognition as a Leader in seven major GRC evaluations across the five major independent firms, including Forrester, Gartner, IDC, Verdantix and Chartis. About Diligent Diligent is the AI leader in governance, risk and compliance (GRC) SaaS solutions, helping more than 1 million users and 700,000 board members to clarify risk and elevate governance. The Diligent One Platform gives practitioners, the C-suite and the board a consolidated view of their entire GRC practice so they can more effectively manage risk, build greater resilience and make better decisions, faster. Learn more at diligent.com. Contacts. Media Julia Stoyanov Marketing Communications Director, Diligent +1-604-669-4225 [email protected] More News From Diligent NEW YORK-( BUSINESS WIRE )-As general counsel and company secretary responsibilities grow faster than team capacity, governance leaders have a chance to shape AI adoption, improve visibility and strengthen board oversight, according to the inaugural Global State of Legal Entity Compliance report from Diligent. The report shows a function becoming more strategic but held back by outdated operating models, with 47% of respondents citing technology gaps and legacy systems as their biggest challeng... NEW YORK-( BUSINESS WIRE )-Diligent, the AI leader in governance, risk and compliance (GRC), today announced that it has been named a Leader in The Forrester Wave(TM): Governance, Risk, and Compliance Platforms Q2 2026 report. Diligent received the highest score possible in the Platform Use of AI and AI Agents criterion, which it believes reflects its leadership in embedding intelligence across the GRC lifecycle. Diligent also received the highest score possible in the criteria of Risk Identificat... TOKYO-( BUSINESS WIRE )-Shareholder activism in Asia has reached record levels, with activity up by almost 23% in 2025 as investors sharpen their focus on the region to capitalize on emerging opportunities, according to Diligent Market Intelligence's Corporate Governance in Asia 2026 report. Almost 250 Asia-based companies were publicly subjected to activist demands in 2025, up from 203 in 2024, with momentum sustained into the opening quarter of 2026 as activists targeted more than 100 issuers... Diligent. Release Versions Media Julia Stoyanov Marketing Communications Director, Diligent +1-604-669-4225 [email protected]

INACTIVE