FirstHR

AI Auditor Job Description Templates and Guide

AI auditor job description templates for bias audits, model risk, and AI governance: 6 role variants with pay benchmarks and FLSA notes. Free DOCX.

Nick Anisimov

Nick Anisimov

FirstHR Founder

Hiring
15 min

AI Auditor Job Description Templates and Guide

6 templates for the role that checks your AI systems: standard auditor, algorithmic bias auditor, model risk auditor, governance auditor, independent contract scope, and a small business first hire. Download as DOCX.

The first time someone asked me to prove that a model we relied on was fair, I discovered we could not answer the question. Not because the answer was bad. Because nobody had written down what the model was trained on, who approved it, or what number would have made us turn it off.

That gap is what an AI auditor exists to close. The role is new enough that most job descriptions online are a list of impressive nouns with no testing method attached, which produces candidates who can describe governance and cannot reproduce a result. The useful version of this posting is much more specific, and much more honest about independence.

At FirstHR we write hiring templates for companies without a risk department. The six below cover a standard auditor, an algorithmic bias auditor for hiring tools, a model risk auditor for regulated industries, a governance and compliance auditor, an independent contract scope, and a small business first hire.

TL;DR
An AI auditor independently tests the AI systems a company builds or buys for bias, accuracy, drift, and control failures, then documents evidence a second auditor could reproduce. No BLS occupation exists for the title. Nearest classifications ran $80,730 to $129,180 in median annual pay (BLS OEWS, May 2025). Six templates below, downloadable as DOCX.

What an AI Auditor Actually Does

An AI auditor independently evaluates AI and machine learning systems and reports what the testing showed. The job is assurance, not development: someone else builds the model, and the auditor checks whether it behaves the way the company claims it does.

The distinction sounds obvious and gets violated constantly. Plenty of postings titled AI auditor describe a person who builds fairness tooling, tunes thresholds, and then reports on their own work. That is a useful engineer. It is not an audit, and calling it one creates a document that will not survive scrutiny when it matters.

Assurance, not development
The auditor checks, the engineer builds
An AI auditor does not ship models. The job is to test what someone else shipped and to write down what the test showed, including when the answer is inconvenient for the team that built it.
Evidence, not opinion
Method stated before the result
A real audit fixes the criteria and the method before fieldwork starts. A review that decides its standard after seeing the numbers is a status update with a serious job title attached.
Independence has a legal meaning
Sometimes an employee cannot do it
Where a rule requires an independent auditor, the definition usually excludes anyone who built, sold, or operates the tool, and anyone with a financial interest in the outcome. That can rule out your own staff.
The scope is the whole lifecycle
Not just the model file
Training data, feature choices, validation, deployment thresholds, monitoring, human override, and vendor tools all sit inside the audit. Most failures happen at the edges, not inside the model.
Write the Reporting Line Into the Posting
The most important sentence in an AI auditor job description is the one naming who this person reports to and what happens when a finding is inconvenient. If the role reports to the engineering leader whose models it tests, say so and describe the escalation path. Serious assurance candidates read that section first and screen you out silently when it is missing. A posting that dodges the question attracts people who will not push back, which defeats the purpose of the hire.

AI Auditor vs Internal Auditor vs AI Analyst

The three roles differ by what they own: an AI auditor tests AI systems for correctness and harm, an internal auditor tests controls and processes across the whole business, and an AI analyst builds and interprets AI-driven analysis rather than checking anyone else’s work. Hiring the wrong one is the most common mistake here.

Small companies frequently want one person to do all three, which is possible for a while and worth stating openly in the posting. What does not hold up is claiming a person is auditing systems they also own.

RolePrimary dutyReports toHire this one when
AI auditorIndependent testing of AI systems for bias, accuracy, drift, and control failureRisk, legal, or the boardAI drives decisions that affect people and you need evidence
Internal auditorAssurance over controls and processes across the businessAudit committee or CFOYou need broad control assurance, not model-specific testing
AI analystBuilding analysis and reporting with AI toolsData or business functionYou want insight produced, not existing systems checked
Compliance officerMapping obligations to operations and owning policyGeneral counsel or CEOThe gap is knowing which rules apply, not testing models
Model risk managerOwning validation standards inside the second lineChief risk officerYou are regulated and need a validation function, not only audit

If the gap you actually have is analysis rather than assurance, the AI analyst templates are a better fit. If it is broad control assurance across the business, start with the internal auditor templates instead.

AI Auditor Duties and Responsibilities

The duty list falls into four groups: data and inputs, model and method, controls and process, evidence and reporting. Most postings cover the second group and skip the other three, which is why they attract data scientists rather than auditors.

Data and inputs
Provenance and consent for training data
Representativeness across the groups affected
Proxy variables that stand in for protected traits
Labeling quality and who did the labeling
Model and method
Performance against a stated benchmark
Disparate impact testing by group
Drift monitoring and the threshold that triggers action
Explainability sufficient for the decision at stake
Controls and process
Change management and model version control
Human override: available, used, and recorded
Approval before deployment, by a named person
Incident response when the model is wrong
Evidence and reporting
Workpapers a second auditor could reproduce
Findings with severity, owner, and due date
Published summaries where a rule requires one
Re-test after remediation, not just a status update

The evidence group is the one that separates a real audit from a thoughtful review. Workpapers have to be reproducible, findings need a severity rating and a named owner, and remediation gets re-tested rather than marked complete on someone’s word. Our guide to writing a job description covers the general structure these templates follow.

6 AI Auditor Job Description Templates

Download all six as one file or copy them individually. Each follows the same structure: company overview, position summary, key responsibilities, qualifications, an independence or classification note, an equal opportunity statement, and how to apply. The bracketed fields are the only parts you need to change.

Download All 6 AI Auditor Job Description Templates
Standard, algorithmic bias, model risk, governance and compliance, independent contract scope, and small business first hire. All in one download.
AI Auditor (Standard)
The generalist assurance role
Lifecycle testing, findings, and remediation tracking, with an independence note that forces you to decide the reporting line before you post.
Algorithmic Bias Auditor
Hiring and HR tools
Selection rates, impact ratios, published summaries, and candidate notices for automated employment decision tools.
AI Model Risk Auditor
Regulated industry, third line
Framework-level assurance over model risk management, with re-performed validation and audit committee reporting.
AI Governance and Compliance Auditor
Inventory, policy, evidence
The role that keeps the AI inventory, runs impact assessments, and holds the evidence customers and acquirers ask for.
Independent AI Auditor
Contract or fractional scope
A scope of work rather than a job posting, for when the rule that applies to you requires a genuinely outside auditor.
First AI Auditor Hire
Small business, no risk team
Part auditor, part builder, with a first 90 days plan and honest language about what independence can mean at your size.

Template 1: AI Auditor (Standard)

The generalist assurance role: lifecycle testing, findings with owners, remediation tracking, and an independence note that forces you to settle the reporting line before you post.

AI Auditor Job Description (Standard)
AI AUDITOR JOB DESCRIPTION
Company: __ ([City, State] / [Remote / Hybrid])
Reports to: [Head of Risk / Head of Compliance / Chief Audit Executive]
Employment type: Full-time
FLSA status: Exempt (see classification note)
Compensation: $_ to $_ per year

ABOUT [COMPANY NAME]

[Company Name] builds [product] for [market]. We use machine learning in
[list the systems: pricing, underwriting, fraud detection, hiring, content
moderation, customer support routing]. We are hiring an AI Auditor to give us
an independent read on whether those systems do what we claim they do.

POSITION SUMMARY

The AI Auditor independently evaluates the AI and machine learning systems this
company builds or buys, tests them for bias, accuracy, drift, and control
failures, documents the evidence, and reports findings to [committee or
executive] with recommended remediation and owners.

KEY RESPONSIBILITIES

Maintain the inventory of AI systems in use, including third-party tools
Plan and run audits across the model lifecycle: data sourcing, training,
validation, deployment, monitoring, and retirement
Test models for disparate impact across protected groups and document the
method, the thresholds, and the result
Review training data for provenance, consent, quality, and representativeness
Evaluate model documentation, version control, and change management
Test human-in-the-loop controls: does the override actually get used
Assess vendor AI tools and the contractual right to audit them
Write findings with severity ratings, named owners, and due dates
Track remediation to closure and re-test
Report to [audit committee / risk committee / executive team] on [cadence]
Keep the audit program aligned to [NIST AI Risk Management Framework /
ISO 42001 / internal standard]

REQUIRED QUALIFICATIONS

[Number] years in audit, model validation, risk, or data science
Working knowledge of statistics and model evaluation metrics
Ability to read Python or R well enough to check someone else's analysis
Experience testing for disparate impact or fairness across groups
Clear technical writing for a non-technical audience
Bachelor's degree in [statistics, computer science, data science, accounting,
or a related field] or equivalent experience

PREFERRED QUALIFICATIONS

[CIA / CISA / CRISC / AI governance certification]
Experience in a regulated industry: [financial services, healthcare,
insurance, employment]
Familiarity with the NIST AI Risk Management Framework
Prior experience presenting findings to a board or audit committee

INDEPENDENCE AND REPORTING NOTE (read before posting)

An audit is only worth what its independence is worth. Decide before you post
whether this role reports into the team that builds the models. If it does,
say so honestly and describe the escalation path that protects the finding. If
your audits are required to be performed by an independent auditor under a law
that applies to you, an employee of the company generally cannot perform them.
Confirm which of your obligations require true third-party independence.

CLASSIFICATION NOTE

This role is normally exempt under the FLSA administrative or learned
professional exemption when the primary duty is analysis, evaluation, and
judgment on matters of significance, and the salary meets the federal threshold
of $684 per week ($35,568 per year) plus any higher state threshold. Confirm
your state's own salary and duties tests. This is general information, not
legal advice.

EEO STATEMENT

[Company Name] is an equal opportunity employer and provides reasonable
accommodations for the essential functions of this role.

COMPENSATION AND HOW TO APPLY

Compensation: $_ to $_ per year, [bonus], [benefits summary]
To apply, email __ with your resume and one example of an
audit finding you wrote and had to defend.

Template 2: Algorithmic Bias Auditor (Hiring and HR Tools)

For automated tools in hiring and promotion: selection rates, impact ratios, published summaries, and candidate notices. Pair it with our guide to AI screening in recruitment before you scope the work.

Algorithmic Bias Auditor Job Description (Hiring and HR Tools)
ALGORITHMIC BIAS AUDITOR JOB DESCRIPTION (HIRING AND HR TOOLS)
Company: __ ([City, State] / [Remote])
Reports to: [Head of People / General Counsel / Head of Compliance]
Employment type: Full-time or [fractional / project]
FLSA status: Exempt when employed directly (see classification note)
Compensation: $_ per year or $_ per audit engagement

ABOUT THIS ROLE

[Company Name] uses automated tools in hiring: [resume screening, assessment
scoring, video interview analysis, candidate ranking, sourcing recommendations].
We are hiring an Algorithmic Bias Auditor to test those tools for disparate
impact and to produce the documentation a regulator or a plaintiff would ask
for.

POSITION SUMMARY

The Algorithmic Bias Auditor tests automated employment decision tools for
disparate impact across race, ethnicity, and sex, calculates selection rates
and impact ratios, documents the methodology and the data limitations, and
produces a published summary where the law requires one.

KEY RESPONSIBILITIES

Inventory every automated tool that substantially assists or replaces a
human decision in hiring, promotion, or performance
Calculate selection rates and impact ratios by race, ethnicity, and sex,
and by intersectional category where the data supports it
Apply the four-fifths rule as a screening indicator, not as a verdict, and
document where statistical significance changes the picture
Assess data sufficiency and state plainly when a category is too small to
test
Review vendor claims and vendor-supplied audit results against your own data
Prepare the published summary of results and the candidate notice
Advise on remediation: threshold changes, feature removal, retraining, or
retiring the tool
Keep the audit record: method, data, dates, and who signed off
Re-audit on the required cadence and after any material model change

REQUIRED QUALIFICATIONS

Background in industrial-organizational psychology, statistics, data science,
or employment discrimination analysis
Direct experience with adverse impact analysis and selection procedure
validation
Comfort with the Uniform Guidelines on Employee Selection Procedures
Ability to explain a statistical finding to a hiring manager without jargon
[Number] years in a testing, validation, or audit function

INDEPENDENCE NOTE (read before posting)

Some jurisdictions require the bias audit to be performed by an independent
auditor, meaning someone who was not involved in using, developing, or
distributing the tool and who has no financial interest in it. If that applies
to you, this posting is for internal readiness work, and the statutory audit
itself still has to go to an outside party. Do not assume an employee can sign
the audit your ordinance requires. Confirm the definition that applies in your
jurisdiction before you scope the role.

CLASSIFICATION NOTE

Exempt under the FLSA learned professional or administrative exemption when
employed directly and the duties and salary tests are met. If you engage an
outside auditor instead, that is a services contract, not employment, and the
independence requirement is usually the reason. This is general information,
not legal advice.

EEO STATEMENT

[Company Name] is an equal opportunity employer and provides reasonable
accommodations for the essential functions of this role.

COMPENSATION AND HOW TO APPLY

Compensation: $_ per year or $_ per engagement
To apply, email __ with your resume and a redacted sample
adverse impact analysis.
Still Using Spreadsheets for Onboarding?
Automate documents, training assignments, task management, and track onboarding progress in real time.
See How It Works

Template 3: AI Model Risk Auditor (Regulated Industry)

Third-line assurance over the model risk framework, with re-performed validation on a risk-based sample and reporting to an audit committee rather than a business line.

AI Model Risk Auditor Job Description (Regulated Industry)
AI MODEL RISK AUDITOR JOB DESCRIPTION (REGULATED INDUSTRY)
Company: __ ([City, State])
Reports to: [Chief Audit Executive / Head of Model Risk Management]
Employment type: Full-time
FLSA status: Exempt (see classification note)
Compensation: $_ to $_ per year

ABOUT THIS ROLE

[Company Name] operates in [banking / lending / insurance / healthcare] and
runs models that affect [credit decisions, pricing, claims, clinical triage].
We are hiring an AI Model Risk Auditor to provide third-line assurance over the
model risk framework and over the machine learning models inside it.

POSITION SUMMARY

The AI Model Risk Auditor independently assesses whether model development,
validation, approval, monitoring, and governance work as documented, tests a
sample of models directly, and reports control gaps to the audit committee.

KEY RESPONSIBILITIES

Audit the model risk framework end to end: inventory, tiering, development
standards, independent validation, approval, monitoring, and retirement
Re-perform validation on a risk-based sample of models
Test performance monitoring and drift thresholds against actual practice
Assess explainability and adverse action reasoning where decisions affect
consumers
Review challenger models and benchmarking evidence
Evaluate data lineage, feature provenance, and proxy variable risk
Test the effectiveness of model overrides and manual exceptions
Assess third-party and vendor model governance, including the right to audit
Issue findings with severity, root cause, owner, and target date
Support [regulatory examinations / external audit] with workpapers
Track issue closure and validate remediation independently

REQUIRED QUALIFICATIONS

[Number] years in internal audit, model validation, or model risk management
Quantitative degree or equivalent experience in statistics or econometrics
Hands-on ability to reproduce a model result, not just read a memo
Understanding of consumer protection and fair lending concepts where relevant
Audit workpaper discipline: evidence, sampling rationale, conclusions

PREFERRED QUALIFICATIONS

[CIA / CISA / FRM / CFA] or equivalent
Prior regulatory examination experience
Experience auditing machine learning models rather than only linear ones

CLASSIFICATION AND GOVERNANCE NOTE

Exempt under the FLSA administrative or learned professional exemption when the
duties and salary tests are met. Structurally, third-line assurance normally
reports to the audit committee rather than to a business line, and mixing the
build function with the assurance function is the single most common finding an
examiner writes up. Decide the reporting line before you post, not after the
first uncomfortable finding. This is general information, not legal advice.

EEO STATEMENT

[Company Name] is an equal opportunity employer and provides reasonable
accommodations for the essential functions of this role.

COMPENSATION AND HOW TO APPLY

Compensation: $_ to $_ per year, [bonus], [benefits summary]
To apply, email __ with your resume.

Template 4: AI Governance and Compliance Auditor

The role that keeps the AI inventory, runs impact assessments, and holds the evidence customers and acquirers ask for. Closer in shape to our compliance officer templates than to a technical audit role.

AI Governance and Compliance Auditor Job Description
AI GOVERNANCE AND COMPLIANCE AUDITOR JOB DESCRIPTION
Company: __ ([City, State] / [Remote])
Reports to: [General Counsel / Chief Compliance Officer / Head of Risk]
Employment type: Full-time
FLSA status: Exempt (see classification note)
Compensation: $_ to $_ per year

ABOUT THIS ROLE

[Company Name] has AI in [number] products and in [number] internal workflows,
and the rules that apply to them are changing faster than our policies are. We
are hiring an AI Governance and Compliance Auditor to hold the framework
together: policy, inventory, assessment, evidence, and the audit trail.

POSITION SUMMARY

The AI Governance and Compliance Auditor maintains the AI system inventory,
runs risk assessments against a recognized framework, audits compliance with
internal AI policy and applicable law, and keeps the evidence a customer,
regulator, or acquirer will ask to see.

KEY RESPONSIBILITIES

Own the AI system inventory: purpose, owner, data, risk tier, and status
Run impact assessments on new and materially changed AI use cases
Map obligations to systems: which rule applies to which tool, and who signs
Audit compliance with internal AI use policy, including shadow AI tools
Maintain evidence against [NIST AI Risk Management Framework / ISO 42001]
Review AI vendor contracts for audit rights, data use, and indemnity
Run the disclosure and notice process where a law requires one
Coordinate external audits and answer customer security questionnaires
Train employees on the AI use policy and record completion
Report the AI risk posture to [executive team / board] on [cadence]

REQUIRED QUALIFICATIONS

[Number] years in compliance, governance, privacy, or audit
Working knowledge of at least one recognized AI risk framework
Ability to read model documentation and ask the right follow-up question
Strong writing: policies, assessments, and findings people actually follow
Comfort operating without a large team behind you

PREFERRED QUALIFICATIONS

Privacy or AI governance certification
Experience with [SOC 2 / ISO 27001] evidence collection
Prior work in a regulated or enterprise-selling environment

COMPLIANCE NOTE (read before posting)

AI rules are a moving target. Some obligations are already live and enforced,
some have been delayed or rewritten mid-cycle, and the mix depends on where you
operate and what the system decides. Write the role around the framework and
the evidence rather than around a single statute, so the job survives the next
amendment. Confirm current obligations with counsel before you commit the
company to a compliance claim in a contract. This is general information, not
legal advice.

EEO STATEMENT

[Company Name] is an equal opportunity employer and provides reasonable
accommodations for the essential functions of this role.

COMPENSATION AND HOW TO APPLY

Compensation: $_ to $_ per year, [benefits summary]
To apply, email __ with your resume and a writing sample.

Template 5: Independent AI Auditor (Contract or Fractional)

A scope of work rather than a job posting, for engagements where the applicable rule requires a genuinely outside auditor and an employee cannot sign the report.

Independent AI Auditor Job Description (Contract or Fractional)
INDEPENDENT AI AUDITOR SCOPE (CONTRACT OR FRACTIONAL)
Client: __ ([City, State])
Engaged by: [General Counsel / Board / Audit Committee / Head of Risk]
Engagement type: Independent contractor, [fixed scope / retainer]
Classification: Not an employee (see independence and classification note)
Fee: $_ per engagement or $_ per [day / month]

ABOUT THIS ENGAGEMENT

[Client Name] needs an independent audit of [system or tool] because
[a law requires it / a customer requires it / the board asked for it]. The
auditor must have had no role in building, selling, or operating the system
under review.

SCOPE SUMMARY

The Independent AI Auditor evaluates [system] against [stated criteria],
performs testing on data the client provides, issues a written report with
findings and an opinion, and delivers any published summary the applicable rule
requires.

SCOPE OF WORK

Agree criteria, materiality, and testing method in writing before fieldwork
Confirm and document independence from the tool, the vendor, and the client
Obtain the data, the model documentation, and the decision logs
Test for [disparate impact / accuracy / drift / control effectiveness]
Document data limitations and any category too small to test
Issue a draft report, take management response, and issue a final report
Deliver the published summary and any required notice language
Retain workpapers for [retention period]

DELIVERABLES

Engagement letter with scope, criteria, and independence confirmation
Testing workpapers with reproducible method
Final report with findings, severity, and recommendations
Published summary of results where the applicable rule requires one
Re-test memo after remediation, if included in scope

REQUIRED QUALIFICATIONS

Demonstrated independence from the system, its vendor, and its operators
[Number] years performing statistical or audit testing of automated systems
Professional credential in audit, statistics, or a related discipline
Errors and omissions insurance of at least $________
References from prior audit engagements of comparable scope

INDEPENDENCE AND CLASSIFICATION NOTE

This is a contractor engagement on purpose. Where a rule requires an
independent auditor, the definition usually excludes anyone employed by the
company, anyone involved in developing or distributing the tool, and anyone
with a financial interest in the outcome. Be careful in the other direction
too: if you set the auditor's hours, methods, and daily direction the way you
would an employee's, you have a worker classification problem regardless of
what the contract says. Keep the engagement scoped to a deliverable and let the
auditor control the method. This is general information, not legal advice.

HOW TO SUBMIT A PROPOSAL

Send a proposal to __ with your independence statement,
proposed method, timeline, fee, and two references.

Template 6: First AI Auditor Hire (Small Business)

Part auditor and part builder, with a first 90 days plan and honest language about what independence can and cannot mean on a team of twelve.

First AI Auditor Job Description (Small Business)
AI AUDITOR JOB DESCRIPTION (FIRST HIRE, SMALL BUSINESS)
Company: __ ([City, State] / [Remote])
Reports to: [Founder / COO / General Counsel]
Employment type: Full-time [or part-time / fractional]
FLSA status: Exempt (see classification note)
Compensation: $_ to $_ per year

ABOUT THIS ROLE

[Company Name] is a small team using AI across [product features and internal
workflows]. We do not have a risk department, an audit function, or a
governance committee. You would be the first person whose job is to know what
our AI systems actually do and to say so plainly.

POSITION SUMMARY

The AI Auditor builds the first version of our AI oversight: an inventory, a
short usable policy, a risk-tiering method, a testing routine for the systems
that matter, and a reporting rhythm the founders will actually read.

KEY RESPONSIBILITIES

FIRST 90 DAYS
Build the AI system inventory, including tools teams adopted on their own
Tier systems by the harm a wrong output would cause
Write a one-page AI use policy people can follow
Pick a framework to anchor to and document the gap
ONGOING
Test the highest-tier systems: accuracy, bias, drift, and failure modes
Review AI vendor contracts before signing, focused on data use and audit
rights
Run a short assessment before any new AI feature ships
Keep the evidence file customers and auditors ask for
Report to the founders monthly in one page, with issues and owners
Train the team on the policy and record who completed it

REQUIRED QUALIFICATIONS

[Number] years in audit, risk, compliance, data science, or analytics
Enough statistics to test a model and enough plain English to explain it
Comfort building a function from nothing, without a template library
Judgment about which risks are real for a company our size
Willingness to do the work rather than to design a program for someone else
to do

SCOPE HONESTY NOTE (read before posting)

At small company scale this role is part auditor and part builder, which means
strict independence is not achievable on day one. Say that in the posting
rather than discovering it in month two. Define the escalation path: who the
auditor can go to when a finding is inconvenient, and what happens then. If a
specific rule requires a truly independent audit of one of your tools, budget
for an outside auditor for that piece and keep this role focused on everything
else.

CLASSIFICATION NOTE

Exempt under the FLSA administrative or learned professional exemption when the
primary duty involves independent judgment on matters of significance and the
salary meets the federal threshold of $684 per week ($35,568 per year) plus any
higher state threshold. A part-time version of this role still has to clear the
full weekly salary threshold to stay exempt, which is a common and expensive
oversight. This is general information, not legal advice.

EEO STATEMENT

[Company Name] is an equal opportunity employer and provides reasonable
accommodations for the essential functions of this role.

COMPENSATION AND HOW TO APPLY

Compensation: $_ to $_ per year, [equity], [benefits summary]
To apply, email __ with your resume and a short note on
the first three things you would check here.

What the Rules Already Require

Employers using automated tools in hiring already carry concrete audit duties in some jurisdictions, and the underlying discrimination standards are decades older than the technology. You do not need a new AI statute to have an obligation worth auditing against.

The clearest live example is New York City Local Law 144 on automated employment decision tools, which requires a bias audit within the previous year, a public summary of the results, and notice to candidates before the tool is used. Underneath it sits the far older four-fifths rule in the Uniform Guidelines on Employee Selection Procedures, which applies to any selection procedure regardless of who or what made the decision.

Automated hiring tools already carry audit duties
New York City Local Law 144 of 2021 bars an employer or employment agency from using an automated employment decision tool unless the tool has been through a bias audit within the previous year, a summary of the audit results is publicly available, and required notices have been given. The city began enforcement on July 5, 2023, and its own guidance clarified that the candidate notice must be provided ten business days before the tool is used. The audit has to be performed by an independent auditor, which is the detail that surprises most employers: the definition excludes people who used, developed, or distributed the tool and people with a financial interest in it, so your own staff often cannot sign it. If you recruit into that city, the obligation follows the job, not your headquarters. This is general information, not legal advice.
The four-fifths rule predates AI by decades
The Uniform Guidelines on Employee Selection Procedures, adopted in 1978 and still in force, say a selection rate for any race, sex, or ethnic group that is less than four-fifths, or eighty percent, of the rate for the highest group will generally be regarded by federal enforcement agencies as evidence of adverse impact. Nothing in that language cares whether the selection was made by a person, a spreadsheet, or a neural network. The same guidelines require employers to keep records of the impact of their selection procedures by sex and by race or ethnic group. That is the single most useful test an AI auditor runs on a hiring tool, and it is also the reason an auditor needs demographic data that many small employers never collected in a usable form. This is general information, not legal advice.
A framework gives the audit something to audit against
An audit without stated criteria is just a review. The NIST AI Risk Management Framework, published by the National Institute of Standards and Technology in January 2023, is the most widely adopted voluntary reference in the United States, organized around four functions: govern, map, measure, and manage. It is not a law and it does not create obligations, which is exactly why it works as an internal yardstick. Write the framework into the job description and into the audit plan, so findings are phrased as gaps against a named standard rather than as personal disagreements with the engineering team. ISO 42001 serves the same purpose where a customer wants a certifiable management system. Pick one, name it in the posting, and stop arguing about the definition of good.
State AI law is a moving target, so hire for the method
Several states have passed or amended broad AI accountability statutes, and the ones aimed at algorithmic discrimination have been rewritten, delayed, and litigated more than once. Colorado is the clearest example: its 2024 artificial intelligence act was amended and pushed back twice before taking effect, and the 2026 replacement narrowed the original duty of care toward disclosure and transparency instead. The practical lesson for an employer is not to chase statutes. Hire for the method: inventory, risk tiering, testing, evidence, and a reporting line. A person who can produce reproducible testing evidence can answer whichever rule lands, while a person hired to comply with one specific statute is out of date the moment it is amended. Confirm your current obligations with counsel rather than with a job posting.

For the internal standard your audits test against, the NIST AI Risk Management Framework is the usual anchor in the United States. Name it in the posting. Our overview of AI in HR covers where these systems tend to show up inside a small company first.

Skills, Credentials, and Independence

The hard requirement is the ability to reproduce a result, not to describe one. An AI auditor who cannot open the data and check the analysis is reading someone else’s homework and grading it on presentation, which is how a bad model passes an audit.

The second requirement is writing. A finding that a hiring manager cannot act on is not a finding. Look for candidates who can state a statistical result in one plain sentence, then defend the method underneath it when challenged.

RequirementHow to handle it in the posting
Statistics and model evaluationRequired; test it with a work sample rather than trusting the resume
Reading Python or RRequired for testing roles, preferred for governance roles; say which you mean
Adverse impact analysisRequired for any role touching hiring or promotion tools
Audit methodology and workpapersRequired; this is what separates an auditor from an analyst
Audit certification (CIA, CISA, CRISC)Preferred, not required; the field is too new for a clean credential bar
Framework knowledge (NIST AI RMF, ISO 42001)Name the one you use and mark it required or preferred
Independence from the systems under reviewState the real position, including where it is imperfect
Regulated industry experienceRequired only if a regulator will read the workpapers
Screen With a Work Sample, Not a Conversation
This field rewards vocabulary, and vocabulary interviews poorly. Hand candidates a real model card, a vendor bias audit summary, or an anonymized set of selection rates and ask what they would test next and what they would refuse to conclude. The strong answers name a specific method, state a data limitation out loud, and decline to draw a conclusion the sample cannot support. The weak answers recite framework functions. Thirty minutes of this tells you more than three interviews.

What to Pay an AI Auditor

There is no Bureau of Labor Statistics occupation for AI auditor. The Standard Occupational Classification system predates the role, so no wage line exists for the title and anyone quoting one is quoting something else. Benchmark against the classifications the work borrows from instead.

Nearest BLS Classifications, National Medians
According to the Bureau of Labor Statistics Occupational Employment and Wage Statistics survey (May 2025), median annual wages were $80,730 for compliance officers, $83,680 for accountants and auditors, $101,860 for management analysts, $120,230 for data scientists, and $129,180 for information security analysts. The 75th percentile ran $109,010 for compliance officers and $158,880 for data scientists (U.S. Bureau of Labor Statistics, OEWS national estimates).
Nearest BLS classificationSOC codeNational median (BLS OEWS, May 2025)When it anchors your range
Compliance officers13-1041$80,730 per yearGovernance and policy emphasis, little hands-on testing
Accountants and auditors13-2011$83,680 per yearAudit methodology, evidence, and independence emphasis
Management analysts13-1111$101,860 per yearProcess and control design across functions
Data scientists15-2051$120,230 per yearRole re-performs validation and writes its own testing code
Information security analysts15-1212$129,180 per yearTechnical control testing and adversarial evaluation

The practical read is that a governance-flavored AI auditor competes in a market near the compliance and audit medians, while a testing-flavored one competes directly with data science and security hiring and has to be paid accordingly. Decide which you are buying before you set the number, publish a good-faith range where pay transparency laws apply, and expect the range to widen once you say the word independent out loud.

Companies Using FirstHR Onboard 3x Faster
Join hundreds of small businesses who transformed their new hire experience.
See It in Action

Exempt or Non-Exempt

An AI auditor employed directly is almost always exempt, under either the administrative or the learned professional exemption. Issuing audit findings on systems that drive company decisions is close to the textbook description of discretion and independent judgment on matters of significance.

The salary tests still apply. The federal threshold is $684 per week, or $35,568 per year, after the 2024 rule that would have raised it was vacated in November 2024 and formally rescinded in May 2026. Several states set higher thresholds, and the state number wins where it is higher. Our breakdown of exempt versus non-exempt classification works through both tests.

Two traps deserve naming. A part-time AI auditor still has to clear the full weekly salary amount to remain exempt, which catches companies that hire the role at two days a week. And an independent auditor engaged precisely because a rule demands independence is a contractor rather than an employee, which means you cannot direct their hours, methods, and daily work the way you would a staff member without creating a worker classification problem. Scope those engagements to a deliverable and let the auditor control the method.

Hiring an AI Auditor Without a Risk Department

Three problems come up at every company small enough that the founder is reading this: the budget, the independence question, and the paperwork. Each has a practical answer.

You cannot afford a person whose only job is to say no
At a company without a risk department, a full-time AI auditor is a hard budget line to defend, and the honest answer is often that you do not need one yet. What you need first is the inventory: a list of every AI system in the business, who owns it, what data it touches, and what happens if it is wrong. That list takes a week and usually reveals two or three systems that genuinely matter and a dozen that do not. Scope the role around those two or three. A fractional auditor on a quarterly engagement, or a part-time hire who also owns compliance, covers most small companies properly. Hire the full-time version when a customer contract, a regulator, or a specific ordinance makes the audit mandatory rather than prudent.
Independence sounds impossible when the whole company is twelve people
Strict independence is a structural idea built for organizations with three lines of defense, and a small company does not have three lines. Pretending otherwise in a job posting is how you lose the candidate in the second interview. Say the real thing instead: this person will build some of what they later assess, the escalation path runs to the founder or the board rather than to the engineering lead, and any audit that a rule requires to be genuinely independent goes to an outside firm. Candidates who take assurance work seriously respect that framing far more than a posting that claims a governance structure you do not have. Write the escalation path into the job description and into the offer letter.
The hire is technical, the paperwork is the same as every other hire
An AI auditor arrives with the same onboarding stack as anyone else, plus a few extras that matter more here: a confidentiality agreement that covers model documentation and customer data, an independence and conflicts declaration, an AI use policy acknowledgment, and evidence that any certification you relied on is current. FirstHR runs that sequence for you. The onboarding wizard walks the new auditor through it, e-signature captures the confidentiality and conflicts declarations, document management stores certification copies with renewal dates attached, and training modules deliver the AI use policy with completion recorded against the employee profile. Applicant tracking is coming soon to FirstHR. FirstHR is an onboarding and HR platform, not a payroll provider.

Once the offer is signed, the work moves to a repeatable onboarding checklist, and you can browse the rest of our hiring templates for the roles that surround this one.

Key Takeaways
An AI auditor independently tests AI systems for bias, accuracy, drift, and control failure, and produces reproducible evidence rather than an opinion.
The single most important line in the posting is the reporting line: who this person answers to and what happens when a finding is inconvenient.
New York City Local Law 144 requires a bias audit within the previous year, a public summary, and candidate notice for automated employment decision tools, and the audit must be performed by an independent auditor.
The four-fifths rule in the Uniform Guidelines on Employee Selection Procedures applies to any selection procedure, whether the decision was made by a person or a model.
No BLS occupation exists for the title, so benchmark against compliance officers at $80,730 up to information security analysts at $129,180 in median annual pay (BLS OEWS, May 2025).
The role is exempt under the administrative or learned professional exemption when duties and salary tests are met, and a part-time version still has to clear the full weekly salary threshold.
An assurance hire arrives with paperwork the rest of your team does not have: a confidentiality agreement covering model documentation, a conflicts and independence declaration, an AI use policy acknowledgment, and certification copies with expiry dates. FirstHR runs that sequence with e-signature, document storage, and renewal tracking so nothing lapses quietly. Applicant tracking is coming soon to FirstHR.

Frequently Asked Questions

What does an AI auditor do?

An AI auditor independently evaluates the AI and machine learning systems a company builds or buys, and reports what the testing showed. The work covers the whole lifecycle rather than the model file alone: where the training data came from and whether it represents the people affected, whether the model performs against a stated benchmark, whether outcomes differ across protected groups, whether drift monitoring exists and actually triggers action, whether a human override is available and used, and whether the vendor contract gives you the right to test the tool at all. The output is evidence, not opinion: workpapers another auditor could reproduce, findings with a severity rating and a named owner, and a re-test after remediation. In regulated industries the same role sits in third-line assurance and reports to an audit committee rather than to the team that built the system.

What should an AI auditor job description include?

Seven things, and the seventh is the one most postings skip. State the AI systems actually in scope by name rather than saying artificial intelligence in general. State the framework you audit against, such as the NIST AI Risk Management Framework, so findings are gaps against a standard rather than personal disagreements. List the testing you expect: bias, accuracy, drift, controls, and vendor review. State the reporting cadence and the audience. State the credential bar and whether it is required or preferred. State the salary range. Then state the reporting line and the independence position honestly, including whether this person reports into the team that builds the models and what the escalation path is when a finding is inconvenient. Candidates who take assurance work seriously read that section first, and a posting that dodges it loses them.

How much does an AI auditor make?

There is no Bureau of Labor Statistics occupation called AI auditor, so no single official wage figure exists. Benchmark against the nearest classifications instead. According to the Bureau of Labor Statistics Occupational Employment and Wage Statistics survey (May 2025), national median annual wages were $80,730 for compliance officers, $83,680 for accountants and auditors, $101,860 for management analysts, $120,230 for data scientists, and $129,180 for information security analysts. Which of those anchors your range depends on the emphasis you actually want. A governance and policy role sits near the compliance and audit medians. A role that re-performs model validation and writes its own testing code sits near the data science and security analyst medians, because you are competing for the same people. Publish a good-faith range where pay transparency law requires one.

Is an AI auditor exempt or non-exempt under the FLSA?

Almost always exempt, under either the administrative or the learned professional exemption. The administrative exemption fits when the primary duty is office work directly related to management or general business operations, including compliance and risk, and includes the exercise of discretion and independent judgment on matters of significance, which is a fair description of issuing audit findings. The learned professional exemption fits where the role requires advanced knowledge in a field of science or learning customarily acquired through prolonged specialized instruction. Either way the salary tests still apply: at least $684 per week, or $35,568 per year, under the federal rule, plus any higher state threshold. Two traps. A part-time version of the role still has to clear the full weekly salary amount to stay exempt. And an audit contractor engaged for genuine independence is not an employee at all, which is a different analysis. This is general information, not legal advice.

Can our own employee perform a required bias audit?

Often not, and this is the most expensive misunderstanding in the field. Where a rule requires an independent auditor, the definition typically excludes anyone employed by the company, anyone who was involved in using, developing, or distributing the tool, and anyone with a financial interest in its outcome. New York City Local Law 144 works this way for automated employment decision tools: the tool must have been through a bias audit within the previous year, a summary of the results must be publicly available, and notice must be given to candidates. An internal hire is still worth making, because someone has to prepare the data, run the internal testing, respond to findings, and manage the outside engagement. Just do not assume that person can sign the audit the ordinance requires. Confirm the applicable definition before you scope the role, and budget for an outside auditor where independence is mandatory.

Do we need an AI auditor if we only use vendor AI tools?

Yes, and buying rather than building rarely transfers the obligation. If an automated tool substantially assists or replaces a human decision about your candidates or employees, the duty generally attaches to you as the employer using it, not to the company that sold it. Vendor-supplied audit results are useful evidence and a reasonable starting point, but they were produced on the vendor’s data across its whole customer base, and your applicant pool may look nothing like that population. Someone on your side needs to read those results critically, test on your own data where the sample supports it, check the contract for a right to audit and for data use terms, and keep the evidence file. That is a real job even when you write no code at all, and it is exactly what the governance and compliance auditor template on this page is scoped for.

How do we hire an AI auditor at a small company with no HR team?

Start with the inventory rather than the posting. Spend a week listing every AI system in the business, who owns it, what data it touches, and what happens when it is wrong, and the list will usually show two or three systems that genuinely matter. Scope the role around those. Decide next whether you need an employee or an engagement: a fractional auditor on a quarterly scope covers most small companies, and a statutory independent audit has to go outside regardless. If you hire, post one specific template with the salary range, the framework, and the honest independence position, then screen with a work sample rather than a conversation, asking the candidate to critique a real model card or a vendor audit summary. Move fast on the offer, then run onboarding as a checklist: confidentiality agreement, conflicts declaration, AI use policy, and certification copies. Applicant tracking is coming soon to FirstHR.

Ready to transform your onboarding?

7-day free trial No credit card required
Start Your Free Trial