AI governance interviews do not look like machine learning interviews. There is no coding exercise and rarely a take-home. What panels test is whether you can run a repeatable decision process inside a company that is moving fast and does not report to you. This guide sets out the questions that actually come up, what the interviewer is listening for in each, and the questions you should be asking them.
Before anything else, be certain which job you are interviewing for. AI governance is inward-facing: you build your employer's own machinery, usually reporting into legal, risk or privacy, and your output is process and recorded decisions (AI governance jobs). AI policy is outward-facing: regulators, standards bodies, consultation responses and testimony (AI policy jobs). AI compliance turns one specific regime into controls and audit evidence (AI compliance jobs). The three share vocabulary and almost no day-to-day work. Candidates prepare for the wrong one and get screened out in the first call more often than they fail on substance. If you are still deciding which fits, start with the AI governance career guide.
Scenario questions
This is the bulk of a governance panel, and it is where offers are decided. Every scenario is a conflict with no clean answer. The interviewer is not checking whether you reach their preferred outcome; they are checking whether you reason like someone who has held the job.
1. A product team wants to ship a feature that failed its model review, two days before launch.
What the interviewer is listening for: that you separate the risk from the deadline. Strong answers ask what specifically failed and whether it is a documentation gap or a substantive harm, look for a scoped release that removes the failing condition (a narrower user set, a human in the loop, a disabled feature branch), and name the person with authority to accept the residual risk in writing. The failure mode is a candidate who either waves it through to be helpful or blocks on principle without offering a path. Ending with "and I record the decision and the accepted risk, with an owner and a review date" is the line that closes the answer.
2. You inherit an AI use-case inventory that is six months stale and nobody maintains.
What the interviewer is listening for: whether you treat the inventory as a product with a maintenance mechanism, not a document you refresh by heroics. Good answers cut the field list down to what actually drives a decision, attach collection to an existing moment teams already go through (procurement, a deployment checklist, an access request), give every entry a named owner, and accept partial coverage of the highest-impact systems over fictional completeness. Mentioning that you would first ask why it decayed, and fix that, marks out experience.
3. A customer sends a 90-question AI due-diligence questionnaire and engineering says they have no time.
What the interviewer is listening for: commercial awareness. This is revenue work, and governance often exists because a deal stalled. Strong candidates answer the large majority from an existing evidence library themselves, isolate the handful of questions that genuinely need an engineer, book a short bounded session for exactly those, and then turn the answers into reusable artefacts so the next questionnaire costs a fraction of the time. Anyone who forwards ninety questions to engineering has failed the question.
4. A vendor model is embedded in your product and you cannot see its training data.
What the interviewer is listening for: that you govern what you can observe. You will not get the training data, so the answer moves to contractual commitments and documentation, your own evaluation of the model on your inputs and your population, monitoring and a change-notification clause for model updates, a fallback if the vendor deprecates a version, and a clear-eyed statement of the residual risk that someone senior accepts. Candidates who insist on training data transparency as a precondition are describing a world that does not exist.
5. You discover an internal team has been using a public LLM with customer data for months.
What the interviewer is listening for: proportionate incident handling, and whether you make it safe to tell you things. Establish the facts before the verdict: what data, whose, under which terms, with what retention or training settings. Loop in privacy, security and legal early. Stop the ongoing exposure and offer a sanctioned alternative in the same breath, because a pure prohibition drives the next team underground. Then ask the structural question of why the sanctioned path was not usable, and fix that. Panels are quietly listening for whether you would punish the discloser.
6. You must decide whether a system is high-risk under the EU AI Act with incomplete information.
What the interviewer is listening for: that you can work under uncertainty and show your reasoning. Strong answers start from the intended purpose and the effect on people rather than the technology, name the specific facts that would change the classification, take a provisional position with a stated assumption set, put a date and an owner on resolving the open facts, and escalate to counsel for the actual legal determination. Saying plainly "this is a legal judgment and I would document my analysis for counsel rather than issue the ruling myself" is a strength, not a dodge. See our EU AI Act page for the general shape of the regime.
Knowledge questions
These are quick, and they exist to check that you have done the work rather than read the headlines.
- What is the difference between provider and deployer duties? Listening for: that you know obligations attach to your role in the chain, that a company can be both at once for different systems, and that putting your own name on a third-party model can change which one you are.
- What does ISO/IEC 42001 certify, and why does that matter commercially? Listening for: that it certifies a management system, not a model, and that its value is auditability by an accredited body, which is what makes it usable as evidence in enterprise procurement.
- What does the NIST AI RMF actually give you? Listening for: a voluntary structuring reference that organises how you govern, map, measure and manage risk. It gives you a shared vocabulary and a shape for a programme. It does not give you obligations or a certificate, and candidates who present it as compliance are marked down.
- How does a model card or system card differ from a risk assessment? Listening for: a card describes a system and its measured behaviour, largely for an external or downstream reader. A risk assessment is a decision instrument for a specific deployment context, with identified harms, owners, mitigations and an outcome. One is documentation, the other is a decision.
- What makes an evaluation decision-grade rather than decorative? Listening for: it tests the behaviour you actually care about on data resembling your real population, it has a threshold agreed before the run, it is reproducible, someone owns the outcome, and a failure genuinely changes what happens next. An evaluation that cannot fail is theatre. This is also where panels check your technical literacy.
Judgment questions
These separate a candidate who has run a programme from one who has read about programmes.
- How do you get a decision recorded when nobody reports to you? Listening for: influence mechanics. Attach the record to something the team already needs (a release approval, a procurement sign-off, a customer answer), make the easy path the documented path, write the decision yourself and ask only for confirmation, and use a named accountable owner rather than a committee. Escalation exists but is the last instrument, not the first.
- How do you decide what not to govern? Listening for: an explicit proportionality rule. Internal, low-consequence, reversible uses get a light path. Systems that affect people's access to money, work, housing, health or liberty get the full treatment. A candidate who wants to review everything will stall the company and be routed around within a quarter, and good interviewers know it.
- How do you handle being the person who slows a launch? Listening for: composure and self-awareness. The best answers reframe the goal as predictability rather than speed or safety in the abstract: engage early enough that governance is a known step rather than an ambush, publish the criteria in advance so nothing is a surprise, be fast on the low-risk majority so your objections carry weight on the few that matter, and be willing to be unpopular on the small number of cases that warrant it.
Questions you should ask them
Governance roles vary enormously in real authority, and the title tells you nothing. These questions are the fastest way to find out whether the job is what the posting claims.
- Who signs off when a review fails? If the answer is vague, or it is the same person who owns the launch date, the gate is decorative.
- Does governance sit under legal, risk, engineering or somewhere else, and who is the ultimate decision-maker? This determines whether you are advising or deciding, and it shapes the whole job.
- How many AI systems are in the inventory today? A confident number means a real programme. "We are working on that" means you are building from zero, which is fine if you know it going in.
- Has anyone ever stopped or delayed a launch on governance grounds? The single most revealing question in the set.
- What happened the last time? Ask for the specific story: who escalated, how long it took, whether the person who raised it is still there.
- What triggered this hire? A stalled enterprise deal, an audit finding, a regulatory deadline and an executive's general unease produce very different jobs.
- What does success look like at twelve months, in artefacts? If nobody can name the artefacts, the role has no definition yet.
Before you interview
Prepare three things. First, one story where you got a decision recorded across a team you did not control, with the mechanism you used. Second, one artefact you can talk through in detail: a review process you wrote, a completed risk assessment for a real system, or a control set you mapped. Third, a clear, jargon-free explanation of what the EU AI Act, ISO/IEC 42001 and the NIST AI RMF are each for, and which question each one answers. Broader context sits on our responsible AI page.
Nothing here is legal advice, and none of it should be treated as a statement of your obligations: it is the general climate of the field as interviewers discuss it, and anyone acting on a legal duty should take their own qualified advice. When you are ready to apply, the live openings are on the AI governance jobs hub and at companies hiring AI governance professionals. Because this is a small function where most companies hire one person, widen the search early: compliance, policy, remote roles and the full company list all surface governance work filed under other titles.
Frequently asked questions
- What questions are asked in an AI governance interview?
- Most panels run three bands. Scenario questions put you inside a live conflict: a feature that failed its model review two days before launch, a stale AI use-case inventory, a 90-question customer due-diligence questionnaire that engineering has no time for. Knowledge questions check whether you can distinguish provider and deployer duties, say what ISO/IEC 42001 certifies, and explain what makes an evaluation decision-grade. Judgment questions test how you get a decision recorded when nobody reports to you, how you decide what not to govern, and how you handle being the person who slows a launch.
- How is an AI governance interview different from an AI policy interview?
- A governance interview tests whether you can build and run internal machinery: review gates, inventories, risk registers, escalation paths. A policy interview tests outward-facing analysis and writing for regulators, standards bodies and the public. A compliance interview tests whether you can turn one regime into controls and audit evidence. Preparing for the wrong one is the most common reason strong candidates fail the first screen.
- What should I ask an employer in an AI governance interview?
- Ask who signs off when a review fails, whether governance sits under legal, risk or engineering and who the ultimate decision-maker is, how many AI systems are in the inventory today, whether anyone has ever stopped a launch, and what happened the last time. The answers tell you whether the role has real authority or is a documentation seat with a governance title.
- Do I need to know the EU AI Act in detail for an AI governance interview?
- You need to know what it is for and how it allocates duties, not article numbers. Be ready to explain risk tiering, the difference between provider and deployer obligations, and that the regime can reach non-EU companies whose systems are placed on the EU market. Panels are more impressed by a candidate who says what evidence they would gather to classify a system than by one who recites text.
- How technical does an AI governance candidate need to be?
- You do not need to train models. You do need to hold a precise conversation with a machine learning team about training data provenance, evaluation design, retrieval and fine-tuning, monitoring and model updates, and to recognise when an answer is evasive. Interviewers test this indirectly, usually through a vendor-model or evaluation scenario.
Live AI governance and policy roles right now
The HartfordHartford, CT+1 more
AccentureBengaluru, India
Related guides
How to Get Into AI Governance: The Roles, the Routes In, and What the Job Actually Is
AI governance is the most transferable function in AI hiring and the most misunderstood. What the work actuall…
9 min read
Machine Learning Engineer Interview Questions (2026): Scenarios and What They Listen For
What ML engineer interviews actually test, and the line between ML engineer, research scientist, data scientis…
10 min read
AI Engineer Interview Questions (2026): Agents, Retrieval, Evals and What They Listen For
AI engineering is the largest function in AI hiring and the most common way in from ordinary software engineer…
10 min read