Citi is looking to establish independent assurance over the firm's adoption and use of AI/GenAI, ensuring that risks are identified, controls are effective, and governance aligns with regulatory, ethical, and strategic objectives.
Requirements
- Strong understanding of AI and machine learning concepts, algorithms and techniques.
- Strong knowledge of IT governance and control frameworks (e.g. COBIT, NIST, Cybersecurity Framework).
- Sound understanding of key AI regulations and laws such SR11-7, FCA, MAS, PRA and EU AI Act.
- Familiarity with data governance principles, data quality management and data security practices.
- Strong understanding of internal audit standards (e.g. IIA Standards) and risk management frameworks (e.g. COSO).
- Experience in planning and executing audits including risk assessment, control evaluation and report writing.
- Ability to identify and assess complex risks and develop effective audit procedures.
Responsibilities
- Develop and deliver the AI/GenAI assurance strategy covering governance, legal, regulatory, cyber, technology, model risk and third party systems.
- Timely development, risk assessment, execution and periodic refresh of the audit plan and approach for recurring risk-based coverage on AI/GenAI
- Provide independent assessment of the firm’s AI/GenAI governance framework and operating model.
- Review controls across AI/GenAI development, deployment, monitoring and lifecycle management.
- Responsible for the coordination and delivery of high-quality, value-add multiple concurrent risk-based audit plans on time and to specification together with the assurance for AI/GenAI.
- Identify and evaluate risks unique to AI/GenAI, including bias, fairness, data privacy, hallucination, misuse and adversarial attacks.
- Incorporate coverage to AI non-model artefacts (e.g. explainability, prompts, embeddings, guardrails, datasets).
Other
- Candidates should have a minimum of 15 years of diversified management experience in audit or a related role with a focus on technology and data.
- Working with AI and machine learning systems, including risk management, governance, technology and models.
- International experience is preferred within highly respected, diversified and complex institutions.
- Proven experience working with regulators and managing regulatory audits or inspections.
- Bachelor’s degree/University degree in computer science, data science, finance, accounting or a related field, or equivalent experience