Compliance Manager H/F

collectivite

  • Paris - 75
  • Indépendant
  • Télétravail partiel
  • Bac +5
  • Services aux Entreprises
Lire dans l'app

Les compétences pour ce job

  • Français
  • Anglais

Détail du poste

Important information

Contract type: Freelance

Daily rate: Salary according to profile

Location: Paris, France

Starting date:

4 to 8 weeks

Work mode: Onsite

Published on: 21 July 2026

What they need

Location: Paris, on site with partial remote
Contract: Freelance mission, independent contractor status
Client: Large organisation in a regulated sector.
Start: September / October
Duration and daily rate: Discussed based on scope and seniority

The mission

The client operates AI systems in a regulated environment governed by evolving requirements: the EU AI Act, GDPR, and the sector rules enforced by its supervisor. Reference frameworks exist, but the organisation has no version adapted to its context, applied by the teams building and buying AI, and supported by evidence available on demand. The role covers three pillars: adapt the framework, implement it, and audit the AI systems against it.

The scope goes beyond policy writing. The framework must be implemented and evidenced so it can be demonstrated to a regulator, a certification body, or a corporate client on request. The mission concludes when an internal owner can operate the system independently, so preparing that handover is included in the role.

What you will do

1. Adapt the governance framework

  • Translate the applicable frameworks (mainly EU AI Act into a single internal control framework calibrated to its risk profile, systems, and way of working.

  • Define the classification logic: which AI systems are in scope, at what obligation level, and on which axes (role in the value chain, risk tier, deployment geography, criticality to the regulated activity).

  • Map obligations to concrete controls. Give each control an owner and specify what evidence proves it. Remove duplicate and unenforceable controls rather than stacking them.

  • Make it hold across the group's entities and jurisdictions

2. Implement it

  • Build the AI system inventory and make it trustworthy: use cases, models, data, vendors, owners, lifecycle stage, current risk classification.

  • Roll controls out with the teams that live with them (engineering, data, product, procurement, legal, security, business lines), turning each into a workable procedure, template, or gate.

  • Stand up the operating cadence: intake and triage of new AI use cases, risk assessments, model and vendor reviews, human oversight arrangements, incident and serious malfunction handling, post-market monitoring.

  • Set up the tooling that carries the evidence (an existing GRC platform or a dedicated AI governance solution) and drive adoption.

  • Run third-party AI governance: due diligence on model, data and platform providers, contractual clauses, and ongoing vendor monitoring.

  • Train and coach the first line so governance is run by the teams, not by you alone. That is what makes the handover possible.

3. Audit AI systems against the framework

  • Design and execute a risk-based audit programme covering the AI systems in scope, across their lifecycle.

  • Test control design and operating effectiveness. Gather evidence, document findings with a defensible severity rating, and agree remediation plans with the owners.

  • Track remediation to closure, re-test, and escalate what does not move.

  • Produce the conformity documentation and technical files that will withstand a supervisor, an external auditor, a certification body, or a corporate client's assessment.

  • Report to the governance committee and executive stakeholders on portfolio posture, control coverage, open gaps, and trend.

Deliverables

  1. AI system inventory, complete and classified against the agreed criteria.

  2. Gap analysis of the current state against the target framework, with a prioritised remediation backlog agreed with the owners.

  3. Adapted control framework, approved by the client's governance body, with named control owners and defined evidence requirements.

  4. Operating procedures: use case intake and triage, risk assessment method, vendor review, incident handling, post-market monitoring.

  5. Audit programme, and its first cycle executed on the highest-risk systems, with a documented findings file and agreed remediation plans.

  6. Conformity documentation pack, ready to be produced on request.

  7. Handover: an internal owner trained and operational, with the documentation to keep the system running.

Profile wanted

Who we are looking for

You are probably a fit if you have:

  • 5 or more years in a role where you owned a control framework and tested it: compliance, operational or technology risk, internal audit, or information security governance. Seniority and evidence of delivery matter more than the job title on the CV.

  • Direct experience in a regulated sector (insurance preferably), and a working feel for what a supervisor or an external auditor will actually challenge.

  • At least one assessment or audit cycle run end to end: scoping, fieldwork, evidence, findings with severity, remediation follow-up, re-test.

  • A track record of building a governance programme from scratch, in an environment where the rules were still moving.

  • Enough technical literacy to read model documentation, evaluation results, data lineage, security controls and logging, and to tell a substantiated answer from a confident one. No coding required.

  • Professional French and English. Deliverables and steering committee material are produced in both.

  • Independence and diplomacy. You will tell people their system does not comply, and you will need them to keep working with you afterwards.

Three routes in

We deliberately open this mission beyond pure AI governance profiles, because control discipline transfers and is harder to acquire than domain knowledge. Each route carries its own bridge condition.

  • From AI governance or AI ethics. Show us that you have run a real audit cycle with evidence and findings, not only policy and awareness material.

  • From internal audit or IT audit. Show us that you have already worked on an AI, ML or algorithmic scope, and that you can read the EU AI Act unaided.

  • From cybersecurity or ISMS work (ISO/IEC 27001, NIST CSF, DORA). Show us that you can move from a security control mindset to AI-specific harm, and that you are fluent in bias, robustness, human oversight and post-market monitoring, not only confidentiality, integrity and availability.

Also valued

  • ISO/IEC 42001 Lead Auditor or Lead Implementer, ISO/IEC 27001 Lead Auditor, CISA, CRISC, CIPP/E.

  • Practical use of a GRC or AI governance platform, and familiarity with conformity assessment mechanics: technical documentation, declarations, notified body interaction.

  • Experience in a multi-jurisdictional group, where one framework has to hold across entities facing different local supervisors.

  • Data protection background, in particular the articulation between DPIA and AI risk assessment.

  • Exposure to model risk management, MLOps practice, or AI evaluation and red teaming.

Publiée le 21/07/2026 - Réf : ba9b9032f6f48e6d9284a74a1a70a6e2

Postuler
Créez votre compte
Hellowork et postulez

sur le site du partenaire !

Voir plus d'offres
Les sites
L'emploi
  • Offres d'emploi par métier
  • Offres d'emploi par ville
  • Offres d'emploi par entreprise
  • Offres d'emploi par mots clés
L'entreprise
  • Qui sommes-nous ?
  • On recrute
  • Accès client
Les apps
Nous suivre sur :
Informations légales CGU Politique de confidentialité Gérer les traceurs Accessibilité : non conforme Aide et contact