Compliance Manager H/F
collectivite
- Paris - 75
- Indépendant
- Télétravail partiel
- Bac +5
- Services aux Entreprises
Les compétences pour ce job
- Français
- Anglais
Détail du poste
Important information
Contract type: Freelance
Daily rate: Salary according to profile
Location: Paris, France
Starting date:
4 to 8 weeks
Work mode: Onsite
Published on: 21 July 2026
What they need
Location: Paris, on site with partial remote
Contract: Freelance mission, independent contractor status
Client: Large organisation in a regulated sector.
Start: September / October
Duration and daily rate: Discussed based on scope and seniority
The mission
The client operates AI systems in a regulated environment governed by evolving requirements: the EU AI Act, GDPR, and the sector rules enforced by its supervisor. Reference frameworks exist, but the organisation has no version adapted to its context, applied by the teams building and buying AI, and supported by evidence available on demand. The role covers three pillars: adapt the framework, implement it, and audit the AI systems against it.
The scope goes beyond policy writing. The framework must be implemented and evidenced so it can be demonstrated to a regulator, a certification body, or a corporate client on request. The mission concludes when an internal owner can operate the system independently, so preparing that handover is included in the role.
What you will do
1. Adapt the governance framework
Translate the applicable frameworks (mainly EU AI Act into a single internal control framework calibrated to its risk profile, systems, and way of working.
Define the classification logic: which AI systems are in scope, at what obligation level, and on which axes (role in the value chain, risk tier, deployment geography, criticality to the regulated activity).
Map obligations to concrete controls. Give each control an owner and specify what evidence proves it. Remove duplicate and unenforceable controls rather than stacking them.
Make it hold across the group's entities and jurisdictions
2. Implement it
Build the AI system inventory and make it trustworthy: use cases, models, data, vendors, owners, lifecycle stage, current risk classification.
Roll controls out with the teams that live with them (engineering, data, product, procurement, legal, security, business lines), turning each into a workable procedure, template, or gate.
Stand up the operating cadence: intake and triage of new AI use cases, risk assessments, model and vendor reviews, human oversight arrangements, incident and serious malfunction handling, post-market monitoring.
Set up the tooling that carries the evidence (an existing GRC platform or a dedicated AI governance solution) and drive adoption.
Run third-party AI governance: due diligence on model, data and platform providers, contractual clauses, and ongoing vendor monitoring.
Train and coach the first line so governance is run by the teams, not by you alone. That is what makes the handover possible.
3. Audit AI systems against the framework
Design and execute a risk-based audit programme covering the AI systems in scope, across their lifecycle.
Test control design and operating effectiveness. Gather evidence, document findings with a defensible severity rating, and agree remediation plans with the owners.
Track remediation to closure, re-test, and escalate what does not move.
Produce the conformity documentation and technical files that will withstand a supervisor, an external auditor, a certification body, or a corporate client's assessment.
Report to the governance committee and executive stakeholders on portfolio posture, control coverage, open gaps, and trend.
Deliverables
AI system inventory, complete and classified against the agreed criteria.
Gap analysis of the current state against the target framework, with a prioritised remediation backlog agreed with the owners.
Adapted control framework, approved by the client's governance body, with named control owners and defined evidence requirements.
Operating procedures: use case intake and triage, risk assessment method, vendor review, incident handling, post-market monitoring.
Audit programme, and its first cycle executed on the highest-risk systems, with a documented findings file and agreed remediation plans.
Conformity documentation pack, ready to be produced on request.
Handover: an internal owner trained and operational, with the documentation to keep the system running.
Profile wanted
Who we are looking for
You are probably a fit if you have:
5 or more years in a role where you owned a control framework and tested it: compliance, operational or technology risk, internal audit, or information security governance. Seniority and evidence of delivery matter more than the job title on the CV.
Direct experience in a regulated sector (insurance preferably), and a working feel for what a supervisor or an external auditor will actually challenge.
At least one assessment or audit cycle run end to end: scoping, fieldwork, evidence, findings with severity, remediation follow-up, re-test.
A track record of building a governance programme from scratch, in an environment where the rules were still moving.
Enough technical literacy to read model documentation, evaluation results, data lineage, security controls and logging, and to tell a substantiated answer from a confident one. No coding required.
Professional French and English. Deliverables and steering committee material are produced in both.
Independence and diplomacy. You will tell people their system does not comply, and you will need them to keep working with you afterwards.
Three routes in
We deliberately open this mission beyond pure AI governance profiles, because control discipline transfers and is harder to acquire than domain knowledge. Each route carries its own bridge condition.
From AI governance or AI ethics. Show us that you have run a real audit cycle with evidence and findings, not only policy and awareness material.
From internal audit or IT audit. Show us that you have already worked on an AI, ML or algorithmic scope, and that you can read the EU AI Act unaided.
From cybersecurity or ISMS work (ISO/IEC 27001, NIST CSF, DORA). Show us that you can move from a security control mindset to AI-specific harm, and that you are fluent in bias, robustness, human oversight and post-market monitoring, not only confidentiality, integrity and availability.
Also valued
ISO/IEC 42001 Lead Auditor or Lead Implementer, ISO/IEC 27001 Lead Auditor, CISA, CRISC, CIPP/E.
Practical use of a GRC or AI governance platform, and familiarity with conformity assessment mechanics: technical documentation, declarations, notified body interaction.
Experience in a multi-jurisdictional group, where one framework has to hold across entities facing different local supervisors.
Data protection background, in particular the articulation between DPIA and AI risk assessment.
Exposure to model risk management, MLOps practice, or AI evaluation and red teaming.
Publiée le 21/07/2026 - Réf : ba9b9032f6f48e6d9284a74a1a70a6e2