Skip to content
Over Unity

Interview questions

AI governance

Builds the policies, records and controls that let an organisation show how its AI is run.

What separates them

Governance is easy to write down and hard to enforce; the tell is whether they have ever actually stopped something.

Ask these

01

Tell me about a time you stopped a team using AI in a way they wanted to, even though it caused friction.

Tests real enforcement experience as opposed to writing policy that nobody is required to follow.

A strong answer

Gives a specific situation, the actual mechanism used to stop it, and how the resulting friction with the team was resolved.

The confident failure

Describes writing a policy document without any specific instance of it being enforced against real resistance.

02

How do you decide what needs a human sign-off before an AI system's output is acted on?

Tests concrete risk-based thinking rather than a blanket rule applied without judgement.

A strong answer

Gives criteria such as how reversible the decision is and who is affected by it, with a real example of where they drew the line.

The confident failure

Says high-risk decisions need human review, without ever defining what counts as high risk in an actual case.

03

What does your process look like for documenting an AI system's decisions in a way that would hold up if someone challenged it later?

Tests whether governance is a working process or a document nobody consults.

A strong answer

Describes a concrete practice such as decision logs or versioned model records, and a real example of it being used when challenged.

The confident failure

Says they keep good records, without naming what is actually recorded or how it was ever used in a real dispute.

04

How do you keep a governance policy from being ignored by teams under delivery pressure?

Tests for real enforcement mechanisms rather than an aspiration that everyone will simply comply.

A strong answer

Describes concrete mechanisms such as approval gates or a named person with authority to block, and a real example of pressure being resisted.

The confident failure

Says they make sure everyone is trained and bought in, with no mechanism described for when that is not enough.

What we ask when assessing for the register

Harder, and answerable only by somebody who has done the work. Published because a question that stops working when it is known was never testing anything.

01

Tell me about an AI use case you approved that you later regretted, and what you changed as a result.

Tests honesty and whether the governance process actually learns from its own mistakes.

A strong answer

Gives a specific case, what went wrong, and a concrete change made to the approval process as a direct result.

The confident failure

Claims to have never approved anything that went wrong, or answers with a hypothetical rather than a real case.

02

Describe the last time you had to escalate a disagreement with a senior stakeholder over an AI risk decision. What happened?

Tests whether they have real authority and will actually use it, rather than holding theoretical veto power.

A strong answer

Gives a specific disagreement, who it was escalated to, and the real outcome, including if they ended up losing the argument.

The confident failure

Describes the governance process in the abstract with no real instance of conflict or its actual outcome.

Ask these whatever the discipline

  • Tell me about something you built that failed in production. What broke, how did you find out, and what did you change?
  • What would you refuse to do on this project, and what would you tell me instead?
  • How would you know, three months in, that this was not working?
  • What is the part of your own work that you are least confident about?
With the answer patterns

If they hold a certification

Relevant here, and none of them is evidence on its own. What each does and does not prove is set out in full on the certifications page.

  • Artificial Intelligence Governance Professional, AIGP, International Association of Privacy Professionals. That the holder has ever made a governance decision that cost somebody something. Governance is easy to describe and hard to enforce, and the exam can only test the first.
  • Advanced in AI Audit, AAIA, ISACA. Technical depth. An auditor who can interrogate a model risk register is not the same as somebody who can tell you whether the evaluation set was any good.
  • ISO/IEC 42001 Lead Auditor and Lead Implementer, Various accredited certification bodies. Consistency. The training is delivered by many different bodies to varying depth, so the name of the training provider tells you more than the certificate does.
  • Certified Information Privacy Professional, Europe, CIPP/E, International Association of Privacy Professionals. Anything AI-specific. It predates all of this, and that is precisely why it is worth more than it looks: a governance lead who does not understand the data law underneath is going to be wrong in expensive ways.
The full register
Or let us assess themWhat this work pays

Over Unity makes introductions between hirers and independent specialists. It is not a party to any engagement, does not hold or transfer payments, and does not determine employment status. Specialists are never charged a fee.