Skip to content
Over Unity

Interview questions

AI risk and compliance

Maps obligations under regimes such as the EU AI Act and ISO 42001 onto what a business is really doing.

What separates them

The real skill is taking a framework everyone can read and applying it to a system that is messy, half documented and doesn't sit neatly in any category; that is where the framework stops helping and judgement starts.

Ask these

01

Take a real system we run, something like an automated tool that scores or screens customers. Walk me through how you would work out which regulations apply and what obligations follow.

Tests whether they can apply a framework to an actual, ambiguous system rather than reciting the framework by name.

A strong answer

They ask what the system actually does and who it affects before naming any regulation. They then name specific obligations that follow, such as a data protection impact assessment or a right to human review, and explain how they would check those are actually met rather than just documented.

The confident failure

They immediately list risk tiers or named regulatory guidance in general terms without asking what the system does. It sounds authoritative but never touches the specific business context and stays at the level of what would need to be assessed.

02

How do you decide which risk category a system falls into when it sits between two categories or the guidance genuinely doesn't say?

Reveals judgement under ambiguity rather than knowledge of a category list.

A strong answer

They describe a specific method for resolving ambiguity, such as erring towards the higher tier when material harm is plausible, and give a real example of a case they judged themselves, including who they told about the decision.

The confident failure

They say it depends on the specifics without ever describing an actual case they resolved, or claim the framework is always clear if you read it properly.

03

Tell me about a time your assessment slowed down or blocked a launch. How did that conversation go?

Tests whether they can hold a position under commercial pressure without simply becoming an obstacle.

A strong answer

They give a specific example and state the risk in terms the business actually cared about. They can also say what changed as a result, such as a phased launch or an added control, rather than a launch that just went ahead unchanged.

The confident failure

They describe compliance as a gate they enforced without describing any negotiation, or claim blocking never happens because they get involved early enough, which avoids the actual question.

04

Once a mapping is done, how do you keep it current as the system or the regulation changes?

Tests whether compliance is a live process tied to triggers or a document that goes stale.

A strong answer

They describe a specific trigger for review, such as a material change to the model or a new piece of regulatory guidance, with clear ownership of who checks it. They give an example of a mapping that actually had to be revised.

The confident failure

They say documentation is kept up to date without describing any trigger or owner, implying it happens through diligence rather than through a process that would catch drift.

What we ask when assessing for the register

Harder, and answerable only by somebody who has done the work. Published because a question that stops working when it is known was never testing anything.

01

Describe a system you mapped where the mapping was genuinely contested, either internally or with a regulator. What was the disagreement and how was it resolved?

Only someone who has done this can describe a real disagreement with any specificity.

A strong answer

They name the actual point of contention, the competing interpretations, who had the authority to decide, and what the eventual resolution was, including cases where the resolution went against their own initial reading.

The confident failure

They describe a mapping that raised some questions and was resolved quickly and smoothly, with no real tension, which sounds rehearsed rather than lived.

02

What is the difference between documenting that a control exists and proving that it operates? Tell me about a case where you had to establish the second.

Distinguishes people who write policy from people who audit reality.

A strong answer

They describe an actual evidencing exercise, for example sampling a set of past decisions or running a specific testing regime, and what that exercise found that the documentation alone had not shown.

The confident failure

They conflate documentation with operation, describing the writing of a policy as the answer to whether a control operates, with no mention of any evidence gathering afterwards.

Ask these whatever the discipline

  • Tell me about something you built that failed in production. What broke, how did you find out, and what did you change?
  • What would you refuse to do on this project, and what would you tell me instead?
  • How would you know, three months in, that this was not working?
  • What is the part of your own work that you are least confident about?
With the answer patterns

If they hold a certification

Relevant here, and none of them is evidence on its own. What each does and does not prove is set out in full on the certifications page.

  • Artificial Intelligence Governance Professional, AIGP, International Association of Privacy Professionals. That the holder has ever made a governance decision that cost somebody something. Governance is easy to describe and hard to enforce, and the exam can only test the first.
  • Advanced in AI Audit, AAIA, ISACA. Technical depth. An auditor who can interrogate a model risk register is not the same as somebody who can tell you whether the evaluation set was any good.
  • AI Security Management, AAISM, ISACA. Hands-on adversarial capability. Managing a security programme and breaking a model are different jobs.
  • ISO/IEC 42001 Lead Auditor and Lead Implementer, Various accredited certification bodies. Consistency. The training is delivered by many different bodies to varying depth, so the name of the training provider tells you more than the certificate does.
  • Certified Information Privacy Professional, Europe, CIPP/E, International Association of Privacy Professionals. Anything AI-specific. It predates all of this, and that is precisely why it is worth more than it looks: a governance lead who does not understand the data law underneath is going to be wrong in expensive ways.
The full register
Or let us assess themWhat this work pays

Over Unity makes introductions between hirers and independent specialists. It is not a party to any engagement, does not hold or transfer payments, and does not determine employment status. Specialists are never charged a fee.