Maps obligations under regimes such as the EU AI Act and ISO 42001 onto what a business is really doing.
What separates them
The real skill is taking a framework everyone can read and applying it to a system that is messy, half documented and doesn't sit neatly in any category; that is where the framework stops helping and judgement starts.
Ask these
01
Take a real system we run, something like an automated tool that scores or screens customers. Walk me through how you would work out which regulations apply and what obligations follow.
Tests whether they can apply a framework to an actual, ambiguous system rather than reciting the framework by name.
A strong answer
They ask what the system actually does and who it affects before naming any regulation. They then name specific obligations that follow, such as a data protection impact assessment or a right to human review, and explain how they would check those are actually met rather than just documented.
The confident failure
They immediately list risk tiers or named regulatory guidance in general terms without asking what the system does. It sounds authoritative but never touches the specific business context and stays at the level of what would need to be assessed.
02
How do you decide which risk category a system falls into when it sits between two categories or the guidance genuinely doesn't say?
Reveals judgement under ambiguity rather than knowledge of a category list.
A strong answer
They describe a specific method for resolving ambiguity, such as erring towards the higher tier when material harm is plausible, and give a real example of a case they judged themselves, including who they told about the decision.
The confident failure
They say it depends on the specifics without ever describing an actual case they resolved, or claim the framework is always clear if you read it properly.
03
Tell me about a time your assessment slowed down or blocked a launch. How did that conversation go?
Tests whether they can hold a position under commercial pressure without simply becoming an obstacle.
A strong answer
They give a specific example and state the risk in terms the business actually cared about. They can also say what changed as a result, such as a phased launch or an added control, rather than a launch that just went ahead unchanged.
The confident failure
They describe compliance as a gate they enforced without describing any negotiation, or claim blocking never happens because they get involved early enough, which avoids the actual question.
04
Once a mapping is done, how do you keep it current as the system or the regulation changes?
Tests whether compliance is a live process tied to triggers or a document that goes stale.
A strong answer
They describe a specific trigger for review, such as a material change to the model or a new piece of regulatory guidance, with clear ownership of who checks it. They give an example of a mapping that actually had to be revised.
The confident failure
They say documentation is kept up to date without describing any trigger or owner, implying it happens through diligence rather than through a process that would catch drift.
What we ask when assessing for the register
Harder, and answerable only by somebody who has done the work. Published because a question that stops working when it is known was never testing anything.
01
Describe a system you mapped where the mapping was genuinely contested, either internally or with a regulator. What was the disagreement and how was it resolved?
Only someone who has done this can describe a real disagreement with any specificity.
A strong answer
They name the actual point of contention, the competing interpretations, who had the authority to decide, and what the eventual resolution was, including cases where the resolution went against their own initial reading.
The confident failure
They describe a mapping that raised some questions and was resolved quickly and smoothly, with no real tension, which sounds rehearsed rather than lived.
02
What is the difference between documenting that a control exists and proving that it operates? Tell me about a case where you had to establish the second.
Distinguishes people who write policy from people who audit reality.
A strong answer
They describe an actual evidencing exercise, for example sampling a set of past decisions or running a specific testing regime, and what that exercise found that the documentation alone had not shown.
The confident failure
They conflate documentation with operation, describing the writing of a policy as the answer to whether a control operates, with no mention of any evidence gathering afterwards.
Ask these whatever the discipline
Tell me about something you built that failed in production. What broke, how did you find out, and what did you change?
What would you refuse to do on this project, and what would you tell me instead?
How would you know, three months in, that this was not working?
What is the part of your own work that you are least confident about?
Relevant here, and none of them is evidence on its own. What each does and does not prove is set out in full on the certifications page.
Artificial Intelligence Governance Professional, AIGP, International Association of Privacy Professionals. That the holder has ever made a governance decision that cost somebody something. Governance is easy to describe and hard to enforce, and the exam can only test the first.
Advanced in AI Audit, AAIA, ISACA. Technical depth. An auditor who can interrogate a model risk register is not the same as somebody who can tell you whether the evaluation set was any good.
AI Security Management, AAISM, ISACA. Hands-on adversarial capability. Managing a security programme and breaking a model are different jobs.
ISO/IEC 42001 Lead Auditor and Lead Implementer, Various accredited certification bodies. Consistency. The training is delivered by many different bodies to varying depth, so the name of the training provider tells you more than the certificate does.
Certified Information Privacy Professional, Europe, CIPP/E, International Association of Privacy Professionals. Anything AI-specific. It predates all of this, and that is precisely why it is worth more than it looks: a governance lead who does not understand the data law underneath is going to be wrong in expensive ways.