Your learning path
AI Compliance and Assurance Lead
Assess AI systems against applicable obligations and prepare evidence for audits and assurance reviews.
First session
Start with one task
Describe a fictional RAG assistant, its users and its data. Use the EU AI Act text to explain which obligations might apply and what you still need to establish.
Open the first skill guide →Use a training lab or a system you own. Testing any other system needs written permission.
What this work involves
- Identify applicable obligations with the relevant legal, privacy and security specialists.
- Map requirements to controls and collect evidence of how those controls operate.
- Prepare AI-related audit material and explain gaps or limitations.
- Support privacy assessments and vendor assurance where they apply.
Learn in order
Your learning steps
Start with the first skill. Each step has a few resources here and a link to the full guide. Skip material you already know.
01AI governance, risk and compliance: NIST AI RMF, ISO/IEC 42001, EU AI Act, CSA AICMThe work is control mapping and conformity evidence: every one of these postings expects you to run an assessment against a named standard and leave a record behind.
- AI Risk Management Framework NIST, standard, free, about 3 h, introThis is the baseline voluntary framework most AI governance programs are built on, and it links to the RMF 1.0 document, the Playbook, and the Generative AI Profile.
- Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST-AI-600-1) NIST, standard, free, about 2 h, workingRead the risks and suggested actions specific to generative AI alongside the base NIST AI Risk Management Framework.
- NIST AI RMF Playbook NIST, tool, free, about 3 h, workingTurns the RMF's four functions into concrete, actionable suggestions you can use as a checklist when running an actual assessment.
02LLM security: prompt injection, jailbreaks, output handlingYou cannot judge whether an AI control works without knowing how the system fails: prompt injection, data leakage through retrieval, and unreliable output.
- OWASP Top 10 for LLM Applications OWASP GenAI Security Project, standard, free, about 3 h, introUse this list of LLM application risks to structure a review, including prompt injection and unsafe output handling.
- Prompt Injection Prevention Cheat Sheet OWASP Cheat Sheet Series, guide, free, about 1 h, workingShort, practical control checklist you can reuse directly in a design review or a client report.
- Web LLM attacks PortSwigger Web Security Academy, lab, free, about 3 h, workingPractise attacks against an LLM-backed application in authorised browser-based labs.
03AI system threat modelling and secure architectureAuditors accept evidence, not diagrams, so you need to read a design and tell which components a control statement actually covers.
- MITRE ATLAS MITRE, guide, free, about 3 h, workingGives you a tactics and techniques matrix for adversarial ML attacks that you can use directly in threat modelling sessions.
- Guidelines for secure AI system development UK National Cyber Security Centre, guide, free, about 2 h, workingWalks through secure design, development, deployment and maintenance decisions for AI systems in plain, practitioner language.
- Gandalf Lakera, lab, free, about 1 h, introLets you try prompt injection against a live guarded LLM so the threats in the frameworks stop being abstract.
04Securing model and agent workloads on cloud platformsMost of the evidence you collect comes from cloud services: logging, key management, access control, so you need to know where to look for it.
- Securing generative AI: An introduction to the Generative AI Security Scoping Matrix AWS Security Blog, guide, free, about 2 h, workingGives you a working model for figuring out which security responsibilities are yours versus the provider's for any generative AI deployment.
- Azure security baseline for Azure OpenAI Microsoft Learn, guide, free, about 2 h, workingLists the specific network, identity and data controls to configure when you run a model workload on Azure.
- Google's Secure AI Framework (SAIF) Google, guide, free, about 1 h, introSets out Google's own conceptual framework for securing AI systems across the ecosystem, useful for comparing against AWS and Azure approaches.
05Application security for LLM-backed softwareSecure development evidence sits inside ISO 27001 and SOC 2 scope, so you need enough AppSec literacy to test whether the practice matches the policy.
- OWASP Top 10 for LLM Applications OWASP GenAI Security Project, standard, free, about 2 h, introThe reference risk list you will map every LLM app review against, so start here.
- Guidelines for secure AI system development UK National Cyber Security Centre, guide, free, about 2 h, workingCovers secure design, build, deployment and maintenance for AI systems the way an AppSec review checklist would.
- HackAPrompt Learn Prompting, lab, free, about 3 h, introHands-on practice crafting prompt injection payloads, the equivalent of learning SQL injection by doing it.
06Advisory and customer-facing delivery skillsAssurance work is written and spoken for other people: auditors, regulators, and customers sending questionnaires, so being clear in front of them is the differentiator.
- Multilayer framework for good cybersecurity practices for AI ENISA, guide, free, about 2 h, workingA structured way to walk a client through AI security practices across the organisation, not just the model layer.
- AI Governance Professional (AIGP) training IAPP, course, USD 1500, about 20 h, advancedA recognised credential for advisors whose clients need a named expert on AI governance and law, not just technical controls.
Put it into practice
Practice an AI assurance gap review for a fictional RAG assistant
Allow about 9 hours, plus setup. This is a practice project, not a certification or a measure of job readiness.
Describe a fictional customer-service assistant and assess the evidence needed for its security and AI governance controls. Separate the assistant from the organisation operating it. ISO/IEC 42001 covers an organisational AI management system, not a product certificate. Check AI Act obligations against the use case, actor role and applicable dates. This exercise produces a practice gap review, not certification or legal assurance.
Use fictional data and an authorised sandbox. Check model, cloud and licence costs before starting.
Project steps
- Write a one-page system description of your fictional RAG assistant: purpose, users, data sources, retrieval pipeline, model, and where it is deployed.
- Decide its EU AI Act risk class and write the reasoning in three sentences, naming the criteria you applied.
- List the AI Act obligations that follow at that class, and for each one write what evidence would satisfy it.
- Use the free ISO/IEC 42001 overview to outline management-system evidence. Use NIST AI RMF for detailed free control mapping; use ISO clauses only if you have authorised access to the standard.
- For each row record: control, what the assistant does today, gap, evidence you would collect, owner, effort.
- Cross-map five control objectives to public NIST guidance and, if available, ISO/IEC 27001 or SOC 2. A mapping identifies overlap; it does not establish that an existing certificate covers this AI use case.
- Add a short DORA or NIS2 note stating whether the assistant would be in scope if the operator were a financial entity or an essential service, and what changes.
- Write a two-page assessment summary: scope, method, top 5 gaps, proposed evidence plan, and what you could not verify.
- Reread the pack cold after a day and delete every finding you could not support with a named evidence item.
What to produce: A gap spreadsheet and a two-page practice review of a fictional AI deployment, with evidence needs, assumptions, proposed owners and legal or certification questions requiring specialist review.
Check your work
- the risk class is stated once, clearly, with the criteria that led to it.
- every gap names a specific evidence item, not a general recommendation.
- At least five control objectives are mapped to named source sections; unavailable licensed standards are recorded as a limitation.
- the summary separates what you verified from what you assumed.
- the spreadsheet could be handed to an auditor without you in the room.
Career context
Security pay by experience
General security benchmarks, not an AI-security salary forecast. Skills and responsibility matter; years of experience alone do not determine pay.
United Kingdom GBP · reported annual salary
Example specialism: security engineering. These are the survey’s experience bands, not AI-security pay or job-level guarantees.
- Experience reported
1–3 years
£45,000–£59,7502026 reported salary rangeNot a zero-experience starting salary.
- Experience reported
4–6 years
£62,500–£75,7502026 reported salary range - Experience reported
7–9 years
£81,000–£98,5002026 reported salary range - Experience reported
10–12 years
£100,000–£115,7502026 reported salary range
United States USD · reported annual salary
Example specialism: security engineering. These are the survey’s experience bands, not AI-security pay or job-level guarantees.
- Experience reported
1–3 years
$59,500–$78,0002026 reported salary rangeNot a zero-experience starting salary.
- Experience reported
4–6 years
$79,750–$96,5002026 reported salary range - Experience reported
7–9 years
$106,500–$129,2502026 reported salary range - Experience reported
10–12 years
$130,500–$150,7502026 reported salary range
Reported annual salary. No bonus, equity or sales OTE added; the source does not explicitly confirm base-only pay. UK and US use separate scales and currencies; no conversion. These are snapshots across people, not a guaranteed pay progression.
Sources and methodology
Sources checked 2026-09-26. These benchmarks are separate from this guide’s small AI-security job sample. Published ranges can overlap and differ by specialism, location and employer.
United Kingdom
Cybershark Recruitment’s 2026 United Kingdom survey, Security Engineering row on page 8. Four published experience bands are reproduced directly, with no interpolation or currency conversion. The whole survey reports 3,861 respondents; counts within each role/experience band and the statistical definition of the range are not provided. Treat this as a directional recruiter benchmark, not a representative national estimate or a salary prediction. Salary and performance bonuses are reported separately, but the report does not explicitly define the table as base-only. We therefore label it reported annual salary, not verified base pay. No bonus, equity, benefits or sales OTE have been added. Zero-experience pay and AI-specific premiums are not established by this table.
- Cybershark Recruitment: United Kingdom Cyber Security Salary Survey, page 8 (PDF) (2026)
Published salary ranges for Security Engineering, by years of experience. Directly transcribed from the report’s table; no pooled job-posting ranges or invented seniority labels.
United States
Cybershark Recruitment’s 2026 United States survey, Security Engineering row on page 7. Four published experience bands are reproduced directly, with no interpolation or currency conversion. The whole survey reports 7,028 respondents; counts within each role/experience band and the statistical definition of the range are not provided. Treat this as a directional recruiter benchmark, not a representative national estimate or a salary prediction. Salary and performance bonuses are reported separately, but the report does not explicitly define the table as base-only. We therefore label it reported annual salary, not verified base pay. No bonus, equity, benefits or sales OTE have been added. Zero-experience pay and AI-specific premiums are not established by this table.
- Cybershark Recruitment: United States Cyber Security Salary Survey, page 7 (PDF) (2026)
Published salary ranges for Security Engineering, by years of experience. Directly transcribed from the report’s table; no pooled job-posting ranges or invented seniority labels.
How this sample informed the learning order
This path uses 4 postings from a 48-posting research dataset compiled on 24 September 2026, not a live vacancy feed. The counts below show how many selected postings explicitly mention each skill. They describe this sample only, not demand across the job market. The learning order also reflects prerequisites.
- AI governance, risk and compliance: NIST AI RMF, ISO/IEC 42001, EU AI Act, CSA AICM4 / 4
- LLM security: prompt injection, jailbreaks, output handling4 / 4
- AI system threat modelling and secure architecture0 / 4
- Securing model and agent workloads on cloud platforms0 / 4
- Application security for LLM-backed software0 / 4
- Advisory and customer-facing delivery skills0 / 4
Reference frameworks for this path
- ISO/IEC 42001 (AI management system)
The certifiable AI management standard this path assesses against; its controls give the structure for the gap spreadsheet.
- EU AI Act (Regulation 2024/1689)
The primary source for risk classes and obligations; read the articles rather than summaries when you decide a class.
- NIST AI RMF 1.0 + Generative AI Profile
Use it to structure the assessment method behind the gap list, and as the framework most US postings name.
- DORA (Regulation 2022/2554)
Sets the resilience, testing and third-party requirements that apply when an AI system runs inside a financial entity.
- ISO/IEC 27001
The certification most organisations already hold; you will map AI features into its controls rather than start a new scheme.