About this role
Key Result Areas
• Develop and implement risk-based AI/GenAI audit strategies aligned with the Bank's AI agenda and regulatory expectations.
• Execute audits over the AI/ML lifecycle — data sourcing, training, validation, deployment, monitoring, retraining, and decommissioning (MLOps/LLMOps).
• Provide assurance on AI governance, model risk management (MRM), ethics, fairness, bias, explainability, and human-in-the-loop controls.
• Audit GenAI/LLM use cases — RAG pipelines, fine-tuning, prompt engineering, guardrails, vector databases, and output validation.
• Assess AI cybersecurity risks — adversarial attacks, prompt injection, data poisoning, model theft, jailbreaks (OWASP LLM Top 10, MITRE ATLAS).
• Evaluate third-party AI risks covering foundation model providers (OpenAI, Anthropic, Google, Meta, Mistral, open-source) and cloud AI platforms (Azure OpenAI, AWS Bedrock, Google Vertex AI).
• Assess compliance with AI and data regulations — CBUAE, QCB, SBP, RBI,UAE PDPL etc.
• Audit AI use in credit, AML/fraud, KYC, chatbots, personalization, trading, and operations automation.
• Prepare and present impactful audit reports to the Board Audit Committee, GCEO, and senior management, translating complex AI concepts into business language.
• Partner in Internal Audit AI transformation — continuous auditing, GenAI-enabled audit tools, and audit team upskilling.
• Guide, coach, and develop AI audit team members; foster a culture of learning, agility, and innovation.
• Support integrated audits by providing AI/technology subject-matter expertise across the Bank.
Knowledge, Skills and Experience Education
• Bachelor's degree in Computer Science, IT, Data Science, AI, Statistics, Mathematics, or a related quantitative field; Master's in AI/ML or Data Science preferred.
Experience
• Minimum 10–12 years in IT audit, technology risk, model risk, or AI/data governance, with at least 3–4 years directly focused on AI/ML or GenAI risk, governance, or audit, preferably in banking.
Certifications
• CISA mandatory (or to be obtained within 12 months).
• One or more preferred: ISACA AAIA (Advanced in AI Audit), CISSP, CRISC, CGEIT, CDPSE.
Technical Knowledge
• Strong understanding of AI/ML concepts — supervised, unsupervised, reinforcement, deep learning, NLP, computer vision.
• GenAI and LLMs — foundation models, transformers, embeddings, RAG, fine-tuning (SFT, RLHF, LoRA), prompt engineering, agentic and multi-modal AI.
• Familiarity with major model versions and providers — OpenAI (GPT-4/4o/5), Anthropic (Claude), Google (Gemini), Meta (Llama), Mistral, and leading open-source models.
• AI platforms/tooling — Azure OpenAI, AWS Bedrock/SageMaker, Google Vertex AI, Databricks, Hugging Face, LangChain, vector databases.
• AI governance and risk frameworks
Skills
• Strong analytical and problem-solving skills focused on novel AI risks.
• Excellent communication and interpersonal skills to convey complex AI concepts to technical and non-technical stakeholders, including the Board.
• Ability to work independently, lead a team, and collaborate across departments and geographies.
Added Advantages
• Hands-on involvement in any part of an organization's AI initiatives (use case build, model validation, AI governance council, MLOps, GenAI product).
• Banking / financial services domain knowledge (credit, fraud/AML, digital channels, compliance).
• Experience with AI-enabled internal audit tools and audit analytics.