The Director, AI Governance, Risk & Responsible AI will operationalize Acosta Group’s AI governance model by turning policy, risk expectations, and Responsible AI principles into practical controls embedded in the AI delivery lifecycle. This leader will establish governance processes for AI use cases, tools, vendors, models, agents, copilots, data usage, lifecycle monitoring, and production readiness.
The role supports the AI CoE operating model of central guardrails, federated execution, and portfolio-driven scaling by enabling Acosta Group to innovate with speed while maintaining appropriate oversight, accountability, security coordination, and evidence of control compliance.
Responsibilities- Operationalize Acosta Group’s AI policies, Responsible AI principles, governance standards, and lifecycle controls across AI initiatives.
- Establish and maintain AI governance workflows for intake, risk classification, review, approval, monitoring, change management, and retirement.
- Partner with Legal, Compliance, Cybersecurity, Privacy, Risk, Data Governance, Technology, and business leaders to embed AI controls into delivery workflows.
- Define governance requirements for GenAI, agentic AI, copilots, traditional AI/ML, workflow automation, externally sourced AI tools, and vendor-delivered AI solutions.
- Maintain enterprise AI inventory requirements, documentation standards, risk tiering, model/agent registry expectations, and evidence artifacts.
- Establish requirements for human-in-the-loop controls, automation boundaries, transparency, traceability, explainability, bias review, data protection, and appropriate use.
- Create governance standards for production readiness, observability, monitoring, incident response, issue escalation, policy exceptions, and ongoing control validation.
- Support third-party AI and tool reviews by assessing responsible AI, data usage, model behavior, security, licensing, auditability, and control implications.
- Develop practical guidance, templates, checklists, review criteria, and decision records that make governance usable by delivery teams.
- Report governance status, control coverage, material risks, open issues, and decision needs to AI CoE and enterprise leadership forums.
- Bachelor’s degree in information technology, Computer Science, Cybersecurity, Data Science, Risk Management, Law, Business Administration, or a related field; advanced degree preferred.
- Preferred Certifications such as CRISC, CISM, CISSP, CIPP, CDPSE, CGEIT, AI Governance Professional, Responsible AI certifications.
- 12 or more years of experience in governance, risk management, compliance, technology risk, cybersecurity governance, privacy, enterprise controls, data governance, or related disciplines.
- 5 or more years of leadership experience overseeing governance, risk, compliance, technology controls, model oversight, Responsible AI, data governance, or regulated technology programs within a large enterprise environment.
- Strong understanding of Artificial Intelligence, Generative AI, machine learning, agentic AI systems, copilots, intelligent automation, foundation models, model lifecycle management, and associated enterprise risks.
- Experience designing and implementing governance frameworks, control structures, risk assessment methodologies, approval workflows, policy enforcement mechanisms, and enterprise oversight processes.
- Demonstrated experience establishing and operationalizing Responsible AI programs, including controls related to fairness, transparency, explainability, accountability, human oversight, privacy, and ethical AI use.
- Experience evaluating and managing AI-related risks across security, privacy, legal, regulatory, operational, reputational, and model performance domains.
- Knowledge of applicable regulatory, privacy, cybersecurity, risk, and governance frameworks, including emerging AI regulations and industry standards.
- Experience reviewing and governing third-party AI vendors, foundation models, SaaS AI platforms, copilots, and AI-enabled technologies.
- Ability to partner effectively with Legal, Compliance, Privacy, Cybersecurity, Enterprise Risk, Data, Technology, Procurement, Internal Audit, and business stakeholders.
- Experience translating governance policies and standards into practical operating procedures, controls, templates, review processes, training materials, and implementation guidance.
- Excellent written, verbal, and executive communication skills, including the ability to clearly explain AI risks, governance requirements, compliance obligations, and mitigation strategies to technical and non-technical audiences.
Work Environment and Physical Requirements
The work environment characteristics described are representative of those an employee may encounter while performing the essential functions of this job. Job may require moderate physical effort including lifting materials and equipment weighing less than 15 pounds. This position involves viewing a computer monitor for more than 30% of the time. Personal protective equipment may need to be worn. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Skills Required
- Bachelor's degree in information technology, Computer Science, Cybersecurity, Data Science, Risk Management, Law, Business Administration, or a related field
- 12 or more years of experience in governance, risk management, compliance, technology risk, cybersecurity governance, privacy, enterprise controls, data governance, or related disciplines
- 5 or more years of leadership experience overseeing governance, risk, compliance, technology controls, model oversight, Responsible AI, data governance, or regulated technology programs in a large enterprise
- Strong understanding of artificial intelligence, generative AI, machine learning, agentic AI systems, copilots, intelligent automation, foundation models, model lifecycle management, and enterprise risks
- Experience designing and implementing governance frameworks, control structures, risk assessment methodologies, approval workflows, policy enforcement mechanisms, and enterprise oversight processes
- Experience establishing and operationalizing Responsible AI programs covering fairness, transparency, explainability, accountability, human oversight, privacy, and ethical AI use
- Experience evaluating and managing AI-related security, privacy, legal, regulatory, operational, reputational, and model-performance risks
- Knowledge of applicable regulatory, privacy, cybersecurity, risk, and governance frameworks, including emerging AI regulations and industry standards
- Experience reviewing and governing third-party AI vendors, foundation models, SaaS AI platforms, copilots, and AI-enabled technologies
- Ability to partner with Legal, Compliance, Privacy, Cybersecurity, Enterprise Risk, Data, Technology, Procurement, Internal Audit, and business stakeholders
- Experience translating governance policies and standards into operating procedures, controls, templates, review processes, training materials, and implementation guidance
- Excellent written, verbal, and executive communication skills
- Advanced degree
- CRISC, CISM, CISSP, CIPP, CDPSE, CGEIT, AI Governance Professional, or Responsible AI certification
What We Do
Acosta Group fuses storied expertise, unmatched connectivity and advanced insight to accelerate brand growth – everywhere you sell. Our collective of the most trusted retail, marketing and foodservice agencies is reimagining how people connect with brands at every point in the consumer journey. Comprised of Acosta, ActionLink, CORE Foodservice, CROSSMARK, Mosaic, Premium Retail Services and Product Connections, Acosta Group understands and anticipates evolving consumer needs, fueling accelerated performance to connect tomorrow's commerce today. The collective delivers end-to-end solutions, including headquarter sales services, omnichannel retail solutions, assisted sales and training, integrated marketing, foodservice sales enablement and culinary solutions, and the most advanced data and insights.









