Cerberus blocks the lethal trifecta at the tool boundary — see the 525-run evidence set.

Warden · Advisory

You need the function long before you can justify the headcount

A fractional AI risk officer embedded in your organization — chairing the governance forum, owning the AI risk register, and preparing what the board and your regulators ask for.

The role exists whether or not anyone holds it

Someone has to decide which AI use cases proceed, maintain the risk register, and answer the board. In most organizations that work is distributed across people who each have a different day job.

  1. Distributed ownership means no ownershipWhen AI risk is everyone's secondary responsibility, the register is maintained by nobody.
  2. The market for the skill is thinPeople who understand both AI systems and regulatory obligation are scarce and expensive to hire.
  3. Regulators expect a named individualSupervisory conversations go better when there is one person who owns the answer.

How the engagement runs

1

Establish the function

Terms of reference, decision rights, escalation path and reporting line, agreed in writing.

2

Operate it

Chair the governance forum, run intake for new AI use cases, and maintain the risk register.

3

Report

Board and committee reporting on AI risk posture, exceptions and material changes.

4

Build the succession

Document the function so a permanent hire inherits a working practice rather than a blank page.

What the engagement includes

  • A named fractional AI risk officer, with agreed days per month
  • A chaired AI governance forum with recorded decisions
  • A maintained AI risk register with owners and treatment plans
  • Use-case intake and approval process, operated rather than just designed
  • Board and committee reporting
  • A documented handover pack for the eventual permanent hire
  • Fractional and advisory: accountability for the function remains with your organization, and we do not hold a regulated officer position on your behalf

Why the role is appearing now

EU AI Act
Regulation (EU) 2024/1689 places per-system obligations that need an owner inside the organization.
ISO/IEC 42001:2023
Certification requires defined roles, responsibilities and management review — a function, not a project.
Customer due diligence
Enterprise buyers increasingly ask who owns AI risk before they will sign.

The function now, the hire later

And when you do hire, they inherit a running governance forum and a maintained register instead of starting over.