Roles
Who Should Be Your Fundamental Rights Impact Assessment Lead?
Someone who has already produced a written assessment that a programme had to answer to: data protection impact assessors, equality and human rights analysts, clinical or benefits audit leads, and public-sector risk officers who have documented harm to a named group. Under EU AI Act Article 27 the duty falls on deployers that are public bodies or private entities providing public services, with 2 December 2027 as the date for Annex III systems [1]. Hire the person who can be the reason a deployment waits.
The takeThis seat fails when it is filled by an author instead of an owner. The assessment Article 27 describes names the affected groups, the specific harms, the human oversight that actually exists, and the complaint route a person can use, and then goes to a market surveillance authority with your organisation's name on it [1]. A lead who has never told a delivery programme that its evidence is not good enough will not start now, under deadline, against a director who has already announced the launch date. Hire for that refusal, and give the seat enough standing that using it does not end a career.
Where Olive fits
Open a role and see what the work shows
Under the automated-decision rules, "the model gave them a 74" is not an explanation. Olive produces no composite and no automated decision at all: a person writes every finding, each one carries the excerpt it rests on, and every released report exports with its rubric, scorer and bank versions attached.
Rank your shortlistWho Is Visibly Hiring a Fundamental Rights Impact Assessment Lead Today?
A vendor's assurance pack lands two weeks before the council's triage tool goes live. It is thorough about model accuracy and silent about who gets deprioritised when the tool is wrong. Somebody inside the authority has to write down which residents are affected, what the harm looks like for them, whether the caseworker can actually overrule the output, and how a person complains. That document is what the law asks for, and usually nobody owns it.
The duty is written for the deployer. EU AI Act Article 27 requires deployers that are bodies governed by public law, or private entities providing public services, to carry out a fundamental rights impact assessment before first use of a high-risk system, covering the deployer's own processes and intended purpose, the period and frequency of use, the categories of people and groups likely to be affected, the specific risks of harm to them, the human oversight measures in place, and the governance and complaint arrangements if those risks materialise. The results go to the market surveillance authority on a template. Annex III systems carry a 2 December 2027 date 1. This is a summary of a European regulation for orientation; whether a given system is in scope and what your organisation owes turns on facts, so check with counsel rather than with a blog.
So the visible hiring is where the duty visibly lands: local and regional authorities running allocation or triage systems, benefits and social security agencies, health bodies, education administrations, police and justice services, and the private operators of public services under contract. Titles are still unsettled. Postings appear as AI governance lead, responsible AI officer, algorithmic impact assessment lead, or as a widened data protection officer role with fundamental rights work bolted on. The category is genuinely still forming, and that is worth saying to candidates rather than pretending a decade of precedent exists.
One consequence for planning: because the assessment has to describe a real deployment context, it cannot be finished before the deployment is designed, and it cannot be honest if it is finished after go-live. The hire is therefore earlier than most organisations expect.
Which Tells Separate a Real Assessment Lead From a Template Filler?
The separating trait is whether a candidate reaches for people or for headings. Ask how they would assess a housing allocation model and listen for the first move. A template filler starts with categories of risk. A real assessment lead starts by asking who applies, who gets refused, who appeals, who never applies at all because the process is hostile, and where in the current paper process the same harm already happens without anyone counting it.
Four tells hold up under an hour of questioning.
They have written something that changed a decision. Ask directly for an assessment, review or report that delayed, altered or stopped a programme, and for what the fallout was. Nobody who has done this work is short of that story, and the ones who have never had one are describing a documentation role.
They can name what their method cannot see. Strong candidates volunteer the limits: an assessment built from staff interviews will miss harms to people who dropped out of the process, and a proxy for disadvantage is not the thing itself. Weak candidates describe the framework as complete.
They treat human oversight as a claim to be tested. The oversight measure in most vendor packs is a caseworker with an override button. Ask the candidate how they would find out whether that override is ever used, and whether the person using it has the time, information and standing to disagree. Good answers involve sitting with the caseworkers.
They distinguish the deployer's duty from the provider's. A candidate who keeps answering with the vendor's conformity documentation has not internalised where the obligation sits 1.
The anti-tells are just as clear. Anyone who proposes to detect whether a document was written by AI is selling something that does not work and is not the question this seat answers. Anyone who cannot describe a complaint route in words a resident would use has written a compliance artefact, not an assessment. And treat certification-only candidates carefully: the credentials in this space are young, and none of them yet substitute for casework.
Which Backgrounds Produce This Person, and How Did They Get Good With AI?
The obvious feeder is data protection. Practitioners who have run real data protection impact assessments under GDPR Article 35 already know how to identify affected people, describe processing in operational terms, and defend an assessment to a regulator 3. Article 27 lets a deployer build on an existing one where the ground overlaps, which makes this the shortest transfer available 1. The gap is that data protection asks about information, and this seat asks about outcomes.
The less obvious feeders are often stronger. Equality impact analysts working under public sector equality duties have spent years documenting differential effect on specific groups, which is the exact muscle Article 27 asks for. Ombudsman and public audit investigators know how to reconstruct what happened to one person and generalise it without overclaiming. Clinical safety officers running hazard analysis for health systems bring a discipline built for harm rather than for compliance. Social researchers who have run participatory work with claimants, patients or families can reach the affected group directly rather than through a proxy. Frontline supervisors from benefits, child protection or housing casework bring the thing nobody else has, which is knowing what actually happens at the desk when the system says no.
On AI fluency, the useful history is practical rather than technical. The candidates who got good at this used models on their own assessments and can say precisely where it failed them: drafting an affected-groups section with an assistant and then deleting the two groups it invented because they sounded plausible; asking a model to argue against their own risk rating and keeping only the objections that survived a check against the case file; using a model to summarise three hundred pages of vendor documentation and then hand-verifying every passage that carried weight. That habit matters here because most of the material this lead reads is now itself model-assisted, confident and lightly sourced. Assessing that material is close to what an AI skills assessment specialist does for people, applied instead to programme evidence, and it is the same instinct a national security AI capability assessor is hired for on the other side of government.
Source This Lead Where Someone Has Already Told a Programme No
Recruit where a written finding has already had consequences. That rules out most general boards and most people whose whole record is commentary on the AI Act. The venues with real practitioner density: data protection officer networks and the national supervisory authorities, public sector internal audit and counter-fraud functions, equality and human rights commissions, ombudsman offices, clinical safety communities in health systems, and the local government data communities where allocation tools already run.
Procurement is an underused pool. The people who have already read vendor claims adversarially, and who know what a contract can and cannot require, sit in commercial teams and rarely get approached for governance seats. So do civil society researchers who have published analyses of deployed public sector systems; they arrive with method and with a network into the affected groups, and the hesitation to hire them is usually about comfort rather than capability.
Screen on artefacts, always. Ask for one redacted assessment the candidate wrote and one they reviewed for someone else. Read both before the conversation. In this discipline the writing is the work: whether the affected groups are named or generic, whether the harms are specific or a risk register, whether the oversight section describes a mechanism or repeats the vendor's sentence. Then ask what they would do differently now.
Be honest in the posting about what is being built. Candidates good enough to hold this seat will ask whether the assessment can actually stop a launch, who signs it, and what happened the last time governance disagreed with delivery. Rehearsed answers do not survive that question, and the ones you want are asking it deliberately.
How Do You Close One, What Does the Seat Pay, and Where Does It Sit?
Close on authority, then on access, then on pay. The winning offer names a reporting line above the programme being assessed, states in writing that the lead's sign-off is a condition of first deployment, and gives them time with frontline staff and affected people rather than only with vendor documentation. Every credible candidate has watched governance get overruled by a delivery date, so independence with no mechanism behind it reads as a warning.
On compensation, the category is too new for a defensible point estimate, and inventing one is the fastest way to lose trust with a candidate who knows the market better than the hiring team. The honest framing is which established band the role hires against. In practice that is senior data protection officer, head of information governance, or senior public audit and assurance grade, sitting one step above generalist policy roles because of the sign-off responsibility. Public bodies will place it on their existing pay scales, which candidates can already read, and the negotiation is about grade rather than about a number. Private operators of public services are bidding against those scales plus the wider premium on AI-adjacent work, which one 2026 analysis of around one billion job advertisements put at an average of 62 percent for roles requiring AI skills 2. As of late 2026 there is no reliable published salary series for this specific title, and any figure quoted without one should be treated as a guess.
Location is mixed, and the split is predictable. Drafting, documentation review and coordination with the market surveillance authority travel fine, and most authorities will offer hybrid. Three parts do not travel: sitting with caseworkers to see whether the override is real, engagement sessions with affected communities, and access to case material that only exists inside a controlled environment. Write the on-site days into the posting with a number attached. A candidate who pushes back on being in the office to observe the actual decision point is telling you which kind of assessment they intend to write.
Common questions
How do I become a fundamental rights impact assessment lead?
Get into a seat where you write assessments that have consequences: data protection impact assessments, equality impact analysis, clinical safety cases, internal audit or ombudsman investigations. Do three of them properly on systems that affect the public, and keep the one that changed a decision. Read Article 27 and the deployer obligations around it alongside that work rather than instead of it, and learn enough about model behaviour to test a vendor's oversight claim rather than repeat it. Then apply into public bodies deploying Annex III systems, where the duty actually sits. The title varies, so search on the obligation rather than on the words.
Is this the same job as a data protection officer?
No, though the overlap is real and Article 27 explicitly allows a deployer to build on an existing data protection impact assessment where the ground is already covered. Data protection asks what happens to information about a person. This assessment asks what happens to the person: which groups are affected, what specific harm they face, whether human oversight is genuine, and how they complain. Some organisations widen the data protection officer role to carry both. That works only if the person has the equality and harms vocabulary as well, and if the workload is funded rather than added.
Can the vendor do the assessment instead?
No. Article 27 places the obligation on the deployer, and the assessment describes the deployer's own processes, intended purpose, affected populations and oversight arrangements, which a vendor does not know and cannot commit to. A vendor can supply information the assessment relies on, and a good contract obliges it to. The signature, the notification to the market surveillance authority and the consequences stay with the deploying body. Treat any supplier offering to hand over a completed assessment as a supplier misreading the regulation, and check the specifics with counsel.
When does this role need to be filled?
Before the deployment is designed rather than before it launches. The assessment has to describe a real deployment context, so it cannot be completed against a system that does not exist yet, and it cannot be honest if it is written after the decision it was meant to inform. For Annex III systems the date in the regulation is 2 December 2027, which sounds distant until you count the procurement cycles and the recruitment lead time in a public body. Organisations already running high-risk systems have the harder version of the problem, because the assessment then has to be retrofitted around a live service.
What does a good interview exercise look like for this seat?
Give the candidate a real vendor assurance pack for a public service system, redacted, and ninety minutes. Ask for the affected groups, the two harms they would prioritise, one oversight claim they would test and how, and the questions they would put to the programme before signing anything. Score the specificity of the groups and the testability of the questions. The failure mode is a clean risk register with no named population in it. Let them use an AI assistant and ask afterwards what it got wrong, because that answer separates the practitioners from the drafters.
References
- 1. Article 27: Fundamental Rights Impact Assessment for High-Risk AI Systems ✓ artificialintelligenceact.eu Places the assessment duty on deployers that are public bodies or private entities providing public services; lists the six required elements, the notification to the market surveillance authority, and the 2 December 2027 date for Annex III systems.
- 2. PwC 2026 AI Jobs Barometer pwc.com Analysis of around one billion job advertisements reporting an average wage premium of 62 percent for roles requiring AI skills. Used only for the macro premium claim, not for this title.
- 3. Article 35: Data Protection Impact Assessment ✓ gdpr-info.eu The existing assessment discipline the most common feeder background comes from, and the one Article 27 allows a deployer to build on.
3 sources, numbered by first appearance. How Olive sources claims
General guidance for hiring teams. What works at one company and one volume may not transfer to yours.
Olive assesses how a person works with AI. It does not detect AI-written documents, and it never produces a score, a ranking, or a match percentage for a person. Candidates read the same report the employer reads.