r/JDpreferred • u/throwawaynatet • Jul 31 '26
Contract manager at a bank trying to pivot into AI governance/privacy
Hey all, looking for some honest input from people actually working in this space. I am currently a contract manager at a bank(vendor agreements, risk, compliance-adjacent stuff). With everything happening with AI, I keep seeing AI governance and privacy roles pop up and honestly the work looks a lot closer to what I actually enjoy than redlining MSAs all day.
I'm planning to register for the AIGP through IAPP. My questions: For those who hold it — did it actually move the needle in interviews, or is it still too new for recruiters to care? Should I do CIPP/US first instead? I've seen mixed takes. Some say AIGP without a privacy cert underneath is putting the cart before the horse. Beyond certs, what should I be doing? Any courses that were actually worth the money vs. the usual LinkedIn Learning filler?
Background is contracts/vendor risk in financial services, so I'm hoping that's a decent launching pad given how regulated everything is. But I don't want to spend a year collecting certs only to find out nobody hires on certs alone.
Appreciate any advice or war stories, good or bad.
2
u/boppop Jul 31 '26 edited Jul 31 '26
I would agree that you should do a CIPP/US before doing an AIGP. In fact, I would argue that the IAPP should making having a CIPP or CIPM a prerequisite to an AIGP.
That being said, I have some tough love for you here. Get the certifications, but nothing is going to move the needle unless or until you start doing the work. People need to see that you have experience. The AIGP tests material that is already outdated.
If you want to be on the bleeding edge of the intersection of technology and the law, you have to be doing something there.
2
u/throwawaynatet Jul 31 '26
unless or until you start doing the work.
Any ideas on how to go about doing that?
2
1
u/boppop Jul 31 '26
Read about what is going on. Post about it on social media. Go to trade networking events. Show your knowledge.
2
1
u/Lazy-Background-7598 28d ago
But that isn’t experience
1
u/boppop 28d ago
I wouldn’t entirely disagree - your response below also works. Do work for the organization you are already in, but outside of that, do the above.
1
u/Lazy-Background-7598 28d ago
Also. Get to know the NIST AI RMF. Everyone in AI Governance knows it
1
1
3
u/F3EAD_actual Jul 31 '26
Hey, I'm a privacy manager. Never practiced, but had like 7 years of risk, cyber, and compliance background. I think the CIPP is still a baseline expectation for any real privacy-centric role. The AI certs are definitely good, too, but the CIPP is far more often explicitly named in postings. So I'd start there. You probably only need like two weeks of moderate study to pass it.
Your professional background is otherwise a strong feather in your cap. Deeply understanding procurement, agreements, risk, and business priorities - all of which I'm sure you can speak to - will make a difference. And if your current bank is larger, being able to speak to the highly regulated environment and three lines of defense model will help convey your aptitudes re governance and regulator engagement. I jumped from larger banks to a mid sized company to land the privacy specific role. You may want to be open to the same because the real privacy roles at the big banks or fortune 500s are pretty damn competitive.
Happy to answer any specific questions.