Date: 20 June 2025
Version: Illustration
Updated by: AI Assurance Institute
Position Title: AI Systems Integration Manager (High-Risk AI)
Section: Position Objective
- Enable the safe, compliant, and sustainable integration of high-risk and general-purpose AI systems into enterprise architecture, ensuring full alignment with the EU AI Act (Regulation (EU) 2024/1689), harmonised standards (EN 18286, prEN 18228, ISO/IEC 42001), and related legislation (GDPR, NIS-2, DORA, Product Liability Directive).
- Act as the organisation authoritative technical owner for AI integration strategy, patterns, and standards (SFIA ARCH6, SINT6).
- Guarantee that every AI integration is modular, observable, traceable, version-controlled, and supports human oversight, rollback, and post-market monitoring (EU AI Act Articles 12, 14, 15, 72).
- Future-proof integration investments against model drift, supply-chain changes, and evolving regulation.
- Influence organisational policy and culture on responsible AI integration (SFIA Level 7 behaviour).
Accountable to
Chief AI Governance Officer / Head of AI Architecture (or GM: Architecture if no CAIO exists)
Responsible for (people)
- AI Integration Architects (SFIA SINT5-6)
- MLOps Engineers - Integration Stream (SFIA MLDE5-6)
- Policy-as-Code & Guardrails Engineers
- Data Pipeline Owners touching high-risk systems
Primarily Performs
- Develop and own the Enterprise AI Integration Strategy & Roadmap (SFIA STRT6).
- Define, publish, and enforce AI Integration Reference Architecture & Pattern Library (approved RAG, agentic, tool-calling, and multi-modal patterns) (SFIA ARCH6, SINT6).
- Lead the AI Integration Architecture Review Board with veto rights on non-conforming designs (SFIA Level 6 autonomy).
- Maintain living artefacts: AI Integration Catalogue, SBOMs, model + prompt + embedding lineage maps, system cards (SFIA DTAN6, ARCD6).
- Perform technical studies and proof-of-concepts on emerging integration technologies (LangChain, LlamaIndex, DSPy, AutoGen, Vertex AI Agent Builder, Azure AI Studio, etc.) (SFIA TECH6).
- Implement and continuously improve policy-as-code guardrails (Open Policy Agent, Conftest, custom AI semantic conventions) for prompt injection, personal data leakage, tool-calling safety, and content moderation.
- Conduct regular audits and red-team testing of production AI integrations (SFIA TEST6, SECM6).
- Deliver mandatory training and awareness programmes on AI integration standards and regulatory obligations (SFIA EVLN6).
- Act as single technical point of contact for notified bodies during conformity assessments of integration layers.
- Conduct regular audits of production integrations for conformance to AI integration standards and regulatory obligations.
- Review the AI integration design of all key projects (especially Annex III high-risk systems) and sign off before go-live.
Key Deliverables
- Annual Enterprise AI Integration Strategy & Roadmap (signed off at management review)
- AI Integration Reference Architecture (Confluence/Notion living site) & Pattern Library
- Quarterly AI Integration Compliance & Performance Report (presented to management review - SFIA METL6)
- Architecture Decision Records (ADRs) for every new pattern or tool
- Automated compliance gate scan reports (OPA + AI-specific policies)
- Full lineage graphs and SBOMs for every high-risk integration
Concurs / Collaborates with
- AI Governance Specialist & Compliance Officer
- Chief Data Officer / Data Architects
- Security Architect (cyber & adversarial robustness)
- MLOps & Platform Engineering Leads
- Risk Management Lead (Article 9)
- Human Oversight & Safety Team
- External Notified Body / Regulators (when required)
Key Result Areas
- 100% of high-risk AI integrations reviewed and approved before production (target > 95% first-pass approval)
- Zero major or critical findings related to integration in notified-body or market-surveillance audits
- Mean time to trace a production output to exact prompt + retrieved chunks + model version < 5 minutes
- Prompt-injection / jailbreak success rate in red-team tests < 1%
- All production integrations pass automated compliance gate on every deploy
- Stakeholder satisfaction (compliance, security, data science) = 4.5/5
Knowledge Required
- EU AI Act (full text) + harmonised standards (EN 18286, prEN 18228)
- SFIA Level 6 proficiency in SINT, ARCH, MLDE, GOVC, RISM
- Modern AI integration stacks (LangChain/LangGraph, LlamaIndex, DSPy, AutoGen, Vertex AI Agent Builder, Azure AI Studio)
- Observability for LLM applications (LangSmith, Phoenix, Helicone, OpenTelemetry AI extensions)
- Policy-as-code (OPA, Gatekeeper) and guardrails
- Model cards, system cards, SBOMs, lineage standards (OpenLineage + AI-specific)
Core Skills Required
- Architecture decision-making under regulatory constraints
- Policy-as-code and automated guardrails (Open Policy Agent, Gatekeeper)
- Communicating complex AI integration risks to executives and regulators
- Running effective architecture review boards
- Incident triage and root-cause analysis for integration failures affecting high-risk systems
Personal Attributes
- Regulatory mind-set combined with technical depth
- Assertive enforcement of standards without blocking innovation
- Strong stakeholder management across legal, risk, and engineering
Qualifications & Experience
- Degree in Computer Science, AI Engineering, or equivalent
- Minimum 2 years in enterprise integration / middleware / API management
- Minimum 2 years hands-on with production LLM / generative AI integrations
- Demonstrate In-depth Understanding (any combination): EN 18286, prEN 18228, ISO/IEC 42001, ITIL 4, Cloud AI (Google Professional ML Engineer, Azure AI Engineer, AWS ML Specialty), COBIT, TOGAF 9/10 or equivalent.
- Proven track record of delivering high-risk or safety-critical integrations in regulated environments (finance, health, aviation, or public sector preferred)