Job Posting:
Since 1953, Ferguson has been a source of quality supplies for a variety of industries. Together We Build Better infrastructure, better homes and better businesses. We exist to make our customers’ complex projects simple, successful, and sustainable. We proactively solve problems, adapt and grow to continuously serve our customers, communities and each other. Ferguson, a Fortune 500 company, is proud to provide best-in-class products, service and capabilities across the following industries: Commercial/Mechanical, Facilities Supply, Fire and Fabrication, HVAC, Industrial, Residential Trade, Residential Building and Remodel, Waterworks and Residential Digital Commerce. Ferguson has approximately 36,000 associates across 1,700 locations. Ferguson is a community of proud associates who operate with the shared purpose of building something meaningful. You will build a career that you are proud of, at a company you can believe in.
The AI Governance and Risk Manager owns the day-to-day execution of AI governance and risk review across Ferguson's AI portfolio - evaluating use cases, vendors, and tools against Ferguson's risk framework, running the AI Impact Assessment process, and building visibility into where AI is being used across the organization, approved or not.
This role works in close, standing partnership with Legal/InfoSec on day-to-day risk determinations. Policy and standards work is co-owned between this role and the Senior Manager, who remains the final checkpoint before any policy artifact moves forward for review by Legal, InfoSec, the AI Council, or other stakeholders; day-to-day operational review and risk assessment is fully owned by this role.
Ferguson's AI governance model is actively maturing. This role will operate against frameworks that are partly built and help finish building the parts that aren't - it is not a role for someone who needs a fully defined process before they can execute.
Location: This role is approved to be either Remote within the United States or Hybrid for associates in Newport News, VA, in accordance with company policy.
Key Responsibilities
Use case and AI Impact Assessment (AIIA)
Own the AI Impact Assessment process for new and materially changed AI use cases, from intake through disposition, including maintenance of the AIIA repository as the governance record of use cases reviewed.
Own the routing logic that determines which reviews a use case or vendor/tool requires - based on data classification, AI Solution Tier, vendor/tool status, and whether the system is agentic - captured through intake questions asked at first contact, before deeper assessment begins.
Ensure AI-specific assessment (classification, tiering, privacy screen, vendor questionnaire, agentic review as applicable) is complete before a use case or vendor request proceeds to Sourcing, InfoSec, and Legal - so those teams receive Ferguson's AI-specific assessment already answered rather than working the AI questions themselves.
Conduct a high-level data privacy impact screen for each use case. The screen identifies whether a use case's data handling raises privacy concerns warranting escalation to a full data privacy assessment; it is a triage step, not a substitute privacy determination.
Assess fairness/bias and explainability considerations as part of the AIIA, calibrated to the use case's risk tier.
Define and apply clear escalation criteria for when a use case requires full PIA, Legal review, or AI Council-level escalation, rather than resolving ambiguous cases informally case by case.
Identify when an approved use case has materially changed (scope, data, vendor terms) and needs re-review.
Vendor and tool risk review
Own the vendor and tool AI risk review process, including sending and evaluating AI risk questionnaires.
Coordinate vendor risk disposition through the Ironclad routing process with Sourcing and InfoSec.
Develop and apply a review approach specific to agentic AI (autonomy level, action scope, data access, escalation path if an agent acts incorrectly) distinct from standard tool/vendor review - in coordination with AI Technology & Innovation on technical risk factors.
Shadow AI
Build visibility into unapproved AI usage across the organization - what's being used, by whom, and why - using discovery tooling and direct engagement with teams.
Evaluate, select, and administer AI governance/discovery tooling as Ferguson brings it in.
Partner with teams found using unapproved tools to understand the underlying need (capability gap, workflow friction, awareness gap) and support migration to approved alternatives, positioning this as enablement rather than enforcement alone.
Feed shadow AI findings into policy and standards work as evidence of where existing guidance has gaps.
Governance infrastructure and reporting
Maintain the AI registry / governance repository as the record of approved use cases, tier, classification, and status.
Track and report governance health - review cycle time, backlog, risk distribution across the portfolio - to the Senior Manager.
Maintain awareness of the AI regulatory landscape and support maintenance of a regulatory register to keep policy and standards current as external requirements evolve.
Policy and standards (co-owned)
Draft and refine AI governance policy, standards, and guidelines (e.g., AUP updates, tiering framework changes, committee charter revisions) in partnership with the Senior Manager.
Bring proposed policy changes to the Senior Manager for review before they move to Legal, InfoSec, AI Council, or other stakeholders for their own review - the Senior Manager is the checkpoint before external visibility, not a gate on day-to-day operational work.
Required Qualifications
Experience in AI/technology governance, risk management, or compliance operations, ideally in a matrixed enterprise environment.
Working knowledge of legal and regulatory considerations related to AI, data privacy, vendor risk, and responsible technology governance, including the ability to recognize potential compliance risks and engage Legal and other stakeholders as appropriate.
Data privacy experience, including working knowledge of data classification and privacy impact assessment methodology - this role's core judgment calls depend on correctly assessing the data a use case or tool touches.
Working knowledge of GRC processes and third-party/vendor risk review.
Experience with AI discovery, monitoring, or governance tooling, including hands-on administration - not solely policy-level familiarity.
Ability to operate independently against a governance framework that is still maturing, and to help build out undefined parts of it.
Autonomous decision making to assess when and what level of governance assessment is needed for AI use cases or vendor requests.
Strong cross-functional coordination skills - this role works constantly with Legal, InfoSec, Sourcing, and business stakeholders who don't report to it.
Preferred Qualifications
Privacy certification (e.g., CIPP/E, CIPM) alongside AI governance training or audit credential.
Familiarity with AI-specific risk considerations (model risk, agentic system risk, bias/explainability) distinct from general IT governance.
Experience standing up or operating governance committee structures at the functional or business-unit level.
At Ferguson, we care for each other. We value our well-being just as much as our hard work. We are committed to a holistic approach towards benefits plans and programs that support the mental, physical and financial well-being of our associates. Our competitive offering not only includes benefits like health, dental, vision, paid time off, life insurance and a 401(k) with a company match, but our associates also enjoy additional meaningful and inclusive enhancements that are adaptable to their diverse situations and needs, including mental health coverage, gender affirming and family building benefits, paid parental leave, associate discounts, community involvement opportunities and more!
-
Pay Range:
-
Actual pay rate may vary depending upon location. The estimated pay range for this position is below. The specific rate will depend on a candidate’s qualifications and prior experience.
-
$9,700.00 - $15,516.67-
Estimated Ranges displayed are Monthly for Salaried roles OR Hourly for all other roles.
-
This role is Bonus or Incentive Plan eligible.
-
Ferguson complies with all wage regulations. The starting wage may be higher in certain locations based on local or state wage requirements.
-
The Company is an equal opportunity employer as well as a government contractor that shall abide by the requirements of 41 CFR 60-300.5(a), which prohibits discrimination against qualified protected Veterans and the requirements of 41 CFR 60-741.5(A), which prohibits discrimination against qualified individuals on the basis of disability.
Ferguson Enterprises, LLC. is an equal employment employer F/M/Disability/Vet/SexualOrientation/GenderIdentity.
Equal Employment Opportunity and Reasonable Accommodation Information

