Writing a CV for a governance role
How to describe privacy and AI governance work so that a hiring manager can see what you did and what changed as a result.
Governance work is hard to put on a CV. Much of its value lies in things that did not happen, and much of the rest is confidential. These are the habits that help a hiring manager see what you actually did.
Describe outcomes, then activity
“Responsible for DPIAs” says little. “Redesigned the impact assessment process so that screening takes one day instead of two weeks, and assessed 40 projects in the first year” shows scale, initiative and a result. Where you cannot give numbers, describe what changed for the teams you supported.
Be specific about scope
- The size and sector of the organisation, and the size of your team.
- Who you advised and how senior they were.
- Which laws and jurisdictions you worked with in practice.
- What you owned outright, and what you contributed to.
Handle confidentiality plainly
You can describe an incident or a regulator enquiry without identifying details: the type of issue, your role in the response and what was improved afterwards. Hiring managers in this field respect discretion and will be wary of a CV that shares too much.
Show how you work with others
Almost every role in this field depends on influence without authority. Include an example of persuading a team to change course, and say how you did it.
Certificates and training
List the ones that are current and relevant, with dates. Put them after your experience unless the advert makes one essential.
Keep it readable
Two pages is enough for most people. Use plain headings and consistent dates, and avoid tables or text boxes that application systems can scramble. Then ask someone outside the field to read it. If they can explain what you do, the CV is working.