AI Governance & Assurance
Translate commitments and standards into lifecycle controls, accountable oversight, evidence, and assurance.
AI governance & assurance · cybersecurity & GRC · product trust
Trust, engineered for consequential technology.
I lead across AI governance, cybersecurity, product and engineering security, GRC, technology and AI audit, and independent assurance so consequential technology can be trusted in practice.
My work sits between strategy and execution: aligning engineering, security, risk, privacy, legal, compliance, and executive stakeholders around AI and technology decisions that withstand scrutiny.
The objective is not more governance. It is evaluable systems, better judgment, clearer accountability, and durable trust.
Translate commitments and standards into lifecycle controls, accountable oversight, evidence, and assurance.
Structure model and system evaluation, technical risk scenarios, testing, monitoring, and decision thresholds.
Connect AI architecture, identity, data access, threats, controls, and evidence to secure product decisions.
Build scalable control and assurance systems that earn confidence from customers, regulators, and leaders.
Use technical depth, analytics, and automation to make independent assurance a source of decision signal.
Strengthen AI data, model supply chains, critical services, and external dependencies before disruption tests them.
Across every domain, policy and risk become evaluation, controls, observable evidence, and decisions.
Translate commitments into evaluable controls, system evidence, accountable oversight, and decisions across the AI lifecycle.
Capabilities designed to transfer across organizations, industries, and technologies.
Turn emerging AI and global technology obligations into control baselines, evidence strategies, and product decisions.
Convert model, agent, data, and system risks into testable scenarios, observable evidence, and decision thresholds.
Connect AI architecture, identity, data access, cloud, threats, and secure development to product execution.
Build scalable assurance mechanisms that make security and compliance defensible to customers and regulators.
Use analytics, automation, AI-assisted evaluation, and technical judgment to improve coverage and insight.
Selected moments from conferences, panels, and practitioner sessions.
The through-line: turn complex risk into systems engineers can use, executives can govern, and assurance teams can trust.
Built repeatable trust mechanisms connecting global product regulation, security engineering, evidence, and resilience, turning emerging obligations into operational readiness.
Architected and advanced RSAIF MOSAIC, translating responsible and secure AI principles into an operating framework, learning pathways, and practitioner guidance.
Explore the RSAIF ecosystemMoved assurance closer to engineering by applying threat-informed thinking across identity, cloud, encryption, authentication, and DevSecOps.
Expanded technology assurance across cloud, data, infrastructure, third parties, and resilience within a regulated financial environment.
Leadership conversations
I am interested in global leadership mandates across AI assurance, product trust, AI security, risk engineering, technology audit, and governance.