AI Governance · Risk · Security
I help organizations ship AI and scale securely—while staying ahead of the EU AI Act, ISO 42001, ISO 27001, SOC 2, and board expectations.
Enterprise security evidence on day one.
Predictable audits and regulator-ready comms.
Controls that live in pipelines—not slide decks.
Business Units Scaled
Risk Reduction
Clean SOC2 Cycles
AI IAs, model cards, and release gates inside CI/CD. Faster launches, audit-ready artifacts, less rework.
ERM built for action—appetite, accepts, and KRIs that trigger budget and roadmap moves.
Incident commander with regulator-grade communications and “never again” control upgrades.
ISO 27001/27701/22301 & SOC 2 programs that produce evidence portals and cut procurement timelines.
ITGC redesign and control consolidation with automated evidence—less audit time, fewer findings.
Security/privacy diligence and Day-90 alignment. Standardized governance, zero critical findings.
Move faster with a release-gate approach and automated evidence.
Read MoreFor a private CV, references, or a role-specific discussion, reach out directly.
CRISC · CISM · CDPSE
ISO 42001 · EU AI Act · ISO 27001 · SOC 2 · SOX
ERM & Board Reporting · Incident Leadership