Governance, Risk & Compliance
AI regulation, data residency, and sector-specific compliance are moving targets. Get it wrong and a project stalls in due diligence or fails an audit. Get it right, and governance becomes a trust signal that speeds procurement up rather than slowing it down.
The problem
Organisations in the public sector, life sciences, telecom, and financial services face an expanding web of regulation — the EU AI Act, GDPR and data regionality, GxP in life sciences, sector-specific reporting obligations — alongside internal pressures to adopt AI and modernise quickly. The governance gap between "we want to use AI" and "we can prove to a regulator that we're using it responsibly" is where projects stall or, worse, proceed without adequate safeguards.
What I do
- Design governance frameworks aligned to the EU AI Act, data regionality requirements, and sector-specific regulation — not generic policy templates, but frameworks that reflect how your organisation actually works.
- Build the policy chain from board-level oversight down to day-to-day operational practice, so governance is actually followed rather than filed away in a SharePoint folder nobody opens.
- Integrate risk management into delivery and PMO structures, so compliance is designed in from the start rather than checked at the end.
Governance that's defensible under audit, faster sign-off from security and procurement teams, and materially lower regulatory risk — without adding months to delivery.
Other services
Technology & Product Leadership
Choosing, building, and roadmapping technology that meets real user and organisational need.
Delivery & Transformation Assurance
Risk-managed delivery for complex, multi-stakeholder programmes.