Governance, risk, and compliance advisory for regulated enterprises, from an executive who built GenAI control frameworks inside a Tier-1 bank.
The gap between those two demands is where audit findings, breach exposure, and bias citations live. Closing it is the entire job.
Rolling out GenAI without a defensible control framework turns every deployment into audit exposure. Speed feels like progress right up until the exam.
Third-party AI and ML pipelines touching PII and confidential information without contract-grade guardrails are a breach waiting to be discovered.
Untracked algorithmic models and estimations are exactly how bias findings and regulatory citations get written. What you cannot see, you cannot defend.
Focused engagements that map to your risk appetite and hold up when the examiner asks for evidence, not explanations.
Design the technical risk architecture, guardrails, and operational frameworks to safely embed AI, ML, and GenAI into core workflows, mapped directly to your stated risk appetite.
Stand up model inventories, data-health metrics, automated control-effectiveness testing, and governance for both structured and unstructured data.
Secure API containment and validation controls for vendor AI and ML ingestion, plus contract-grade standards for PII and CI acquisition, retention, and destruction.
Control-design reviews, validation gates, and regulatory-change mapping so you walk into exams with an evidence trail already built.
Most AI governance advice is written by people who have never sat across the table from an OCC examiner or shipped software under FDA Class II and III scrutiny. I have done both.
At JPMorgan Chase I led control management across CAO foundational and common program controls, cross-LOB oversight, and Card digital controls and data quality, and I was appointed Integration Pillar Lead for the enterprise LLM Champion Network, building the strategy to embed generative AI into control workflows across multi-billion-dollar Digital and Card portfolios.
"I translate legal obligations into control frameworks that hold up under examination."
Thirty minutes on your AI adoption goals and current control posture. No pitch deck, no obligation.
Book a Discovery CallEvery engagement ends with something your team owns and can defend: frameworks, standards, and evidence, not a slide deck that ages out before the next audit cycle.
Design the technical risk architecture, guardrails, and operational frameworks to safely embed AI, ML, and GenAI into core workflows, mapped to your risk appetite. You get a control model that lets the business move without the risk function losing the thread.
Stand up model inventories, data-health metrics, automated control-effectiveness testing, and governance for structured and unstructured data, so model sprawl becomes a managed inventory instead of an open finding.
Secure API containment and validation controls for vendor AI and ML ingestion, plus contract-grade standards for PII and CI acquisition, retention, and destruction, so a vendor's model doesn't become your breach.
Control-design reviews, validation gates, and regulatory-change mapping so you walk into exams with evidence, not explanations, and your first line already knows the answer before it's asked.
If a model error, a biased output, or a third-party data leak would put you in front of a regulator, we should talk.
Thirty minutes on your AI adoption goals and current control posture. We decide together whether there's a fit before anyone signs anything.
A focused review of your AI and model-risk exposure, delivered as prioritized findings ranked by regulatory and financial consequence.
Control frameworks, standards, and playbooks your team owns and can defend, with the knowledge transfer to run them without me.
The first conversation is diagnostic, not transactional. You'll leave it knowing where your real exposure sits.
Book a Discovery CallTwenty-five years across two of the most heavily regulated industries in the world: Tier-1 banking and FDA-regulated diagnostics.
I didn't come to AI governance from a lab or a startup. I came to it from the inside of institutions where a control failure has consequences measured in regulatory action, not churn.
For 12 years at JPMorgan Chase, I held governance, risk, compliance, and control-leadership roles, most recently as a GRC & Control Manager in the CAO organization. I led control management across foundational and common program controls, cross-line-of-business oversight, and Card digital controls and data quality. When the firm set out to embed generative AI into control management, I was appointed Integration Pillar Lead for the enterprise LLM Champion Network, responsible for the strategy that let GenAI enter control workflows across multi-billion-dollar Digital and Card portfolios without opening new risk.
Before that, 13 years at Roche Diagnostics leading technical infrastructure and software teams under FDA Class II and III medical-device regulation and 21 CFR Part 820. That's where I learned that "we followed the process" only counts if you can prove it.
The through-line across both careers is the same discipline: taking legal obligations, privacy regulations, and contract mandates and turning them into control frameworks that survive examination. That's the work I now do independently, for the leaders who need it before they need it.
"The person you bring in before the regulators do."
A sample of how I think about AI risk in regulated environments. Not thought-leadership for its own sake, the operating beliefs that shape every framework I build.
Controls designed once the model is already in production tend to describe risk rather than contain it. The framework has to exist before the first inference, or you're papering an exam finding.
The moment a third party's AI ingests your PII, their retention and destruction practices become your regulatory liability. Contract-grade guardrails aren't legal boilerplate, they're a control.
Most organizations underestimate how many models, scripts, and estimations are quietly making decisions. Bias findings almost always trace back to something that was never on the list.
"Most AI governance fails because it was written by people who have never had to defend a control to an examiner. I have. That changes what you build."
— Shiloh Shaeed ElThe discovery call is where general positions become specific to your portfolio, your regulators, and your risk appetite.
Book a Discovery CallThirty minutes on your AI adoption goals and current control posture. If there's a fit, we'll map the next step. If there isn't, you'll still leave with a clearer view of your exposure.
Book directly through the calendar, or send a short note and I'll follow up personally, usually within one business day.
Open the booking calendar →