AI Governance, Risk & Compliance Advisory

Deploy AI Without Betting the Institution.

Governance, risk, and compliance advisory for regulated enterprises, from an executive who built GenAI control frameworks inside a Tier-1 bank.

Shiloh Shaeed El, AI Governance, Risk and Compliance advisor
Shiloh Shaeed El  |  25 years across regulated banking & diagnostics
12 yrsJPMorgan Chase GRC & control leadership
13 yrsRoche Diagnostics regulated technology
Pillar LeadEnterprise LLM Champion Network
$B portfoliosDigital & Card control oversight
The pressure you're under

Your teams want AI. Your regulators want evidence.

The gap between those two demands is where audit findings, breach exposure, and bias citations live. Closing it is the entire job.

Adoption is outrunning control.

Rolling out GenAI without a defensible control framework turns every deployment into audit exposure. Speed feels like progress right up until the exam.

Your vendors are ingesting your data.

Third-party AI and ML pipelines touching PII and confidential information without contract-grade guardrails are a breach waiting to be discovered.

Models are multiplying past your inventory.

Untracked algorithmic models and estimations are exactly how bias findings and regulatory citations get written. What you cannot see, you cannot defend.

How I Help

Four ways I turn AI risk into controls you can defend.

Focused engagements that map to your risk appetite and hold up when the examiner asks for evidence, not explanations.

01

AI Risk & Governance Architecture

Design the technical risk architecture, guardrails, and operational frameworks to safely embed AI, ML, and GenAI into core workflows, mapped directly to your stated risk appetite.

02

Model & Data Governance Programs

Stand up model inventories, data-health metrics, automated control-effectiveness testing, and governance for both structured and unstructured data.

03

Third-Party AI Risk (TPRM)

Secure API containment and validation controls for vendor AI and ML ingestion, plus contract-grade standards for PII and CI acquisition, retention, and destruction.

04

Pre-Audit Defense & Regulatory Readiness

Control-design reviews, validation gates, and regulatory-change mapping so you walk into exams with an evidence trail already built.

Explore the engagements →
Shiloh Shaeed El
Built inside the institutions you answer to.Tier-1 banking & FDA-regulated diagnostics.
About Shiloh

I spent 25 years being accountable for the controls, so your team doesn't learn them the hard way.

Most AI governance advice is written by people who have never sat across the table from an OCC examiner or shipped software under FDA Class II and III scrutiny. I have done both.

At JPMorgan Chase I led control management across CAO foundational and common program controls, cross-LOB oversight, and Card digital controls and data quality, and I was appointed Integration Pillar Lead for the enterprise LLM Champion Network, building the strategy to embed generative AI into control workflows across multi-billion-dollar Digital and Card portfolios.

"I translate legal obligations into control frameworks that hold up under examination."

Read the full background →
Start here

The cheapest time to fix AI governance is before the finding.

Thirty minutes on your AI adoption goals and current control posture. No pitch deck, no obligation.

Book a Discovery Call
How I Help

Engagements built for the exam, not the demo.

Every engagement ends with something your team owns and can defend: frameworks, standards, and evidence, not a slide deck that ages out before the next audit cycle.

01

AI Risk & Governance Architecture

Design the technical risk architecture, guardrails, and operational frameworks to safely embed AI, ML, and GenAI into core workflows, mapped to your risk appetite. You get a control model that lets the business move without the risk function losing the thread.

02

Model & Data Governance Programs

Stand up model inventories, data-health metrics, automated control-effectiveness testing, and governance for structured and unstructured data, so model sprawl becomes a managed inventory instead of an open finding.

03

Third-Party AI Risk (TPRM)

Secure API containment and validation controls for vendor AI and ML ingestion, plus contract-grade standards for PII and CI acquisition, retention, and destruction, so a vendor's model doesn't become your breach.

04

Pre-Audit Defense & Regulatory Readiness

Control-design reviews, validation gates, and regulatory-change mapping so you walk into exams with evidence, not explanations, and your first line already knows the answer before it's asked.

Who I serve

The regulated few who can't afford to be wrong.

If a model error, a biased output, or a third-party data leak would put you in front of a regulator, we should talk.

BanksFintechsInsurance carriersHealthcare & hospital systemsPharma & life sciencesMedical devicePayments & card
How engagements work

A clear path from exposure to defensible controls.

1

Discovery Call

Thirty minutes on your AI adoption goals and current control posture. We decide together whether there's a fit before anyone signs anything.

2

Governance Assessment

A focused review of your AI and model-risk exposure, delivered as prioritized findings ranked by regulatory and financial consequence.

3

Framework Build & Handoff

Control frameworks, standards, and playbooks your team owns and can defend, with the knowledge transfer to run them without me.

Bring me in before the regulators do.

The first conversation is diagnostic, not transactional. You'll leave it knowing where your real exposure sits.

Book a Discovery Call
About

Built inside the institutions you answer to.

Twenty-five years across two of the most heavily regulated industries in the world: Tier-1 banking and FDA-regulated diagnostics.

Shiloh Shaeed El, GRC executive
Shiloh Shaeed ElAI Governance, Risk & Compliance Advisory · Columbus, OH

I didn't come to AI governance from a lab or a startup. I came to it from the inside of institutions where a control failure has consequences measured in regulatory action, not churn.

For 12 years at JPMorgan Chase, I held governance, risk, compliance, and control-leadership roles, most recently as a GRC & Control Manager in the CAO organization. I led control management across foundational and common program controls, cross-line-of-business oversight, and Card digital controls and data quality. When the firm set out to embed generative AI into control management, I was appointed Integration Pillar Lead for the enterprise LLM Champion Network, responsible for the strategy that let GenAI enter control workflows across multi-billion-dollar Digital and Card portfolios without opening new risk.

Before that, 13 years at Roche Diagnostics leading technical infrastructure and software teams under FDA Class II and III medical-device regulation and 21 CFR Part 820. That's where I learned that "we followed the process" only counts if you can prove it.

The through-line across both careers is the same discipline: taking legal obligations, privacy regulations, and contract mandates and turning them into control frameworks that survive examination. That's the work I now do independently, for the leaders who need it before they need it.

  • GRC & Control Manager (CAO), JPMorgan Chase
  • Integration Pillar Lead, enterprise LLM Champion Network
  • Card digital controls, data quality & cross-LOB control oversight
  • 13 years of FDA Class II/III & 21 CFR Part 820 regulated technology leadership
  • Serves clients nationally, remote, from Columbus, OH

"The person you bring in before the regulators do."

Book a Discovery Call
Perspectives

Positions I'll defend in a control review.

A sample of how I think about AI risk in regulated environments. Not thought-leadership for its own sake, the operating beliefs that shape every framework I build.

Governance

Governance written after deployment is just documentation of your exposure.

Controls designed once the model is already in production tend to describe risk rather than contain it. The framework has to exist before the first inference, or you're papering an exam finding.

A recurring theme in my assessments
Third-party risk

Your vendor's model is now your data-retention problem.

The moment a third party's AI ingests your PII, their retention and destruction practices become your regulatory liability. Contract-grade guardrails aren't legal boilerplate, they're a control.

Where TPRM engagements start
Model risk

You can't govern an inventory you've never counted.

Most organizations underestimate how many models, scripts, and estimations are quietly making decisions. Bias findings almost always trace back to something that was never on the list.

The first thing I ask to see

"Most AI governance fails because it was written by people who have never had to defend a control to an examiner. I have. That changes what you build."

— Shiloh Shaeed El

Want this thinking applied to your environment?

The discovery call is where general positions become specific to your portfolio, your regulators, and your risk appetite.

Book a Discovery Call
Contact

Book a discovery call.

Thirty minutes on your AI adoption goals and current control posture. If there's a fit, we'll map the next step. If there isn't, you'll still leave with a clearer view of your exposure.

Two ways to start the conversation.

Book directly through the calendar, or send a short note and I'll follow up personally, usually within one business day.

Open the booking calendar →
Email
sshaeedel@yahoo.com
Phone
317-938-7917
Based
Columbus, OH · serving clients nationally

Tell me where your risk sits.

A few details so our first call is useful from minute one.

Thank you. Your request is in.

Shiloh will follow up personally, usually within one business day. For anything time-sensitive, call 317-938-7917.