I am an Information Security Analyst and ISMS Manager specializing in Governance, Risk, and Compliance (GRC) for startups, SMEs, and regulated industries. My work focuses on helping organizations securely adopt AI technologies while aligning with global standards such as ISO 42001, EU AI Act, NIST AI RMF, GDPR, and NDPR. I provide frameworks, policies, and risk-based oversight to ensure AI systems are ethical, transparent, and secure.
| Project | Scope | Governance Approach | Standards (In view) |
|---|---|---|---|
| AI Chatbot Website Implementation | A customer-facing chatbot for a service startup, ensuring compliance, transparency, and security. | Implementing ISO 42001 governance, AI use policy, vendor risk assessment, and bias review. | ISO 42001, GDPR |
| AI Voice Assistant | A zero-retention AI voice assistant for healthcare use cases with PHI. | Applying HIPAA safeguards, privacy-by-design, encryption, and AI compliance framework. | HIPAA, GDPR, ISO 42001, NIST AI RMF |
My approach to AI governance is built on key principles: