About Me

I am an Information Security Analyst and ISMS Manager specializing in Governance, Risk, and Compliance (GRC) for startups, SMEs, and regulated industries. My work focuses on helping organizations securely adopt AI technologies while aligning with global standards such as ISO 42001, EU AI Act, NIST AI RMF, GDPR, and NDPR. I provide frameworks, policies, and risk-based oversight to ensure AI systems are ethical, transparent, and secure.

Featured Case Studies (On-going)

Project Scope Governance Approach Standards (In view)
AI Chatbot Website Implementation A customer-facing chatbot for a service startup, ensuring compliance, transparency, and security. Implementing ISO 42001 governance, AI use policy, vendor risk assessment, and bias review. ISO 42001, GDPR
AI Voice Assistant A zero-retention AI voice assistant for healthcare use cases with PHI. Applying HIPAA safeguards, privacy-by-design, encryption, and AI compliance framework. HIPAA, GDPR, ISO 42001, NIST AI RMF

AI GOVERNANCE SAMPLE DOCUMENT

AI Guiding Principles

My approach to AI governance is built on key principles:

Governance Structure

Model Inventory Process