AI governance · Compliance · Literacy
Building governance for the AI transition.
Governance that works in the building, not just in the binder.
The AI opportunity is growing faster than most governance can move. My focus is closing that gap without creating bureaucracy that slows innovation — designing the governance, assurance, model risk management, responsible AI and regulatory compliance capabilities that let organisations adopt AI safely while continuing to move quickly. I do this as Head of AI and Transaction Data Governance at Swift.
Governance only works when it's embedded into delivery. So I learn this technology by doing, and I build teams that stay close to it.
My background spans two decades in environments where getting data governance wrong isn't an option: financial crime compliance at Swift, and before that leading data analytics and OSINT teams at the UK Foreign and Commonwealth Office on counter-terrorism and counter-proliferation work.
The shift
From tools people use to systems that act
Most governance was designed for AI as a tool people use, not AI as a capability people own and answer for.
Most organisations begin with AI as a personal productivity tool. The real challenge starts when AI becomes embedded in operational processes, customer journeys, engineering workflows and decision-making. At that point the governance challenge shifts from managing isolated tools to managing systems of AI: chains of AI decisions, agentic workflows and organisation-wide dependencies. My contribution is building the governance muscle for that shift.
For the most autonomous end of that spectrum — systems that orchestrate, decide and act — I directed the development of a five-dimension model for governing agentic AI, stress-tested against the leading international frameworks.
The measure of success isn't the number of reviews completed, policies written or committees established. It's whether an organisation can confidently deploy increasingly capable AI while maintaining trust, accountability, resilience and regulatory compliance — capturing the value of AI while governance evolves at the same pace as the technology itself.
What I do
Three things, done properly
Making AI visible
You cannot govern what you cannot see. I build the visibility layer — inventory, use-case registration and clear ownership — that turns scattered, unregistered AI activity into something an organisation can steer. For agentic AI, ownership and cataloguing come first: no owner, no oversight.
Risk and opportunity trade-offs
Governance should speed the right work up and slow the risky work down. I triage AI use by risk and apply oversight in proportion, and I read AI regulation at the level of the statute, not the summary — turning it into operating instructions a business can act on, from the deployer position, where most organisations actually sit.
AI literacy as a control
Literacy is a control, not a nice-to-have. When people understand what they're accountable for, fewer things go wrong upstream. I design literacy by role: what a senior sponsor decides, what a builder controls and what a second-line reviewer must catch are three different briefs.
Approach
How I work
The best governance is almost invisible. I don't set out to create more process, more approvals or more bureaucracy — I design frameworks, decision pathways and operating models that help people move quickly while understanding risks, responsibilities and boundaries. When governance is clear, practical and trusted, teams spend less time in uncertainty and more time creating value.
Successful AI adoption is rarely a technology challenge; it's usually a confidence challenge. So I put as much effort into people as into policy — executive AI literacy, board education, role-based learning pathways and plain-spoken governance communications that give people the confidence to experiment, learn and adopt safely.
And complex change succeeds when people feel both challenged and supported. I lead through collaboration, psychological safety and clear decision-making, bringing technical and non-technical communities to a common understanding and helping organisations move from strategy to sustained adoption.
The career behind this, and the full set of skills I bring, are on the Skills page.
Currently
Currently working on
- A regulator-ready AI governance framework, compliant with the EU AI Act and aligned with ISO 42001.
- How AI incidents get caught, escalated and stood down — including the regulatory notification clock, and where the lifecycle usually breaks: monitoring, triage and decommissioning after go-live.
- Enterprise-wide AI literacy and specialised upskilling for second-line functions, software development and senior leadership.
- Workforce strategy for the future of work: how roles, tasks and skills change as human-AI collaboration models mature.
Let's talk
I'm always interested in talking to others working on AI governance, assurance and capability-building — whether that's a conference, a working group, or a conversation. Get in touch.