Customer assurance that can be defended
Structure security and compliance responses around approved evidence, accountable owners, review cadence and explicit exceptions so recurring diligence is consistent and inspectable.
Md. Abdullah Al Owasi · Technology Risk & AI Governance
I design the operating logic behind technology risk, control assurance, third-party governance and AI risk: requirements, controls, evidence, ownership, exceptions, remediation, monitoring and residual-risk decisions. The portfolio is built so a reviewer can inspect how the reasoning works, not just read a list of frameworks.
Business value appears when evidence, ownership and risk treatment move together.
Structure security and compliance responses around approved evidence, accountable owners, review cadence and explicit exceptions so recurring diligence is consistent and inspectable.
Connect control intent to evidence, testing, exceptions, remediation and retesting so assurance work can operate continuously instead of becoming a one-time audit exercise.
Translate AI inventories into risk classification, ownership, human oversight, evaluation, monitoring and transparency decisions using NIST AI RMF, ISO/IEC 42001 and EU AI Act concepts.
Prioritize vendor scrutiny by criticality, data exposure, assurance evidence, processor obligations and residual risk rather than treating every questionnaire as equally material.
Open risks: 8 · Monitor risks: 7 · Inherent 208 → Residual 127.
A recurring assurance rhythm connects evidence freshness, exceptions and remediation decisions.
Integrated modules turn assurance, third-party risk and AI governance into traceable decision systems.
A control-to-evidence architecture that decomposes broad trust claims into accountable owners, reviewable evidence, framework references, exceptions and remediation decisions.
| Domain | Decision question | Evidence path | Priority |
|---|---|---|---|
| Access | Can privileged access be defended? | RBAC · MFA · access review | High |
| Encryption | Is customer data protected in transit and at rest? | TLS · storage · KMS evidence | High |
| Incident | Can escalation and notification be evidenced? | IR plan · exercise · notice flow | High |
| Assurance | What independent or internal evidence supports the claim? | SOC scope · ISO evidence · control record | High |
A vendor-governance model that turns criticality, public assurance evidence, processor obligations and AI-provider risk into approve, remediate, accept or reject decisions.
| Domain | Decision question | Evidence path | Priority |
|---|---|---|---|
| OpenAI | Tier 1 | Retention / model data-use configuration | Medium |
| AWS Bedrock | Tier 1 | IAM / KMS / region design | Low-Med |
| Slack | Tier 1 | Sensitive collaboration data / apps | Medium |
| GitHub | Tier 1 | Source code / secrets / AI tooling | Medium |
An enterprise AI inventory model connecting business purpose, stakeholders, oversight, NIST AI RMF functions, risk treatment, monitoring and EU AI Act transparency decisions.
| Domain | Decision question | Evidence path | Priority |
|---|---|---|---|
| Support chatbot | Escalation required | Disclosure / quality | Implement |
| Voice agent | Material-issue escalation | Interaction transparency | Implement |
| Code assistant | Developer + CI review | Secret / vulnerability | Control |
| Risk summarizer | CISO / GRC approval | Risk misstatement | Control |
Tap a use case to inspect oversight and transparency evidence.
Ten systems spanning assurance, technology risk, third-party risk and AI governance. Each shows the operating logic, evidence path, ownership model, exception state and decision structure behind the work.
Architects a governed path from buyer question to evidence, owner, exception and remediation decision.
SOC 2 TSC · ISO/IEC 27001:2022 · GDPR Art. 28Turns AI principles into an accountable inventory, risk model, oversight structure, evaluation plan and monitoring workflow.
NIST AI RMF 1.0 · NIST GenAI Profile · ISO/IEC 42001:2023Creates an evidence-led approve / remediate / accept / reject decision trail for critical vendors and AI providers.
GDPR Art. 28 · SOC 2 · ISO/IEC 27001Connects control intent to evidence, cadence, ownership, test logic, exceptions and retesting.
AICPA Trust Services Criteria · ISO/IEC 27001:2022Translates control and compliance activity into accountable residual-risk decisions, treatment plans and KRIs.
ISO 27001 risk treatment · NIST AI RMF · Enterprise GRCMaps interactive and synthetic AI use cases to provider/deployer transparency, provenance, marking and disclosure decisions.
EU AI Act Article 50 · NIST AI RMF · ISO/IEC 42001Defines preventive and detective controls for sensitive-data exposure through unsanctioned or poorly governed AI use.
NIST GenAI Profile · ISO/IEC 27001 · ISO/IEC 42001Standardizes high-friction security answers around governed evidence, ownership and review dates.
SOC 2 · ISO 27001 · GDPR · NIST AI RMFConverts processor and subprocessor obligations into operational controls, evidence requests and accountable decisions.
GDPR Article 28 · ISO 27001 supplier/privacy controlsStructures evidence cadence, request ownership, exception tracking, remediation and retesting for repeatable assurance operations.
SOC 2 · ISO/IEC 27001 · Continuous GRCEach capability points to a system, artifact, control model or decision structure that can be inspected and discussed in a technical interview.
Risk, controls, evidence, ownership, exceptions, remediation and assurance workflows.
Applied in · 10-system operating portfolioTrust Services Criteria translated into control, evidence, testing and assurance structures.
Applied in · 15-domain control inventoryISMS control architecture, risk treatment, ownership and evidence mapping.
Applied in · Control-to-evidence architectureGoverned buyer answers with evidence paths, accountable owners and review cadence.
Applied in · 25-question assurance knowledge basePopulation/sample logic, expected results, exceptions, remediation and retesting.
Applied in · Audit-operations systemGovern, Map, Measure and Manage applied to enterprise AI inventory and risk decisions.
Applied in · 15-use-case AI governance registerProvider/deployer transparency analysis for interactive and synthetic AI use cases.
Applied in · 15-use-case transparency registerAI management-system concepts integrated with accountability, risk and evidence workflows.
Applied in · AI governance operating architecturePurpose, data, stakeholder, oversight, evaluation, monitoring and residual-risk mapping.
Applied in · AI governance decision registerApproved channels, prompt classification, secret detection, redaction and unsanctioned-use controls.
Applied in · 12-control governance standardCriticality tiering, evidence review, contractual risk, findings and treatment decisions.
Applied in · 10-vendor TPRM registerProcessor instructions, subprocessors, assistance, deletion, audit rights and evidence requirements.
Applied in · 12-clause processor control setEvidence requests spanning assurance, IAM, cryptography, privacy, resilience and AI providers.
Applied in · 20-question vendor-risk assessmentLikelihood, impact, residual risk, appetite, treatment, KRI and escalation logic.
Applied in · 15-risk executive registerData transformation and repeatable artifact-generation workflows for governance and evidence operations.
Applied in · GRC evidence workbooksTyped interfaces for decision systems, interactive evidence views and portfolio tooling.
Applied in · This portfolioStatic-first web architecture, metadata, accessibility and deployment discipline.
Applied in · This portfolioVersion control, change traceability, repository documentation and delivery workflow.
Applied in · Portfolio repositoryStructured thinking for evidence inventories, risk registers, ownership and relational decision data.
Applied in · Computer Science systems foundation + GRC systemsTechnical foundation for decomposing governance problems into inputs, states, dependencies and decision logic.
Applied in · Computer Science systems foundation + operating portfolioFramework knowledge matters when it changes how controls are designed, evidence is collected, ownership is assigned, exceptions are handled and decisions are made.
Govern, Map, Measure and Manage provide the primary risk lifecycle used across the AI inventory, oversight, evaluation and monitoring architecture.
Open primary source ↗Source-linkedISMS requirements inform risk treatment, accountable control ownership, evidence structure and the relationship between governance intent and operating proof.
Open primary source ↗Source-linkedSecurity, availability, processing integrity, confidentiality and privacy criteria inform control-and-evidence structures used in customer assurance and audit operations.
Open primary source ↗Source-linkedTransparency obligations guide deployer/provider decisions for interactive AI, synthetic media, generated text and disclosure contexts.
Open primary source ↗Source-linkedProcessor obligations are translated into subprocessor, audit-right, deletion, assistance, confidentiality and security-evidence requirements.
Open primary source ↗I am open to high-ownership opportunities across Technology Risk, GRC, Security Compliance, Third-Party Risk and AI Governance. Send the role, business context and hardest unresolved risk question. My portfolio shows the architecture and decision logic I would bring to the conversation.
The fastest useful conversation starts with the mandate and the unresolved decision. The evidence behind the work is already available below.
Open to high-ownership opportunities across Technology Risk, GRC, Security Compliance, TPRM and AI Governance.