Background
Before I wrote a word about AI, I spent my career at global energy majors — Texaco, then Shell — in controllership and business-assurance roles. That work is where my perspective comes from. At that scale, "governance" is not a policy document. It is the daily, concrete question of who has authority to do what, whether the controls actually operated, and whether — if a regulator, an auditor, or a partner asked — you could prove what happened.
The specific work shaped how I think. SOX controls and process design taught me that a control you cannot evidence is not a control — it is an intention. Data-privacy stewardship for a large payment-card operation taught me what real stakes look like when sensitive data moves at volume. Lean Six Sigma gave me a discipline I still use: define and govern the problem first, then fix it or route it to the right expert — never paper over it. And governance, risk, and assurance work tied it all together: assurance is not a department, it is a habit of proving that things are what you say they are.
I am a retired Certified Public Accountant and a Certified Fraud Examiner (CFE). The CFE credential, which I earned alongside investigations work, matters to how I approach AI: fraud examiners are trained to assume things go wrong, that records get reconstructed after the fact, and that the org chart of who is supposed to do what is nearly worthless in an investigation. What matters is the evidence of what was actually done, by whom, with what authority.
How I think about AI governance
Most AI governance is written by two kinds of people: technologists, who ask whether the model performs and whether it is fair; and lawyers, who ask whether it complies. Both questions are necessary. Neither is the one a fraud examiner asks first.
The forensic question is colder: when this goes wrong, where is the evidence, who had control at the moment it happened, and could we prove it to someone who was not there? Applied to AI, that reframes everything — audit trails before accuracy, segregation of duties applied to models, control testing rather than control listing, and building every process as if someone will one day have to reconstruct exactly what happened from the records alone.
It also means being honest about which regulator actually reaches you first. In a regulated industry, generic frameworks tell you what to govern but not what is urgent. Finance, healthcare, government contracting, and insurance each have a different binding constraint — and that ordering, not the framework, is what should set your priorities.
Much of what I do comes back to assurance — and to a blind spot I see constantly. Large companies have controllers and assurance functions whose whole job is proving the process works. Most small and mid-sized organizations do not, so no one is asking whether the controls actually operate. AI raises the stakes: it can genuinely improve those processes, but only if you govern them first. Used well, it sharpens assurance. Used carelessly, it just automates the blind spot.
Independent by design
I write independently. I do not sell a governance platform, I am not a vendor, and I have no product to move. That independence is deliberate: it means the analysis follows the evidence, not a sales motion. If a framework is good, I will say so. If a control is theater, I will say that too.