Responsible AI • Risk • Governance

AI Risk &
Governance
Professional

Managing the risks behind intelligent systems.

I bring established experience across enterprise risk, governance, compliance and safety-critical operations to a developing specialism in AI governance, Responsible AI and technology risk.

LinkedIn · TODO ukenneth@hotmail.com United Kingdom
14+years across risk, compliance and safety
06regulated-sector roles documented
01developing AI-risk specialism
Professional direction

Where AI meets established risk practice

A deliberate progression from enterprise risk, cyber compliance and safety-critical operations into the governance of intelligent systems.

My career has trained me to ask the questions that responsible AI demands: What can go wrong? Who could be affected? Which controls are credible? Who owns the decision? What evidence supports it?

Across critical infrastructure, rail, financial services, healthcare change and engineering, I have worked with risk assessments, control design, RCSA, audit, privacy, incident documentation, third-party risk and senior stakeholder decisions.

I am now applying that foundation to AI risk and governance—building practical fluency in AI-specific harms, human oversight, model limitations, regulatory classification and assurance without overstating AI-industry experience.

Risk-led decision support
Evidence and control thinking
Regulated-sector perspective
Cross-functional facilitation
Capabilities

AI risk, governance and assurance

Established GRC capabilities are separated clearly from the AI-specific knowledge I am developing and demonstrating through independent case studies.

Developing AI application

AI Risk Management

  • AI risk identification
  • Risk registers
  • Control design
  • Residual-risk thinking
  • Monitoring
Developing practice

Responsible AI

  • Accountability
  • Human oversight
  • Transparency
  • Fairness
  • Safety
Established transferable practice

Governance & Controls

  • Governance structures
  • Policies
  • RCSA
  • Roles and accountability
  • Control monitoring
Established GRC; AI regulation developing

Regulatory & Privacy Risk

  • GDPR
  • DPA 2018
  • DPIAs
  • Compliance monitoring
  • EU AI Act awareness
Developing practice

AI System Risk

  • Model limitations
  • Hallucination risk
  • Automation bias
  • Misuse
  • Third-party AI risk
Established transferable practice

Assurance

  • Internal audit
  • Control reviews
  • Evidence
  • Incident documentation
  • Continuous improvement
Framework literacy

Frameworks I use or study

This is a working knowledge map—not a certification claim. AI-specific standards are labelled as areas of active study.

Built around a familiar principle: governance should produce traceable decisions, proportionate controls and evidence that withstands challenge.

F-01AI

NIST AI RMF

Studying application across GOVERN, MAP, MEASURE and MANAGE.

F-02AI

ISO/IEC 42001

Studying AI management-system governance and assurance expectations.

F-03Regulation

EU AI Act

Developing risk-classification and obligation awareness.

F-04Regulation

UK AI principles

Studying the UK’s principles-based regulatory approach.

F-05Risk

ISO 31000

Risk-management principles applied in established risk practice.

F-06Cyber

NIST CSF

Used in documented risk and compliance responsibilities.

F-07Cyber

ISO 27001 / 27005

Used for security controls and information-risk assessment.

F-08Privacy

GDPR / DPA 2018

Privacy, DPIA and data-subject-rights experience.

Method

A lifecycle for accountable AI risk decisions

Select a stage to see how discovery moves through control, governance, monitoring and independent challenge.

Stage 01

Define the system, purpose, context, stakeholders and foreseeable impacts.

Experience

Risk thinking across regulated industries

Career history is presented as documented—not rewritten as fictional AI employment. The value lies in the discipline that transfers.

September 2019 — Present

United Kingdom

National Grid

Risk Engineer

01

Enterprise and project-risk work supporting controls, quantified risk analysis, value management and programme decisions in critical national infrastructure.

  • Develops risk treatment and controls by analysing recurring-risk trends and interdependencies.
  • Leads QSRA and QCRA workshops, using best/worst-case analysis and P50/P80 values to support funding and scope decisions.
  • Supports enterprise risk management through dependency analysis, RCSA and continuous control monitoring.
  • Contributes to third-party risk management and contractor compliance.
Enterprise riskControl assuranceQuantitative analysisThird-party risk

August 2016 — August 2019

Milton Keynes

Network Rail

Risk & Compliance

02

Risk, privacy and cyber-compliance responsibilities in a regulated infrastructure environment.

  • Conducted risk assessments and compliance audits against ISO 27001, PCI DSS, GDPR and NIST CSF.
  • Developed and maintained policies, risk registers, remediation plans and control-effectiveness tracking.
  • Implemented third-party cyber-risk processes and supported DPIAs, DSARs and privacy enquiries.
  • Delivered awareness training and facilitated internal audits and control reviews.
GRCPrivacyAudit readinessSecurity controls

March 2015 — August 2016

Northampton

Barclaycard

Compliance Analyst

03

Data-protection, payment-security and incident-documentation support within financial services.

  • Conducted PCI DSS gap analyses, risk assessments and security audits.
  • Supported controls protecting cardholder data and reducing fraud exposure.
  • Managed incident-response documentation and timely security-incident reporting.
  • Supported training on cyber policy and data-protection practice.
Financial servicesPCI DSSIncident managementData protection

August 2014 — February 2015

United Kingdom

Leeds and York Partnership NHS Foundation Trust

Project Manager

04

Managed a care-progression change programme with responsibility for scope, constraints, risk, delivery governance and health and safety.

  • Delivered the programme in line with budget and stakeholder requirements.
  • Established PMO processes and led planning across objectives, scope, constraints, risks and deliverables.
  • Supported crisis resolution, team performance and implementation of health-and-safety requirements.
Healthcare changeDelivery riskStakeholder managementSafety

December 2012 — August 2014

Leeds

T&M Reuse

PMO Analyst

05

Programme controls, scheduling, reporting and RAID-log management across delivery and subcontractor activity.

  • Tracked schedule deviation against risk tolerance and initiated mitigating action.
  • Monitored subcontractor activity and reported progress to the programme management board.
  • Maintained activity and RAID logs plus weekly and monthly progress reporting.
Programme controlsRAIDReportingMitigation

December 2011 — October 2012

Glasgow

Petrofac

Chemical Process Technician

06

Process-improvement and operational-safety responsibilities in an engineering environment.

  • Collected data for process improvements and used process-simulation software to evaluate production methods.
  • Assessed safety and environmental issues and checked equipment against specification and capacity.
  • Supported safe working conditions and health-and-safety compliance.
Process safetyOperational controlsEnvironmental riskData-led improvement
Education

Technical foundations

Dates to confirm

MSc Chemical Process Engineering

Specialised in design and process engineering

Institution not stated in source CV

Dates to confirm

BSc Physics

Specialised in solid-state physics

Institution not stated in source CV

Professional development

Risk, delivery and safety

International Certificate in Enterprise Risk ManagementCertified
Digital Risk Management CertificateIn view
ISO 27001 Lead ImplementerCredential details to confirm
PRINCE2 FoundationCertified
NEBOSH General Health & SafetyCredential details to confirm
Value Management Foundation CoursePassed
AML and Financial Crime CompliancePassed
KYC Standards and ControlsPassed
Earned Value ManagementPassed
Jira and Agile Project ManagementIntroductory course passed
SAP Enterprise Resource PlanningIntroductory course passed
Minimum Industrial Safety TrainingOPITO-approved; passed

Professional affiliations

Institute of Chemical Engineers (IChemE)Institute of Risk Management
Portfolio

AI risk in practice

Independent, hypothetical case studies designed to make the risk method visible. They do not represent client or employer work.

View all projects
01 / 05Case study

Portfolio Project / Independent Case Study

Generative AI in Healthcare

A structured risk assessment for a hypothetical generative-AI assistant in a healthcare organisation.

Clinical safetyPrivacyHuman oversight
View case study
02 / 05Case study

Portfolio Project / Independent Case Study

AI Governance Framework

An operating model for accountable AI inventory, classification, approvals, monitoring and incidents.

Operating modelAccountabilityControls
View case study
03 / 05Case study

Portfolio Project / Independent Case Study

EU AI Act Classification

A worked classification exercise for a hypothetical AI-enabled workforce screening system.

ClassificationObligationsTransparency
View case study
04 / 05Case study

Portfolio Project / Independent Case Study

AI Vendor Risk Assessment

A due-diligence method extending established third-party risk thinking to AI suppliers.

Third partiesSecurityResilience
View case study
05 / 05Case study

Portfolio Project / Independent Case Study

NIST AI RMF Assessment

Application of GOVERN, MAP, MEASURE and MANAGE to a realistic customer-service AI use case.

NIST AI RMFAssuranceMonitoring
View case study
Risk instrument

Risk made visible

An accessible matrix component for assessing inherent and residual risk within each case study.

Every cell includes a numeric score and a text category, so the decision never relies on colour alone. Select a cell to test the interaction.

Interactive control

5 × 5 risk matrix

Selected 12High
Likelihood →
Impact →
L LowM ModerateH HighC Critical
Capability map

Clear about depth. Serious about growth.

Technical AI risk knowledge is distinguished from established risk, compliance and delivery capabilities.

Risk & Governance

Established
Enterprise risk managementRCSARisk treatmentRisk registersControl monitoringPolicy development

Compliance & Assurance

Established
Internal controlsAudit preparationCompliance monitoringGap analysisIncident documentationRemediation planning

Cyber, Data & Third Parties

Established
NIST CSFISO 27001 / 27005PCI DSSGDPR / DPA 2018DPIAsVendor risk

AI Risk & Responsible AI

Developing specialism
AI risk assessmentHuman oversightAI governanceModel limitationsAI incident thinkingAI regulatory awareness

Leadership & Delivery

Established
Workshop facilitationStakeholder managementCross-functional workingPMO governanceTrainingProgramme controls

Risk Tooling

Documented in CV
ArcherOneTrustServiceNow GRCARMPredict@RISKPrimavera Risk Analysis
What I bring

Risk thinking built in complex, safety-conscious environments

AI systems increasingly influence people, privacy, safety, organisations, reputation, regulation and trust. Those consequences require more than a policy statement.

My perspective is grounded in making risk visible, facilitating challenge, assigning controls, monitoring effectiveness and helping accountable people make better decisions.

Experience across critical infrastructure, transport, finance, NHS change and engineering brings a practical understanding of regulated environments and operational consequences to the AI-governance conversation.

Insights

Thinking in public

An MDX-ready editorial area for practical analysis on AI risk, controls, assurance and responsible decisions.

Insights index
I-01Draft planned

From Enterprise Risk to AI Risk

What established risk disciplines contribute to responsible AI decisions.

I-02Draft planned

Human Oversight Is More Than a Checkbox

Designing oversight with authority, competence, time and escalation routes.

I-03Draft planned

Understanding the NIST AI Risk Management Framework

A practitioner’s guide to GOVERN, MAP, MEASURE and MANAGE.

I-04Draft planned

What Safety-Critical Industries Can Teach AI Governance

Learning from infrastructure, engineering and health-and-safety controls.

I-05Draft planned

AI Risk Registers: What Should Organisations Record?

A practical view of traceability, ownership, controls and residual risk.

I-06Draft planned

Third-Party AI Risk Beyond the Questionnaire

Testing evidence across data, models, security, continuity and incidents.

Start a conversation

Building safer, accountable AI systems requires good risk thinking.

Interested in AI Risk, Responsible AI, AI Governance, Technology Risk and AI Assurance opportunities.

ukenneth@hotmail.com United Kingdom LinkedIn URL to add

A hidden honeypot field is included. Add rate limiting and server-side validation in the selected form service before launch.