Skip to content
View ai-data-doc's full-sized avatar

Block or report ai-data-doc

Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
ai-data-doc/README.md

Hi, I'm the AI-Data-Doc

AI governance · GRC engineering · incident response. I make governance, risk, and compliance executable — including for AI systems — through controls as code, automated evidence, and continuous monitoring, and I lead the incidents when those controls are tested for real.

17 years across GovTech, international healthcare, critical infrastructure, and US federal / state / local government — environments where the audit burden is heaviest, AI assurance is becoming mandatory, and the cost of getting it wrong is real.


Front and center: securing and governing AI systems

I build and audit AI management systems to ISO/IEC 42001 — the certifiable standard for governing how AI is developed, deployed, and operated safely. I pair it with the NIST AI Risk Management Framework and ISO/IEC 23894 to give regulated organizations a defensible answer to the question every board and auditor is now asking: how do you know your AI is secure, accountable, and under control?

ISO/IEC 42001 Lead [Implementer / Auditor] — [credential ref / year]

This is the rare convergence I lead with: someone who can write the AI control, map it to the frameworks, automate its evidence, and respond when an AI-driven system is part of an incident.

What I do

AI governance & assurance

  • ISO/IEC 42001 AI management systems — establishing, implementing, and auditing AIMS for secure AI development and deployment.
  • AI risk management — NIST AI RMF and ISO/IEC 23894 applied to real model and system risk, not checkbox theater.
  • AI controls as code — extending compliance-as-code to AI-specific controls (data governance, model lifecycle, transparency, human oversight).

GRC engineering

  • Compliance-as-code — control mapping and crosswalks across frameworks; policy-as-code; OSCAL-based control catalogs and SSP components.
  • Evidence automation & continuous control monitoring — pipelines that collect, timestamp, and store control evidence so audits stop being fire drills.
  • Risk quantification & tooling — turning qualitative risk into something measurable, and wiring GRC platforms into the systems that hold the data.

Incident response

  • I lead incidents end-to-end — detection through containment, eradication, recovery, lessons-learned — including incidents involving AI-enabled systems — and feed what I learn back into the control set.

How I work

I think in process, controls, and decisions — not product logos. I'm fluent in automation and build it where it counts (Python / IaC); for heavier engineering I architect and direct. Most of what's here is deliberately vendor- and framework-neutral so it ports across stacks.

Frameworks: ISO/IEC 42001 · NIST AI RMF · ISO/IEC 23894 · NIST 800-53 / 800-171 / 800-61 · OSCAL · MITRE ATT&CK · ISO/IEC 27001 · CSF Regimes: FedRAMP · CMMC · StateRAMP · HIPAA / HITRUST · CISA ConMon


Pinned work

Repo What it shows
🤖 ai-management-system ISO/IEC 42001 + NIST AI RMF controls as code — securing AI development end-to-end
🏗️ controls-as-code Framework crosswalks, OSCAL control components, policy-as-code — GRC that executes
📊 evidence-automation Continuous control monitoring: collect → timestamp → store control evidence on a schedule
🧭 emerging-threat-triage Tool-agnostic IR framework — advisory to action, branch logic, NIST-phase mapping
📑 incident-case-studies Sanitized, method-focused postmortems — how I scope, contain, and decide

A note on what's here

Everything in these repositories is original or sanitized. Nothing reflects confidential details of any employer, client, or engagement — environments are generalized, indicators are synthetic, evidence samples are mock. That discipline is the same standard I bring to handling regulated and AI-governance material as a practicioner.

Popular repositories Loading

  1. controls-as-code controls-as-code Public

    Multi-framework security controls as code — one source of truth crosswalked to NIST 800-53, CSF, ISO 27001/42001, CMMC, with OSCAL output, OPA policy tests, and CI.

    PowerShell 1

  2. ai-management-system ai-management-system Public

    AI Management System (ISO/IEC 42001) as code — AI controls crosswalked to NIST AI RMF and ISO 23894, lifecycle-tagged, with an AI risk register and CI validation.

    Python 1 2

  3. ai-data-doc ai-data-doc Public