5 June 2026/9 min read
Governance as Code: When the Rulebook Can Enforce Itself
Most governance lives in documents nobody can execute. The shift that matters — and the one agentic AI now forces — is codifying policy so classification, retention, lineage, and access are enforced by the system at every layer, not asserted in a PDF.
Read article/3 June 2026/6 min read
Agentic Development Governance: Shipping Fast Without Shipping Risk
I built the governance layer I would want to sign off on as a risk owner — deny-by-default guardrails, an append-only audit trail, and AI-security evals mapped to the OWASP LLM Top 10 and NIST AI-RMF — and put it on GitHub.
Read article/1 June 2026/7 min read
Bord.Room: Designing Governance Into a Hospitality Platform From the First Line
Most hospitality software leaves the hard part — governance — to spreadsheets and memory. Bord.Room treats tenant isolation, data governance, and a contemporaneous compliance record as architecture — now in pre-production with a single pilot tenant, on a build designed for secure multi-tenant operation from the start.
Read article/1 May 2026/4 min read
Standing Up Data Governance: Tooling, Records, and the PMO Discipline to Make It Stick
Most organisations don't have a data problem; they have a governance-of-data problem. At Auto & General I work the gap with requirements-led tooling selection, a working OpenMetadata POC, records control, and PMO discipline.
Read article/1 December 2025/3 min read
Owning the Risk: What Running a Brokerage Teaches You About Financial and Privacy Obligations
There is a meaningful difference between advising on risk and carrying it. As the accountable Principal of a mortgage brokerage, I owned NCCP, Best Interests Duty, Privacy Act, and AML obligations under real consequences.
Read article/15 January 2025/3 min read
Buying a Business: Due Diligence and Integration on the SME Scale
M&A sounds like a big-end-of-town discipline. At the SME scale you are the entire deal team, and every diligence gap is a personal liability. Acquiring Prova Pizzeria taught me cross-domain risk from the inside.
Read article/1 November 2024/4 min read
From ISM Control to Vendor Decision: Translating Cyber Risk for People Who Sign the Cheque
A security control framework is only as good as a senior leader's ability to act on it. At the Queensland Police Service, my work turned the ISM from a compliance document into a basis for IAM/PAM investment and procurement decisions.
Read article/