Home

Insights

Risk, governance, and technology resilience.

Longer essays on second-line thinking — applied AI governance, data governance, cyber risk, and regulated-business judgement, each drawn from work I have actually owned and built.

5 June 2026/9 min read

Governance as Code: When the Rulebook Can Enforce Itself

Most governance lives in documents nobody can execute. The shift that matters — and the one agentic AI now forces — is codifying policy so classification, retention, lineage, and access are enforced by the system at every layer, not asserted in a PDF.

Read article
3 June 2026/6 min read

Agentic Development Governance: Shipping Fast Without Shipping Risk

I built the governance layer I would want to sign off on as a risk owner — deny-by-default guardrails, an append-only audit trail, and AI-security evals mapped to the OWASP LLM Top 10 and NIST AI-RMF — and put it on GitHub.

Read article
1 June 2026/7 min read

Bord.Room: Designing Governance Into a Hospitality Platform From the First Line

Most hospitality software leaves the hard part — governance — to spreadsheets and memory. Bord.Room treats tenant isolation, data governance, and a contemporaneous compliance record as architecture — now in pre-production with a single pilot tenant, on a build designed for secure multi-tenant operation from the start.

Read article
1 May 2026/4 min read

Standing Up Data Governance: Tooling, Records, and the PMO Discipline to Make It Stick

Most organisations don't have a data problem; they have a governance-of-data problem. At Auto & General I work the gap with requirements-led tooling selection, a working OpenMetadata POC, records control, and PMO discipline.

Read article
1 December 2025/3 min read

Owning the Risk: What Running a Brokerage Teaches You About Financial and Privacy Obligations

There is a meaningful difference between advising on risk and carrying it. As the accountable Principal of a mortgage brokerage, I owned NCCP, Best Interests Duty, Privacy Act, and AML obligations under real consequences.

Read article
15 January 2025/3 min read

Buying a Business: Due Diligence and Integration on the SME Scale

M&A sounds like a big-end-of-town discipline. At the SME scale you are the entire deal team, and every diligence gap is a personal liability. Acquiring Prova Pizzeria taught me cross-domain risk from the inside.

Read article
1 November 2024/4 min read

From ISM Control to Vendor Decision: Translating Cyber Risk for People Who Sign the Cheque

A security control framework is only as good as a senior leader's ability to act on it. At the Queensland Police Service, my work turned the ISM from a compliance document into a basis for IAM/PAM investment and procurement decisions.

Read article