I evaluate high-risk AI systems against real regulatory and management frameworks — EU AI Act, NIST AI RMF, and ISO/IEC 42001 — and turn that analysis into practical, executive-ready governance decisions. Founder of Nexus Risk & AI Advisory.
Teams are shipping AI features and vendor models into production without knowing their real risk exposure — until a regulator, auditor, or customer complaint finds it first.
Most teams can't say whether their AI use case is high-risk under the EU AI Act, or what that would require.
Vendor AI tools get adopted without a risk register, a documented review, or an accountable owner.
AI tools get bought and left half-used — nobody has audited where they actually save time or money.
Framework-based AI governance reviews and efficiency audits that turn ambiguity into an evidence-backed decision.
Classify a system's risk level, run it against EU AI Act / NIST AI RMF / ISO 42001, and produce the risk register and decision memo a committee can act on.
Find out where AI tools are actually saving time and money in your workflows — and where spend isn't earning its keep.
Ongoing, part-time governance support for teams that need the function but aren't ready for a full-time hire.
The same process behind every case study on this site.
Define the AI use case and classify its risk level before anything else.
Run the system against EU AI Act, NIST AI RMF, and ISO/IEC 42001 requirements.
Risk register, vendor review, human oversight procedure — the artifacts a real review needs.
An executive-ready recommendation: approve, conditionally approve, delay, or reject.
Every review is mapped to EU AI Act, NIST AI RMF, and ISO/IEC 42001 — not vibes.
Risk registers and decision memos written for a governance committee, not a textbook.
Grounded in end-to-end case studies, not just policy summaries.
Client testimonials coming soon — until then, here's the work itself.
Led a high-risk AI governance assessment of an automated small-business loan underwriting system, covering fairness, explainability, human oversight, vendor risk, and production-readiness.
View Case Study →The Automated Loan Underwriting case study is an applied training exercise completed as part of an AI GRC practitioner program, using a simulated organization to demonstrate a full high-risk AI governance review end to end. Real client engagements are handled confidentially through Nexus Risk & AI Advisory.
Primarily the EU AI Act, NIST AI Risk Management Framework, and ISO/IEC 42001, applied to the specific regulatory context of the client's industry.
Both — I'm open to full-time AI governance/risk roles as well as fractional advisory and audit engagements through Nexus Risk & AI Advisory.
Book a free discovery call, or email me directly — both linked below.
Book a free discovery call, or reach out directly — I read every message.