Services

GovernGuard is an independent practice: one AI security architect with 25+ years in regulated environments, now working where AI governance frameworks meet production systems. Every piece of work covers the program that satisfies your regulators and the guardrails that satisfy your engineers.

Full background and credentials on the About page.

The work

Standing up and running the program

Working alongside security leaders who are establishing or operating an AI governance program. Framework selection and rollout (NIST AI RMF, ISO/IEC 42001), EU AI Act readiness, policy and control design, and someone to think through the AI decisions that can’t wait.

Finding out where the program actually stands

A fixed-scope review of your AI governance posture: where your program stands against the framework you’ve chosen (or need to choose), which controls exist only on paper, and a prioritized, engineering-aware remediation path. Written so it lands with your board and your builders.

Building the guardrails

Hands-on design and build of the controls themselves: LLM guardrails, evaluation harnesses, model risk controls, complete tool mediation, and the audit evidence that proves they run. The controls get built and handed over, so your team can operate them after I leave. For a working example, see the reference implementation on GitHub.

Running it from the inside

Interim or fractional ownership of your AI governance program, for organizations that need someone accountable for the outcome. I run the program from the inside: standing up the function, owning the framework roadmap and the control backlog, and handing a working program to its permanent owner when the time comes. Structured as a part-time embedded engagement or a longer-term contract.

How the work is structured: an ongoing retainer, a fixed-scope piece, an embedded part-time arrangement, or a longer-term contract, whichever fits the problem.

How it starts

Work starts with a conversation, not a contract. A short call to establish whether the problem is one I’m the right person for. If it is, I scope it in writing: objectives, deliverables, timeline, and what I need from your side. I work remote, independent, and hands-on.

Confidentiality is the default from the first conversation. Inquiry contents stay private, and I’ll sign an NDA before any deeper discussion if you prefer. Nothing from client work ever appears in the writing on this site.

Who this is for

The practice serves CISOs and security leaders at regulated enterprises and defense organizations. The work suits teams that need someone who can defend a control set to an auditor and then build it. If that’s the problem in front of you, start below.

Start an inquiry

Tell me what you’re weighing — a program, an assessment, or a build — through the contact form. I answer every serious inquiry personally.