Secure, governed AI
for regulated industries.
We help healthcare, financial-services, and enterprise clients build, deploy, and govern AI responsibly โ so innovation ships without betting the company on it.
Scott Baker
12+ years in enterprise security, compliance, and cloud architecture across regulated industries โ including HITRUST certification and HIPAA compliance in healthcare. He applies NIST AI RMF, ISO 42001, and the EU AI Act so client AI stays secure, auditable, and compliant.
Every day I do the real work of an AI Governance Officer and study for the IAPP AIGP exam: I train models (locally on GPU and on GCP/Vertex), then govern them end to end โ impact assessments, data provenance, bias & fairness testing, model cards, drift monitoring, incident response โ publishing every artifact, each mapped to NIST AI RMF, ISO 42001, and the EU AI Act. Real technical stack: Python/PyTorch, AWS & GCP, BigQuery, Vertex AI, IAM, VPC-SC, CMEK, DLP.
Governance, not just compliance. I keep a human in the middle of every AI decision โ a model drafts and cites, but a person decides, owns, and signs. At CIOX Health the security & privacy policies were copy-pasted boilerplate; I rewrote them to be real โ aligned to the company's mission, values, and regulatory obligations (HIPAA, HITRUST). I bring that same ownership to what AI can't own: remediating the technical architecture, authoring the policy, and standing behind the audit response.
I orchestrate AI to move fast โ without cutting corners. I use retrieval-grounded AI to draft artifacts, map controls, and flag gaps โ cited to source, never guessing โ while a human stays accountable at every gate. I stand up the working pieces of a governance program: AI inventory, controls, artifacts, monitoring, and audit-ready evidence.
The value to your team: one person who bridges hard engineering and executive risk โ who helps AI ship and keeps it compliant, auditable, and safe.
The result: I put AIGP, NIST AI RMF, ISO 42001, and the EU AI Act into practice โ turning frameworks into running, audit-ready governance that produces evidence, not binders. Hire me and you get a governance function that executes.
Let's talk.
If you'd like to hire me โ or just have questions โ please reach out.
Governance that keeps pace with the models.
Practical, evidence-producing controls across the full AI lifecycle โ not a binder that sits on a shelf.
AI Governance Programs
Stand up policies, roles, and an AI governance committee mapped to NIST AI RMF and ISO 42001 โ sized to your maturity and risk tolerance.
Risk & Impact Assessments
Model impact assessments, risk classification (incl. EU AI Act tiers), bias and safety testing, and a documented risk register.
Responsible Deployment
Pre-deployment reviews, vendor & open-source model due diligence, model cards, human-oversight design, and go/no-go decisions.
Data Governance & Privacy
Lawful-basis and provenance reviews, PII/PHI controls, data-minimization, and privacy-by-design for training and inference.
Continuous oversight, not a one-time audit.
Because a model that passed review last quarter can drift into a liability this one.
Map
Use case, context, applicable law, and stakeholders โ before a line of code.
Measure
Impact assessment, bias/robustness testing, and risk scoring against agreed thresholds.
Manage
Controls, model cards, human oversight, and vendor terms red-lined and flowed down.
Monitor
Continuous monitoring, incident response, red-teaming, retraining โ and a documented kill switch.
Built for the industries where getting AI wrong is expensive.
Healthcare
Clinical decision support and patient-facing GenAI under HIPAA/HITRUST, with human oversight where it counts.
Financial Services
Credit and underwriting models with fair-lending (ECOA/FCRA) and high-risk governance built in.
Retail & E-commerce
GenAI support and recommendation systems with transparency, disclosure, and vendor-LLM risk managed.
Enterprise & HR
Hiring and screening AI aligned to Title VII and EU AI Act high-risk obligations.
A specialist bench for governed AI.
We keep the team small and senior โ the people who own the outcome are the people in the room.
Scott Baker
AI governance, cloud security, and healthcare compliance.
Marisol Vega
Two decades leading regulated-industry technology and professional-services delivery.
Anika Rao
ML platforms and MLOps at scale; makes governance enforceable in the pipeline, not just on paper.
Marcus Bell
Privacy counsel and GRC leader; keeps engagements aligned to GDPR, HIPAA, and the EU AI Act.