AI Governance ยท Risk ยท Compliance

Secure, governed AI
for regulated industries.

We help healthcare, financial-services, and enterprise clients build, deploy, and govern AI responsibly โ€” so innovation ships without betting the company on it.

NIST AI RMF 1.0ISO/IEC 42001ISO/IEC 42005 EU AI ActHIPAA / HITRUSTSOC 2NIST CSF 2.0
Scott Baker

Scott Baker

Owner, Founder & Chief AI Officer

12+ years in enterprise security, compliance, and cloud architecture across regulated industries โ€” including HITRUST certification and HIPAA compliance in healthcare. He applies NIST AI RMF, ISO 42001, and the EU AI Act so client AI stays secure, auditable, and compliant.

Every day I do the real work of an AI Governance Officer and study for the IAPP AIGP exam: I train models (locally on GPU and on GCP/Vertex), then govern them end to end โ€” impact assessments, data provenance, bias & fairness testing, model cards, drift monitoring, incident response โ€” publishing every artifact, each mapped to NIST AI RMF, ISO 42001, and the EU AI Act. Real technical stack: Python/PyTorch, AWS & GCP, BigQuery, Vertex AI, IAM, VPC-SC, CMEK, DLP.

Governance, not just compliance. I keep a human in the middle of every AI decision โ€” a model drafts and cites, but a person decides, owns, and signs. At CIOX Health the security & privacy policies were copy-pasted boilerplate; I rewrote them to be real โ€” aligned to the company's mission, values, and regulatory obligations (HIPAA, HITRUST). I bring that same ownership to what AI can't own: remediating the technical architecture, authoring the policy, and standing behind the audit response.

I orchestrate AI to move fast โ€” without cutting corners. I use retrieval-grounded AI to draft artifacts, map controls, and flag gaps โ€” cited to source, never guessing โ€” while a human stays accountable at every gate. I stand up the working pieces of a governance program: AI inventory, controls, artifacts, monitoring, and audit-ready evidence.

The value to your team: one person who bridges hard engineering and executive risk โ€” who helps AI ship and keeps it compliant, auditable, and safe.

The result: I put AIGP, NIST AI RMF, ISO 42001, and the EU AI Act into practice โ€” turning frameworks into running, audit-ready governance that produces evidence, not binders. Hire me and you get a governance function that executes.

Contact

Let's talk.

If you'd like to hire me โ€” or just have questions โ€” please reach out.

What we do

Governance that keeps pace with the models.

Practical, evidence-producing controls across the full AI lifecycle โ€” not a binder that sits on a shelf.

๐Ÿงญ

AI Governance Programs

Stand up policies, roles, and an AI governance committee mapped to NIST AI RMF and ISO 42001 โ€” sized to your maturity and risk tolerance.

๐Ÿ“‹

Risk & Impact Assessments

Model impact assessments, risk classification (incl. EU AI Act tiers), bias and safety testing, and a documented risk register.

๐Ÿš€

Responsible Deployment

Pre-deployment reviews, vendor & open-source model due diligence, model cards, human-oversight design, and go/no-go decisions.

๐Ÿ”’

Data Governance & Privacy

Lawful-basis and provenance reviews, PII/PHI controls, data-minimization, and privacy-by-design for training and inference.

How we work

Continuous oversight, not a one-time audit.

Because a model that passed review last quarter can drift into a liability this one.

โ‘ 

Map

Use case, context, applicable law, and stakeholders โ€” before a line of code.

โ‘ก

Measure

Impact assessment, bias/robustness testing, and risk scoring against agreed thresholds.

โ‘ข

Manage

Controls, model cards, human oversight, and vendor terms red-lined and flowed down.

โ‘ฃ

Monitor

Continuous monitoring, incident response, red-teaming, retraining โ€” and a documented kill switch.

Who we serve

Built for the industries where getting AI wrong is expensive.

๐Ÿฅ

Healthcare

Clinical decision support and patient-facing GenAI under HIPAA/HITRUST, with human oversight where it counts.

๐Ÿ’ณ

Financial Services

Credit and underwriting models with fair-lending (ECOA/FCRA) and high-risk governance built in.

๐Ÿ›’

Retail & E-commerce

GenAI support and recommendation systems with transparency, disclosure, and vendor-LLM risk managed.

๐Ÿง‘โ€๐Ÿ’ผ

Enterprise & HR

Hiring and screening AI aligned to Title VII and EU AI Act high-risk obligations.

About us

A specialist bench for governed AI.

We keep the team small and senior โ€” the people who own the outcome are the people in the room.

Scott Baker

Scott Baker

Founder & Chief AI Officer

AI governance, cloud security, and healthcare compliance.

MV

Marisol Vega

Chief Executive Officer

Two decades leading regulated-industry technology and professional-services delivery.

AR

Anika Rao

Chief Technology Officer

ML platforms and MLOps at scale; makes governance enforceable in the pipeline, not just on paper.

MB

Marcus Bell

Chief Privacy & Compliance Officer

Privacy counsel and GRC leader; keeps engagements aligned to GDPR, HIPAA, and the EU AI Act.