AI Feature Launch Gate (Interactive)
An interactive launch-gate that walks an AI feature through the safety, governance, and readiness checks required before it ships.
A working portfolio of interactive tools, governance frameworks, registers, and playbooks — the practical instruments for building, assuring, and overseeing AI you can trust.
Each hub collects the tools and documents for one domain. AI Governance is fully populated; Cybersecurity and Data Privacy are growing.
Dr. Vianney C. helps organizations adopt AI at enterprise scale without losing control of security, privacy, compliance, or trust. She has led global cybersecurity, AI governance, and data privacy programs across multinational organizations, designing the operating models, governance frameworks, and executive decision making processes that enable innovation while reducing risk.
Filter by theme, or open a hub to browse by collection.
An interactive launch-gate that walks an AI feature through the safety, governance, and readiness checks required before it ships.
A browsable library of tooling mapped across the AI lifecycle — data, build, evaluation, deployment, and monitoring — so teams can see what to use at each stage.
An interactive explorer that maps AI use cases to the tooling, controls, and governance guardrails each one needs — from selection through deployment.
A structured, standards-aligned method for identifying assets, threats, and vulnerabilities, then rating each risk by likelihood and impact. Risk levels calculate automatically using the NIST SP 800-30 model.
A complete controls audit covering all 18 CIS Critical Security Controls v8.1 — 153 safeguards — cross-mapped to NIST CSF 2.0 and ISO/IEC 27001:2022. Score implementation and filter by Implementation Group to scope to your maturity.
Assess and mature a zero-trust architecture across the five CISA pillars — identity, devices, networks, applications and workloads, and data — plus cross-cutting capabilities. Aligned to NIST SP 800-207 and the CISA Zero Trust Maturity Model 2.0.
A comprehensive assurance checklist for auditing AI systems against governance, safety, and control expectations.
The playbook behind the launch gate: the criteria, roles, and decision flow for approving an AI feature to go live.
A tracking workbook to run features through the launch gate — capturing checks, owners, decisions, and sign-off status.
A launch-gate workbook that checks an AI feature against both safety and data-privacy requirements before release — the privacy crossover of the launch-gate series.
An end-to-end AI governance playbook tailored to a financial institution's regulatory, risk, and model-governance context.
A reusable master template for building an organization's AI governance playbook — adapt the sections to your own context.
A reusable register for logging, scoring, and tracking AI risks with owners, mitigations, and residual-risk ratings.
A step-by-step guide to setting up and running the AI Risk Register: fields, scoring, ownership, and review cadence.
✦ Supplied with AI Risk Register
A white paper on why and how to run an AI risk register, and how it fits into a broader responsible-AI program.
✦ Supplied with AI Risk Register
A study guide covering the major AI standards and frameworks — a reference for practitioners preparing for governance and assurance work.
Embed security across the software lifecycle — requirements, threat modeling, secure implementation, testing, release, CI/CD, and AI/LLM applications. Aligned to OWASP ASVS 5.0, the OWASP Top 10:2025, and SAMM.
Build organizational resilience — a continuity program, business impact analysis, recovery strategy and backups, continuity and DR plans, testing and exercises, and plan maintenance. Aligned to ISO 22301 and NIST SP 800-34.
Assess and harden cloud posture across nine control areas — shared responsibility, identity, data, network, logging, workloads, secrets, and cloud incident response. Aligned to CSA CCM v4.1, CIS Foundations Benchmarks, and provider best practice.
Govern cryptography end to end — approved algorithms, the key-management lifecycle, PKI and certificate management, transport security, post-quantum readiness, and crypto governance. Aligned to NIST SP 800-57, FIPS 186-5, and the 2024 post-quantum standards.
Quantify the business consequences of a cyber incident across five impact dimensions, set recovery objectives (RTO/RPO/MTD), and tier each process by criticality. Ratings follow the worst-case rule and feed directly into continuity and recovery planning.
A structured model for assessing the potential impact of emerging AI capabilities, with a companion write-up explaining how to apply it.
A review template for assessing organizational readiness to handle emerging AI capabilities and the risks they introduce.
A toolkit for running structured external-expert consultations and workshops — planning, facilitation, and capturing findings.
A working model for quantifying the cost, benefit, and return on investment of AI initiatives across a financial-crimes program.
A practical playbook for making financial-crimes AI models explainable and auditable to regulators, model-risk teams, and internal audit.
A governance framework defining roles, controls, and review gates for AI models used across anti-financial-crime functions.
A ready-to-use workbook of model inventory, controls, and review tracking to operationalize governance for financial-crimes AI models.
A structured roadmap for scoring and sequencing financial-crimes AI use cases by value, feasibility, and risk.
A crosswalk mapping model policies to safety-review requirements, so teams can see how each policy is evidenced during review.
Practical, standards-aligned hardening across eight domains — architecture, firewalls, remote access, wireless, device hardening, monitoring, and access control. Each domain pairs best-practice guidance with a step-by-step how-to and a trackable checklist.
A strategy pitch for applying AI responsibly across Nigeria's oil & gas sector — opportunities, value, and the governance to make it safe.
A catalog of high-value AI use cases across the oil & gas value chain, with the governance considerations for each.
Secure operational technology, industrial control systems, and IoT — segmentation and the Purdue model, IEC 62443 zones and conduits, secure remote access, OT-aware patching and monitoring, safety systems, and IoT device hardening.
Operate a defensible privacy program — governance and Privacy by Design, data mapping and ROPA, lawful basis and consent, data-subject rights and DSAR handling, DPIAs, cross-border transfers, vendors, and breach response. Aligned to GDPR and CCPA/CPRA.
A register for monitoring the real-world impact of deployed AI — capturing incidents, harms, benefits, and follow-up actions over time.
A ready-to-present briefing pack for a Responsible AI Council: mandate, agenda, decision rights, and standing reporting.
Build a threat-informed defense — the intelligence lifecycle and tiers, MITRE ATT&CK, Kill Chain and Diamond models, STIX/TAXII sharing, structured threat modeling with STRIDE and PASTA, and operationalizing intelligence into detection and hunting.