CAIRNCYBER ADVISORY

Work

Establishing AI security governance at a global asset manager

Sector
Asset management
Scale
Institutional scale, UK-regulated

Situation

The business was moving quickly on generative AI, and demand was arriving faster than any existing assurance route could deal with it. That was not unusual at the time. Nobody had really settled what secure adoption looked like for this kind of technology, so there was nothing meaningful to hold a new system against.

Constraints

A regulated environment with firm governance expectations. Several stakeholder groups with fair and competing interests across risk, legal, data privacy and technology. And a business that was not prepared to wait.

Approach

I led the development of an AI security standard covering model governance, data handling across environments, acceptable use and vendor onboarding.

Alongside it I introduced gateway controls, so that governance applied early and at a point where it could actually be enforced. We scoped those from the start to cover agentic systems as well as generative ones, because the move in that direction was already visible.

A good deal of the work was with legal, data privacy and business owners, getting the data storage and protection requirements clear enough that delivery teams were not left interpreting them one by one.

Outcome

The firm ended up with a standard it could apply to real systems, and a control point able to enforce it, both in place before the main wave of adoption arrived.

Frameworks: NIST AI RMF · OWASP Top 10 for LLMs · ISO 42001 · NIST CSF

Discuss similar work →

Start a conversation

Send an outline of the problem and the timescale. I reply to every enquiry that is a plausible fit, usually within one working day.