Responsible AI Governance

Muhammed Sulaiman

Responsible AI Officer — AI Governance & Ethics, Risk & Compliance, Agile Transformation.

NIST AI RMF ISO 42001 EU AI Act SC Cleared
Based inLondon, UK
ClearanceSC Cleared
Experience9+ years, regulated environments
CurrentlyVirgin Media O2 · Indigomark

Governance and delivery leader with 9+ years operationalising policy, risk, and compliance controls in regulated environments across insurance, telecoms, and financial services. Track record of embedding accountability into technology delivery: IAM across the user lifecycle, privacy-by-design in the product lifecycle, and compliance checkpoints in CI/CD. Now specialising in AI governance, applying NIST AI RMF, ISO 42001, and the EU AI Act through hands-on practicum work.

Headshot
184 × 230
40%
Risk reduction in claims processing time through automation governance
30%
Partner trust uplift via structured accountability frameworks
50%
Delivery velocity boost through transparent Agile governance
10%
Quality uplift via root-cause analysis cycles

About

§ 01

Nine years of delivery leadership across insurance, telecoms, and financial services taught me the same lesson from three different regulatory angles: governance only works when it's built into delivery, not bolted on afterward. IAM across the full user lifecycle, privacy-by-design in the product cycle, compliance checkpoints in CI/CD — the pattern repeats because accountable technology delivery and responsible AI delivery are the same discipline.

That's the lens I now bring to AI governance specifically — applying the NIST AI Risk Management Framework, ISO 42001, and the EU AI Act to real systems, not hypothetical ones. Current work spans an AI tool inventory and third-party risk programme at Virgin Media O2, and a client-style AI governance engagement at Indigomark covering policy drafting, tool evaluation, and incident workflows mapped to US and EU regulation.

Applied practicum

Trained through the AI Governance Academy's Applied AI Governance Portfolio — hands-on work translating NIST AI RMF, ISO 42001, and EU AI Act requirements into the governance policy, incident playbook, and impact assessment featured under Portfolio below.

Core Competencies

§ 02

AI Governance & Risk

NIST AI RMFISO 42001EU AI Act AI & Third-Party Risk AssessmentPolicy Design & Implementation Incident & Audit WorkflowsAI Risk/Control Frameworks

Regulatory & Compliance

UK GDPRISOPrivacy by Design Security OversightIAM

Technology & Architecture

AWSCloud ArchitectureMicroservices IAMCI/CD PipelinesSonarCloud

Delivery & Transformation

Agile ScrumKanbanSAFePRINCE2 DevOpsXPSDLC Stakeholder AccountabilityCross-functional Leadership

Governance Tools

OneTrustServiceNow GRC Microsoft PurviewIBM Watsonx.governance

Professional Experience

§ 03
Nov 2025 —
Present
Applied AI Governance — Technology RolesIndigomark
London

Applied AI governance frameworks to a client-style engagement, owning the deliverable lifecycle from kickoff to final delivery across six sprints.

  • Performed an AI tool inventory and third-party risk assessment, identifying high-risk usage patterns including PII entered into public LLMs and unverified health claims in marketing copy.
  • Drafted an AI Governance Policy, Acceptable Use Policy, Tool Evaluation Checklist, and Incident Report workflow, mapping controls across the EU AI Act and US sector regulations (HIPAA, FTC, FDA, EEOC/Title VII).
Mar 2024 —
Present
Delivery Manager — AI & Platform GovernanceVirgin Media O2
London

Leads partner-facing digital platform delivery, ensuring accountability, risk mitigation, and oversight across multi-stakeholder settings.

  • Performed an AI tool inventory and third-party risk assessment, identifying high-risk usage patterns — PII entered into public LLMs, unverified health claims in marketing copy — and recommending tiered mitigations.
  • Architected a structured release governance cadence, reducing unplanned incidents and driving a 30% uplift in partner trust through transparent deployment accountability.
  • Instituted a daily risk triage and defect governance forum with partners, embedding a culture of proactive risk management.
  • Led structured root-cause analysis programmes following adverse events — a 50% reduction in systemic defects and a 10% rise in customer satisfaction.
Feb 2022 —
Mar 2024
Senior Scrum Master — Data Automation & Digital TransformationEsure
London

Led ethical digital transformation in claims fulfilment and data automation, overseeing AI-adjacent platform delivery in a regulated insurance environment.

  • Governed the end-to-end rollout of the Esure Flex automation platform, reducing claims processing time by 40% within regulatory boundaries.
  • Orchestrated 5 mandatory system integrations for a Salesforce CRM implementation, applying technical governance and data integrity controls at each point.
  • Established ethical delivery standards and psychological safety protocols that improved team morale by 40%.
  • Implemented Agile governance practices that accelerated team velocity by 50% and cut project delays by 15% within 6 months.
Jun 2021 —
Feb 2022
Scrum Master — Developer Platform & Privacy-by-DesignOutSystems
London

Led privacy-focused Freemium platform delivery, ensuring security and compliance throughout the product lifecycle.

  • Validated privacy and security assumptions through Proof-of-Concept governance with Architecture and Security teams, improving compliance and delivery efficiency.
  • Led risk scoring with executives, translating technical findings into business recommendations that cut liability and enhanced competitiveness.
  • Guided Product Owners on ethical backlog prioritisation, aligning features to both user and organisational needs.
  • Managed multi-team dependency governance and data-contract alignment across PI iterations.
Aug 2018 —
May 2021
Scrum Master — Identity, Access & CompliancePrudential International Assurance
Dublin

Led delivery governance across two onsite and one remote team on a large-scale transformation focused on security, identity management, and regulatory compliance.

  • Partnered with the Security team to define and govern IAM requirements across the full user lifecycle.
  • Introduced SonarCloud code-quality governance, establishing measurable standards for test coverage and integrity.
  • Configured and automated the CI/CD pipeline with embedded compliance checkpoints.

Portfolio — Governance Case Files

§ 04

Selected governance artefacts built through applied practicum work, demonstrating end-to-end policy, risk, and incident-response capability.

Policy · Insurance Claims AI
WSF Insure — AI Governance Policy
Version1.0
Effective16 Jan 2026
ReviewAnnual
ApprovalExecutive Sponsor

An organisation-wide policy governing the design, deployment, and operation of AI systems used to automate or augment insurance claims processing — built to keep claims AI fair, explainable, accurate, secure, and compliant while protecting policyholders and regulatory trust.

Structured around the NIST AI Risk Management Framework:

GOVERNOversight, accountability, culture
MAPContext & use-case risk
MEASURERisk & performance assessment
MANAGEMitigation & monitoring

Scope covers every AI touchpoint in the claims journey:

  • Claim intake & triage
  • Fraud detection & flagging
  • Damage assessment & document analysis
  • Coverage determination support
  • Claim settlement recommendations
  • Claims-related customer communications

Applies to all employees, contractors, and third-party vendors involved in the programme, with defined governance structure, risk classification, and monitoring & audit cycles.

Operational Runbook · Confidential
AI Incident Response Playbook
Version1.0
StatusActive
OwnerAI Governance Lead
ReviewQuarterly

A structured runbook for detecting, classifying, escalating, and resolving incidents involving AI systems in production, active pilot, or third-party integration — covering models, incidents, and the data pipelines that feed them.

Every incident is classified against a four-tier severity model, which sets response timelines and notification paths:

LevelDescriptionResponseNotifies
SEV-1 · CriticalRisk of harm to individuals; major legal/regulatory breach; core system failureWithin 1 hourCEO, Legal, DPO, Board, Regulator
SEV-2 · HighSignificant bias/fairness violation; material data breach; partial system failureWithin 4 hoursAI Governance Lead, CISO, Legal
SEV-3 · MediumDegraded performance, unexplained model drift, unconfirmed privacy concernWithin 24 hoursAI Governance Lead, Product Owner
SEV-4 · LowMinor anomaly or near-miss, no confirmed harmWithin 5 business daysAI Governance team, incident register

Severity can be escalated at any time on new information; downgrading requires sign-off from the AI Governance Lead.

Responsible AI Impact Assessment · HR Tech
AI Resume Checker
TeamTalent Acquisition Tech
StageDeployed, Jan 2026
ReviewersHR, Legal, DPO, DEI, Eng

An internal tool that evaluates applicant CVs for relevance, skills match, and experience alignment, giving recruiters structured screening insights. The assessment mapped its impact before deployment across three lenses:

Fairness watch

Non-native speakers, older and career-break applicants

Fairness watch

Women, ethnic minorities, disabled applicants

Fairness watch

All demographic groups — monitored continuously

Guardrail: not authorised for sole rejection decisions or protected-characteristic inference. Human approval is required before any screening decision is finalised.

Credentials & Training

§ 05
AI Governance Academy

Applied AI Governance Portfolio — hands-on practicum applying NIST AI RMF, ISO 42001, and the EU AI Act to real governance artefacts.

Portfolio Graduate
SAFe Advanced Scrum MasterScaled Agile
2020
Professional Scrum Master (PSM1)Scrum.org
2018
PRINCE2 PractitionerAXELOS
2015
MSc, Oil & Gas ManagementPlymouth University
2014

Get in Touch

§ 06

Open to Responsible AI, AI Governance, and AI Risk & Compliance roles — bringing 9+ years of regulated-environment delivery and hands-on NIST AI RMF, ISO 42001, and EU AI Act practicum work to the table.

SC
CLEARED
LONDON