Responsible AI Governance

Muhammed Sulaiman

Responsible AI Officer — AI Governance & Ethics, Risk & Compliance, Agile Transformation.

Based inLondon, UK
ClearanceSC Cleared
Experience9+ years, regulated environments
CurrentlyVirgin Media O2 — Platform Governance

A governance-minded transformation leader with 9+ years embedding structured, accountable, and human-centred delivery frameworks across complex, regulated environments — designing ethical oversight mechanisms, managing multi-stakeholder risk, and operationalising policy into practice. Now focused on shaping trustworthy, compliant, and ethical AI ecosystems.

40%
Risk reduction in claims processing time through automation governance
30%
Partner trust uplift via structured accountability frameworks
50%
Delivery velocity boost through transparent Agile governance
10%
Quality uplift via root-cause analysis cycles

Core Competencies

§ 01
AI Governance & Ethical Oversight Risk Management & Mitigation Regulatory Compliance — GDPR, ISO Policy Design & Implementation Responsible Technology Deployment Stakeholder Accountability Frameworks Cross-functional Team Leadership Digital & AI Transformation Identity & Access Management Privacy by Design & Security Oversight Audit & Continuous Improvement SAFe · Scrum · Kanban · PRINCE2

Professional Experience

§ 02
Mar 2024 —
Present
Senior Scrum Master — AI & Platform GovernanceVirgin Media O2
London

Governs the responsible and compliant delivery of partner-facing digital platforms — accountability structures, risk mitigation protocols, and continuous oversight across multi-stakeholder environments.

  • Architected a structured release governance cadence, reducing unplanned incidents and driving a 30% uplift in partner trust through transparent deployment accountability.
  • Instituted a daily risk triage and defect governance forum with partners, embedding a culture of proactive risk management.
  • Led structured root-cause analysis programmes following adverse events — a 50% reduction in systemic defects and a 10% rise in customer satisfaction.
  • Defined and enforced supplier accountability lines, with documented escalation pathways for ethical, on-time delivery.
Feb 2022 —
Mar 2024
Senior Scrum Master — Data Automation & Digital TransformationEsure
London

Governed AI-adjacent automation platforms in a heavily regulated insurance environment, applying structured risk controls and compliance checkpoints.

  • Governed the end-to-end rollout of the Esure Flex automation platform, reducing claims processing time by 40% within regulatory boundaries.
  • Orchestrated 5 mandatory system integrations for a Salesforce CRM implementation, applying technical governance and data integrity controls at each point.
  • Established ethical delivery standards and psychological safety protocols that improved team morale by 40%.
  • Directed quarterly PI Planning for 6+ Agile teams, accelerating delivery velocity by 50% and cutting project delays by 15%.
Jun 2021 —
Feb 2022
Scrum Master — Developer Platform & Privacy-by-DesignOutSystems
London

Governed delivery of a developer-facing Freemium platform, embedding privacy-by-design and security principles from discovery through production.

  • Ran Proof-of-Concept governance with Architecture and Security teams to validate privacy and security assumptions before build.
  • Embedded privacy-by-design into the product lifecycle as a non-negotiable design requirement, not an afterthought.
  • Managed multi-team dependency governance and data-contract alignment across PI iterations.
Aug 2018 —
May 2021
Scrum Master — Identity, Access & CompliancePrudential International Assurance
Dublin

Led delivery governance across two onsite and one remote team on a large-scale transformation focused on security, identity management, and regulatory compliance.

  • Partnered with the Security team to define and govern IAM requirements across the full user lifecycle.
  • Introduced SonarCloud code-quality governance, establishing measurable standards for test coverage and integrity.
  • Configured and automated the CI/CD pipeline with embedded compliance checkpoints.

Case Files — Governance Work

§ 03
Policy · Insurance Claims AI
WSF Insure — AI Governance Policy
Version1.0
Effective16 Jan 2026
ReviewAnnual
ApprovalExecutive Sponsor

An organisation-wide policy governing the design, deployment, and operation of AI systems used to automate or augment insurance claims processing — built to keep claims AI fair, explainable, accurate, secure, and compliant while protecting policyholders and regulatory trust.

Structured around the NIST AI Risk Management Framework:

GOVERNOversight, accountability, culture
MAPContext & use-case risk
MEASURERisk & performance assessment
MANAGEMitigation & monitoring

Scope covers every AI touchpoint in the claims journey:

  • Claim intake & triage
  • Fraud detection & flagging
  • Damage assessment & document analysis
  • Coverage determination support
  • Claim settlement recommendations
  • Claims-related customer communications

Applies to all employees, contractors, and third-party vendors involved in the programme, with defined governance structure, risk classification, and monitoring & audit cycles.

Operational Runbook · Confidential
AI Incident Response Playbook
Version1.0
StatusActive
OwnerAI Governance Lead
ReviewQuarterly

A structured runbook for detecting, classifying, escalating, and resolving incidents involving AI systems in production, active pilot, or third-party integration — covering models, incidents, and the data pipelines that feed them.

Every incident is classified against a four-tier severity model, which sets response timelines and notification paths:

LevelDescriptionResponseNotifies
SEV-1 · CriticalRisk of harm to individuals; major legal/regulatory breach; core system failureWithin 1 hourCEO, Legal, DPO, Board, Regulator
SEV-2 · HighSignificant bias/fairness violation; material data breach; partial system failureWithin 4 hoursAI Governance Lead, CISO, Legal
SEV-3 · MediumDegraded performance, unexplained model drift, unconfirmed privacy concernWithin 24 hoursAI Governance Lead, Product Owner
SEV-4 · LowMinor anomaly or near-miss, no confirmed harmWithin 5 business daysAI Governance team, incident register

Severity can be escalated at any time on new information; downgrading requires sign-off from the AI Governance Lead.

Responsible AI Impact Assessment · HR Tech
AI Resume Checker
TeamTalent Acquisition Tech
StageDeployed, Jan 2026
ReviewersHR, Legal, DPO, DEI, Eng

An internal tool that evaluates applicant CVs for relevance, skills match, and experience alignment, giving recruiters structured screening insights. The assessment mapped its impact before deployment across three lenses:

Fairness watch

Non-native speakers, older and career-break applicants

Fairness watch

Women, ethnic minorities, disabled applicants

Fairness watch

All demographic groups — monitored continuously

Guardrail: not authorised for sole rejection decisions or protected-characteristic inference. Human approval is required before any screening decision is finalised.

Credentials & Toolkit

§ 04

Education & Certifications

SAFe Advanced Scrum MasterScaled Agile
2020
Professional Scrum Master (PSM1)Scrum.org
2018
PRINCE2 PractitionerAXELOS
2015
MSc, Oil & Gas ManagementPlymouth University
2014

Governance & Compliance Tools

JIRAAzure DevOpsConfluencePower BIMiroMural

Technology & Architecture

AWSCloud ArchitectureMicroservicesIAMCI/CDSonarCloud

Frameworks & Methodologies

Agile ScrumKanbanSAFePRINCE2DevOpsPrivacy by Design

Get in Touch

§ 05

Open to Responsible AI, AI Governance, and AI Risk & Compliance roles — bringing 9+ years of regulated-environment delivery and hands-on NIST-aligned governance work to the table.

SC
CLEARED
LONDON