PMP — Project Management Professional badge
Project Management ProfessionalPMP · PMI · active
Digital Marketing Institute
Certified Digital Marketing ProfessionalDigital Marketing Institute
Red & Yellow Creative School of Business
Media ManagementRed & Yellow Creative School of Business

Click any image to enlarge.

ai riskly · governance dashboard
AI Riskly dashboard — governance posture with 4 systems tracked, a Register → Classify → Risk → Controls → Documents loop, EU AI Act classification tiers and a risk-posture breakdown.
AI Riskly AI System Registry — a catalog of AI use-cases with risk tiers, lifecycle and model-type filters, and CSV/XLSX export.

Flagship · Risk-assessment tool Building now

AI Riskly — the governance loop in one app

A working web app for AI-governance practitioners — and my flagship portfolio artifact. It runs the full loop the frameworks demand: register every AI use-case → classify its risk → route proportionate controls → collect evidence → generate the required documents. Regulatory rules ship as versioned data, so deadlines and tiers can be updated without touching code.

What it does:

  • AI system registry — a central catalog of every use-case with owner, provenance, lifecycle and risk tier.
  • Risk classification engine — questionnaires mapped to EU AI Act tiers (prohibited / high / limited / minimal + GPAI), NIST AI RMF and ISO 42001, with a crosswalk so one answer satisfies many frameworks.
  • Risk register, controls & evidence, and a document generator — model cards, FRIA and Annex IV skeletons produced from registry data.
  • Next.js 16
  • TypeScript
  • Supabase
  • Versioned rule data
  • EU AI Act
  • NIST AI RMF
  • ISO 42001
Policyv1 · adopted

Generative AI Acceptable-Use Policy

1. Purpose & scope 2. Permitted & prohibited use cases 3. Human-review requirements 4. Brand, IP & confidentiality safeguards 5. Disclosure & labelling 6. Escalation & incident handling
Adopted across a digital team + partner agencies

Real artifact · Policy

AI Acceptable-Use Policy

An operational AI policy I authored and enforced — permitted and prohibited use cases, human-review requirements, brand & IP safeguards, disclosure rules and escalation paths. Written before most peers had one, and adopted across a digital team and its partner agencies.

Why it matters:

  • Turns a values statement into rules people can actually follow — with owners, review points and consequences.
  • Maps directly to the NIST AI RMF “Govern” function and EU AI Act transparency duties.
  • Auditable: versioned, dated and referenced in day-to-day review workflows.
  • Policy design
  • NIST AI RMF
  • Human oversight
  • IP & brand risk
AssessmentEU AI Act · NIST

AI Risk Assessment & Classification

CV screeningHigh-risk
Support chatbotLimited
Spam filterMinimal
Social scoringProhibited
Use-case → tier → required controls

Real artifact · Risk assessment

AI Risk Assessments

Structured assessments that take a real AI use-case, classify its risk against the EU AI Act and NIST AI RMF, and map the proportionate controls and documentation each tier requires — the practical output an auditor or a regulator expects to see.

What's inside:

  • Use-case intake, data & model provenance, and impact context.
  • Tier classification (prohibited / high / limited / minimal + GPAI) with the reasoning recorded.
  • Control & evidence mapping, plus the documents the tier triggers (model card, FRIA, technical file).
  • EU AI Act
  • NIST AI RMF
  • ISO/IEC 42001
  • Risk scoring
  • Controls mapping

Let's talk

Ready to put this to work for your AI governance program.

If you're hiring for AI governance, risk or compliance — I'd welcome the conversation. The résumé has the full picture; email is fastest.