top of page
BLOG


It's Time for AI to Deliver the Goods
When we talk about AI adoption, most people mean efficiency. Making existing processes faster. Swapping one process stack for another. Here's the thing. With what has been borrowed against AI, efficiency does not come close to settling the account. Because that is what this is. A debt. We have directed much of the world's capital into a single technology and away from everything else it could have funded. That capital was not free. It was borrowed against a promise. And capit
ย


Audit Will Not Make AI Safe
Audit Will Not Make AI Safe Ask almost anyone in compliance where the field ought to be heading and the answer comes back the same. Compliance should become proactive. It should anticipate risk rather than react to it. It should build the capability to meet obligations, not merely the paperwork to prove them. The obligations themselves have already moved. Regulation and standards have shifted toward risk-based and outcome-based designs, and they now ask organizations to conte
ย


Investing in the Opportunity to Succeed
Investing in the Opportunity to Succeed Every business creates value under uncertainty. Some of that uncertainty can be reduced. It comes from what the organization does not yet know. About its processes. Its risks. Its obligations. The conditions it works in. Learning reduces it. So does capability. This is uncertainty you buy down. Some of it cannot be reduced. Variation is part of real conditions, and no amount of learning removes it. This is uncertainty you contend with b
ย


Forward Assurance for AI Systems
Forward Assurance for AI Systems Audit looks backward. It verifies that something was done. Forward assurance is confidence that a system will keep its promises in operation โ and that confidence cannot be inspected in after the fact. It is engineered in, by design. The gap AI is adopted when it can be trusted with the work that matters. We trust a mission critical system because we trust the people who design and build it, and the discipline they follow. That is what has to
ย


Why AI is Used to Govern AI
Governance is a form of regulation. Cybernetics is the study of regulation in machines and living systems. It gives us two rules that matter here. First, the regulator must model the system it regulates. This is the Conant-Ashby theorem. Every good regulator of a system must be a model of that system. Second, the regulator must hold at least as much variety as the system it controls. This is Ashby's Law of Requisite Variety. Only variety can absorb variety. A set of finite co
ย


THE FUTURE OF LEAN COMPLIANCE
Elevate Compliance Huddle ยท Session 100 THE FUTURE OF LEAN COMPLIANCE Elevate Compliance Huddle ยท Session 100 Monday, September 14 ยท Noon ET ยท Live on Zoom In our last webinar we explored what the future of compliance might look like in the age of intelligence. Obligations moving from rules to outcomes. AI arriving in the value chain, in the products organisations make, in their suppliers' processes, and in the compliance function itself. The message was this: compliance
ย


What Stops Compliance From Improving
I have used the same Compliance Program Scorecard for ten years. No one has ever disagreed with their score. That tells me the scorecard is reliable at evaluating compliance. People see where their compliance stands and they recognize it. What the scorecard gives them is where and how to improve. The reason that matters more now is AI. It does not change what compliance is. It changes what it takes to produce it. Obligations do not disappear when work moves to machines. They
ย


The Future of Compliance in the Age of Intelligence
Most conversations about AI and compliance go one of two ways. Either they are about technology, which tools to buy and what to monitor with them. Or they are about regulations, which rules now apply and how to map controls to them. Both are worth having. Neither is the one I think we are missing. Buying the right tools and knowing the right rules will not be enough, because underneath both is a culture and capability problem that AI is exposing rather than creating. AI adopt
ย


We Built Fences and Called It Governance
Structural governance asks: are we inside the line? Directional governance asks: are we going to make it? Nearly every governance instrument we have answers the first question. The risk register. The control matrix. The attestation. The RAG dashboard. The assurance map. Not one of them answers the second. A ship inside its shipping lane is not thereby on course. Four years ago I wrote about bounded-set and centred-set compliance. A bounded set is defined by a boundary and you
ย


ISO 9001:2026 โ Time to Model Your Quality System
The revised standard is close. ISO/TC 176/SC 2 has completed the technical revision and submitted the Final Draft, with publication expected in September 2026. Organizations then have a three-year transition period, to September 2029. The revision is an evolution rather than a rewrite โ the process approach, the harmonized structure, and the core requirements stay. What's new is context. Among the themes carried through the drafts is digitalization, with reliable data treated
ย


Applying PDCA to the Obligation-Promise Cycle
PDCA Applied to Obligation/Promise Cycle An obligation is a requirement the organization must fulfil. It may be mandatory or voluntary, external or internal, and it stays active for as long as it is imposed or adopted. A promise is a voluntary commitment made by an agent about its own behaviour. Obligations give rise to promises. That is how an obligation becomes operational. The cycle runs between them. Obligations produce promises, promises are kept through operational capa
ย


Why Compliance Fails to Advance
Every so often I take stock of where compliance actually is as a discipline, compared to where the effort we pour into it says it should be. The honest answer has bothered me for some time, and I want to work through it with you here. Compliance has never had more resources. More frameworks, more software, more staff, more attention from the board than at any point in my career. By almost any measure of activity, the field has grown enormously. And yet, measured the only
ย


๐๐ผ๐ ๐ช๐ฒ ๐๐ฟ๐ฎ๐บ๐ฒ ๐๐ป๐๐ฒ๐น๐น๐ถ๐ด๐ฒ๐ป๐ฐ๐ฒ ๐ง๐ฒ๐ฐ๐ต๐ป๐ผ๐น๐ผ๐ด๐ ๐ช๐ถ๐น๐น ๐๐ฒ๐๐ฒ๐ฟ๐บ๐ถ๐ป๐ฒ ๐ช๐ต๐ฎ๐ ๐๐ ๐๐๐ถ๐น๐
The information technology era is ending, at least in part. It collected data and moved it to where it was needed. Intelligence technology is different. What that era becomes is not settled. It is being decided now, in procurement decisions and architecture reviews, by the answers being given to questions like these. ๐ธ ๐๐ฑ๐ผ๐ฝ๐๐ถ๐ป๐ด ๐๐ ๐๐ฒ๐ฟ๐๐๐ ๐๐ป๐ด๐ถ๐ป๐ฒ๐ฒ๐ฟ๐ถ๐ป๐ด ๐๐ Adoption selects a vendor and measures uptake. Engineering establishes that a system is safe, r
ย


Two Kinds of AI Strategy: Adopt or Adapt?
Which one will you choose? Digital transformation has always been a challenge. Re-engineering a business to use new technology carries real risk, and more so when the benefits aren't easily realized. That is the part the current AI conversation keeps skipping. There are two ways to bring AI into a business, and they are not the same thing. You can adopt it: take the technology as given and fit the business around it. Or you can adapt it: start from the business you already ha
ย


Should You Adopt ISO 42001 or ISO 5338?
ISO 42001 has quickly become a standard organizations reach for when they want to take AI seriously. It is the first international management system standard for artificial intelligence โ a framework for governing AI across an organization, built in the same family as ISO 9001 for quality and ISO 27001 for information security. It is a genuine step forward, and for many businesses it can help. But before adding it to the shelf alongside your other management systems, it is wo
ย


Managing Requisite Context for AI Workflows
Many organizations are adopting AI in their business, whether as generative AI or as AI agents. In all cases, the AI needs a context to work from, and for the AI to be effective that context must be requisite. An AI model knows nothing about your organization. Everything it produces on your behalf rests on the context supplied at the moment of use. If that context covers what the task requires, the workflow can be trusted. If it doesn't, the model fills the gaps with public d
ย


Irresponsible AI Adoption in Safety-Critical Sectors
There was a time when safety was engineered into the business, the plant, and the operations. It required qualified engineers to ensure harm was avoided, and that risks, when they occurred, were mitigated. Systems were built with instrumentation, controls, and adaptive regulators to keep everything operating within safe limits. This was done so that everyone had the best possible chance of returning home to their families at the end of the day. Then someone threw a stochastic
ย


The Golden Thread of Assurance - Wrap Up
We just completed the final session in our series on the Golden Thread of Assurance. Assurance is the proactive means of providing confidence that obligations have been met, are being met, and will be met. It runs through everything critical to compliance โ and it answers a question many organizations have had to ask: why did we have an incident when we had checked all the boxes? The boxes were checked. The thread was broken. The golden thread connects the spaces in between.
ย


OOPS, we put the obligations in the wrong place.
For years I've watched the same thing happen across every regulated sector I've worked in. The obligations are documented. The controls are implemented. The audit gets passed. And still, when something goes wrong, you find that no one โ not one identifiable person, not one accountable part of the organization โ was holding the thing that failed. It's tempting to call this negligence: managers handing their responsibilities off to consultants, departments, and auditors. There
ย


Regulating AI with Institutional Knowledge
Today many organizations use AI that is general. It was trained on the public record, not on any one sector or business. It does not know your mission, your values, your goals, your processes, your protocols, or your standard operating procedures. When you ask it a question, it answers from what is common across everyone, not from how that knowledge applies to the particulars of what you do. In a regulated, high-risk domain this is a problem. The general model gives you the
ย


Engineered Regulation for AI Systems
In every industry where failure is consequential, we learned to engineer control into a system before we trusted it to run. With AI, we are skipping that step. The discipline we are missing has a name: engineered regulation. Engineered Regulation for AI Systems No one runs a refinery with a big red button and good intentions. Before the plant starts, engineers design the control loops that hold temperature and pressure where they belong. They add independent safety systems th
ย


Is AI Causing Your Mission to Drift?
Compliance is now vulnerable. Every promise you've made โ privacy, security, quality, financial integrity, legal adherence, ethical values โ now runs through systems that are unreliable, uncertain, and unable to align with your mission. So ask the hard questions: Does your AI know your obligations, your values, your promises? Does it follow your processes, your standard operating procedures, your policies? Will it cost you your legal license โ or your social license โ to oper
ย


AI Adoption Is Leading to Greater Efficiency, Not Innovation
There is a quiet assumption running underneath the loudest investment of our age, and Sunday is a good day to bring it into the light. We are building compute. Enormous, almost unimaginable quantities of it. We are miniaturizing computers at one end โ fabricating features measured in handfuls of atoms โ and scaling them up at the other into hyperscale clouds that span continents. The capital is real, the engineering is genuine, and the people doing it are among the most capab
ย


What Full-Text Search Already Taught Us About AI
We have been here before. In the enterprise, there have always been two kinds of searches. The first looks for the exact answer you get from a query (deterministic). The second looks for the closest answer you can find through full-text search (probabilistic). We knew the difference, and we learned how to use each kind. Full-text search gave us the approximate answers. It returned a ranked list of the most relevant results โ useful when you are browsing, less so when you need
ย
bottom of page
