Writing from the audit chair.
I've spent over twenty five years in IT audit and cybersecurity, most of it inside financial services, healthcare, and technology organisations where the stakes for getting risk assessment wrong are high and the systems under review keep getting more complex.
The last several years of that have been spent inside AI and machine learning audits specifically; sitting in the room while models get built, deployed, and governed, and asking the questions that traditional IT audit training doesn't quite prepare you for. What does "tested" actually mean for a model that keeps learning? Who's accountable when a pipeline, not a person, made the decision? Where does a framework's language stop matching what the system in front of you actually does?
That's the gap this blog lives in. Most AI governance content is either too abstract to use in a real review, or too shallow to survive contact with an actual system. I write from the audit chair, for the practitioners who have to ask the hard question in the room, not just cite the framework that mentions it.

Najwan Hudaihed