Prepared by
Andrew Moore
25+ years of board-reported technology, cyber, and cryptography risk at Royal London, HSBC, Barclays, and EY.
- ISO/IEC 42001 Senior Lead Implementer
- CISSP
- CRISC
- CIPP/E
A working library for AI governance, risk, and control.
A structured Risk & Control Library, a Tools Library of downloadable practitioner artefacts, a curated Resources library, and an open Thought Experiment testing how AI governance actually works in practice, built for C-suite and AI governance practitioners.
Start here
Find the walk that matches your role.
Each is a short, curated path through the site in the register that role actually reads in — not a separate site, just a different door in.
Governance, compliance, security, engineering: one system, four seats.
Start wherever matches the conversation you're already having. Each page stands alone, but the four are presented as one connected structure here, not four separate topics.
Governance
Explain how organisations operationalise AI governance through roles, policy, evidence, and controls.
Read more →Compliance
Map the EU AI Act, ISO/IEC 42001, and NIST AI RMF into practical executive and audit views.
Read more →Security
Capture LLM threats, output validation, and human-in-the-loop safeguards in a technical view.
Read more →Engineering
Architecture, evaluation, production monitoring, and incident response for AI systems actually running, not just designed.
Read more →∴
Contents.
Everything else the site holds, in two groups: the structured reference library, and the independent reading kept apart from it.
Structured reference data
Risks
Individually assessed AI risks, scored by severity and mapped to the controls and frameworks that address them.
Controls
Practical AI controls mapped to ISO/IEC 42001, the EU AI Act, and NIST AI RMF, ready to reference against your own control set.
Tools
Checklists, register templates, and working documents built for running an AIMS, free to download.
Glossary
A searchable glossary of AI governance, compliance, and security terminology, cross-referenced with frameworks and best practices.
Independent reading
Articles
Long-form writing in Andrew's own voice — including the Thought Experiment, an evolving public investigation into governing a UK-regulated retail bank's AI.
News
Timely updates on AI governance, compliance, and security: regulatory changes, emerging standards, and thought leadership.
Resources
A curated, opinionated library of the regulation, standards, thought leadership, and learning material practitioners keep close at hand.
Explore further