From IT Governance to AI Governance: The Practitioner's Transition Guide

If you run COBIT assessments, hold CISA, CRISC, or ISO 27001, or sit inside an IT governance function, you already own roughly 70% of what AI governance requires. This guide maps the 30% gap and lays out a 90-day plan built around ISO 42001.

Share
T governance professional reviewing an ISO 42001 AI management system framework at a workstation
IT governance professionals — COBIT, CISA, CRISC, ISO 27001 — already own 70% of what AI governance requires. The remaining 30% is a defined, learnable extension, and ISO/IEC 42001 is the operating credential that closes it.

If you already run COBIT assessments, hold CISA, CRISC, or ISO 27001 credentials, or sit inside an IT governance function, you already own roughly 70% of what AI governance requires. The remaining 30% — model lifecycle oversight, AI-specific risk categories like bias and drift, and third-party AI supply chain assurance — is a defined, teachable extension of what you do today, not a new discipline. This guide maps the exact gap, shows how your existing certifications translate, and lays out a 90-day plan built around ISO/IEC 42001, the international AI management system standard.

Written for IT auditors, GRC managers, IT directors, CISOs, and COBIT-certified practitioners looking to move into AI oversight roles without abandoning the governance discipline they've spent a career building.

Key Takeaways

70% of AI governance is IT governance. Board-level oversight, control frameworks, risk registers, third-party assurance, audit trails — the muscle you already use for IT and information security transfers directly to AI management systems.

Three gaps define the 30%. Model lifecycle governance, AI-specific risks (bias, drift, hallucination, adversarial inputs), and the AI supply chain — foundation models, training data provenance, and vendor accountability.

ISO 42001 is the operating credential. It defines an auditable AI management system, mirrors the ISO 27001 clause structure IT auditors already know, and is the certification employers are starting to specify in AI governance job descriptions.

CISA, CRISC, COBIT, ISO 27001 carry over. Your existing certifications map cleanly to specific AI governance responsibilities. They are the foundation, not the obstacle. What they don't cover is the AI-specific management system layer.

Roles hiring now. AI Governance Officer, AI Risk Manager, Responsible AI Lead, AI Auditor, Model Risk Manager. The demand curve is currently ahead of the supply of practitioners who can actually audit an AI system end-to-end.

90 days is a realistic timeline. ISO 42001 Lead Implementer as the entry credential, ISO 42001 Lead Auditor as the audit-track extension. The bundle is the fastest path for practitioners already fluent in ISO 27001-style management systems.

On This Page

The 70/30 Reality: What Transfers, What Doesn't

I have spent the last three years watching IT auditors and GRC managers approach AI governance the same way — with the assumption that it is a new discipline they have no foundation in. It is not. AI governance is governance applied to a system class that learns. The oversight muscle is the same muscle. The evidence requirements are the same evidence requirements. The board reporting cadence is the same board reporting cadence. The control frameworks are cousins, not strangers.

Here is what actually transfers from IT governance to AI governance without modification:

  • Governance structures. Board oversight committees, risk appetite statements, three lines of defence, RACI matrices, delegated authority frameworks — all of it applies to AI management systems with almost no change.
  • Risk methodology. Threat identification, likelihood and impact scoring, residual risk acceptance, risk registers, treatment plans. ISO/IEC 42001 uses the same risk-based thinking anchor point as ISO/IEC 27001.
  • Control design and audit evidence. Statement of Applicability, control objectives, control testing, non-conformity classification, corrective action tracking. If you have led an ISO 27001 audit, you can lead an ISO 42001 audit with roughly a month of focused study.
  • Third-party assurance. Vendor due diligence, contractual controls, right-to-audit clauses, evidence of the vendor's own certification. The mechanics do not change when the vendor is a foundation model provider instead of a SaaS platform.
  • Policy architecture and management review. Policy hierarchy, document control, management review meetings, internal audit programme, continual improvement. AIMS uses the same Annex SL harmonised structure as ISMS.

What does not transfer — the 30% — is the part that is specific to how AI systems actually behave. That is where the study time goes. The rest is muscle memory.

Your Existing Toolkit: Why COBIT, ISO 38500, and ISO 27001 Are the Foundation, Not the Obstacle

The frameworks you already know are not obsolete. They are the substrate on which AI governance is being built. Here is how each one maps forward.

COBIT 2019: The EDM Model Extends Directly to AI Oversight

COBIT's governance system is built on the Evaluate, Direct, Monitor (EDM) domain — five governance objectives that a board or governance body uses to steer enterprise IT. Every one of those objectives applies to AI without modification. EDM01 (framework setting), EDM02 (benefits realisation), EDM03 (risk optimisation), EDM04 (resource optimisation), and EDM05 (stakeholder engagement) are exactly the governance questions a board needs to answer about its AI portfolio: what is our AI strategy, what value are we getting, what risks are we running, what talent and compute do we need, and who do we need to keep informed.

Where COBIT stops is at the management-system layer. It tells you what governance objectives to set, but not how to build an auditable AI management system that a certification body can assess against a published standard. That is the seam where ISO/IEC 42001 slots in — as the AIMS layer that operationalises what COBIT specifies at the governance layer.

If you hold COBIT 2019 Foundation or Design and Implementation, you already understand the governance philosophy. Reading ISO/IEC 42001 will feel familiar rather than foreign — the two documents talk to each other.

ISO/IEC 38500: Six Principles That Translate Almost Word-for-Word

ISO/IEC 38500 is the corporate governance of IT standard. Its six principles — responsibility, strategy, acquisition, performance, conformance, and human behaviour — read almost unchanged if you substitute "AI" for "IT" throughout. The principle of human behaviour, in particular, becomes acutely relevant to AI governance because it forces a governing body to consider how AI systems affect the people who use them, are subject to them, or work alongside them. That is a principle ISO/IEC 42001 explicitly picks up in its requirements for impact assessment.

If ISO/IEC 38500 has been part of your governance vocabulary, moving into AI oversight is not a philosophical shift. It is an application shift.

ISO/IEC 27001: The Management System Structure Is Identical

This is the biggest carry-over of them all. ISO/IEC 42001 uses the same Annex SL harmonised management system structure as ISO/IEC 27001 — Context of the organisation (Clause 4), Leadership (Clause 5), Planning (Clause 6), Support (Clause 7), Operation (Clause 8), Performance evaluation (Clause 9), Improvement (Clause 10). Every clause title is the same. The internal audit programme, the management review cadence, the corrective action process, the document control expectations — a practitioner who has implemented or audited an ISMS can pick up an AIMS with roughly a month of focused study on the AI-specific content.

The controls in Annex A are of course different in content — ISO 42001 Annex A covers AI-specific control objectives around impact assessment, data quality, transparency, human oversight, and lifecycle management — but the structural approach (control objectives, statement of applicability, control testing) is identical to how you already handle Annex A of ISO 27001.

This is why we routinely recommend that organisations should have a mature ISO/IEC 27001 posture before pursuing ISO/IEC 42001. Not because the standard requires it, but because 27001 gives you the management system foundation that 42001 assumes exists.

The Three Gaps You Actually Need to Close

These are the parts of AI governance that IT governance did not prepare you for. They are learnable — but you have to actually learn them, not assume they are covered by extension.

Gap 1: Model Lifecycle Governance

Traditional IT governance treats a system as something you build, deploy, monitor, and eventually decommission. An AI system has additional lifecycle stages that do not exist for conventional software: data acquisition and curation, feature engineering, model training, validation, deployment, monitoring for drift, retraining, and end-of-life. Each stage carries governance obligations that a CISA-trained auditor will not have encountered as a distinct concern.

Concretely: what evidence do you require that training data was lawfully sourced and representative? Who signs off that a model is fit for production? What triggers a retraining event, and who approves it? What happens when the model's performance degrades because the real world has moved on from the data it was trained on?

ISO/IEC 42001 Annex A addresses this directly through controls on AI system impact assessment, data for AI systems, and AI system lifecycle. This is where a Lead Implementer course does most of its bridging work — it forces you to think about model-specific controls the way you already think about access controls.

Gap 2: AI-Specific Risk Categories

Your CRISC training taught you how to think about IT risk. AI introduces risk categories that are not covered by the standard IT risk taxonomy: bias in outputs, model drift over time, hallucination in generative systems, adversarial inputs designed to manipulate predictions, unintended emergent behaviour, and explainability failures where the system cannot justify its own decision. These are not extensions of confidentiality, integrity, and availability. They are a new axis.

A GRC manager coming into AI governance needs a working vocabulary for these risk categories, needs to know which ones apply to which system classes (a computer vision model has different risk exposure to a large language model), and needs to understand how they interact with the risk categories you already track. Adversarial input risk, for instance, is a subset of both AI risk and information security risk — it does not sit cleanly in either taxonomy alone.

The frameworks that help here are ISO/IEC 42001's risk clauses (Clause 6), the NIST AI Risk Management Framework (as a companion reference, not a substitute), and — for European-scoped organisations — the risk categories baked into the EU AI Act. A practitioner-oriented ISO 42001 Lead Implementer course covers all three by design.

Gap 3: The AI Supply Chain

The third gap is the one most IT governance professionals underestimate on their first pass through the standard. When you procure a SaaS platform, your third-party risk assessment covers a bounded set of concerns — security posture, data handling, uptime, subprocessors. When you procure an AI capability, you inherit a much longer chain: the foundation model provider, the training data those models were built on, the fine-tuning provider, any embedded evaluation datasets, and the infrastructure vendor running the inference workload.

Right-to-audit clauses that work for a conventional SaaS vendor tend not to translate to a foundation model provider. Training data provenance is often opaque by design. Model behaviour can change between versions in ways that are not documented the way a software changelog documents changes. Contractual controls have to be built specifically for this.

ISO/IEC 42001 addresses this through controls on suppliers, customers, and third-party relationships (Annex A). Learning to design third-party AI assurance is the single skill that turns a good IT auditor into a viable AI auditor.

Credential Translation: How Your Existing Certifications Map to AI Governance

The credentials you hold today are not sunk cost. They are the reason you are competitive for AI governance roles at all. What follows is a plain reading of which parts of AI governance your current certifications already cover, and where the operating layer sits.

Your Existing Credential What It Covers for AI Governance Gap to Close
ISACA CISA Audit methodology, evidence gathering, control testing, IS process reviews. Directly applicable to AI system audits. AI management system clauses, Annex A AI controls, model-specific audit techniques.
ISACA CRISC IT risk identification, risk response, control monitoring. Risk methodology transfers directly. AI-specific risk categories (bias, drift, hallucination, adversarial inputs), risk categorisation approaches used by ISO 42001 and the EU AI Act.
COBIT 2019 (Foundation / Design & Implementation) Governance system design, EDM domain, board-level oversight, benefits realisation, performance management. The AIMS operating layer — how governance intent translates into an auditable, certifiable management system.
ISO 27001 Lead Implementer Management system structure (Annex SL), Statement of Applicability, control implementation, internal audit. The single closest carry-over. AI-specific Annex A controls, model lifecycle, third-party AI supply chain assurance.
ISO 27001 Lead Auditor Audit programme design, on-site audit conduct, non-conformity reporting, corrective action follow-up. AI-specific evidence expectations, how to audit a model rather than a control, working with data science teams during fieldwork.
ITIL 4 Service management, change control, incident response. Applies to AI systems in production. Governance-level accountability for AI outcomes, which sits above service management.

A Note on Conceptual AI Credentials

A parallel category of AI governance credentials has emerged from privacy and IT audit professional bodies — the IAPP AIGP and ISACA's AAISM being the most visible examples. These credentials cover the conceptual layer well: legal and regulatory landscape, ethics frameworks, high-level AI risk vocabulary, and the shape of AI governance programmes.

What they do not do is equip you to implement or audit an AI management system against a published, certifiable standard. They are signal credentials — useful on LinkedIn, useful for demonstrating awareness in an interview, useful for legal and privacy practitioners who need AI fluency without operating responsibility. They are not operating credentials.

For practitioners moving from CISA, CRISC, COBIT, or ISO 27001 into operational AI governance roles — the roles where you actually have to build, run, or audit an AIMS — the operating credential is ISO/IEC 42001 Lead Implementer for the build side and ISO/IEC 42001 Lead Auditor for the audit side. That is not a marketing position. It is the reflection of what the roles actually require you to do.

The Career Map: Roles That Are Hiring Now

The demand curve for AI governance practitioners is currently running ahead of the supply. Job boards in the United States, the United Kingdom, the European Union, the GCC, Singapore, and Australia are all listing roles that did not exist eighteen months ago. Here is the current shape of the market.

Role What the Role Does Best-Fit Background
AI Governance Officer Owns the AI governance programme, chairs the AI governance committee, reports to the board on AI risk and value. GRC manager, DPO, or IT governance lead with ISO 27001 or COBIT background.
Responsible AI Lead Sets ethical AI principles, runs impact assessments, works with product teams on fairness and transparency. Privacy or ethics-adjacent professional with ISO 42001 fluency.
AI Risk Manager Maintains the AI risk register, runs risk assessments on new AI systems, tracks residual risk against appetite. CRISC-certified risk professional or ISO 27005-trained practitioner.
AI Auditor (Internal) Conducts internal audits of AI systems and the AIMS itself, reports non-conformities, follows up corrective actions. CISA or ISO 27001 Lead Auditor with ISO 42001 Lead Auditor as the operating credential.
AI Compliance Manager Maps AI systems to regulatory obligations (EU AI Act, sectoral regulations), maintains evidence for external audits. IT compliance manager, GRC analyst, or DPO with ISO 42001 Lead Implementer.
Chief AI Officer / Head of AI Governance Executive-level accountability for AI strategy, portfolio, and oversight. Reports to CEO or board. CIO, CISO, IT director, or Head of Risk with the ISO 42001 Lead Implementer + Lead Auditor bundle.

Two patterns are worth naming out loud. First, none of these roles requires a technical machine learning background. They require governance discipline applied to AI. The technical layer is a collaboration surface, not an entry requirement. Second, the practitioners who are winning these roles right now are the ones who have paired an existing IT governance credential with ISO 42001 — because employers can read that combination in five seconds and know what they are buying.

The 90-Day Transition Plan

Ninety days is a realistic timeline for a practitioner who already holds an IT governance credential and is prepared to give the transition serious study time — roughly 6–8 hours a week. Here is how the ninety days actually break down.

Days 1–30: Foundation

Read ISO/IEC 42001 in full. It is not a long document. Sit with the clauses and read them the way you first read ISO/IEC 27001 — clause by clause, cross-referencing where the language differs and where it is identical to what you already know. Read the NIST AI Risk Management Framework alongside it as a companion reference. Read the EU AI Act's structure — you do not need to memorise the annexes, but you should be able to describe the risk-tier approach in a conversation.

Build a personal glossary of terms that were not in your ISO 27001 vocabulary: foundation model, fine-tuning, retrieval-augmented generation, model drift, hallucination, adversarial input, differential privacy. You do not need to be able to build any of these — you need to be able to talk about them without flinching.

Days 31–60: Credentialing

This is where the operating credential goes in. For most practitioners transitioning from IT governance, the entry point is ISO/IEC 42001 Lead Implementer. It teaches you the AIMS build side: how to establish the management system, how to run the risk assessment, how to design the Statement of Applicability, how to implement the Annex A controls, how to prepare for certification audit.

If you are on an audit track — CISA, ISO 27001 Lead Auditor background, or currently sitting in an internal audit function — you will also want ISO/IEC 42001 Lead Auditor. In practice, the fastest and most cost-effective path is the Lead Implementer + Lead Auditor bundle, because you get the build view and the audit view in one sitting and the two views reinforce each other. Auditors who understand what a good implementation looks like are better auditors.

Days 61–90: Application

Do the work inside your current organisation before you look for the next one. Run an informal AI inventory — every AI-adjacent system your organisation uses, from procurement-tier SaaS with AI features embedded, to internally built models, to the copilots your developers have installed. Score them against the ISO 42001 risk categories. Present the inventory and the risk view to your leadership team.

Two things happen when you do this. First, you get real, current, referenceable practitioner experience on your CV — not "studied for a certification" but "conducted the organisation's first AI inventory and risk assessment." Second, your current employer often turns into your first AI governance client, because you have just made yourself the only person in the building who can talk about AI risk in language the board understands.

CERTIFICATION PATHWAY

Start your transition with the operating credential the roles are actually asking for.


PECB's ISO/IEC 42001 Lead Implementer certification teaches you to build and run an auditable AI management system — the exact skill AI Governance Officer, AI Compliance Manager, and AI Risk Manager roles specify. Delivered online, PECB-certified, taught by an active ISO 42001 implementer.

reconn.io  |  Dubai  |  Remote delivery worldwide

What This Looks Like in Practice: Three Transition Patterns

These are three transition patterns we see repeatedly at reconn. Not case studies from anonymised clients — just the shapes the transitions actually take. Read the one that maps closest to where you are today.

Pattern A: IT Auditor → AI Auditor

You hold CISA or ISO/IEC 27001 Lead Auditor. You have run ISMS audits, sat in exit meetings with auditees, and written non-conformity reports. The transition into AI auditing is direct.

The credential to add is ISO/IEC 42001 Lead Auditor. The Lead Auditor course teaches you AIMS audit methodology on top of the ISO 19011 audit principles you already apply, and gives you the AI-specific evidence expectations that a CISA background does not cover: how to audit a model rather than a control, what to ask a data science team, what documentation to request, how to write findings that a technical team and a governance committee can both act on.

Time horizon: 90 days from decision to credential-in-hand. Career horizon: internal audit teams and Big-4-style advisory practices are recruiting for this profile aggressively.

Pattern B: GRC Manager → AI Governance Officer

You currently run a GRC function or manage compliance programmes anchored around ISO/IEC 27001, PCI DSS, or a regional data protection regulation. Your work is programme-shaped, not audit-shaped — you build, run, and evidence management systems.

The credential to add is ISO/IEC 42001 Lead Implementer. It gives you the build-side view: how to establish an AI management system, how to design the AI governance committee, how to run the impact assessments Annex A calls for, how to prepare the organisation for external certification audit. This is the profile employers are looking for when they post an "AI Governance Officer" role.

A useful pairing: many Pattern B practitioners are also the DPO or the ISMS owner in their current organisation. Making the AI governance programme an extension of the existing GRC function — rather than a separate initiative — tends to be the shortest path to actually getting one built.

Pattern C: CISO / IT Director → Head of AI Governance or Chief AI Officer

You are already at the executive layer. You have run IT or information security functions, sat in front of boards, owned budgets, and made the case for governance programmes as strategic investments rather than compliance cost. The move into AI oversight at this level is less about learning new skills and more about establishing credible authority on a domain the board is now asking about weekly.

The bundle path — ISO/IEC 42001 Lead Implementer plus Lead Auditor — is the pragmatic choice at this level. It gives you the build view and the audit view simultaneously, which is what an executive owning AI oversight needs. You will not personally implement or audit; you will direct people who do. But you cannot direct what you cannot audit-read. See our companion piece on how to become a Chief AI Officer for the executive-layer view.

Time horizon: the bundle is designed to be studied concurrently, so 90–120 days is realistic for a working executive.

The Bottom Line

IT governance professionals moving into AI governance are not starting from zero. They are extending a discipline. The frameworks you already work with — COBIT, ISO/IEC 38500, ISO/IEC 27001 — are the substrate. The credentials you already hold — CISA, CRISC, COBIT, ISO 27001 Lead Implementer or Lead Auditor — cover the majority of what the new roles require.

What sits on top is a defined, learnable layer: an AI management system standard (ISO/IEC 42001), a small set of AI-specific risk categories, and a supply chain that behaves differently from conventional IT procurement. The operating credential that closes the gap is ISO/IEC 42001 Lead Implementer on the build side, Lead Auditor on the audit side, or the bundle for practitioners who need both.

The market is currently paying for practitioners who can do this work. The credential is available. The path is ninety days. The frameworks you already know are still the frameworks that matter.

NEXT STEPS

Ready to make the transition the fastest way — with both the build view and the audit view?


The PECB ISO/IEC 42001 Lead Implementer + Lead Auditor bundle is the pragmatic path for practitioners moving from IT governance into AI oversight. You get the AIMS build side and the audit side in one programme, at a bundled rate, with reconn's advisory support throughout.

reconn.io  |  Dubai  |  Remote delivery worldwide

Further Reading

Frequently Asked Questions

Do I need a technical AI or machine learning background to move into AI governance?

No. AI governance roles require governance discipline applied to AI, not the ability to build models. A working vocabulary — foundation models, fine-tuning, drift, hallucination, adversarial inputs — is enough. The value you bring is the same governance rigour you already apply to IT and information security: risk assessment, control design, audit evidence, board reporting. Technical machine learning skills are a collaboration surface with data science teams, not an entry requirement for the role.

I already hold CISA and CRISC — do I really need ISO/IEC 42001 as well?

Yes, if the target role involves building, running, or auditing an AI management system. CISA and CRISC cover audit methodology and IT risk management brilliantly, and both transfer directly. What they do not cover is the AIMS clause structure, the AI-specific Annex A controls, model lifecycle governance, or the third-party AI supply chain. ISO/IEC 42001 Lead Implementer or Lead Auditor closes that specific gap. Together, CISA plus ISO 42001 is currently the strongest employer-facing credential combination for AI audit and governance roles.

How does ISO/IEC 42001 compare to conceptual AI governance credentials like AIGP?

They serve different purposes. Conceptual credentials from privacy and audit professional bodies cover the legal, ethical, and high-level risk landscape well. They are useful signal credentials for practitioners who need AI fluency without operating responsibility — privacy lawyers, ethics practitioners, board-facing generalists. ISO/IEC 42001 Lead Implementer and Lead Auditor are operating credentials: they equip you to actually build, run, or audit an AI management system against a certifiable standard. For IT governance practitioners moving into operational AI oversight roles, the operating credential is the one employers are increasingly specifying by name in job descriptions.

Which ISO 42001 credential should I take first — Lead Implementer or Lead Auditor?

Lead Implementer first, in almost every case. It gives you the build-side view of the management system — how it is designed, how the Statement of Applicability is constructed, how the risk assessment feeds control selection, how the Annex A controls actually get implemented. Once you have that mental model, Lead Auditor becomes considerably easier because you are auditing something you understand from the inside. Practitioners who take Lead Auditor first sometimes end up auditing a management system they have never seen built, which produces shallow audits. If you need both — and audit-track practitioners usually do — the bundle is the fastest path.

How does ISO/IEC 42001 relate to the NIST AI Risk Management Framework?

They are complementary, not competing. ISO/IEC 42001 is a certifiable management system standard — an organisation can be independently audited and certified against it. The NIST AI RMF is a voluntary risk management framework that is highly useful as a companion reference for structuring risk work, but it is not certifiable. In practice, most mature AI governance programmes use ISO/IEC 42001 as the auditable spine and NIST AI RMF for depth on specific risk practices. For career purposes, ISO/IEC 42001 is the credential employers are hiring against; NIST AI RMF is the framework they expect you to know.

Do employers actually recognise ISO/IEC 42001 yet?

Recognition has accelerated sharply. Job descriptions for AI Governance Officer, AI Risk Manager, and AI Compliance Manager roles increasingly list ISO/IEC 42001 by name, particularly in regulated industries (financial services, healthcare, insurance) and in jurisdictions with active AI regulation (EU AI Act scope, Singapore, UK). Certification bodies including BSI, SGS, TÜV SÜD, DNV, and Schellman have accredited ISO/IEC 42001 audit practices. The pattern mirrors how ISO/IEC 27001 recognition scaled in the late 2000s — from "emerging" to "table stakes" faster than practitioners expected.

Can I make the transition without leaving my current role?

Yes, and it is often the strongest path. Study for ISO/IEC 42001 Lead Implementer while continuing in your current IT governance role. Once credentialed, run the first AI inventory and impact assessment inside your existing organisation — most organisations do not yet have one. That work is directly referenceable practitioner experience. The transition then happens inside the same building, or gives you the CV depth to move externally as a credentialed practitioner rather than as a candidate with only theoretical knowledge.

Is ISO/IEC 27001 a prerequisite for ISO/IEC 42001?

Not formally — the standard does not require it. Practically, we recommend it. ISO/IEC 42001 assumes the management system muscle that ISO/IEC 27001 builds, and the AI-specific controls in Annex A rest on an information security foundation that 27001 provides. Organisations attempting ISO/IEC 42001 without a mature ISMS routinely find themselves rebuilding basic management-system infrastructure mid-implementation. For practitioners on the credential side, 27001 experience makes the 42001 course dramatically more absorbable.

EXPERT GUIDANCE

Not sure which pathway fits your background? Talk to a practitioner, not a call centre.


reconn's advisory team includes active ISO 42001 implementers and auditors. A ten-minute conversation is usually enough to map your existing credentials against the right ISO 42001 pathway — Lead Implementer, Lead Auditor, or the bundle — and give you a straight answer on timing and next steps.

reconn.io  |  Dubai  |  Remote delivery worldwide
Shenoy Sandeep

About the Author

Shenoy Sandeep

Shenoy Sandeep is the Founder of reconn, an AI-first cybersecurity firm based in Dubai, UAE. With 20+ years across cybersecurity focussing on offensive security and threat intelligence portfolio, and over 10 years in Enterprise AI, AI governance and data protection, he has assisted over 25+ startups in scaling their business in the Middle East and African region.

Training is Shenoy's passion project and reconn has associated themselves with PECB, the global leaders in personal certifications for AI, cybersecurity, data protection, privacy and business continuity professionals. He is a PECB-certified trainer and one of the world's early PECB-certified AI professionals, also specialising in ISO/IEC 27001, ISO/IEC 27701, ISO 42001, ISO 22301, and GDPR.

Via Reconn, Shenoy runs an advisory service assisting organisations in the EMEA with compliance and certification on ISO 42001, ISO 27001, ISO 27701, ISO 22301 and local data protection and privacy laws. His current interests include EU AI Act, NIS2, DORA, EU/UK GDPR, UAE PDPL and SDAIA PRPL.