top of page


What Evidence Must Exist Before You Increase an Agent’s Authority?
This AI maturity scorecard shows how organizations can evaluate evidence before increasing an AI agent’s authority. It connects NIST AI RMF’s Govern, Map, Measure, and Manage functions with the ISO/IEC 42001 Plan-Do-Check-Act cycle.
Daniel Ruggles
2 days ago2 min read


AI Agent Sprawl is Now a Board Issue
AI Agent sprawl is the successor to shadow IT, with one important difference. A hidden app mostly stores or displays information. A hidden agent can act.
Daniel Ruggles
Sep 12 min read


EU AI Act, NIST AI RMF, and ISO 42001: One Operating Model-Converged AI Framework
Most organizations do not need three separate AI governance programs. They need one operating model that uses each framework for a distinct purpose.
Daniel Ruggles
Aug 252 min read


Agentic AI Changes the Governance Equation
Agentic AI and the Governance Equation Traditional AI governance generally assumes a familiar pattern: a model receives an input, produces an output, and waits for the next request. Agentic AI changes that pattern —and the governance equation, and the risk that comes with it. An AI agent can plan work, select tools, access business systems, communicate with other agents, make decisions, and take action with limited human involvement. Depending on its authority, an agent might
Daniel Ruggles
Aug 133 min read


Stop Comparing AI Frameworks—Build One Governance Operating System
Stop Comparing AI Frameworks—Build One Governance Operating System Posts keep stacking the EU AI Act, NIST AI RMF, and ISO/IEC 42001 side by side as if they were competing products on a shelf. The result is decision paralysis: legal teams treat the Act as non-negotiable law, risk teams cling to NIST’s practical structure, and audit-minded leaders push for ISO 42001’s certifiable management system. Teams end up running three parallel programs, duplicating work, and still feeli
Daniel Ruggles
Aug 105 min read


Your AI Pilot Didn’t Fail Because of the Model- Failure Rate
MIT research shows that roughly 95% of enterprise generative-AI pilots deliver no measurable revenue or productivity gains. Only about 5% make it into production with clear P&L impact
Daniel Ruggles
Aug 103 min read


EU AI Act Enforcement Is Live: What CIOs Need to Do This Week—Not Next Quarter
The EU AI Act’s general application date arrived on August 2, 2026. CIOs should immediately identify every AI system that reaches the EU, confirm that required disclosures are working, assign accountability, and begin collecting evidence of compliance.
Daniel Ruggles
Aug 33 min read


Responsible Artificial Intelligence Maturity Matrix
Two prominent Maturity Models from the ISACA ecosystem stand out — but they serve fundamentally different purposes. The Capability Maturity Model Integration (CMMI) is a battle-tested organizational process maturity model. The ISACA Advanced in AI Security Management (AAISM) is a professional certification focused on individual expertise in AI security. While both address governance, risk, and controls in the AI era (especially with the recent launch of CMMI’s Artificial Inte
Daniel Ruggles
Jun 243 min read


AI Bias Categories and Definitions
According to ISA/IEC 42001, AI bias enters at multiple points: 1. Historical bias (training data reflects past discrimination), 2. Measurement bias (proxies correlating with protected characteristics), 3. Aggregation bias (works well on average, fails for subgroups), 4. Deployment bias (used outside the intended context). Bias can be invisible in overall metrics while causing severe harm to specific groups. Disaggregated testing (across demographic groups)
Daniel Ruggles
Jun 243 min read


AI Algorithms - When to use
Here's a clear, practical table of the most used AI/ML algorithms, categorized by type, along with their best applications: Algorithm Category Appropriate Uses (Best When...) Real-World Examples Linear Regression Supervised (Regression) Predicting continuous numerical values with linear relationships House price prediction, sales forecasting, demand estimation Logistic Regression Supervised (Classification) Binary or multi-class classification with probabilistic outputs Spam
Daniel Ruggles
Jun 242 min read


AI Incidents - Causes and Remediation Approaches
Here’s a practical table summarizing the most frequently reported categories of AI incidents, drawn from real-world databases like the AI Incident Database and established risk taxonomies. Type of AI Incident Primary Causes Possible Remediation Strategies Bias & Discrimination Biased/historical training data, unrepresentative sampling, proxy variables, and societal patterns amplified by the model Diverse & audited datasets, bias testing & fairness metrics, regular impact asse
Daniel Ruggles
Jun 242 min read


Teamwork Beats Silos: Why Cross-Functional Collaboration Makes Risk Management Smarter
In today's fast-moving world, risks don't stay neatly within one department. Cyber threats, compliance issues, operational disruptions, and reputational challenges can impact an entire organization in a matter of hours. That's why one of the most important risk culture beliefs is simple: Cross-functional collaboration optimizes risk response. When people from different teams work together, organizations can identify risks earlier, make better decisions, and respond more effec
Daniel Ruggles
Jun 12 min read


Qualitative vs Quantitative Risk Analysis: When to Use Each in Your Risk Register
In the world of project management, one of the most important tools you have is the risk register. Simply listing risks isn’t enough. You need to analyze them effectively. That’s where the debate between qualitative and quantitative risk analysis comes in. Assessing risks based on scenarios that role-play potential vulnerabilities on the business value of assets can be a bit overwhelming. There are criteria for choosing the right method at the right time — and for building a
Daniel Ruggles
May 292 min read


Avoidable Risks - Kubernetes and Containers
Avoidable cloud risks.
Daniel Ruggles
May 181 min read


PMO Shortcomings
What issues face existing PMOs or those trying to establish/revitalize a PMO? Excessive bureaucracy, instead of enabling delivery teams. PMOs are often tasked with portfolio oversight but may lack real authority over staffing, budgeting, or prioritization. Overly focused on governance, documentation, status reporting, and rigid processes. Teams are spending more time updating dashboards and preparing presentations than solving actual business problems Some PMOs operate as iso
Daniel Ruggles
May 61 min read


Project Management Office (PMO)…why have one
Attributes associated with building the case for a PMO include: Implementation of a project management methodology (if in doubt use PMBOK...
Daniel Ruggles
Jan 7, 20232 min read


Communication Etiquette
E-mail seems to be the preferred method of communication for teams regardless of how widely dispersed they might be to one another. ...
Daniel Ruggles
Jan 7, 20233 min read


The case for serverless architecture
Serverless technology should not be applied to all application initiatives. Serverless technology should not be applied to all...
Daniel Ruggles
Dec 25, 20222 min read


Kubernetes and Serverless Architecture – Differences and Similarities
Kubernetes and serverless architecture (AWS – Lambdas, Azure Functions, and Google Functions, etc.) offers powerful platforms and...
Daniel Ruggles
Dec 25, 20222 min read


Cloud Migration Success
The keys to a successful cloud migration strategy are: Ensure that the business applications face minimal disruption or long-term outage,...
Daniel Ruggles
Dec 25, 20226 min read
bottom of page