TEGH VIRK
AI Governance Lab Online
Résumé
AI GOVERNANCE × GRC × CYBERSECURITY

Govern AI before AI governs risk.

I’m Tegh Virk — a GRC, audit, and information security professional applying proven control thinking to AI governance, responsible AI, model risk, and enterprise AI assurance. Govern.

AI Governance FocusNIST AI RMF · ISO/IEC 42001
Trust LayerRisk · Controls · Assurance
FoundationCISA · Security+ · ISO Audit
AI GOVERNANCE ROUTESSELECT MODULE
AI GOVERNANCE · MODEL INVENTORY · IMPACT ASSESSMENT · HUMAN OVERSIGHT · DATA GOVERNANCE · MODEL MONITORING · GENAI RISK · TRANSPARENCY · THIRD-PARTY AI · AI INCIDENT RESPONSE ·
02 / GOVERNANCE OPERATING SYSTEM

Turn AI principles into operational controls.

The governance layer connects strategy, ownership, risk classification, data governance, human oversight, testing, monitoring, third-party assurance, and incident management into one auditable control environment.

CONTROL STACKLIVE
GOV-01AI Inventory & Ownership

Identify models, use cases, vendors, accountable owners, business purpose and lifecycle status.

RISK-02AI Impact & Risk Assessment

Classify potential harms, affected stakeholders, data sensitivity, security and regulatory exposure.

HUM-03Human Oversight

Define decision rights, escalation paths, override authority and review requirements.

MON-04Post-Deployment Monitoring

Track model quality, drift, incidents, complaints, control failures and material changes.

03 / AI LIFECYCLE ASSURANCE

Governance follows the model from idea to retirement.

The strongest AI governance program is not a one-time compliance review. It follows the system lifecycle—before procurement or development, through testing and deployment, and into continuous monitoring and eventual retirement.

1 / Intake

Use Case Triage

Purpose, owner, users, affected people, decision criticality and model type.

2 / Assess

AI Impact Assessment

Risk tier, privacy, security, safety, fairness, transparency and legal impact.

3 / Validate

Testing & Evaluation

Robustness, misuse, hallucination, prompt-injection, bias and control effectiveness.

4 / Operate

Monitoring & Change

Drift, incidents, model updates, vendor changes, user feedback and re-approval.

AI
ASSURANCE
01INTAKE
02ASSESS
03TEST
04APPROVE
05MONITOR
06RETIRE
04 / REGULATORY & RISK RADAR

One control layer. Multiple AI regimes.

The portfolio centers on translating AI requirements into reusable governance controls instead of managing every framework in isolation.

Risk Framework

NIST AI RMF

Use the Govern, Map, Measure and Manage functions to structure trustworthy AI risk management.

Management System

ISO/IEC 42001

Build an Artificial Intelligence Management System with policies, objectives, risk treatment and continual improvement.

Generative AI

NIST GenAI Profile

Extend AI risk management to generative-AI risks and corresponding risk-management actions.

Regulation

EU AI Act

Risk-based obligations, AI literacy, GPAI governance and transparency requirements inform enterprise control design.

MODEL RISKLEGALSECURITYTRUST
05 / EXPERIENCE BRIDGE

Existing GRC depth, redirected toward AI assurance.

My AI-governance positioning is grounded in real audit, security, access, process-control and compliance work—not a fictional AI job title.

2026

Stanford Health Care — IT Intern

Clinical and enterprise technology support across ServiceNow, Epic, Workday, access workflows, software governance, audit readiness and endpoint operations.

Access GovernanceAudit ReadinessClinical SystemsSoftware Review
2022 — Present

Fabrinet — Process Technician

Controlled documentation, quality compliance, audit evidence, CAPA, traceability, test procedures and change control in electronics manufacturing.

Process ControlTraceabilityCAPAEvidence
2021 — 2022

PwC — Associate, IT Audit

NIST-based assessments, ITGC / SOX / ISO 27001 audit work, ISMS policies, control validation, risk reporting and security awareness.

NISTISO 27001ITGCISMS
2021

Deloitte — Audit Intern

Third-party compliance, data risk assessments, security-standard exceptions, evidence gathering, maturity assessments and remediation recommendations.

Third-Party RiskPCI DSSHIPAARisk Assessment
06 / TRUST CREDENTIALS

Audit credentials behind the AI governance story.

UNLOCKED 2024

CISA

Certified Information Systems Auditor · ISACA

UNLOCKED 2024

Security+

CompTIA Security+

UNLOCKED 2023

CSM

Certified Scrum Master · Scrum Alliance

UNLOCKED 2021

ISO/IEC 27701

Lead Auditor credential

AI GOVERNANCE LAB

NIST AI RMF · ISO/IEC 42001 · GenAI Governance

Portfolio focus: control mapping, AI inventories, impact assessments, human oversight, AI vendor risk, model monitoring, AI incident response and regulatory traceability.

EDUCATION

UPES · Stanford · UC Santa Cruz · Year Up United

B.Tech Computer Science, Product Market Fit, Project & Program Management, and Network Security.

07 / CONTACT

Building the control layer for responsible enterprise AI.

Open to AI Governance, Responsible AI, GRC, AI Risk, IT Audit, Cybersecurity, Trust & Safety, and Information Security conversations.