Runa Dalal builds the frameworks CISOs hand to their boards.
A working toolkit of AI governance frameworks, risk assessments, and practice-building strategy — built by a practitioner and sharpened through real engagements, turning regulatory pressure into governance programs that pass audit, and AI adoption into something a risk committee can actually sign off on.
Runa Dalal builds the frameworks CISOs hand to their boards. Every artefact, every chapter, every credential in this track exists to close one gap: the distance between regulatory pressure and a governance program that actually passes audit.
AI adoption is accelerating faster than most risk committees can process. The work here turns that pressure into something a board can sign off on — structured, evidence-backed, and repeatable.
Frameworks that pass audit and satisfy risk committees.
Turning a single engagement into a scalable, sellable offering.
Translating technical risk into executive-ready language.
Frameworks built, not just referenced. Every artefact below started as a real engagement problem — 'how mature are we, really?' — and was generalized into something reusable.
A practitioner-level introduction to the OWASP AI Maturity Assessment model: its lineage, its business-function layers, and why regulated use cases need it.
A diagnostic tool for scoping an organization's AI risk exposure, including a risk heat map and a sequenced remediation roadmap.
A ten-category set of exploratory questions to ask before running any AI maturity assessment, designed to surface the evidence gaps that a self-reported maturity score usually hides.
End-to-end consent governance framework — discovery through ongoing monitoring — mapped across GDPR, CCPA, LGPD and India's DPDP Act, with block-until-consent technical controls.
This workflow covers the full lifecycle of consent governance — from initial discovery of data touchpoints through to ongoing monitoring — ensuring compliance across all major privacy jurisdictions simultaneously.
A market-entry and growth strategy for a professional services firm's Global Capability Centre practice — the throughline from GRC delivery into practice-building and go-to-market thinking.

A nine-chapter field guide for risk leaders taking AI governance from a one-off assessment to a repeatable, sellable practice. Structured across three acts.
Map your AI landscape. Understand what you have, what you've borrowed, and where your data governance stands.
Adopt frameworks, score maturity with evidence, and design the policies and controls your AI systems need.
Turn your framework into a practice offering, sell governance to boards, and build the business case for growth.
You Can't Govern What You Haven't Mapped
Pillar: AI Inventory & Maturity Baselining
Borrowed Risk — Governing AI You Didn't Build
Pillar: Vendor & Third-Party AI Risk
Data Governance & Consent in the Age of AI
Pillar: Data Governance & Consent

The first act is about visibility. Before any governance program can be designed, risk leaders need a complete picture of their AI landscape — what systems exist, which are built in-house versus procured, and where data flows across the organization.
Chapters 01 and 02 are live and available now. Chapter 03 on data governance and consent is in development.
Adopting OWASP AIMA and the NIST AI RMF
Framework Adoption · Coming soon
Maturity Scoring & Evidence
Assessment & Evidence · Coming soon
Policy & Control Design for AI Systems
Policy & Control Design · Coming soon
Turning a Framework into a Practice Offering
Practice-Building · Coming soon
Selling Governance to a Board That Doesn't Speak Risk
Executive & Board Reporting · Coming soon
The Case for the Business
Go-to-Market & Growth Strategy · Coming soon
Building toward AI governance, deliberately — sequenced to compound with what's already there, ISO 27001 depth extending directly into AI-specific governance standards.
Held. The base the rest of this track is built on. Deep implementation experience in information security management systems — the structural foundation for everything that follows.
Prioritized first for its regulatory breadth. The IAPP AI Governance Professional credential covers the full spectrum of AI regulatory frameworks — EU AI Act, NIST AI RMF, and emerging global standards.
AI management systems — a direct extension of the 27001 base. ISO 42001 is the emerging international standard for AI management systems, and the natural next step for practitioners who have already built on the 27001 foundation.
One chapter a month, plus the artefact it's built on. No spam, no drip campaign — just the framework.
© 2026 Runa Dalal. Bengaluru → Available for advisory & partner-track conversations.
AI governance framework design, risk assessments, and board-ready reporting for regulated organizations.
For professional services firms looking to build or scale a GRC or AI governance practice.
Runa Dalal — Cyber Risk & AI Governance Advisory