THE DPO CENTRE
Powered by
AI ASSURANCE: Are your existing controls enough?

AI ASSURANCE: Are your existing controls enough?

OCT

20

Tuesday, October 20

2:00 PM - 2:45 PM

Register

You may already have security and privacy controls in place, but with AI being built into more systems and supplier relationships, the challenge is knowing whether those controls mitigate the risks.

Customers may ask for evidence, while you may need similar assurance from your own suppliers. What should you be able to provide and what should you expect in return?

Stanford’s 2026 AI Index* found that ISO/IEC 42001 was already influencing responsible AI decision-making at 36% of organisations surveyed, with NIST AI RMF influencing 33%, reflecting growing interest in more formal AI standards and frameworks.

In this session, experts from IS Partners and the DPO Centre will discuss how to assess existing controls, identify gaps, and bring security assurance, data protection and AI governance together.

You’ll learn:

  • Where AI can expose gaps in existing security and privacy controls
  • How NIST AI RMF, HITRUST AI and established assurance approaches such as SOC 2 fit into a wider AI assurance approach
  • What evidence to look for when assessing third-party AI suppliers
  • How to give customers assurance that your controls are in place and working

 

The session will close with a Q&A, with the chance to ask experts from the DPO Centre and IS Partners about your own AI assurance and governance challenges.

 

*The 2026 AI Index Report, Stanford HAI

Speakers

Michael  McCagh

Michael McCagh

Data Protection Officer, DPO Centre

Michael is a highly qualified Data Protection Officer and certified AI Governance Professional. He has over 10 years’ experience advising organisations on global data protection legislation and AI compliance. Michael develops cross-jurisdictional privacy programmes and governance frameworks that support innovation while managing regulatory risk. With deep expertise in the EU AI Act and emerging technologies, he helps organisations stay ahead of rapidly evolving legal and compliance expectations.

Ian Terry

Ian Terry

Senior Director, Cybersecurity Services, IS Partners

Ian has a strong background in healthcare security, supporting organisations with risk assessments, remediation, and compliance against recognised frameworks. His work has included helping businesses achieve HITRUST certification and contributing to the development of SaaS security tools. Working across cybersecurity and assurance, Ian helps healthcare providers and business associates in applying practical security controls that align with regulatory requirements and operational realities.

Joe Ciancimino

Joe Ciancimino

Senior Director, Attest Services, IS Partners

Joe has over 10 years’ experience in IT audit and assurance, helping organisations assess the effectiveness of their controls across complex technology and regulatory environments. His expertise includes System and Organisation Controls (SOC) reporting and leading audits against ISO 27001 and ISO 42001. Joe works closely with organisations to identify weaknesses and respond to evolving cybersecurity, technology, and AI governance requirements while maintaining robust and effective controls.

Angelique Hamilton

Angelique Hamilton

Data Protection Officer, DPO Centre

Angelique is an accomplished Data Protection Officer and privacy professional with over 20 years’ experience in information governance and regulatory compliance. She has led transformative programmes across various sectors, with expertise in AI governance and risk management. Angelique advocates for the thoughtful and transparent use of advanced technologies and is known for her collaborative approach to strengthening compliance and driving meaningful change.

OCT

20

Tuesday, October 20

2:00 PM - 2:45 PM

Register