About

Tristan Jones

AI governance, technology risk, and audit professional with 15+ years of experience assessing technology controls and designing evidence-based risk methodologies for financial institutions. Develops traceable AI and cybersecurity governance assessments aligned with NIST AI RMF, CRI, NIST 800-53, ISO/IEC 42001, and ISO 27001.

View Resume

Career Arc

From building systems to auditing them to governing AI that augments the work.

2010 — 2016

IT Management

Built and managed enterprise IT infrastructure — servers, databases, networks, and end-user systems. Hands-on with the full technology stack before moving to the audit side.

2016 — 2022

IT Audit

Transitioned to IT audit under ISACA COBIT methodology. Designed and executed audits for enterprise systems, access controls, change management, and data integrity.

2022 — Present

IT Risk & AI Governance

Specialized in threat-informed risk assessment, AI governance, and CRI Profile implementation for financial services. Building a governed AI workforce for audit automation.

During a major banking engagement, I recognized that expert advisory work was being crowded out by manual assessment effort. I designed a methodology and supporting platform that compresses the assessment phase so senior practitioners can spend more time interpreting verified gaps, challenging assumptions, and advising leadership on threat-informed risk.

What Sets This Apart

Technical Depth

I built servers and databases before I audited them. When I assess a control, I understand the system underneath it — not just the policy document.

Threat-Informed

Every assessment starts with the threat landscape, not the compliance checklist. Controls exist to mitigate specific adversary behaviors — MITRE ATT&CK is the map.

AI-Augmented

A governed AI workforce handles repetitive analysis while I focus on judgment. Same rigor I apply to client controls, I apply to my own AI agents.

Certifications

Active and in-progress credentials. Click a card to see what it covers.

CISA

Active

Certified Information Systems Auditor

ISACA

CISA

click to flip back

Validates expertise in auditing, controlling, and assessing enterprise IT and business systems.

Knowledge Domains

IS Audit ProcessIT GovernanceIS Acquisition & DevelopmentIS Operations & ResilienceInformation Asset Protection

AAIA

Active

Advanced in AI Audit

ISACA

AAIA

click to flip back

Validates ability to assess AI systems for governance, risk, ethics, and regulatory compliance.

Knowledge Domains

AI Governance & StrategyAI Development & ImplementationAI Operations & MonitoringAI Risk & Compliance

AWS AIF

Active

AWS Certified AI Practitioner

AWS

AWS AIF

click to flip back

Validates understanding of AI/ML concepts, generative AI, and responsible AI practices on AWS.

Knowledge Domains

AI & ML FundamentalsGenerative AI FoundationsFoundation Model ApplicationsResponsible AIAI Security & Compliance

CRISC

Previously Certified

Certified in Risk & IS Control

ISACA

CRISC

click to flip back

Validates expertise in identifying and managing enterprise IT risk and implementing information systems controls.

Knowledge Domains

IT Risk IdentificationIT Risk AssessmentRisk Response & ReportingIT & Security Controls

Mentors

I owe my level of expertise to these three professionals. Each shaped a different dimension of how I approach risk, audit, and governance work.