Portfolio

Tristan Jones

Technology risk and AI governance professional. 15+ years in IT audit, cybersecurity controls, and financial services.

IT Management2010–2016
IT Audit2016–2022
IT Risk & AI Governance2022–Present

Currently targeting

AI Governance LeadTechnology Risk ManagerAI Risk & Controls ArchitectSenior IT Audit Manager

Synthetic demonstration environment. Heritage Community Bank is fictional. All facts, findings, evidence, and deliverables were created for portfolio and methodology testing.

Completed Work

Full case studies with methodology, evidence, and deliverables.

Risk AssessmentPublished
Board Risk Appetite Report

Turn Board risk tolerance into an operational decision framework. A structured governance process that converts individual director perspectives into quantified risk appetite, resolves material disagreement, establishes Board-approved thresholds, and calibrates assessment severity across six enterprise risk domains. Board intent → risk thresholds → severity calibration → remediation priority.

Risk AppetiteBoard GovernanceSeverity CalibrationFinancial Services
Controls & CompliancePublished
CRI Coverage Assessment — PR.AA-01.01

Turn regulatory requirements into evidence-traceable coverage decisions. A governed, AI-assisted assessment of 568 institutional controls against 16 CRI v2.2 Identity and Credential Management capabilities — producing reproducible coverage conclusions, structured findings, remediation priorities, and a complete human-review audit trail. Every conclusion traceable. Every judgment reviewable. No client data leaves the environment.

CRI ProfileCoverage AssessmentFinancial ServicesAI-Assisted
Risk AssessmentPublished
CRI Threat Advisory — From Control Gaps to Threat-Informed Risk Decisions

Transform control coverage gaps into actionable threat intelligence by connecting CRI requirements to adversary behavior, defensive countermeasures, regulatory exposure, detection opportunities, and prioritized remediation. This demonstration shows how a defensible analytical chain can bridge GRC, cyber risk, and security operations while preserving evidence lineage and distinguishing assessed fact from analytical inference. AI-assisted, human-governed analysis with explicit provenance and review boundaries.

MITRE ATT&CKD3FENDThreat MappingCRI ProfileDetection EngineeringFFIEC
Tooling & AutomationPublished
Control Profiler

Turn unstructured control libraries into reusable governance intelligence. An AI-assisted classification engine that converts institutional controls into structured metadata across 18 action verbs, 7 dimensions, and SCF-aligned domains — enabling one control library to be systematically mapped across CRI, NIST CSF, SOC 2, PCI-DSS, ISO 27001, and other frameworks. Classify once. Map repeatedly. Preserve human judgment.

Control ProfilingSCFMetadataAI-AssistedFramework Mapping

Vision

The CRI Assessment WorkBench

Human-Led · AI-Assisted · Audit-Defensible

Transform AI from an assessment engine into a governed assessment partner that accelerates expert reviewers while preserving human judgment and accountability.

Download the deck (PDF)
The CRI Assessment WorkBench — slide 1 of 9
The CRI Assessment WorkBench — slide 2 of 9
The CRI Assessment WorkBench — slide 3 of 9
The CRI Assessment WorkBench — slide 4 of 9
The CRI Assessment WorkBench — slide 5 of 9
The CRI Assessment WorkBench — slide 6 of 9
The CRI Assessment WorkBench — slide 7 of 9
The CRI Assessment WorkBench — slide 8 of 9
The CRI Assessment WorkBench — slide 9 of 9

Current Research

In-progress work that will become full case studies.

Threat-Informed Risk Assessment

Risk Assessment

AI Governance in Operation

AI Governance

Integrated Risk Deliverables

Tooling & Automation

MITRE Validation Methodology

Controls & Compliance

AI Observability (Splunk)

Tooling & Automation

Conversation Starters

Questions to Ask Me

  • Walk me through your CRI assessment methodology — what makes it threat-informed?
  • How did you handle control design for a department being onboarded at MUFG?
  • What is your approach to AI governance beyond policy writing?
  • How do you maintain human accountability when using AI in assessment?