Portrait of Farhoud Shirzadi
FARHOUD SHIRZADI

AI RISK GOVERNANCE & AUDIT

Builder of Pegesis (policy-first AGS) — agents compute under policy, emit schema-validated outputs, and only then narrate. Runtime approvals, output controls (block/redact/route/approve), and a Decision Trace yield deterministic, auditable, offline results.

ELLITE RECURSIVE-GENIUS 100×

Skills — Governance & Assurance

Experience

Governance Signals (What Audit Cares About)

Architecture — Policy Router & Cognitive Loop

Intent & Org Detection: Cognitive loop extracts intent & organization, then the policy router selects ags/clients/{org}/{domain}, inheriting/merging relevant policies.

Enforcement: The merged policy governs calculators, data retrieval, redaction, output schemas, and presentation style. Outputs can be composite (analytics table + chart + summary) or specialized (e.g., heatmap for “report walmart service for last week”).

Secrets & Safety: Sensitive fields (e.g., sessionToken, accessKeyId, token) are masked and excluded from review trails while maintaining trace integrity.

Decision Trace & Evidence (Proof, not promises)

Target Roles — RBC

Targeting roles that require governance-by-design, runtime controls, and strong auditability for AI systems.

Best-Fit Families

  • AI Governance / Responsible AI / AI Risk & Controls
  • Model Risk / Validation / Audit (incl. GenAI/LLM)
  • Data Trust & Privacy, Third-Party & Platform Controls
  • AI Platform Guardrails / Safety Engineering

Regulatory & Control Alignment

  • NIST AI RMF 1.0 • ISO/IEC 23894 (AI risk) • SOC 2
  • OSFI (Model Risk & Third-Party) • PIPEDA • GDPR
  • Secure SDLC • Change Management • Explainability

What I Bring

Projects

Resume — AI Risk Governance & Audit

Targeting roles that require controls, evidence, explainability, and safe enablement of AI at scale.

Summary

  • Built a policy-first AGS (Pegesis): approvals & output controls embedded in execution.
  • Evidence by default: Decision Trace with deterministic replay manifests.
  • Composite outputs: calculators & templates → policy-styled reports or visuals (e.g., heatmaps), then optional narration (fact-locked).

Core Competencies

  • AI Governance & Risk • Policies & Controls • Approvals/Redaction/Routing • Evidence & Lineage
  • Model/Platform Risk • Explainability • Secure SDLC • Change Management • SoD • Audits & KRIs
  • Python • FastAPI • WebSockets • MS SQL • Weaviate • Azure • Docker • Cloudflare

Links

Education

Two-year Computer Science Diploma (co-op), Canada

Contact

Toronto, ON • Canada
Email: shirzadif@hotmail.com
LinkedIn: linkedin.com/in/farhoudshirzadi