Skip to main content
AUTHOR

Alyssa O'Brien

CEO, Devensa, Inc.

Articles by Alyssa

Title card: Is your AI governance tool actually governance? Governance sits above controls.

AI Governance

Is Your AI Governance Tool Actually Governance?

Many AI governance tools are controls tools. Learn how governance and controls differ, why it matters, and what to ask before you buy.

A DPO oversight ring beside a separate product team box. Independent oversight is not operational authority.

Privacy

Who Owns Privacy? Why a DPO Title Doesn't Guarantee Accountability

Twenty US states now have comprehensive privacy laws in effect. See why an independent DPO still isn't the same as owning privacy operationally.

Data lineage from sign-up form to CRM to a named owner. Three hands touch the customer record and one is accountable.

Data Governance

Who Actually Owns the Data?

Poor data quality costs the average organization $12.9 million a year, according to Gartner. See why the owner-versus-custodian confusion is usually to blame.

Obligation map linking three obligations to control owners. One has a named owner and two are unassigned.

Compliance

Who Owns This Requirement?

Nearly 4 in 10 organizations have lost revenue or a bid over missing compliance evidence. See why tracking a requirement isn't the same as owning it.

Risk register with four owner rows. Three list a department and one lists a named person, J. Alvarez.

Risk Management

What Happens When Risk Ownership Isn't Assigned

Firms without board-level risk visibility are 20% more likely to face major risk events. See what happens when a risk register lists departments instead of names.

Two overlapping circles labelled IT and Security, with the overlap asking who decides. IT keeps the lights on. Security decides the risk.

Cybersecurity

Security Ownership: Why “IT Handles That” Is Usually Wrong

IT and security get treated as one job. They aren't. See where that confusion actually breaks, and what the 2026 DBIR shows about the cost of unassigned risk decisions.

Use case inventory with eight tiles and one reviewed. Six departments already use AI, and one tool got a risk review before launch.

AI Governance

What Happens When No One Owns the AI Policy

A policy without a named owner is a document, not a control. See what shadow AI adoption looks like without real governance behind it.

Two lines for the finance ledger and product analytics converge on one reported number once governance is applied.

Data Governance

Five Data Findings That Repeat in Every Audit

Poor data quality costs the average company $12.9M a year. See the five data findings that repeat in audit after audit and what actually fixes them.

Oversight perimeter drawn around a network of twelve observed AI systems. The frame is the deliverable.

AI Governance

Five Signs an AI Deployment Has No Governance Behind It

No model inventory, no owner when things go wrong, no real review before approval. See the five signs an AI deployment has no governance behind it.

Board view with a compass and four live risk scores for third-party risk, regulatory change, incident exposure and control coverage.

Risk Management

Five Signs Your Risk Register Is a Filing Cabinet, Not a Tool

Firms without board-level risk visibility are 20% more likely to face major risk events. See the five signs a risk register has stopped being a tool.