Sarfaraz Chougule
Board & AdvisoryAI Governance · Cyber Risk22+ Years · CISSPIndia / US / EU

The pager, not the deck.

Statement

More than two decades running global IT and security functions in regulated industries. I owned the budget, the uptime and the audit date. Now I advise boards and executive teams on technology risk and AI governance. Most AI governance is written by people who never owned an audit. Mine comes from the other side.

Evidence below
Board Advisory AI Governance CMMC GovRAMP ISO 27001 NIST HIPAA M&A Integration Cloud Modernisation Enterprise Architecture

Carried, not observed

Selected · across 22+ years
001Product

MSP Copilot

Agentic automation for day-to-day M365 and Azure operations, with a full audit trail on every action. Approval workflows, rollback, permission boundaries. The model took a weekend; the governance took months. Internal tool that became a product.

Agentic AIBuilt & shipped
002Regulated

CMMC & GovRAMP readiness

Implementation in environments where audit readiness and risk mitigation are not negotiable. Control design, evidence discipline, and the unglamorous work of proving it — to assessors who do not accept intent as evidence.

US Defense & GovLed
003Operations

M&A, integration, transition

Global IT and security functions with full operational and financial accountability. Large-scale integrations and offshore transitions — where the risk is never the technology, it is the six months where two estates run at once.

P&L ownershipAccountable
004Governance

Board oversight & cyber maturity

Translating technology complexity into structured oversight, measurable controls and informed decisions. Maturity reporting directors can act on, and risk framed against enterprise strategy rather than control counts.

Board & ExCoAdvised
005Architecture

Cloud modernisation

Enterprise architecture and cloud programmes aligned to ISO 27001, NIST and HIPAA — delivered inside real constraints of legacy estate, budget cycles and audit calendars, not on a whiteboard.

AWS · AzureOwned
The Clock

What boards should be watching

The regulatory calendar that actually reaches the board agenda. Maintained weekly. If it moves, this moves.

In forceEU AI Act · Article 50 transparency02 AUG 2026Live
NextDPDP · consent manager provisions13 NOV 2026T−58d
CriticalDPDP · full enforcement, maximum penalties13 MAY 2027T−239d
DeferredEU AI Act · high-risk systems, Annex III02 DEC 2027T−442d
DeferredEU AI Act · high-risk in regulated products02 AUG 2028T−686d

Two caveats most consultants won't tell you. As of August 2026 the Data Protection Board still has no Chairperson and no Members — MeitY was advertising all five posts as recently as June. And the 12-month compression MeitY floated in January covers Significant Data Fiduciaries, not everyone, and has not been gazetted. Plan for May 2027. Watch November 2026.

Reporting this to a board? Cybersecurity board reporting — what belongs on the page, what to cut, and the cadence that holds →

Point of view

Positions I'll defend

I write regularly on LinkedIn. These four are the positions underneath — the ones I keep coming back to, and the ones I'll argue in a room.

The weekly posts, on LinkedIn
On agents001

Governance is the accelerator

It is not what slows agents down. It is what lets you say yes to the next ten use cases without flinching.

On evidence002

If it can't be audited, it isn't ready

An agent that cannot explain every action, name who approved it and produce evidence for an auditor is not enterprise-ready.

On delivery003

No accountable owner, no green light

Most failed programmes were doomed at kickoff. Steering committees diffuse responsibility; shared ownership works right up until something breaks.

On adoption004

Clean process beats bold adoption

Agents reward the tightest guardrails, not the earliest mover. They surface every gap you have quietly tolerated — in production, at the worst moment.

Open to

Board. Advisory. Leadership.

Three conversations I'm having. Each is a different commitment, and I'd rather be explicit about which is which.

Board & advisory

Non-executive and advisory roles where technology risk, AI governance and regulatory readiness need someone who has owned the outcome, not just reviewed the paper.

Commitment
Quarterly

Senior leadership

CIO, CISO and equivalent mandates — global functions, regulated environments, transformation or integration programmes carrying real operational and financial accountability.

Commitment
Full time

Selective consulting

A small number of engagements a year: AI governance frameworks, CMMC and GovRAMP readiness, and cyber maturity reporting that survives a board's second question.

Commitment
Scoped
Boundaries

What I don't do

  • 01
    Certify anyoneCMMC assessment is for authorised C3PAOs. SOC 2 attestation requires a licensed CPA firm. ISO certificates come from accredited bodies. I get organisations ready and work alongside whoever assesses them.
  • 02
    Audit what I builtIndependence rules exist for a reason. If I designed the control environment, someone else assesses it.
  • 03
    Sell AI strategy without governanceAn agent programme without approval workflows, rollback and an audit trail is technical debt with a demo attached. I won't help build the demo.
  • 04
    Take a mandate without an accountable ownerNo single accountable owner, no green light. It has saved more budgets than any framework, and it is the one thing I won't negotiate.
Contact

Start a conversation

Board, advisory, leadership or a scoped engagement. Tell me which and what the constraint is.

me@sarfarazchougule.com

Direct. No form, no gatekeeper, no autoresponder.