Runa Dalal — Cyber Risk & AI Governance Advisory

Runa Dalal builds the frameworks CISOs hand to their boards.

A working toolkit of AI governance frameworks, risk assessments, and practice-building strategy — built by a practitioner and sharpened through real engagements, turning regulatory pressure into governance programs that pass audit, and AI adoption into something a risk committee can actually sign off on.

Bengaluru, IndiaISO 27001 Lead ImplementerIAPP AIGP (in progress)OWASP AIMA Practitioner
Get Notified

What This Practice Does

Runa Dalal builds the frameworks CISOs hand to their boards. Every artefact, every chapter, every credential in this track exists to close one gap: the distance between regulatory pressure and a governance program that actually passes audit.

AI adoption is accelerating faster than most risk committees can process. The work here turns that pressure into something a board can sign off on — structured, evidence-backed, and repeatable.

Regulatory Pressure → Governance Programs

Frameworks that pass audit and satisfy risk committees.

One-Off Assessment → Repeatable Practice

Turning a single engagement into a scalable, sellable offering.

AI Adoption → Board Sign-Off

Translating technical risk into executive-ready language.

Artefact Register — The Toolkit

Frameworks built, not just referenced. Every artefact below started as a real engagement problem — 'how mature are we, really?' — and was generalized into something reusable.

AI Governance Artefacts

AIMA-01 — AI Governance Framework Primer

A practitioner-level introduction to the OWASP AI Maturity Assessment model: its lineage, its business-function layers, and why regulated use cases need it.

Presentation-readyNIST AI RMFEU AI Act

AIMA-02 — AI Governance Gap & Risk Assessment Template

A diagnostic tool for scoping an organization's AI risk exposure, including a risk heat map and a sequenced remediation roadmap.

Presentation-readyMaturity scorecard

AIMA-03 — AI Maturity Scoping Question Bank

A ten-category set of exploratory questions to ask before running any AI maturity assessment, designed to surface the evidence gaps that a self-reported maturity score usually hides.

Working documentPre-assessment

Compliance & GTM Artefacts

GRC-04 — Eight-Stage Cookie & Consent Deployment Workflow

End-to-end consent governance framework — discovery through ongoing monitoring — mapped across GDPR, CCPA, LGPD and India's DPDP Act, with block-until-consent technical controls.

Field-testedMulti-jurisdiction

This workflow covers the full lifecycle of consent governance — from initial discovery of data touchpoints through to ongoing monitoring — ensuring compliance across all major privacy jurisdictions simultaneously.

GTM-01 — Regional Market Growth Strategy for a GCC Practice

A market-entry and growth strategy for a professional services firm's Global Capability Centre practice — the throughline from GRC delivery into practice-building and go-to-market thinking.

DeliveredGTMPractice-build

The Practice Playbook

A nine-chapter field guide for risk leaders taking AI governance from a one-off assessment to a repeatable, sellable practice. Structured across three acts.

1

Act I — See It

Map your AI landscape. Understand what you have, what you've borrowed, and where your data governance stands.

2

Act II — Govern It

Adopt frameworks, score maturity with evidence, and design the policies and controls your AI systems need.

3

Act III — Scale It

Turn your framework into a practice offering, sell governance to boards, and build the business case for growth.

Act I — See It

Chapters 01–03: Building the Foundation of Visibility

Chapter 01

You Can't Govern What You Haven't Mapped

Pillar: AI Inventory & Maturity Baselining

Live

Chapter 02

Borrowed Risk — Governing AI You Didn't Build

Pillar: Vendor & Third-Party AI Risk

Live

Chapter 03

Data Governance & Consent in the Age of AI

Pillar: Data Governance & Consent

Coming soon

The first act is about visibility. Before any governance program can be designed, risk leaders need a complete picture of their AI landscape — what systems exist, which are built in-house versus procured, and where data flows across the organization.

Chapters 01 and 02 are live and available now. Chapter 03 on data governance and consent is in development.

Act II & III — Govern It & Scale It

1

Chapter 04

Adopting OWASP AIMA and the NIST AI RMF

Framework Adoption · Coming soon

2

Chapter 05

Maturity Scoring & Evidence

Assessment & Evidence · Coming soon

3

Chapter 06

Policy & Control Design for AI Systems

Policy & Control Design · Coming soon

4

Chapter 07

Turning a Framework into a Practice Offering

Practice-Building · Coming soon

5

Chapter 08

Selling Governance to a Board That Doesn't Speak Risk

Executive & Board Reporting · Coming soon

6

Chapter 09

The Case for the Business

Go-to-Market & Growth Strategy · Coming soon

Credential Track

Building toward AI governance, deliberately — sequenced to compound with what's already there, ISO 27001 depth extending directly into AI-specific governance standards.

Foundation — ISO/IEC 27001 Lead Implementer

Held. The base the rest of this track is built on. Deep implementation experience in information security management systems — the structural foundation for everything that follows.

In Progress — IAPP AIGP (AI Governance Professional)

Prioritized first for its regulatory breadth. The IAPP AI Governance Professional credential covers the full spectrum of AI regulatory frameworks — EU AI Act, NIST AI RMF, and emerging global standards.

Next — ISO/IEC 42001 Lead Implementer

AI management systems — a direct extension of the 27001 base. ISO 42001 is the emerging international standard for AI management systems, and the natural next step for practitioners who have already built on the 27001 foundation.

Get in Touch

Get the Next Chapter When It Drops

One chapter a month, plus the artefact it's built on. No spam, no drip campaign — just the framework.


© 2026 Runa Dalal. Bengaluru → Available for advisory & partner-track conversations.

Bengaluru, IndiaISO 27001 Lead ImplementerIAPP AIGP (in progress)OWASP AIMA Practitioner

Advisory Engagements

AI governance framework design, risk assessments, and board-ready reporting for regulated organizations.

Partner-Track Conversations

For professional services firms looking to build or scale a GRC or AI governance practice.