The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/AI & Data/LEAD WITH DATA Podcast
LEAD WITH DATA Podcast artwork

Season 6 - Episode 8 - "When Governance Stopped Being a Document and Became a System" with Natalie Hogan

LEAD WITH DATA Podcast · 2026-08-01 · 38 min

0:00--:--

Key moments - from our scoring

Substance score

64 / 100

Five dimensions, 20 points each

Insight Density13 / 20
Originality12 / 20
Guest Caliber15 / 20
Specificity & Evidence11 / 20
Conversational Craft13 / 20

Natalie Hogan, working in superannuation and regulated finance, explains how her organization moved beyond traditional siloed governance frameworks to create an integrated policy-as-code system that integrates with AI agents. The core insight: governance dies not in crisis but when policies remain documents that people don't understand or follow. By chunking policies into knowledge bases readable by both humans and AI, and deploying AI agents to guide users through processes, her team made governance an enabler rather than a blocker. They built dozens of agent types - from capturing AI governance knowledge three times daily to monitoring live member-facing chatbots to flagging next-best-actions in call centers. The approach required building data semantic models, partnering with technical specialists who could apply data engineering principles to AI governance, and taking a risk-based approach (starting with highest-risk initiatives like autonomous systems and member-facing tools). For regulated industries managing APRA reporting, superannuation advice rules, and emerging psychosocial hazard laws, this system bridges the gap between policy intent and actual practice, turning governance from a compliance checkbox into continuous, embedded oversight.

Key takeaways

  • →Transform governance from static documents into policy-as-code: chunk policies into human- and AI-readable knowledge bases that can be versioned, approved, and updated as industry changes evolve.
  • →Take a risk-backward approach: identify your highest-risk AI initiatives first (autonomous systems, member-facing services, regulated advice), then design governance frameworks specifically to mitigate those risks.
  • →Embed governance into workflow through AI agents: build agents that guide users through compliant processes, monitor quality in real-time, and automate repetitive governance checks rather than relying on training and manual enforcement.
  • →Integrate data and governance teams structurally: governance teams need access to technical specialists who can apply data engineering principles to build semantic models, version-controlled knowledge sources, and automated assessment systems.
  • →Expand governance scope beyond critical data to all data quality rules: AI can monitor broader data dimensions simultaneously using tools like Snowflake, moving beyond fragmented governance of only critical data elements.

Guests

Natalie Hogan

Topics in this episode

Policy-as-codeLLM governanceAI governance semantic modelsAPRA regulated reportingSnowflake (data quality monitoring)Member-facing AI chatbotsAI agent governance frameworkEnterprise model governanceKnowledge base chunkingInfo quality frameworks

Questions this episode answers

What's the difference between data governance and AI governance?

Data governance focuses on ensuring data quality, accuracy, and compliance with established rules (static frameworks like DMBOK). AI governance is about using AI safely and securely while providing guardrails that enable creative, compliant use - it's a dynamic, evolving set of controls because AI itself is constantly changing and doesn't fit traditional governance templates.

How do you make governance policies actually stick instead of just sitting in documents?

Convert policies to policy-as-code: chunk them into knowledge bases readable by both humans and AI, version-control them, require approval before deployment, and deploy AI agents that guide users through processes and automatically check compliance, embedding governance into the workflow rather than relying on training alone.

What kinds of AI agents are you building in superannuation?

Agents range from capturing AI governance knowledge three times daily to monitoring live member-facing chatbots for regulatory compliance, flagging next-best-actions for call center staff, automating assessment workflows, and providing members information about superannuation rules - each designed to automate repeatable tasks while maintaining human oversight on high-risk decisions.

What data foundations or info quality changes are needed for member-facing AI in a regulated industry?

Move from data quality to info quality: knowledge sources must be version-controlled with approval workflows, readable by AI (no ambiguity), readable by humans for review and sign-off, and testable - AI agents can validate that questions get expected answers based on approved knowledge, surfacing drift or hallucinations before they reach members.

What skills and team structure do you need to build governance-as-code with AI agents?

You need technical specialists who can apply data engineering principles to AI engineering, build data semantic models for governance data, and manage version-controlled knowledge sources; positioning your governance team structurally alongside (not separate from) your data and AI practice teams gives you access to these critical specialists.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

13 / 20

The episode contains several valuable ideas about operationalizing governance through AI and policy-as-code, but substantial portions involve explanation of basic concepts (what is AI governance vs. data governance) and repetitive discussion of the same framework. The guest delivers genuine insights about moving from silos to integrated knowledge bases and treating agents as employees, but these are interspersed with considerable throat-clearing and general reflections that don't add density.

The hardest part, I think, for data and AI governance is the embedment. You can have a great policy. Trying to embed that into an organization would take a rollout period, training period. You'd have to do, potentially assessments, checking of what's been done. And now you can have that all built into one.
So the gap between governance on paper and governance, that's really is where a lot of I think Programs tend to die from leaders that I talk to.

Originality

12 / 20

The core concept of policy-as-code and embedding governance into workflows is relatively novel for traditional governance practitioners, and the framing of agents as employees with permissions/access models is interesting. However, the underlying ideas about risk-based approaches, cross-functional collaboration, and iterative learning are standard governance playbook material. The presentation feels incremental rather than fundamentally reconceptualizing the space.

So we have a lot of promptathons, we have a lot of hackathons where we just say be creative and think outside of the box.
we need to treat them as if they are and employee. So we need to ensure that they have the right level of access to the right areas that we've assessed them to ensure that we're not breaching privacy concerns.

Guest Caliber

15 / 20

Natalie Hogan is a credible operational practitioner with 15+ years in superannuation and regulated environments, currently executing governance transformation at scale in a complex, regulated industry. She is clearly embedded in actual implementation work, not a consultant or thought leader. However, her specific seniority level and organizational scope are never explicitly stated, limiting ability to assess true decision-making authority and scale of impact.

Been working in superannuation or finance since I left school and my focus in superannuation has been for the last 15 years originally from financial planning and then moving into risk, uh, reporting and risk performance metrics and uh, moving into regulated reporting as well.
we did a, uh, check on all of that across the organization. We started to look at where our uh, gaps were and what we started to need to bring in.

Specificity & Evidence

11 / 20

The episode contains few concrete examples, metrics, or timelines. While the guest mentions specific governance frameworks (DMBOK, APRA reporting, model governance, agent governance), her descriptions remain largely conceptual. No specific numbers on agent adoption, cost savings, timeline to implementation, or measurable governance improvements are provided. The superannuation regulatory context is relevant but underutilized for concrete examples.

What do I need to do? I'm starting in an AI initiative. How do I go through this process? And it would ask questions reading its knowledge bank and then come back to you with a roadmap that says this is what you need to do to complete this and stay compliant
So if they've got a particular purpose that helps that particular team do a function and you have some that, you know, they might be doing assessments by checking recordings of the service center, for example, and ensuring that they meet certain regulation criteria.

Conversational Craft

13 / 20

The host (Reena) asks solid clarifying questions and demonstrates genuine curiosity about operationalizing governance, with productive follow-ups on data foundations, agent roles, and team capabilities. However, she rarely pushes back on vague claims or asks for specific metrics. The conversation feels collaborative but lacks the edge of rigorous challenge - she accepts conceptual explanations without demanding concrete validation, and misses opportunities to pressure-test the sustainability of the approach or challenge optimistic framing.

So when you went from driving data governance through Having agents and working in practice, uh, what did that mean for the people who were trying to use the data and what did it mean for the business?
Yeah, because I know there's been so many times where I've gone, I just want to know how much I've got in there, how, what's this payment for? And so good to be able to just quickly get that information

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker A69%
  • Speaker C28%
  • Speaker B3%

Most-used words

data63governance50agents23start20different19organization18agent18policy14process14information14across13knowledge12help12approach11started11teams11

Episode notes

I sit down with Natalie Hogan who shares how her organisation moved governance off the page and into daily practice by using AI to rebuild it. Static policies became a living, chunked knowledge base that both people and AI agents could read, query and act on, closing the long-standing gap between governance written down and governance actually followed.

Full transcript

38 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: How do we bring all of those policy documents together and have it in such a format that it can be read by humans, but it can also be read by the AI? So that meant that, you know, we could have a knowledge base, we could chunk it all down into policy info chunks and they can be reviewed little bits at a time. The hardest part, I think, for data and AI governance is the embedment. You can have a great policy. Trying to embed that into an organization would take a rollout period, training period. You'd have to do, potentially assessments, checking of what's been done. And now you can have that all built into one.

Speaker B: Welcome back to the Lead With Data podcast. I'm your host, Reena Gami. I'm, um, co founder of connexus, who specialises in data analytics, recruitment, working with technology and data leaders to identify the right talent for your organization. This podcast is about the real work of leading with data. Not just the technology, but the judgment calls, trade offs and experiences that sit behind the scenes. Each episode features thoughtful conversations with leaders across data, technology and the business, exploring what they've learned, what's been challenging and what's truly made a difference. I would also like to say a sincere thank you to our sponsor, Experian Australia. Through solutions like Aperture Data Studio, Experian helps organizations govern, improve and trust their data so it can drive real business impact. To learn more, visit experian.com au or feel free to get in touch with me and I'll happily connect you with one of the fabulous members of the Experian team. And to all our, uh, listeners, thank you for tuning in. I really appreciate your continued support. Please keep sharing the topics you'd like me to bring to the show.

Speaker C: Welcome back to another episode of the Lead With Data podcast, the show where I sit down with people running data and AI inside real organizations to talk about what actually works and what's not working and their learnings across their journeys. Today we're talking about something every leader is wrestling with right now. How do you let AI agents loose on your data without losing control? And my guest has done it in one of the more kind of harder and regulated environments. Most data governance sort of dies the same way, not in the crisis, but just quietly. You build the frameworks, you write policies, they're good and people look at them as a document, but nobody really understands what they're doing with it or if it's actually working. So the gap between governance on paper and governance, that's really is where a lot of I think Programs tend to die from leaders that I talk to. So in this episode, really wanted to talk about closing that gap with the technology that's now available to us and uh, not just another framework, but actually putting it into the flow of the work itself and how we can make everyone's job easier. So with that, I'd love to welcome you on the show, Natalie. Thank you for joining me.

Speaker A: Thanks Reena. I'm so happy to be here.

Speaker C: I'll start off by just getting you to give us a bit of an overview of your background. I know you don't come from a traditional pure data governance background, so just a very high level background of what you've done and where you're at now.

Speaker A: Been working in superannuation or finance since I left school and my focus in superannuation has been for the last 15 years originally from financial planning and then moving into risk, uh, reporting and risk performance metrics and uh, moving into regulated reporting as well. So doing a lot of reporting for APRA and the strategic view into data and now AI governance.

Speaker C: Great. And I know I heard you speak in the past and I think, you know what's really important in today's topic and age is, is how you make data governance and AI governance, I guess, really, really relatable to people. So I want to start with one question here. Where most governance gets stuck, you, you said that where you're at now and in organizations, you always have good frameworks and good policies. They've been around for a while. The hard part is really making them kind of stick. So for you, what did making them real actually look like and what was it costing when they were just on paper?

Speaker A: Excellent question. For me, moving from traditional governance, where everything is on paper like you said, is siloed. So each individual area of the business have their own frameworks and policies. Uh, they don't speak to each other at all. It made rolling out policies harder and now when we look at it, we want to try and have an enabler where they're just guided through the process. That means the training approach changes for them and it's much, much easier. So all you have to do is train on. Hey, when you need to ask questions, you go to this one location. When you uh, need to complete a registration, you go to this one location. And all of the knowledge lives in the same area and can speak to each other as well and talk to each other. It's a new way of just looking at policy and having policy as code.

Speaker C: So when you went from driving data governance through Having agents and working in practice, uh, what did that mean for the people who were trying to use the data and what did it mean for the business?

Speaker A: Yeah, ah, I guess the biggest shift we've seen is more around the focus into AI. We needed to ensure that the data itself, as it's being ingested by the AI has to use and gets thrown back to the normal data governance that we've been trained on for years and years and years. That is very static. Have they got good data quality rules in place? Are all the data quality meeting across all of the different dimensions? How can you ensure that the data that's being used to train AI is trusted, reliable and accurate? So for us, for them to be able to access that data, we had already been through the uplift of the data in that space. What we're seeing now is the move from beyond just your critical data elements into, if you harness the power of AI, uh, that spreads beyond that one. So you can have AI looking at all of the different data quality rules across all your data as opposed to just your fragmented little bits here and there. You can set the rules to look at it all with the likes of Snowflake for example.

Speaker C: So for the listeners, Natalie, I think what would be really, really interesting is just to understand what was the data governance environment like before you started using AI and um, you know, policies in practice paint a picture of what that was like and what were the considerations and what was your approach to getting to where you're at now.

Speaker A: I went into an environment with data governance that had been around for a very, very long time. It had like, things like the DMBOK that you could follow. It came with a, ah, documented, almost templated policies that you had that you could then roll out across your organization. It was very cookie cutter approach and every organization could pick it up and follow through. When we have now been introduced to AI and had to bring in AI governance as well, we had to throw that rulebook almost out the window. It didn't work for AI governance itself. So we still have our data governance, but on top of that one, we had to have a look at and be almost ahead of the industry in writing our own internal rulebook because nobody has done this really. We're trying to write the rules for something that's constantly changing and evolving and it's never going to be static. So what we had to have a look at as the organization is just say, well, what are our current policies and frameworks that would touch AI that we would need to uplift? So we did a, uh, check on all of that across the organization. We started to look at where our uh, gaps were and what we started to need to bring in. Some of those things were around introducing an enterprise wide model governance that also covered off our machine learning and our uh, LLMs as well, how that would look, rolling that one out to the organization, introducing an agent governance framework as well. At the enterprise level we also have our AI risk management framework. And I think it was at that point where we're saying this is a lot of new policies, a lot of new requirements that is needed for the organization as well. How do we expect all of our employees to be able to understand what they need to do? And that moved it into the next phase, um, which is now that policy as code. How do we bring all of those policy documents together and have it in such a format that it can be read by humans, but it can also be read by the AI. So that meant that, you know, we could have a knowledge base. We could chunk it all down into policy info chunks and they can be reviewed little bits at a time. So if we needed to change anything based on our learning, our uh, testing industry changes, we could go in and just amend a certain part of the knowledge base and then that would feed into the rest of our system basically. So you could have AI agents over the top of that, where you could just go in and ask questions. What do I need to do? I'm starting in an AI initiative. How do I go through this process? And it would ask questions reading its knowledge bank and then come back to you with a roadmap that says this is what you need to do to complete this and stay compliant and you can ask questions along the way. And so, uh, that's where I see the future of AI and data governance is having it in a more chunked down knowledge base that's readable by AI and readable by humans so that we can work together.

Speaker C: Yeah. Okay, so I think when I came into this discussion with you, I, I think I had a different version of what this discussion was going to be about. But what you just said there has just explained it to me. So thank you for that. Now I've got a couple of questions. So when we talk about AI governance, I mean, I obviously know about this, this is our world. What, what's the difference with AI governance and data governance? For somebody who's listening and going, what does it actually mean? And I know it's changing a lot of. But how would you explain that?

Speaker A: So for AI governance it Was how do we use AI safely and securely and provide those guardrails so that we can be creative and we can harness the new powers that are out there to create something really cool and really new and something that can do all sorts of different things depending on where in the workplace you are. So being able to have that as more of a, an enabler to have them safely going through this really confusing, new, difficult, complex space and just make it nice and easy for them. And that in itself is complex as well, like going through that journey. But the best way that we found to be able to provide the guidance and the governance around that one is to immerse ourselves in it as well. And through that process, I think that's how we came to our solution of having AI help us with it as well, is that we need to. It is so complex. And how do we reach all areas of the business simultaneously and keep them up to date as to what is changing constantly?

Speaker C: Yeah, and I think you've hit the nail on the head. I think every organization is trying to figure out how do we encourage our team to use it, or how do we hold them back from doing so much with it, or how do we kind of put parameters around this? And that's a real challenge, you know, and being able to use AI governance to help you do that and make it more accessible and encourage people is great. So I'd love to dig in a bit more into some of the stuff that this has allowed your teams to do. So, Natalie, talk us through some of the AI initiatives and you don't need to go into detail because I understand certain things you can't share, but just talk to us at a high level or give us some examples of some of the things that your teams are doing with AI and what you had to do as, uh, a data on AI governance team to put those parameters and governances in place.

Speaker A: Great, great question for us. We had a look and worked with the business on what a blue sky approach to AI would mean for all the different areas. And then we were able to take some of those amazing ideas and say, well, what is the most high risk approach or a risk AI initiative that we might have? And then how do we govern that? And coming backwards from there, we're just like, cool, okay, well, if we have say something that's completely autonomous, that has no human in the loop, what will we need to do to monitor that one in a completely live scenario? If we had something that was direct to our members, how do we ensure that what's Going out to the members is accurate and isn't providing them with any incorrect information or as you mentioned before, breaching any of those regulations that we have to adhere to as well. So being in superannuation, we have multiple different types of regulation, but we also have advice. So that adds on another complexity in there as well. So once we knew what all the big risks were, we could go backwards from there and say, okay, what do we need to do to fill in that gap and how do we work our way towards that? And so that's when we had a look at, you know, what do we need to bring in from a monitoring perspective and start looking at what sort of toolings that we could bring on to help us understand the live and continuous monitoring of these if they were in place. We needed to have a look at bringing all of the risk and privacy teams on board so that we all spoke as one being in all different areas of the business. We have new laws that we need to consider for WHS in New South Wales, for psychosocial hazards in the workplace and what these agents and AI might bring. So we've worked closely and reached out to um, all different areas and that's when we've sort of realized that we all need to be working as one all together and speak to each other more. So I think for listeners who are going on this journey, I would say take that risk based approach, have a look at what is the most riskiest things you can think of and then develop your roadmap on how you can mitigate those risks through your policy, through your design, through the tooling that you're looking for before you even look at embarking on releasing that, uh, that type of initiative. And I think you also get a lot of learnings from just having lots of play arounds with it. So we have a lot of promptathons, we have a lot of hackathons where we just say be creative and think outside of the box. And we learn a lot from those as well about what is the potential and what could be done so that we can also mitigate those risks and bring those ideas to life.

Speaker C: Yeah, and that sounds like such a huge, I mean I can imagine when you first kicked it off that would have been a big, big project and initiative because you bringing so many different people into the conversation, different expertise to be able to put these together. What did you have to do with the data foundations? Because ultimately it's all based on that. So were there some changes you had to make with your data foundations and tooling and technologies and things like that. And what were they?

Speaker A: Yeah, and I think it depends on the initiative that you're looking at. So I would say that if you're looking at something like a member facing AI in that particular one, you want to ensure that you are meeting all of the regulation. And for those data foundations, it becomes more of the info foundations. So when I was talking earlier about the chunking down the policy, and that's similar with these AIs is you have to have your knowledge source that is version controlled, that has an approval or a deployment process where you have the versions in draft format and then they get approved. It has to be in a readable format that the AI can read and there's no ambiguity. And it also has to be readable by humans so that they can do the um, the reviews and the checks and the sign off of it all as well. And within that sort of process, you also have particular agents that might have certain roles that can help you with the checking as well on all of that. And they can help you with those data foundations, like the data quality, to say, well, if I was to ask this particular question, I should expect a certain answer and it can test your AI for you. And did it actually answer it as you should have seen it based on the knowledge that was in there? But yes, it's very much moved from a data quality into an info quality for AI.

Speaker B: Yeah, yeah.

Speaker C: And talk to us about some of the different roles that your agents play. Like what different roles have you created within your AI agents?

Speaker A: There's been a lot. We have hundreds across the organization. Yeah. But it's from something simple for, uh, we might have an agent that's capturing knowledge on a regular basis. For my whole team, for example, on when it's mentioning anything to do with AI governance, or we save that three times a day where we dedupe the information and it picks up any conversations, meetings, transcripts that we've had and puts all of the information into one channel. And that channel can be queried where we can say where are we up to with this? Without having to actually ask the other person. So sort of like automating our information into a channel within teams, we have other teams that help with doing first runs on assessments. So gather the information I need and then send to a human for checking as well. We have other agents that are very, very simple that work across their own inboxes and they might pull out all of the tasks that need to be done for them and prioritize them in order and Give them a rating based on certain keywords that might pop up on what their work might be. They're more like simple, what we call personal agents. Then you can move into more agents that are shared among teams as well. So if they've got a particular purpose that helps that particular team do a function and you have some that, you know, they might be doing assessments by checking recordings of the service center, for example, and ensuring that they meet certain regulation criteria. And it might do the first run of those ones and then is sent out for checking afterwards. Basically anything that can be repeated can become an agent is the sort of frame that we've had and rolled out and then we've um, done training to the whole organization on that.

Speaker C: Yeah, so a lot of the agents that you're currently building and then you've got working in your environment specific to internal, so productivity efficiencies, accuracy, you know, capturing data, capturing information. Or have you also built, uh, some agents that are helping with your member experience. So say if I called into the call center or I wanted to ask some questions about my superannuation or like, do you, have you started to work on those kind of agents yet, Natalie?

Speaker A: We have and it's still very much in testing. And I think that's probably more around the blue skying. What can we do, what's possible. And that has helped us, I think, get to a point where we can say, here's a uh, chatbot, you can message this chatbot and find out a little bit more information about what you could potentially do as far as the regulation is concerned with your superannuation. So what are the rules around non concessional contributions? What are the rules around concessional? You know, if I have caps, if I can do spouse contributions, it's very, very general in nature. But through that whole process it helps you to really understand what you need in place to do all the monitoring of all of that. Because if something like that is to drift, then you have a lot of risk associated with it. So that's one of the ones that member facing one. There's other sort of agents that we have, they're more third party agents that are built into software where you can have a look at things like what is the next best conversation based on this particular member's conversation they're having with us. So if they were to call in, they might have some key things that they're talking about. As the officer is having a conversation with the member, they can get a prompt to say, by the way, this particular person might need to Do a contribution prior to the end of the year, maybe raise that with them so that we can help them better. So the idea is that we can ensure that we're giving that particular member the most of all of the services that we offer and that way that they can continue to build on their superannuation and have better outcomes as well.

Speaker C: Yeah, because I know there's been so many times where I've gone, I just want to know how much I've got in there, how, what's this payment for? And so good to be able to just quickly get that information and find out, you know, rather than having to wait on the phone and answer, uh, security questions and. But it is a tough one because there's so much privacy and PPI attached to each individual that it's, you know, I think we'll get to a stage where, you know, they'll have really good governance and protection and things like that, but.

Speaker A: Exactly. And I think that world is not too far away where you'd be able to do that, Rina. It's just ensuring that we can do it safely. And also consider the members perspective if they don't want to be included in this, because not everybody is embracing AI like we are, which I sometimes forget, but sometimes members don't want their information to be used in training AI, for instance. So I think with the new privacy laws, we need to be able to consider all of that information that is actually being created from the agents as their personal information and then if they want to be able to request it, how do we go about allowing that to happen?

Speaker C: Yeah, yeah. And what kind of expertise did you need to build into your team, Natalie, to be able to develop these agents? Because my head's going to train these models to prompt these models. They would have needed to be done in a certain way and to ensure that meets all the regulatory requirements as well and all the risks attached to the industry that you work in. So talk me through the type of skills and capabilities, capabilities you have had to build into the team that's actually made this happen.

Speaker A: Yeah, great question. And I don't think I would have been able to go as far as we have with policy as code if it wasn't for having some pretty switched on technical people involved in this whole process that can really dive into the AI and approach the AI from a data perspective. So things like where is all of the AI data going when we're creating policy as code? And then we base it on a data semantic model. So we now have like a data and AI governance semantic model. So all of the data we're obtaining from all of the assessments will go into one location and then we can build off that to create all of the reporting we need. And that's very, very similar to data. So this technical person was able to basically copy over their principles from almost data engineering into AI engineering and build out this process for us in saying that. And that is very difficult for a lot of AI and data governance teams to have that sort of capability within their teams. We're structured that we can sit alongside. Our practice is the data and AI practice. So we have a lot of specialists in AI. We're at the hub of it all in providing the governance alongside it. So we do have access to those types of individuals. So for people out there that are a little bit more one step away from those teams, I would say start making friends with your data services team or your data engineers, or people who are really, really just passionate and curious about AI and then really approaching it from that particular angle where you're picking up deployment pipelines, you're picking up version control, and then you can use that in a similar way for your AI.

Speaker C: Yeah, yeah. And look, I think the challenge that a lot of organizations are having at the moment is, you know, how do we contain the excitement and the rigor and the, uh, boundaries around how our business is using or our employees are using AI? And it's often seen as, you know, data governance are just, they're just going to stop us from doing this or we're going to have to do this much more work. But I mean, the way you've described it, why wouldn't you do that? I mean, yes, it requires a lot of work initially to get that put in place, but it almost takes away the hard part of data, uh, governance professionals roles, which has been having to talk to people, having to get them to understand because you're actually adding it into what they're doing. Well, they're having to deal with it in what they're doing day to day. So as soon as they start to go and do something with AI, you know, the boundaries or the policies or the frameworks pop up into what they're trying to do. That sort of basically guides them into doing things the right way. Is that sort of how it works in practice?

Speaker A: Yeah, that's exactly how it works. The hardest part, I think for data and AI governance is the embedment. You can have a great policy. Trying to embed that into an organization would take a rollout period, training period. You'd have to do, potentially, assessments, checking of what's been done. And now you can have that all built into one. You've got traceability, you've got visibility of what's happening all across the organization, all the way across AI initiatives to the agents that might be built on, on those, through to what models they're using. And you can see the bigger picture as well. So you've got that end to end and it becomes a. Here is a tool that you use. That's all you need. You know, we will guide you through everything. They don't need to know about all the different types of legislation that's. That's come about to put this in place, the key principles of it all. Yes. Because they want to be building these to ensure they adhere and not have to stop partway through to say, oh, no, I forgot about privacy. What am I doing to ensure that we're not leaking member details?

Speaker C: Yes.

Speaker A: But they can check in at the beginning and say, I'm thinking about building this. What would you consider that I would need to do through this? And it's all there for them to hold their hand the whole way through.

Speaker C: Yeah. How did you land on this initiative? Like, what was the reason why you started this in the first place? Because it's not often the place that people start. So what prompted this and what made this journey start?

Speaker A: I think it started when we wanted to roll out model governance and we said to ourselves, okay, we need to roll out model governance. What does that look like? Model governance? We need them to complete a register. Okay, what would that look like? And we started off with your Word document for the policy and your register in Excel. And then when considering we work in data and AI in the team, we were just like, can we have an agent that could just handle model governance? So we started looking at that, but once again, that was a siloed approach. So we're just like, yes, we could have an agent that would look after model governance. We'll have an agent that looks after agent governance and takes down all of the data and collects it along the way and builds us a nice pretty register that we can have a look at. But it was still very siloed when we started. I think there was more questions of how does the model governance fit into the overall process? Or how does agent governance fit into the whole AI process? We mapped out the AI process from end to end, and it was complex. It was, what are the triggers? When do people need to do what, when? And we can't take this to a Human and say, here you go, follow this. Because it was a huge mirror board for us to capture it all. So, um, that's when we said, okay, we're going to need an agent to route to all these other ones. But it was still a siloed approach. And so, long story short, it was very iterative. Like, we took a problem and then we started looking wider and it just became a more organizational problem. And now we can look at it to say, what do all of these assessments? What do all of these policies and the intent of them, what do they have in common? So maybe the AI could ask that question once and then it can take it through all of those assessments. So you're not sitting there writing down, this is my initiative, this is the sponsor, this is the owner, multiple times across multiple different Excel forms or teams forms. It's there in one location. And so that was the evolution of it. And I think it's going to evolve even more from here. But it's the dynamic nature of AI.

Speaker C: Yeah, no, it's good. And the reason I ask that question is because, you know, some people do just get stuck at where do we start? You know, what, when do we do it? When's the right time? And I don't think there's any right time. I think you just have to start to think about where you want to go with AI and start to build, like you said, some of those approaches and those, uh, foundations and frameworks to start allowing you to do some of the more siloed things, I guess, which then will probably expand across the. What's that meant in terms of the demand that's coming through? I mean, now that you've made it so accessible. And I ask this question all the time, does that mean that you're getting loads of agents, many agents being built, and then you're having to work on them? Or like, have you. Have you noticed there's been an increase in demand for people building things? Like, what's it been like?

Speaker A: I think we're starting to see the shift from the thinking of having just a, uh, personal agent that can help with your day to day into how would. Or could my agent talk to somebody else's agent? And that's when you're starting to think of almost that silicon workforce where, if you wanted to get to that point, we need to start thinking about user access and the permissions that they have. But we are seeing that shift now because we're seeing what it can do. I think all we're getting is excitement when we're talking about what it can do and going out to all the different teams. We want to incorporate you into this process. Here's a template that we're creating that will help you to get on board quicker. But even then we're finding that we have to do the training on top of that. To say this is how you can build an agent, this is what it all means in the background. This is a tool, this is a skill, this is a knowledge base, this is how you can incorporate power Automate. And at that point we work alongside the AI enablement team or our AI practice and they're doing the training and building the skills so we can get them into all of those courses so they can learn and get better across the whole organization and move up into that next category of agent building.

Speaker C: Yeah, yeah. And, um, when you say silicon workforce, what do you mean by that?

Speaker A: It's, I guess it's a new, newer concept where if we're getting agents to do some of our tasks for us, we need to treat them as if they are and employee. So we need to ensure that they have the right level of access to the right areas that we've assessed them to ensure that we're not breaching privacy concerns. If we've got what we're calling a gap or a ceiling gap between what your, say, for instance, co pilot is classified as for data. It's a nice safe environment if you're using it. Just, um, you and your copilot, however, if you create an agent and you're feeding it really sensitive information, you could potentially be unearthing that information to an audience that shouldn't be seeing that one. So we need to consider the difference between those. So the silicon workforce or the agent workforce needs to know who their audience is and how much data they're actually allowed to share. Obviously it doesn't know that intuitively. So there is an assessment involved that is managed through our process. They need to have a number assigned to them like we do. We all have employee codes. They need to have their own unique reference. We need to know who their boss is. So if their boss leaves, we know that somebody else can come and step in and look after them and be responsible for them. There's a lot of different things that we consider, uh, which builds out what we call our agent register, basically. So all that different information that we have can help us manage our agent like it is an employee.

Speaker C: Yeah, yeah. And I love that, uh, it's that, you know, people talk about their agents. Yeah. Like they are, they're Performing a person or a part of a person's job, aren't they? So they're essentially are. Oh, God. I feel like. Yeah, there's so much that changes with this, with every conversation that I have. I suppose what I'd like to touch on is maybe what were some of your learnings through this, this process, Natalie?

Speaker B: What were the.

Speaker C: Some of the things that you wish you'd known that would be really helpful for other people, People when they're sort of going through this?

Speaker A: Good question. We're learning something almost every day, but that's helping us to then make decisions. So the learnings is more around just getting in and doing it and practicing it and playing around with it to get your own learnings as you go. Because each different, depending on what tool you're building it on, has its own rules. Each organization has its own rules as well. So I think for us, the things that we would have been great to learn quicker was once we've got our traditional framework already approved in our nice little word document, is how we can then chunk that down, info chunks and what that actually looks like. And that's a very, very new concept and something that we've had to learn how to do, I guess, from it all. And that's been a pretty fun one actually. Yeah, I don't know. There's been a lot of learnings.

Speaker C: Was there something that you kind of went, okay, we, we could have approached this differently. We hadn't actually thought about that. Was there any one of those kind of examples? Was there anything like that?

Speaker A: Yeah, I think for us, even though it was an iterative approach, we did try to copy our old traditional governance into the individual agents. And so we weren't considering them talking to each other at that point. And I think that approach was still keeping up the silos around the organization and the moving to all of it. Being in the one knowledge base and just having the info chunks or the knowledge chunks shared out amongst the different parts of the organization was the big aha, uh, moment for us. This can be more of a system as opposed to just an automation.

Speaker C: Yeah, fantastic. That's great. If there was one thing that you would like to leave the listeners with with regards to doing something similar to what you've done, what would that be?

Speaker A: I think it would be to start. Just to get in and start. Consider, always have the end goal in mind of what the biggest risk would be that you want to mitigate. But you need to start somewhere. And as soon as you start, start using AI to help you along the way with all of this as well. Start using it iterate and make sure you've got humans there in the loop. Our feedback, our reviews of everything along the way has been instrumental in ensuring that we get this right as well.

Speaker C: And what would you say to your peer who is still stuck? Not stuck, but still struggling with the we can't do this because we still need to get our data quality done. We still need to get this sorted before we start working on this, but really wants to provide access and enable the business to start working with AI. What would your advice to them be?

Speaker A: I would say don't get left behind in all of this. We started rolling AI governance out before we had finished rolling out data governance. We had done the high risk side of things in data governance, but we continue to roll that out alongside our AI. I would say making sure that you have the capacity to focus on this will just help rocket you and your organization further into the world of AI.

Speaker C: Thank you.

Speaker B: Lovely.

Speaker C: Well, thank you so much, Natalie. It's been really, really good and I've really enjoyed the conversation. Thank you so much for taking out the time. I'm super excited to hear during our conversations that we have, what things you guys are building. I, uh, know you guys are doing some great stuff, so I'm looking forward to hearing more about it. But thank you so much for joining me on the show.

Speaker A: Thank you for having me and for listening to me, Rayvon. I get a little too excited about all of the projects we're working on, so I appreciate your time.

Speaker C: No, it's great. I mean, I always think data governance and AR governance, you know, traditionally is to some people always been quite a dry topic, but I actually think it's really interesting. And my recent episodes on data governance are getting a lot of listens, so I think it's definitely a hot topic.

Speaker B: Lovely.

Speaker A: Um, thanks, Reena. Good to chat.

Speaker C: A big thank you to our listeners.

Speaker A: Your support helps us share these valuable

Speaker B: conversations with more people.

Speaker C: If you're enjoying the podcast, please give it a like or follow.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • From Compliance Theater to GRC Infrastructure: Why AI Breaks Traditional GRC ft Jasmine Kaur, Principal of Security & Assurance Engineering @ CoreWeaveSecurity & GRC Decoded · on Policy-as-code96 / 100
  • The Agentic Operating Model: Beyond the Copilot HypeM365.FM · on Policy-as-code72 / 100
  • Science of SaaS Startups Podcast with Conor Bronsdon - LinearBScience of SaaS Startups · on Policy-as-code62 / 100
  • AI Is Making Content Easier. It's Not Making It Better.B2B Marketing: Tomorrow's Best Practices... Today · on LLM governance61 / 100

More from LEAD WITH DATA Podcast

All episodes →
  • Season 6 - Episode 6 - Moneyball for Golf: How a lean team can punch above it's weight!66 / 100
  • Season 6 - Episode 7 - Wins with Tight Budgets - The Real Path to AI Capability in a Cash Strapped Sector"
  • Season 6 - Episode 5 - "The Insurance Nobody Wants: Why Data Governance Matters Now" with Belinda Toniolo
  • Season 6 - Episode 4 “Build, Ship, Improve” - The Commercial Mindset Behind AI That Reaches Real Customers" with Tracy Moore
  • Season 6 - Episode 3 - "The one question that changed HR’s influence on business performance forever" with Sarah Novelli
Explore the best B2B AI & Data podcasts →
All LEAD WITH DATA Podcast episodes →