Wisdom N. Kwashie Jnr

AI Governance Specialist

I help organisations adopt AI responsibly, with policies, controls and risk assessments their teams can actually run. I spent fourteen years in digital marketing at a leading telecommunications provider in Africa, and that is where I learned to write rules people follow, and to bring legal, risk and commercial teams in early rather than after the fact.

Portrait of Wisdom N. Kwashie Jnr
PMP, Project Management Professional badge

Project Management ProfessionalPMP, Project Management Institute

About this portfolio

This portfolio holds the AI governance artefacts I have developed: policies, controls and risk assessments, each built around a specific use case to show how I think and how I would operationalise AI governance for an organisation.

Artefacts

Use-case artefacts from my AI governance work. The list grows as the work does.

21 pages

Momento Media AI Governance Policy

AI Governance Policy

Purpose: Set the rules for how a small creative company uses generative AI on client work.

Setting: Momento Media, my own company, as the case study.

Context: Momento Media uses generative AI on client campaigns, and I wanted to see what real governance looks like for a company that size: named owners and clear approval paths, without pretending there is a compliance department.

Scope:

  • 11 sections covering risk tiers, approval paths, data and model controls, monitoring, incidents, procurement, exceptions and review
  • 6 appendices: a model card, a risk assessment, an audit checklist, two forms, and a crosswalk to NIST AI RMF and ISO/IEC 42001
  • Three risk tiers that decide who approves each use case
  • One worked example running through it all: a custom image-generation model for a skincare brand

What this demonstrates:

  • Draft policy language a small team can enforce
  • Design role-based accountability with independent audit
  • Set approval thresholds for spend and data
  • Map internal rules to external frameworks

Deliverable: 21-page policy, v1.0, effective 30 July 2026, reviewed quarterly.

Download PDF

5 pages

Momento Media AI Governance Operationalization Artifacts

Operationalizing the AI Governance Framework

Purpose: Turn one policy principle, data minimisation, into controls a team can deploy.

Setting: Momento Media, my own company, as the case study.

Context: A policy is only as good as what happens on Monday morning. These four short artefacts take one principle from the policy and show what it looks like in practice: technical standards for a customer-churn model, a risk-register entry for automated candidate screening, a pre-deployment approval gate, and a decision log.

Scope:

  • Technical standards with real numbers: raw identifiers purged within 30 days, a 40-feature cap, cohorts of at least 100 users
  • A High-risk register entry with inherent and residual ratings
  • A four-step approval gate, one sign-off per function, with a 0.80 adverse-impact ratio as the fairness pass mark
  • An append-only decision log with explanatory factors and a human-override field

What this demonstrates:

  • Translate a principle into measurable standards
  • Write register entries that name an owner and a residual risk
  • Design approval gates with separation of duties
  • Specify logs that make automated decisions auditable

Deliverable: 5-page document, four artefacts, revised 1 October 2026.

Download PDF

6 pages

Momento Media AI Risk Assessment: Content Generation System

AI Risk Assessment: Content Generation System

Purpose: Assess the third-party AI content tool our creative teams use, before we lean on it any harder.

Setting: Momento Media, my own company, as the case study.

Context: Momento Media's creative teams use a cloud-based generative AI system for client campaign images and video. I assessed it using the scoring method from my own policy, so the two documents work as one system.

Scope:

  • Three risks scored: IP and likeness, cost drift, data leakage
  • Likelihood × impact scoring, inherent and residual
  • Primary and supporting controls for each risk
  • An owner, a detection method and a 30, 60 or 90-day action window for each risk

What this demonstrates:

  • Score risk with a defined, repeatable method
  • Choose controls and say plainly what risk remains
  • Assign accountable owners and deadlines
  • Link each control back to a policy rule

Deliverable: 6-page assessment, revised 3 October 2026.

Download PDF

Background

I did not start in AI governance. I spent fourteen years in digital marketing, most of them at a leading telecommunications provider in Africa. Along the way I authored the company's online and social media policy and then had to make it work across commercial, legal, risk and compliance teams, which taught me more about governance than any framework has.

Three habits from those years come with me:

  1. Bring stakeholders in early.A control people helped design is a control they run.
  2. Explain why a control exists.Rules without reasons get worked around.
  3. Keep the business moving within the rules.Governance that stops delivery gets switched off.

My PMP is how I turn all of that into owners, timelines and evidence.

Get in touch with me.

Email
nunya.kwashie.jnr@gmail.com
LinkedIn
linkedin.com/in/wnkwashie
Based in
Southern California
Credential
PMP, Project Management Institute

Download PDF