Prof. Hernan Huwyler, MBA, CPA, CAIO

AI Governance & Responsible AI Director | Quantitative Risk & Digital Compliance Expert | Algorithmic Auditing Specialist | GRC Professor & Executive Trainer | Keynote Speaker & Executive Consultant

📍 Copenhagen, Denmark — Serving Europe & Global Clients

AI Governance Responsible AI Quantitative Risk GRC Algorithmic Auditing Digital Compliance AI Risk Management EU AI Act

Value Delivered: AI Governance & Quantitative Risk Results

20+

Years in GRC & Risk Management

Directed enterprise risk, compliance, and AI Governance programs for Fortune 500 multinationals across 4 continents. Deep expertise in Responsible AI, Algorithmic Auditing, and Digital Compliance for regulated industries.

6

Industries Transformed

Energy (ExxonMobil, Veolia, Baker Hughes), Financial Services (Danske Bank), Technology & AI (Milestone Systems/Canon, Capgemini), Facility Management (ISS), Manufacturing (Tenaris), Professional Services (Deloitte). Applied Quantitative Risk modeling and AI Governance across every sector.

2x

Faster Risk Assessments

Designed Quantitative Risk models using Monte Carlo simulation (Python, R) that cut assessment timelines by half while increasing analytical rigor. Replaced qualitative heat maps with probabilistic loss distributions and Value-at-Risk metrics for AI systems.

40%

Reduction in Manual Compliance Effort

Led AI-driven Digital Compliance automation initiatives reducing manual review workloads by up to 40%. Deployed Algorithmic Auditing checkpoints ensuring audit-defensible AI outputs in pharmaceutical, automotive, and financial services.

80+

Subsidiaries Under Risk Oversight

Managed GRC frameworks covering 80+ subsidiaries across Iberia and Latin America for a global utility. Established enterprise-wide AI Governance policies, risk taxonomies, and Responsible AI controls at scale.

13+

Years as Executive Professor

Professor at IE Business School since 2013. Program Director for Advanced Compliance. Executive trainer in AI Governance, Responsible AI, Digital Compliance, GRC, and Quantitative Risk. Guest lecturer at 6 universities. Published author and keynote speaker on Algorithmic Auditing and AI Risk Management.

AI GRC Technical Advisory, Training & Speaking Services

Available for knowledge dialogues, executive training, keynote speaking, board advisory, and interim management engagements across Denmark, Northern Europe, and globally. My practice focuses exclusively on AI Governance, Responsible AI, GRC, Quantitative Risk, Algorithmic Auditing, and Digital Compliance.

✅ AI Governance & EU AI Act Advisory

Design and implement enterprise-wide AI Governance frameworks aligned with the EU AI Act, ISO/IEC 42001, and NIST AI RMF. AI lifecycle governance, policy design, approval gates, risk classification, and board-level AI strategy. Prepare organizations for conformity assessments and regulatory readiness.

✅ Quantitative Risk Modeling for AI

Build probabilistic risk models using Monte Carlo simulation, Bayesian networks, and scenario analysis in Python and R. Quantify AI-related operational, compliance, and reputational risks. Calculate risk-adjusted ROI, Value-at-Risk, and Expected Shortfall for AI investments. Replace subjective heat maps with data-driven decision support.

✅ Algorithmic Auditing & AI Assurance

Design and execute Algorithmic Auditing programs for ML models, GenAI systems, and third-party AI solutions. Bias detection, fairness testing, model drift monitoring, adversarial robustness evaluation, and explainability assessments. Deliver audit-defensible documentation for regulators and internal audit committees.

✅ Responsible AI & Digital Compliance

Implement Responsible AI principles across the organization: fairness, transparency, accountability, privacy, and safety. Build Digital Compliance programs spanning GDPR, EU AI Act, DORA, NIS 2, SOX, and FCPA. Integrate AI ethics into existing GRC frameworks. Design KRIs, control matrices, and monitoring dashboards.

✅ Keynote Speaking & Executive Workshops

Engaging keynote presentations and half/full-day executive workshops on AI Governance, Responsible AI, Quantitative Risk for AI, Algorithmic Auditing, Digital Compliance, and the future of GRC. Conference keynotes, corporate board briefings, leadership offsites, and university masterclasses. Delivered in English and Spanish.

✅ Executive Training & Certification Programs

Custom executive education programs in AI Governance, AI Risk Management, and Digital Compliance. Designed and delivered training at IE Business School, Universidad Complutense de Madrid, UNIR, Comillas/ICADE, and CEF. Certified Chief AI Officer (CAIO) program lead and instructor. Corporate upskilling for risk, compliance, audit, and technology teams.

Professional Experience

Sr. Manager — AI Governance, GRC & AI Risk Management | Applied AI Lab Lead
Capgemini
January 2025 – Present | Copenhagen, Denmark
  • Leading enterprise-wide AI risk and control initiatives, integrating machine learning, predictive models, and advanced analytics to enhance operational resilience and regulatory compliance.
  • Directing AI Governance initiatives, conducting feasibility studies, and implementing AI-driven Quantitative Risk models for fraud detection, regulatory reporting, and cybersecurity threat identification.
  • Managing full project lifecycles, from AI risk modeling and Digital Compliance assessments to strategic deployment, ensuring regulatory alignment and business value realization.
  • Conducting digital transformation and AI Governance projects, optimizing business processes to enhance risk mitigation, model interpretability, and auditability.
  • Advising senior executives on AI Governance, Responsible AI, algorithmic accountability, and Quantitative Risk decision frameworks, providing data-driven insights for Digital Compliance and operational risk management.
  • Leading AI risk assessments and controls implementation, ensuring adherence to EU AI Act, NIS 2, GDPR, SOX, FCPA, and DORA while leveraging machine learning explainability techniques.
  • Designing and executing Algorithmic Auditing programs, incorporating AI bias detection, adversarial testing, and model risk validation using Python, TensorFlow, PyTorch, and Scikit-learn.
  • Implementing GRC frameworks aligned with ISO/IEC 42001, COSO, and NIST AI RMF, ensuring robust Algorithmic Auditing and regulatory compliance.
  • Deploying AI threat models based on NIST 800-53, MITRE ATT&CK, Microsoft STRIDE, and Google DREAD to proactively identify vulnerabilities across AI systems.
  • Developing AI cost-benefit analysis and Quantitative Risk-adjusted ROI models to optimize AI investment strategies and mitigate financial exposure.
  • Founded and led the Applied AI Lab (RIOT), an internal acceleration program developing AI Governance methodologies and Responsible AI playbooks for Fortune 500 clients across life sciences, defense, telecom, and energy.
Executive Education Director, Professor & Speaker — AI Governance, GRC & Compliance
IE Business School & IE Law School
January 2013 – Present | Madrid, Spain
  • Promoting corporate sustainability, ethical leadership, Responsible AI, Digital Compliance, and enterprise risk management through executive education programs.
  • Director, Advanced Program in Compliance (2016+): GRC frameworks, ISO 37001, ISO 19600, OCEG, compliance & reputation risks, KRIs, data privacy, AI Governance.
  • Professor at Universidad Complutense de Madrid, UNIR, Comillas Pontifical University/ICADE, and CEF — teaching AI Governance, Responsible AI, GRC, Algorithmic Auditing, and Digital Compliance in masters programs.
  • Keynote speaker and workshop leader at industry forums on AI Governance, Responsible AI, Quantitative Risk, cyber risk, privacy, and Algorithmic Auditing.
  • Chairman, Compliance Day 2016 (iiR Spain). Co-host, C5 Forum Anti-Corruption Spain 2016.
  • Speaker at The Institute of Internal Auditors (IIA) and ISACA on fraud mitigation, corporate criminal liability, and AI assurance.
  • Certified Chief AI Officer (CAIO) program lead and instructor — Copenhagen Compliance / Information Security Institute.
Head of Group AI Risk Management & AI Governance — Quantitative Risk, Responsible AI, Digital Compliance
Milestone Systems (Canon Group)
August 2022 – November 2024 | Copenhagen, Denmark
  • Led cross-functional teams to identify, assess, and quantify risks across AI, software development, finance, operations, compliance, cybersecurity, and revenue.
  • Designed, evaluated, and backtested Quantitative Risk models for decision-making processes using Python, R, Monte Carlo simulation, and ISO 31000/23894/42001.
  • Drove Digital Compliance with EU AI Act, GDPR, FCPA, OFAC, CCPA, export controls, anti-trust, software licenses, and data ethics requirements.
  • Managed Algorithmic Auditing and control readiness programs to certify SOX controls, information security, privacy, and AI software development processes.
  • Implemented Responsible AI governance ensuring confidentiality, integrity, and availability of AI computer vision and video analytics solutions.
  • Prevented losses and incidents through root-cause analysis, risk awareness promotion, and GRC framework implementation.
  • Resolved all external audit observations. Promoted enterprise-wide risk culture as a strategic business partner.

Milestone Systems, part of Canon, is the world's largest provider of AI computer vision and video management software.

IT Risk & Control Governance Sr. Lead — Responsible AI, GRC & Digital Compliance
Danske Bank
June 2020 – August 2022 | Copenhagen, Denmark
  • Led and coached risk, internal control, and compliance specialists across the bank's IT organization.
  • Established and maintained a cyber risk and control program protecting bank-wide IT systems and information assets.
  • Assessed information security, cybersecurity, cloud services, and IT risks against ISO 27001, 27002, 27017, 27701, NIST 800-53, PCI DSS, COBIT, and EBA/FSI regulatory requirements.
  • Delivered ongoing training and cyber risk maturity development. Reported risks and audit observations to senior leadership.
Head of Supplier Due Diligence Compliance Strategy & Procurement CoE
Danske Bank
September 2019 – July 2020 | Copenhagen, Denmark
  • Piloted centralized due diligence processes to comply with EBA outsourcing guidelines. Managed Digital Compliance across suppliers, outsourcers, and third parties.
  • Led a team of senior compliance, risk, and privacy experts. Designed GRC processes for regulatory requirements including GDPR and FSB guidance.

Danske Bank is the largest bank in Denmark and the second largest across the Nordics, serving 3.3 million customers.

Head of Center of Excellence for Risk Management & Compliance
ISS A/S
June 2018 – September 2019 | Copenhagen, Denmark
  • Established the GRC Center of Excellence in risk management, internal controls, and compliance in collaboration with Deloitte Denmark.
  • Implemented ISO 31000-aligned risk frameworks, governance policies, and self-assessment processes serving Fortune Global 500 clients.
  • Enabled enterprise-wide risk awareness, compliance monitoring, and Digital Compliance across 120 countries with nearly 500,000 employees.
Senior Manager — Operational Risk / Risk Advisory
Deloitte Denmark
June 2017 – June 2018 | Copenhagen, Denmark
  • Led a portfolio of GRC, risk advisory, and Digital Compliance consultancy projects across Deloitte North West Europe.
  • Managed engagements in business process transformation, operational risk assessment, compliance audits, GDPR, SOX, cybersecurity governance, and third-party compliance for energy, pharma, banking, and manufacturing clients.
Risk Management & Internal Controls Director
Veolia
May 2011 – June 2017 | Madrid, Spain
  • Directed GRC frameworks for 80+ subsidiaries across Iberia and Latin America. Led a team of 14 risk and audit specialists.
  • Implemented Quantitative Risk modeling, control self-assessments, and risk taxonomies under ISO 31000, COSO, COBIT, GDPR, and SOX standards. Library of 800+ risks and KRIs.
  • Coordinated training for internal auditors and control specialists across the global organization.

Veolia: global leader in energy, water, and waste management — 220,000 employees in 45 countries.

Compliance Audit Coordinator
Tenaris (Techint Group)
August 2008 – September 2010 | International
  • Developed comprehensive compliance assurance programs aligned with SEC, FCPA, SOX, GAAP, IFRS, and OFAC requirements.
  • Engineered automated alerting systems reducing manual review efforts by 25%. Enhanced SAP GRC data utilization with MicroStrategy BI integration.
SAP/Finance Business Process Specialist & Compliance Auditor
Baker Hughes (GE)
April 2006 – June 2008 | Houston, TX
  • Managed SOX §404 compliance audits and financial reviews at worldwide locations. Conducted SAP controls audits and process re-engineering.
  • Won the Baker Hughes Core Value Award (Gold) for improving audit methodology.
Inventory & Accounting Compliance Specialist — US Crude Oil
ExxonMobil
March 2005 – April 2006 | Dallas/Fort Worth, TX
  • Mitigated market, credit, and operational risks for crude oil trading, reducing past-due items by 60% in one year.
  • Designed risk monitoring, early warning systems, and automated controls for the finance and control migration.
Enterprise Risk Services — Sr. Risk, IT & SOX Consultant / Sr. Financial Auditor
Deloitte
January 2001 – March 2005 | 4 years
  • Performed SOX, risk, operational, and IT controls audits. Evaluated business process controls and technology risk.
  • Directed engagement teams for financial and control audits across multiple industries including financial services and energy.

Selected AI Governance & Quantitative Risk Projects

Enterprise AI Governance & Autonomous Systems Controls

Capgemini | Global Automotive & Autonomous Vehicles OEM | Gothenburg, Sweden | 2025–2026
  • Engineered a group-wide AI Governance operating model with lifecycle controls, approval gates, and risk acceptance thresholds across global subsidiaries.
  • Established Algorithmic Auditing protocols for third-party AI solutions and internal ML models — bias, security, and reliability assessment.
  • Developed Quantitative Risk taxonomy for AI threats aligned with ISO/IEC 42001, ISO 42005, and NIST AI RMF.
  • Institutionalized Responsible AI principles through RACI matrices defining C-suite accountability across model development, deployment, and decommissioning.
  • Delivered Digital Compliance framework for EU AI Act readiness across 15+ business divisions.

AI Clinical Data Automation & Algorithmic Quality Assurance PoC

Capgemini | Top-10 Global Pharmaceutical Company | Copenhagen, Denmark | 2025
  • Led proof-of-concept for AI-driven Digital Compliance automation of clinical trial data review using AWS DataBrew and GenAI prompt engineering.
  • Executed Algorithmic Auditing on automated data processes ensuring AI-generated corrections met GxP regulatory control attributes.
  • Applied Quantitative Risk assessment modeling error rates and false-positive thresholds for go/no-go executive decisions.
  • Embedded Responsible AI safeguards ensuring zero compromise to patient safety or data integrity.
  • Proved ROI justifying enterprise-wide pilot deployment. Strengthened AI Governance documentation for regulatory inspections.

ESG GRC Automation & Data Architecture Transformation

Capgemini | Major Global Energy Corporation | Houston, TX | 2025–2026
  • Directed GRC transformation automating ESG reporting (GHG Scope 1–3, water, sustainability), reducing compliance costs and increasing data fidelity.
  • Architected Digital Compliance workflows spanning SAP MDG, IoT sensors, and enterprise data lakes.
  • Applied Quantitative Risk modeling to validate environmental estimation methodologies aligned with ISO 14064 and ISO 14001.
  • Instituted AI Governance models overseeing automated reporting tools for accuracy, transparency, and traceability.
  • Advised C-suite on Responsible AI practices for corporate sustainability targets.

Applied AI Lab (RIOT) — AI Governance & Responsible AI Acceleration

Capgemini | Internal Innovation Program | Copenhagen, Denmark | 2025–Present
  • Founded and led the Applied AI Lab developing AI Governance methodologies, Responsible AI playbooks, and Algorithmic Auditing toolkits for Fortune 500 client engagements.
  • Created technical AI use cases on SAP Joule, ServiceNow AI, and enterprise Copilots across life sciences, defense, telecom, and energy.
  • Built Quantitative Risk and Digital Compliance go-to-market roadmaps driving new business development.
  • Trained consulting teams in GRC, Quantitative Risk modeling (Python, R), and AI Governance advisory methodologies.

Quantitative Risk Modeling & AI Financial Exposure Validation

Milestone Systems (Canon) | Copenhagen, Denmark | 2022–2023
  • Designed and backtested Quantitative Risk framework using Monte Carlo simulation to calculate VaR and financial exposure for enterprise AI systems.
  • Pioneered Algorithmic Auditing pipelines using Python and R to stress-test ML models for data drift, bias, and adversarial vulnerabilities.
  • Enforced Responsible AI controls quantifying algorithmic bias in AI computer vision products.
  • Bridged data science and GRC by translating algorithmic uncertainties into financial metrics for Digital Compliance with EU AI Act and ISO 42001.

Publications on AI Governance, Quantitative Risk & GRC

AI Management Systems: Operational Playbook for Chief AI Officers and Compliance Risk Managers

Google LLC | ISBN 9798233615009 | 2026

End-to-end framework for institutionalizing AI Governance across the enterprise. Translates the EU AI Act, ISO/IEC 42001, and NIST AI RMF into measurable engineering and oversight tasks. Introduces "Moneyball" approach to AI risk — Quantitative Risk modeling of algorithmic bias, model drift, and risk-adjusted ROI. Covers Algorithmic Auditing, Responsible AI controls, Digital Compliance, and the AI Control Matrix linking telemetry to regulatory mandates.

Standardized Threat Taxonomy for AI Security, Governance, and Regulatory Compliance

arXiv:2511.21901 | Computer Science — Cryptography & Security | 2025

First rigorous bridge between technical AI vulnerabilities and financial Quantitative Risk Assessment. Unified ontology of 9 Critical Domains and 53 Threat Categories validated against 133 real-world incidents. Maps vectors to ISO/IEC 42001 controls and NIST AI RMF. Enables Algorithmic Auditing practitioners to move from qualitative heat maps to Monte Carlo-based Quantitative Risk Assessment for AI Governance and Digital Compliance.

Quantitative Risk Assessment in R: An Open-Source Convolutional Framework for Modeling Uncertainty and Reserves

Zenodo | Quantitative Finance & Risk Management | 2025

Open-source Quantitative Risk framework using convolutional Monte Carlo methods in R. Integrates Poisson frequency and Lognormal severity distributions. 100,000+ simulations. Applicable to financial plans, compliance, cybersecurity, and operational risk. Supports AI Governance and Responsible AI programs requiring rigorous Quantitative Risk quantification.

GRC Framework: Governance for Risk and Compliance

Ediciones Roble | ISBN 9788416756230 | 2017

Comprehensive 328-page guide on implementing integrated GRC frameworks. Covers enterprise risk management, internal controls, compliance program design, and governance structures — the foundational methodology underlying modern AI Governance, Digital Compliance, and Responsible AI implementations.

Additional Published Articles

Internal Auditor Magazine (IIA), SAPexperts, The Risk Universe, Metricstream, Tribuna del Compliance, LawyerPress, Lefebvre

Published expert articles on COSO-ISO 31000 convergence, GDPR compliance for SAP, third-party due diligence, and dimensions in risk measurement. Ongoing thought leadership on AI Governance, Algorithmic Auditing, and Quantitative Risk methodologies.

Speaking & Executive Training: AI Governance, Responsible AI & Quantitative Risk

Available worldwide for keynote speaking, executive workshops, corporate training, and conference presentations. Languages: English and Spanish. Delivered in person and virtually.

🎤 Keynote Topics

• AI Governance in 2025: What Boards Must Know About the EU AI Act
• Quantitative Risk for AI: Monte Carlo Methods for Executive Decision-Making
• Algorithmic Auditing: How to Audit AI Before Regulators Audit You
• Responsible AI Is Not Optional: Building Trust in the Age of GenAI
• Digital Compliance Transformation: From GDPR to the EU AI Act
• GRC for the AI Era: Integrating Governance, Risk & Compliance for Intelligent Enterprises
• The "Moneyball" Approach to AI Risk: Replacing Heat Maps with Data

🎓 Training Programs & Certifications

• Certified Chief AI Officer (CAIO) — Program Lead & Instructor
• Advanced Program in Compliance — Director (IE Business School)
• AI Governance & Responsible AI for Executives (Custom Corporate)
• Quantitative Risk Modeling: Python & R for Risk Professionals
• Algorithmic Auditing & AI Assurance for Internal Audit Teams
• Digital Compliance Masterclass: EU AI Act, DORA, NIS 2
• GRC Framework Design & Implementation Workshop

Speaking & Teaching Affiliations

IE Business School IE Law School Universidad Complutense de Madrid UNIR Comillas / ICADE CEF iiR Spain IIA — Institute of Internal Auditors ISACA C5 Forum Anti-Corruption Copenhagen Compliance Information Security Institute

Core Skills, Certifications & Technical Capabilities

Primary Expertise (Target Keywords)

AI Governance Responsible AI Quantitative Risk Management Algorithmic Auditing Digital Compliance GRC AI Risk Management

Regulatory & Standards Frameworks

EU AI Act ISO/IEC 42001 ISO 23894 NIST AI RMF ISO 31000 COSO COBIT GDPR DORA NIS 2 SOX §404 FCPA ISO 27001/27701 ISO 37001/37301 ISO 14001/14064 PCI DSS NIST 800-53 MITRE ATT&CK / ATLAS

Technical Tools & Languages

Python R TensorFlow PyTorch Scikit-learn XGBoost Keras Monte Carlo Simulation SAP FiCo SAP GRC SAP MM AWS DataBrew Signavio MicroStrategy

Professional Certifications

CAIO — Certified Chief AI Officer CPA — Certified Public Accountant MBA CRISC — Certified in Risk & Information Systems Control CISRM — Certified Information Systems Risk Manager PMI-ACP — Agile Certified Practitioner ISO 37301 Compliance Management IBM Cybersecurity Analyst Quantitative Finance with R

Languages

English — Native / Bilingual Spanish — Native / Bilingual French — Professional Working

Education

University of Cambridge
International Diploma in Business, Management & Administration | 2010–2011
Escuela Superior de Negocios y Tecnologías
MBA in Organizational Management | 2010–2011
Escuela de Negocios y Dirección
Management Skills Program | 2011
Universidad del Centro Educativo Latinoamericano
Certified Public Accountant (CPA) — Public Accounting, Tax, Finance, Management | 1995–2000

Meet Hernan Huwyler — AI Governance Consultant, Speaker & Trainer

Available for knowledge counseling, interim management, executive training, keynote speaking, and board advisory engagements. Specialized in AI Governance, Responsible AI, Quantitative Risk, Algorithmic Auditing, Digital Compliance, and GRC. Based in Copenhagen, Denmark — serving European and global clients.