Advisory

Helping non-tech operators adopt AI without failing the audit.

I help non-tech operators in fintech and healthtech adopt AI without failing the audit.

That sentence is the whole offer. This post explains what it means, who it is for and how the work runs.

The CEO says go. Compliance says no. Employees use AI anyway.

This is the pattern I see in regulated companies. Leadership wants AI. Security and compliance slow it down, for good reasons. Meanwhile, people on the team are already pasting work into tools nobody approved.

Nobody in that picture is wrong. But the company ends up with the worst of both worlds: real risk, and very little value.

Where rollouts stall

Why operators, not engineers

Most AI advice is written for people who write code. But in a regulated company, the people who decide whether AI changes anything often run operations, finance, support or compliance. They own the process. They own the risk. And they are usually the ones who got handed AI with no playbook.

You should not need to learn how models work to roll them out safely. You need a clear policy, tools you are allowed to use, training that fits your team, and a way to show it is working. That is the job.

What "failing the audit" really means

An auditor will not ask how clever your AI is. They will ask simple questions. What AI is in use? Who approved it? What data goes into it? How do you know? If the honest answer is "we are not sure," that is the finding.

So the work starts with those questions, not with the tools.

The method: Govern. Enable. Measure.

How to start

Most companies start with an AI Readiness Review. It takes two weeks and has a fixed scope. You get an inventory of the AI in use, a risk review and gap list, a draft AI use policy and a 90-day plan. If nothing is worth doing, I will say so.

After the Review, the next steps are a 90-day pilot rollout with one or two teams, and ongoing advisory: a monthly report, policy updates and tool reviews.

Who it is for

Fintech, payments, healthtech and insurance companies with PCI, HIPAA or SOC 2 in scope, usually about 50 to 500 people. The work is usually sponsored by the CEO or COO.

What I don't touch: your product AI and engineering roadmap. Those stay with your CTO.

Why me

I have spent 20 years in security and production systems, including time at PayPal. Today I lead AI adoption inside a regulated fintech. I'm usually the person who says no. That's why I can get you to yes.

Talk it through

If your team got handed AI and you own whether anything changes, book a 30-minute call. We will talk about where your rollout is stuck and whether a Readiness Review makes sense.

Book a 30-minute call Email info@chamsdel.online See how it works

Not ready for a call? Start with the newsletter.