AI Governance, Risk & Compliance

Hi, I'm Olivia.
I write, research,
and build in AI GRC.

Cybersecurity professional researching and building at the intersection of artificial intelligence, governance, risk, and compliance. Founder of AIxGRC and graduate student at Georgetown University studying AI governance and cybersecurity policy.

NIST
AI RMF Aligned
ISO
42001 Ready
EU
AI Act Compliant

Olivia Athelus

Olivia Athelus is a cybersecurity professional focused on artificial intelligence governance, risk management, and responsible technology oversight.


She created AIxGRC as a platform to document research, frameworks, and projects exploring how organizations can responsibly deploy AI while aligning with global governance standards such as the NIST AI Risk Management Framework, ISO/IEC 42001, and emerging regulatory policies.


Olivia is currently pursuing graduate studies at Georgetown University, where her research focuses on AI governance, cybersecurity policy, and regulatory risk management. Her long-term work explores how AI governance intersects with ethics, public policy, and high-impact sectors such as healthcare.


LinkedIn GitHub
Areas of Focus
AI Risk Management NIST AI RMF, ISO 42001, and lifecycle risk analysis.
AI Regulation & Policy EU AI Act, U.S. executive orders, and global compliance frameworks.
Security Standards PCI DSS, SOC 2, ISO 27001 applied to AI systems.
Research & Insights Published newsletters on real-world AI governance case studies.
AI Governance in Healthcare Exploring how AI risk management, patient safety, and regulatory oversight intersect in clinical and health technology systems.
GU Georgetown
University

Portfolio

Projects, research, and whitepapers built through academic coursework, independent study, and the AIxGRC brand.

EU AI Act Compliance Analysis

A deep-dive whitepaper analyzing how the EU AI Act's high-risk classification applies to biometric retail AI — using Sephora as a case study.

Whitepaper  ·  EU AI Act
Financial AI & Security Standards

Research mapping PCI DSS, SOC 2, and ISO 27001 requirements onto AI systems in financial services — credit scoring, fraud detection, and risk modeling.

Research  ·  FinTech GRC
Ethical AI Design for Vulnerable Users

Analysis of emotional AI chatbot case studies — examining where ethical design failed and what responsible safeguards look like for at-risk populations.

Research  ·  AI Ethics
AI GRC Framework Mapping

Comparative mapping of NIST AI RMF, ISO 42001, and the EU AI Act — identifying overlaps, gaps, and practical implementation priorities for organizations.

Coming Soon  ·  Frameworks
AI Risk Assessment Template

A practitioner-ready AI risk assessment template built on NIST AI RMF principles, designed for teams beginning their AI governance journey.

Coming Soon  ·  Tools
Georgetown Capstone Project

Graduate-level research project in progress. Details to be shared upon completion. Topics span AI policy, risk governance, and regulatory compliance.

→ In Progress  ·  Academic

Insights

View All on LinkedIn
EU AI Act
Sephora, AI, and the EU's New Rules

How Sephora's virtual try-on and biometric AI tools come under the EU AI Act's high-risk classification — and what responsible retail AI compliance looks like in practice.

LinkedIn Newsletter  ·  EU AI Act  ·  Retail AI
Financial AI
PCI DSS, SOC 2 & ISO 27001 — How Financial AI Can Align With Security Standards

A practical GRC guide to translating PCI DSS, SOC 2, and ISO 27001 for AI systems in credit, fraud detection, and financial risk modeling.

LinkedIn Newsletter  ·  FinTech  ·  Security Standards
AI Engineering
Simulating AI Pipelines with Gates, Feedback, and Batch Processing

A technical exploration of how AI pipelines can be simulated and stress-tested using gates, feedback loops, and batch processing patterns.

LinkedIn Newsletter  ·  AI Engineering  ·  Technical
AI Ethics
AI-Enabled Suicide: When Compassion Meets Code

Examining the tragic case of Adam Raine alongside Replika's life-saving protocols — and what the contrast reveals about ethical AI design for vulnerable users.

LinkedIn Newsletter  ·  AI Safety  ·  Mental Health

AIxGRC Roadmap

A look at what I'm building next — ongoing projects, planned research, and future directions for the AIxGRC brand.

01
Whitepapers

Publishing in-depth whitepapers on AI governance topics — starting with EU AI Act compliance and financial AI security alignment.

02
GRC Toolkits

Building open, practitioner-ready templates — AI risk assessment tools, policy frameworks, and audit checklists grounded in NIST and ISO standards.

03
Case Studies

Real-world AI governance analyses across industries — retail, finance, healthcare, and the public sector — applying regulatory frameworks to actual deployments.

04
Georgetown Research

Sharing academic research and capstone work from Georgetown University as it develops — connecting theory to practice in AI policy and risk governance.

Governance Frameworks

The regulatory and risk management frameworks that form the foundation of my research and applied work in AI governance.

Risk Management
NIST AI RMF

The National Institute of Standards and Technology AI Risk Management Framework — a voluntary, flexible framework for managing risk throughout the AI lifecycle.

Management System
ISO/IEC 42001

The international standard for AI management systems — providing requirements and guidance for responsible development, deployment, and governance of AI.

Regulation
EU AI Act

The European Union's landmark AI regulation applying a risk-based classification system to AI systems, with binding obligations for high-risk deployments.

Information Security
ISO/IEC 27001

The globally recognized standard for information security management systems — foundational for securing the data and infrastructure underpinning AI systems.

Trust & Cloud
SOC 2

The AICPA trust services framework evaluating security, availability, processing integrity, confidentiality, and privacy — critical for AI-powered SaaS platforms.

Payment Security
PCI DSS

Payment Card Industry Data Security Standards — applicable wherever AI systems process, transmit, or store cardholder data in financial services contexts.

Emerging
AI Regulation — Global

Monitoring emerging AI regulations across the U.S., UK, Canada, and beyond — including executive orders, sector-specific rules, and proposed legislative frameworks.

Let's Connect

I'm always open to conversations about AI governance, research collaborations, speaking opportunities, or just connecting with others in the GRC space. Reach out — I'd love to hear from you.