Governance is not the brake. It is what lets you ship.

AnjaneyaTurai

Role
AI Lead, Governance
Organisation
South East Water
Also
Founder, Novareck AI
Based
Melbourne, Australia
Scroll — the register begins below
Anjaneya Turai
12+ patents granted MDS, Univ. of Melbourne Stanford AI in Healthcare
01 — Position

Everyone can build it. Almost nobody can defend it.

Twelve weeks to a working pilot. Twelve months to an answer for the regulator.

I lead AI governance at a Victorian water utility, which means I sit at the point where an exciting demo meets a privacy commissioner, a procurement panel, a legal team, and a board that has to sign something. The interesting work is not getting the model to answer. It is being able to show, months later, who approved it, on what evidence, and what happens when it is wrong.

My route here ran through the build side. Data science degrees, a Master of Data Science at Melbourne, twelve granted patents in AI and cybersecurity, and years shipping models before governance was a job title anyone wanted. That matters, because governance written by people who have never deployed anything becomes paperwork, and paperwork gets routed around.

Alongside the utility work I run Novareck AI, an independent consultancy taking the same audit-ready approach to SMEs and regulated industries, and I teach and speak on AI governance to people who have to make these calls next quarter, not in theory.

Principle 01

Evidence, not assertion

A vendor claim is not a control. Every risk assessment I sign is grounded in the vendor's own published documentation, cited and dated, so the finding survives the vendor changing their marketing page.

Principle 02

Controls at design time

Retrofitting governance onto a live system means choosing between switching it off and accepting the risk. Constraints belong in the architecture review, not the incident review.

Principle 03

Registers that match reality

Most organisations have an application register and a shadow estate that ignores it. A register nobody can see into is a comfort object. Discovery has to be automatic or it is fiction.

02 — Trajectory

Build first. Then govern.

Consulting, banking, insurance, legal, and now water. The regulated end of every one of them.

Current
AI Lead, Governance
South East Water · Melbourne
  • Own the AI governance and third-party AI risk framework, including the organisation's formal AI use policy
  • Lead the enterprise Microsoft 365 Copilot rollout across licensing strategy, governance, agent adoption and training
  • Built the Agent Risk Assessment register, colour-coded and risk-rated for executive review
  • Policy work grounded in OVIC and OECD frameworks and aligned to the wider corporate policy suite
Founder & Principal Consultant
Novareck AI
  • Independent AI consultancy for SMEs and regulated industries, built on an audit-ready governance proposition
  • AI and data science delivery, IT and tech consultancy, and applied ML for clients without an internal AI function
  • Training and enablement across AI, data science and cyber
Artificial Intelligence Lead
FGD Family Law
  • Creation and deployment of AI solutions for clients, partners and stakeholders in a legally sensitive setting
  • Internal AI infrastructure and operations, including confidentiality and privilege constraints on model use
Artificial Intelligence Engineer
Horsell Technology
  • Built a recommendation system end to end, using film plotlines as the semantic basis for personalised suggestions
  • Used the OpenAI API for data collection, streamlining acquisition and algorithm refinement in the same loop
Business Intelligence Unit
Star Union Dai-Ichi Life Insurance
  • Document analysis: classifying document type and assessing quality using Laplacian, Canny and Sobel techniques
  • Applied AWS Rekognition alongside custom deep learning models across the intake pipeline
Data Scientist
AlgoAnalytics
  • Removed downtime and lifted throughput through code and algorithm optimisation using Cython
  • Worked on multi-object tracking pipelines including DeepSort
Chief Technical Officer
Skills Enrich
  • Owned technology development and delivery for external customers, vendors and partners
  • Ran internal IT operations alongside the product build
Deloitte · KPMG · ANZ
Consulting, advisory and banking
  • Deloitte India — technology strategy and innovation, cloud computing and optimisation
  • KPMG India — data cleaning, visualisation and executive presentation
  • ANZ Bank — customer data analysis and insight generation
Education
Master of Data Science
The University of Melbourne
  • Bachelor of Science, Data Science — Gold Medal, ranked first in cohort
  • Associate Degree, AI in Healthcare — Stanford University
  • Google certified data and analytics credentials
03 — Impact

Delivered, not projected.

Hover any cell for where the number comes from.

12+
Patents granted
AI & cybersecurity · India + US
Org-wide
Release of AI products
Microsoft 365 Copilot
Multiple
AI policies & frameworks
Authored and consulted
3+
International papers published
Peer-reviewed · indexed
60+
Vendor AI assessments
Grounded in official vendor documentation
5+
Frameworks referenced
3 applied end to end
8+
Years in data & AI
Consulting → banking → utility
Every figure above is traceable to a delivered artefact.
04 — Selected work

What the register actually holds.

Context, approach, control, outcome. The four questions an auditor asks in that order.

Third-Party AI Risk Framework

A defensible way to say yes, and a documented way to say no, to vendor AI.
Enterprise utility · Third-party assurance
In force
Context
Every vendor in the stack shipped an AI feature at once. Procurement had no consistent basis to assess them, so decisions were being made on vendor marketing claims rather than evidence.
Approach
Built a full AI governance and risk assessment framework for third parties, formalised as organisational policy and sequenced into the existing procurement gates rather than bolted beside them.
Control
Findings are grounded exclusively in official vendor documentation — cited, dated, and re-checkable. A public AI fabrication case study sits in the framework as the worked example of what unverified output costs.
Outcome
60+ vendor AI assessments completed against the framework. Repeatable by someone who is not me, which is the only real test of a framework.

Microsoft 365 Copilot — Early Adopter Programme

Governing generative AI across an org-wide user base without stopping the rollout.
Enterprise programme · Generative AI at scale
Running
Context
Copilot inherits every permission the user already has. At enterprise scale that turns latent oversharing into a live data exposure question on day one.
Approach
Led the rollout across licensing strategy, governance, agent adoption and training as one programme, so entitlement decisions and control decisions were made by the same people at the same time.
Control
A structured acceptance-test register, a legal-reviewed early adopter acknowledgement, a delivery Gantt, kick-off materials, and an Agent Risk Assessment register colour-coded to the corporate risk rating scale.
Outcome
Org-wide release under a governance wrapper that legal signed and executives can read. Policy work aligned to OVIC and OECD frameworks and carried into the corporate policy suite.

Shadow AI Discovery Platform

The register problem: teams keep adopting tools that never reach the register.
Product concept · In development
In development
Context
Organisations maintain application registers for cyber and AI risk. Meanwhile staff sign up to free tools and build agents that never appear in the register at all. The risk view is accurate and useless at the same time.
Approach
Entra ID application discovery under a multi-tenant OAuth architecture, surfacing what is actually connected rather than what was declared.
Control
A five-stage governance pipeline sits behind discovery — the defensible part, and the reason this is not another inventory tool.
Outcome
Targeting one dashboard across the low-code and agent estate: Copilot Studio agents, declarative agents from Agent Builder, Power Apps and Power Automate flows.

Azure-Native Voice Agent

A speech-to-speech agent built inside the tenancy boundary, not around it.
Prototype · Claude API + Azure
Prototype
Context
Voice agents are the fastest route to a governance problem: audio is personal information, and most reference architectures move it somewhere nobody assessed.
Approach
Built a working prototype on the Claude API with Azure-native STT, LLM and TTS components, keeping the data path inside assessed infrastructure.
Control
Produced a full SVG architecture diagram of the system so the data path is reviewable by security and privacy before anyone argues about the voice.
Outcome
A reference pattern for conversational AI that can survive a privacy impact assessment rather than one that has to be explained away after it.

Novareck AI

Independent AI consultancy for organisations that cannot afford to get this wrong.
Novareck AI · SMEs and regulated industries
Open for work
Context
Smaller organisations in regulated sectors carry the same obligations as large ones with none of the internal governance function to meet them.
Approach
An audit-ready proposition: AI and data science delivery, IT and tech consultancy, and web and software work, with the assurance artefacts produced as part of delivery rather than sold afterwards.
Control
Governance materials, risk registers and policy scaffolding are handed over with the build, so the client owns the evidence trail.
Outcome
Engagements spanning machine learning, analytics, AI enablement and training across Australian and international clients.
05 — Research & IP

Twelve granted patents, and counting.

Filed across AI and cybersecurity in India and the United States, alongside published research and national awards.

12+
Granted patents
AI · cybersecurity · India + US
IEEE
Xplore publication
Amity University conference
×2
ICCTES papers
Cyber Technologies & Emerging Sciences
2024
Future Leader Award
Dr. APJ Abdul Kalam Inspire Awards
2023
Young Researcher Award
Scientific International Publishing House
GDSC
Speaker, 2026
Session on AI governance
AI-501
Course taught
AI in HR — teaching & assessment
Book
AI & ML: An Industrial Perspective
Author · available on Flipkart
Gold
Medal, BSc Data Science
Ranked first in cohort
Where I have worked and studied
06 — Stack

What I actually use.

Governance instruments on the left, the things being governed on the right.

LLM & agent engineering

  • Claude API tool use · MCP
  • OpenAI & Azure OpenAI
  • Function calling structured output
  • Multi-agent orchestration
  • LangChain · LangGraph
  • Semantic Kernel
  • Copilot Studio · Agent Builder
  • Prompt versioning & caching
  • Streaming & token budgeting
  • Guardrails & refusal design

Retrieval & knowledge

  • RAG hybrid · rerank
  • Chunking & layout parsing
  • Embeddings dense · sparse
  • FAISS · Chroma · pgvector
  • Azure AI Search
  • GraphRAG entity linking
  • Query rewriting & HyDE
  • Groundedness scoring
  • Citation & provenance tracking

Model ops & evaluation

  • Fine-tuning LoRA · QLoRA · PEFT
  • Quantisation GGUF · AWQ · INT8
  • vLLM · Ollama · llama.cpp
  • Hugging Face Transformers
  • Eval harnesses LLM-as-judge
  • Red teaming & jailbreak testing
  • Drift & regression gating
  • MLflow · Weights & Biases
  • Latency & cost profiling

ML, speech & vision

  • PyTorch · TensorFlow
  • scikit-learn · XGBoost
  • pandas · NumPy · spaCy
  • Speech-to-text Azure · Whisper
  • Text-to-speech & VAD
  • Diarisation & streaming audio
  • OpenCV Canny · Sobel · Laplacian
  • DeepSort object tracking
  • Recommender systems
  • Cython optimisation

Platform & data

  • Azure AI Foundry · Functions
  • Key Vault & private endpoints
  • AWS Rekognition · S3
  • Google Cloud
  • Docker · Kubernetes
  • CI/CD & IaC
  • Power BI DirectQuery
  • Dataverse · Power Query M
  • Entra ID app discovery
  • Python · R · SQL · C/C++ · Java

Governance & assurance

  • AI policy authoring
  • Third-party AI risk assessment
  • Agent risk registers exec-rated
  • Privacy impact assessment
  • OVIC · OECD principles
  • ISO/IEC 42001 alignment
  • NIST AI RMF
  • Acceptance test registers
  • Model & system documentation
  • Executive risk reporting
07 — Contact

Bring the hard one.

Governance questions, AI risk reviews, speaking, or consultancy work.

If you are standing up AI governance from nothing, trying to get a Copilot rollout past legal, or holding a vendor claim you cannot verify, that is the conversation I want.

I also take speaking and teaching work on AI governance for audiences who have to make real decisions, and consultancy engagements through Novareck AI.

Questions about data science, AI, ML, or guidance on research papers and patents are welcome too.

00:00
0%
X+0.0000
Y+0.0000