Sumit Sharma
I audit security controls in financial services, and I write about the parts nobody has settled yet.
Melbourne. Cloud identity, privileged access, attack surface, and the regulation that sits over all of it. I came up through offensive security, which changes how I audit — it is easier to judge whether a control holds when you know how it gets bypassed.
Working onAug 2026
How anyone audits an AI system
Organisations are deploying AI faster than anyone has agreed how to assure it. The old control frameworks half-fit. The new ones, NIST AI RMF and ISO 42001, are still being translated into things an auditor can actually test.
Most of what exists is legal commentary or vendor marketing. Very little of it tells you which questions to ask or what evidence to request. That gap is what I'm working through, against NIST CSF 2.0 and APRA CPG 234 as the starting point.
Recent
Nothing published yet. First piece is in progress — it will appear here and on the writing page.
Code
Loading repositories…
Terms
I don't consult, I don't take paid work, and I have nothing to sell. If something here is useful to you, that is the entire point.
Elsewhere