About
I’m Hernan Huwyler, an AI, risk, privacy, and compliance practitioner focused on one thing: helping organizations build AI that works in production and stands up to real scrutiny from regulators, auditors, and boards.
Over the years, I’ve led technology, risk, privacy, and compliance programs in large enterprise environments, including work supporting Fortune 500 organizations and Big Four-style professional services teams. That “in the trenches” experience shaped how I approach AI: not as a science project, and not as a slide deck, but as a system that must be engineered, documented, monitored, and defended over its full lifecycle.
On the development side, I build and oversee predictive modeling work using scikit-learn and PyTorch, with a practical focus on the decisions that make models succeed (or fail) after deployment: feature design, evaluation design, drift and stability, monitoring strategy, retraining triggers, and the operational realities of shipping models into production workflows. I care about performance, but I care just as much about reliability, interpretability where needed, and clear accountability for outcomes.
On the governance side, I help organizations operationalize AI controls using a management-systems mindset aligned with frameworks and standards like ISO 42001, ISO 23894, and the NIST AI Risk Management Framework. My goal is to translate governance requirements into concrete engineering and operational tasks, things teams can actually implement: model documentation, data lineage, testing evidence, human oversight design, incident response, third-party/vendor risk controls, and end-of-life decommissioning.
A major theme in my work is moving beyond vague “AI ethics” language into measurable, decision-grade risk management. That includes quantifying exposure where possible (e.g. the financial and regulatory impact of bias or failure modes), treating model drift as a business risk (not just a technical metric), and creating governance that accelerates delivery instead of slowing it down.
I currently serve as Executive Education Director at IE Law School, where I design programs that prepare senior leaders to govern AI and build effective compliance functions. My background includes professional training in business and accountability (MBA/CPA), which shows up in how I frame AI governance: as an operational “heartbeat” that connects strategy, engineering execution, and defensible outcomes.
What I help teams do
- Design and deploy predictive models with scikit-learn and PyTorch in real business processes
- Set up practical model risk management: bias testing, validation evidence, monitoring, drift response
- Build an AI Management System (policies + procedures + controls + metrics) that teams can run
- Align AI programs to ISO/NIST vocabulary so Legal, Risk, Compliance, and Engineering stay coordinated
- Strengthen vendor AI risk reviews beyond “we don’t train on your data” by addressing the full stack: fine-tuning, retrieval, logs, telemetry, and termination/ownership questions
Topics I speak and write about
AI governance that scales, EU AI Act readiness, operationalizing ISO 42001, model monitoring and drift, risk quantification, third-party AI risk, and bridging data science with executive accountability.