MEET THE SPEAKER: GYEYOK HARUNA – SPEED WITHOUT THE BLAST RADIUS: THE GOVERNANCE GEARBOX FOR AI IN FINANCIAL SERVICES
Speaker Name: Gyeyok Haruna
What's one thing you hope attendees take away from your session?
I want attendees to leave with one question they can ask on Monday morning. What gear is my organisation actually in right now. Not "how do we remove governance from the room," but "which gear do we need to be in for the terrain ahead." That question comes from a line I built after getting tired of watching good governance work get treated as friction. Governance is not a handbrake. It's a gearbox. A handbrake only ever does one thing, it stops you. It doesn't help you take the next corner, and it definitely doesn't help you take it faster next time. A gearbox is different. It's what actually lets a car move at all, you just have to be in the right gear for the terrain. I first tested this properly at IRM UK's Data Governance, AI & MDM Conference, walking practitioners through how five gears, Foundations, Scaling Controls, Strategic Alignment, Continuous Assurance, and Responsible Innovation, shift an organisation from stalling on AI to moving with it. In financial services specifically, I've watched this play out again and again. Teams that treat governance as a checkpoint stay stuck in first gear, afraid to accelerate. Teams that treat it as a gearbox move faster, not slower, because they're not white-knuckling every decision. That single reframe, from obstacle to mechanism, is the thing I've watched change how teams operate, long after the session ends.
In one sentence, what do you do and what is your role?
I'm Gyeyok Haruna, Data & AI Governance & Compliance Lead, and I help organisations turn data and AI governance from something that slows them down into the thing that lets them move faster with confidence, through a framework I call the Governance Gearbox.
What's the biggest challenge facing the industry in this area?
The biggest challenge is speed outpacing structure. Financial services is moving faster than it ever has, instant payments, open banking, AI adoption, all landing at once, and most institutions are still governing at the pace they used to move at. That gap is where the real risk lives. What makes it harder in fintech specifically is the two-speed problem. Incumbents are held back by legacy systems and years of accumulated process, they know how to govern but struggle to move fast. Challengers move fast by design, but they're still earning the institutional trust that comes with mature governance. Both are solving the same problem from opposite directions, and neither can just borrow the other's playbook wholesale. I see this play out in the same way. A team ships something genuinely good, a new payments flow, a fraud model, an onboarding tool, and governance gets treated as the thing that happens after launch, once someone asks the right question in a review meeting. By then you're not designing governance anymore, you're doing forensic reconstruction. You're trying to explain decisions that were made under pressure, by people who have since moved on to the next sprint, using documentation that was never built to be read by anyone outside the original team. I've never seen a team successfully bolt governance onto a system that's already live and already causing problems. It's always slower, expensive, and painful than designing it in from the first gear. The teams that get this right don't treat governance as a gate at the end of the process. They treat it as part of how the thing gets built in the first place, the same way security or performance would be. The wider industry challenge sits underneath all of that. Until governance is treated as infrastructure rather than paperwork, this gap between speed and structure isn't going to close on its own. It's going to keep showing up, one incident at a time, until enough organisations decide to build differently.
What's one piece of advice you'd give to someone working in fintech today?
Build your governance foundations before you're forced to retrofit them. That's not advice I give lightly, it comes from watching the same pattern play out too many times. A team moves fast, ships something genuinely good, and governance gets treated as a conversation for later, once the thing works, once there's time, once someone in a review meeting asks the question nobody wanted to ask first. By the time that conversation happens, you're not designing governance anymore. You're trying to reconstruct decisions that were made under pressure, by people who have since moved on to the next sprint, using documentation that was never built to be read by anyone outside the original team. I've never seen that go smoothly. It's always slower, more expensive, and more painful than building it in from the first gear. The advice isn't to slow down. It's to build the foundations at the same speed you're building everything else. Define who owns what before you need to know who owns what. Write down the decision, not just the outcome. Treat your data lineage and your model documentation the way you'd treat your source code, something that has to survive the person who wrote it moving on. If you're early in your career in fintech, this is also where you can genuinely stand out. Most people are focused on shipping the feature. The ones who also think about how that feature gets governed, how it gets explained to a regulator, a risk committee, or a customer who wants to know why a decision was made, are the ones who end up in the room when it matters. Governance isn't the boring part of the job. It's the part that makes everything else you build actually trustworthy enough to scale.
What book, podcast, newsletter, or resource would you recommend to our audience?
I'd recommend "The Easy Peasy Guide to the EU AI Act" by Jamal Ahmed. Most people reading regulation stop at knowing what it says. This book is built for the harder part, understanding what actually needs to happen in practice once the article numbers stop meaning anything to the people you're trying to bring along with you. What I appreciate about it is that it doesn't treat the Act as something to survive. It treats it as something to operationalise, which is exactly the gap I spend most of my time working in. If you're in fintech and trying to translate "what does the regulation say" into "what does my team actually do on Monday," this is the resource I'd put in your hands first.
What topic will you be speaking about at FinTech Connect 2026?
Speed Without the Blast Radius: The Governance Gearbox for AI in Financial Services. It's built around a framework I call the Governance Gearbox; five gears that treat AI governance as the thing that lets an organisation accelerate safely, not the thing that slows it down. I'm speaking on the Financial Security & Compliance Stage, where I've watched that tension between speed and control play out most clearly.
Just for fun: if you could have dinner with any person, past or present, who would it be and why?
I'd want dinner with a CEO of a major financial institution currently steering their organisation through large-scale AI adoption. Not a specific name, more the seat itself. I want to understand what the view looks like from up there. I'd want to know what they're actually seeing when they look at the pace their organisation is moving at, and whether they see speed and doing things properly as two competing priorities, or genuinely believe both can happen at once. No organisation plans to get fined or make headlines for the wrong reasons. So what's the gap between that intention at the top and what actually shows up in the day to day for the people building and running the systems. Strategy usually moves top down, the direction gets set, then it gets pushed through leadership layers until it lands with the people actually doing the work. What I'd genuinely want to know is whether that CEO has ever tried to see it from the other direction. Not just communicating the vision downward, but actually stepping into the shoes of the person implementing it, and asking whether what they're expecting is realistic at the pace they're expecting it. I think that's the conversation most governance work is missing. Not a lack of good intentions at the top. A lack of anyone at the top pressure testing whether their intentions actually survive contact with how the work really gets done.
What industry trend are you watching most closely?
Agentic AI governance. We've mostly figured out, imperfectly, but figured out, how to govern AI that generates an output for a human to review. Someone reads the recommendation, checks it, decides whether to act on it. That review step has been doing a lot of quiet work in keeping organisations safe, even when the underlying governance wasn't perfect. What we haven't figured out is how to govern AI that takes autonomous action on our behalf, no human in the loop checking the decision before it happens. That's not a small shift, it removes the safety net most current governance frameworks are quietly relying on without saying so out loud. Financial services is going to be one of the first places this gets tested properly, and not gently. These are systems that don't just suggest a payment gets flagged or a transaction gets reviewed, in an agentic model they execute the action themselves. Move the money, approve the loan, close the account. The gap between "AI suggested this" and "AI did this" is where I think the next few years of governance conversation is going to live, and most organisations haven't built for that gap yet because they built their governance for the world where a human was always the last checkpoint.
Why is this topic particularly important right now?
Instant payments, open data, and AI adoption have all raised the stakes at the same time, not one after another where organisations could adapt in sequence, but all landing together. Decisions happen faster, more of them are automated, and the cost of getting one wrong, the blast radius, is bigger than it's ever been because the systems are more interconnected than they used to be. This creates a particular kind of pressure in fintech specifically. Incumbents are held back by legacy systems and years of accumulated process, they know how to govern, but struggle to move at the speed the market now expects. Challengers move fast by design, that's the whole point of being a challenger, but they're still earning the institutional trust that comes with mature governance, and trust doesn't move at the same speed as a product roadmap. Both are solving the same underlying problem from opposite directions, and neither can simply borrow the other's playbook wholesale. What both need, and what most organisations in this space don't yet have, is governance that scales at the speed they're actually trying to move at, not governance that was designed for a slower era and is now being stretched to cover a faster one. This isn't a future problem to plan for eventually. The systems making these decisions are already live, right now, in production, today.
What's one prediction you have for the next 3-5 years?
If organisations don't prioritise data and AI governance now, foundations first, ahead of the rush to build agentic systems, the gaps that already exist are going to get exposed, and probably not quietly. I expect we'll start seeing more organisations facing regulatory fines and public incidents over the next few years, not because the technology itself failed, but because nobody built the governance structure to catch a problem before it went live and started making autonomous decisions. The pattern I keep seeing is teams that treat governance as something you retrofit once the system is already working, once there's time, once someone in a review meeting finally asks the question nobody wanted to ask first. By then it's not governance design anymore, it's forensic reconstruction, trying to explain decisions that were made under pressure by people who have since moved on to the next build. The more interesting story is the flip side. The organisations taking governance seriously now, before it's forced on them by an incident, a regulator, or a headline, are the ones that will still be standing when things start breaking elsewhere. I don't think governance is going to be the thing that held the cautious organisations back over the next five years. I think it's going to be the thing that separates who scaled safely from who scaled recklessly and got lucky for a while. Luck runs out. Foundations don't.