Leading Gen AI Adoption with Hoang Vinh Nguyen
Apex Executive Insights
Leading Generative AI Adoption Through Governance and Control
An Apex 1:1 with Hoang Vinh Nguyen, VP, Internal Audit, Bank of China USA
Like many organizations across our industry, we discovered that Generative AI is not only reshaping enterprise technology but also redefining the risk landscape at a pace few organizations have experienced before. In leading GenAI implementation programs, I learned that the greatest challenge is rarely the technology itself. It is aligning the speed of innovation with the discipline of governance and control.
Very early, I realized that traditional IT controls were not designed for the realities of AI. Risks such as model bias, privacy exposure, hallucinations, adversarial manipulation, and opaque decision making demand a fundamentally different approach. Assurance cannot be treated as a checklist performed after deployment. It must be embedded throughout the AI lifecycle, with model risk, data governance, and third party dependencies managed as interconnected components of a single ecosystem. One of my most valuable lessons was recognizing that effective assurance teams cannot remain observers. While establishing governance guardrails, my team and I worked closely with stakeholders to build and scale AI enabled capabilities. Controls were designed and embedded early in the lifecycle, allowing risk management and audit functions to develop a deep understanding of how AI solutions are designed, deployed, governed, and continuously monitored.
Another lesson is that trust with regulators, executive management, and Audit Committees is not built through theoretical compliance. It is earned through practical solutions, technical credibility, and measurable outcomes. When we invest in multidisciplinary teams and develop talent that understands both technology and risk, governance ceases to be a constraint and becomes a catalyst for innovation, resilience, and sustainable growth.
About the Author
Nguyen is a Governance, Risk, and Compliance executive with more than 25 years of global leadership experience across banking, insurance, and financial services. As a former Chief Technology Officer for a major APAC insurance organization, where he led enterprise technology transformation, digital innovation, and operational resilience, he brings a unique perspective that bridges technology execution with governance. His expertise spans technology risk, cybersecurity, AI governance, internal audit, and regulatory compliance. He advises boards and executive leadership on building trusted, resilient, and technology ecosystems with strong governance that enable innovation while managing risk.
SHARE THIS ARTICLE