About Diane R. Jones
I help organizations make complex systems governable. My work sits at the intersection of cybersecurity, GRC, software architecture, and AI governance, with a focus on translating system behavior into control intent, admissibility boundaries, and evidence that can support accountable decisions.
From Systems to Governance
I began my career in software development, including writing in Assembler, and later moved through technology leadership, cybersecurity, and GRC roles. Over time, I became increasingly focused on the gap between what organizations intend to govern and what their systems actually do in operation.
That gap became especially visible with AI-enabled systems. As models, agents, tools, retrieval, and automation became part of business workflows, traditional governance mechanisms began to show their limits. Policies, frameworks, testing, and monitoring still matter, but they are not enough unless they connect to the system’s actual behavior and points of consequence.
Current Work
I’m focused on the AI Admissibility Framework and the Control Intent Engine. AI Admissibility asks what must be true before an AI-enabled system is allowed to act. The Control Intent Engine is a tool that explores how governance can begin from system reality rather than framework checklists, activating relevant governance intents and mapping them consistently to frameworks such as NIST, ISO, and SOC 2.
Background
Founder, Strategic GRC & Security
CISSP, CCSP
Experience across software development, cybersecurity, third-party risk, vulnerability management, governance, and control design
Creator of the AI Admissibility Framework and Control Intent Engine
Speaker and contributor on AI governance, system control, and GRC modernization
How I Work
I seek engagements where the problem is complex, the existing control model is unclear, and leaders need practical ways to move from risk awareness to governed action.
My approach is structured, system-centered, and designed to help organizations make decisions they can explain, operationalize, and defend.