Verwandte Artikel zu The Wrong Question: A Compliance Leader's Playbook...

The Wrong Question: A Compliance Leader's Playbook for Adopting AI Without Creating Risk - Softcover

Nichols, Matthew

 
9798188095895: The Wrong Question: A Compliance Leader's Playbook for Adopting AI Without Creating Risk

Inhaltsangabe

Everyone in the room was asking the wrong question.

At a business conference packed with sharp, experienced operators, the AI discussion kept circling back to one question: What's the best AI? The instructors answered as best they could. Nobody pushed back on the question itself.

Matt Nichols didn't say anything out loud. But he knew: if that's the question you're leading with, you haven't yet run into the problem that actually matters.

"What's the best AI" is the same question as "what's the best vehicle." The answer depends entirely on what you're hauling, how far, and who's driving. A box truck and a Formula 1 car are both excellent at what they do. Neither is the best. The question only makes sense once you know the job.

This book is about getting the question right — and building the foundation that makes every AI decision after it easier, faster, and defensible when an auditor or a regulator eventually asks how you made it.

Written by someone who's actually been in the room when the auditor showed up.

Matt Nichols spent 25 years in the Marine Corps as a senior counterintelligence and human intelligence officer, with approximately 12 years across combat and contingency operations. He later served as a federal agent with NCIS and the Diplomatic Security Service before transitioning to business operations.

Today he is VP of Operations for a healthcare-adjacent holding company with five businesses supporting independent pharmacies and a pharmacy benefit manager — where he owns security, compliance, SOC 2, HIPAA/HITECH, and AI governance. His last SOC 2 Type 2 audit returned zero findings.

This is not consulting theory. It is not research. It is what he built, defended under audit, and ran in a real regulated environment.

What this book covers:


  • How to prepare your technical environment before any AI tool goes live

  • How to map your data exposure so you know what you're actually protecting

  • How to build governance that's lightweight enough to use and strong enough to survive an audit

  • How to vet vendors and read contracts — including BAAs and NDAs — the way a counterintelligence officer reads a source report

  • How to select tools by job fit rather than hype

  • How to roll AI out to employees without creating the shadow AI problem you were trying to avoid

  • How to run a breach risk assessment if something goes wrong — and what to have ready before it does

  • How to make the whole program something you can hand an auditor instead of something you hope they never ask about





If you're running a business in or near a regulated environment — healthcare, pharmacy, finance, anything that touches protected health information or sensitive client data — this book was written for you.

Nothing here is legal, compliance, or security advice. It's a record of what one compliance leader did, what he learned, and what he'd do differently. Your judgment and your counsel always carry more weight than anything written here.

But if you want to stop asking the wrong question, this is where to start.

Die Inhaltsangabe kann sich auf eine andere Ausgabe dieses Titels beziehen.