Gary Cheung
Beyond1n0 · Information Risk & AI Governance
I’m Gary Cheung, an information risk leader working at the intersection of AI governance, technology risk, and business judgment.
Beyond1n0 examines how AI developments change decision authority, accountability, and business risk, especially in insurance and other regulated businesses. The news is the context; the judgment is the point.
My focus
Who owns the decision?
When can governance still influence the design?
What needs executive judgment?
Professional experience
My financial services experience shapes a practical view of oversight: connect risk to the decision, make authority explicit, and give leaders a clear basis for judgment.
Manulife Asia · Hong Kong
Second-line information risk leadership with Asia oversight responsibilities across technology and information security risk.
Professional certifications: CISSP · CEH · PCNSE · CCNP
The perspectives shared here are my own.
Three governance questions
Policies matter. These questions help connect them to the decisions leaders actually need to make.
01 · Decision accountability
When AI influences an outcome, who has the authority to approve, challenge, or stop it — and who remains accountable for the consequences?
02 · Design-phase governance
Does governance arrive while objectives, data flows, and decision rights can still be shaped, or only after the important choices have been made?
03 · Executive judgment
Which uncertainties and trade-offs need explicit executive judgment, rather than being absorbed into technical controls or routine approval?
Selected writing
Accountability
Why governing models and controls still leaves a fundamental question about decision ownership.
Governance timing
What happens when oversight begins after the architecture and operating assumptions are already set.
Leadership & oversight
The shift from constraining system behavior to establishing authority, accountability, and oversight.
Applied governance
Considering AI in a client-facing or operational workflow? I help frame the intended use, clarify decision ownership, and surface the safeguards and trade-offs leaders need to consider.
Clarify the intended outcome, the role of AI, and who holds decision authority.
Examine assumptions, information flows, human intervention, and escalation while choices are still open.
Surface material trade-offs and uncertainties, identify the accountable owner, and define what would trigger reconsideration.
Contact
If you are deciding where AI belongs in a business workflow, I welcome a conversation about the intended use, accountable owner, and material safeguards.
Beyond1n0 is my space for independent thinking on information risk and AI governance.