April 8 2025
CIO 2026

Shaping the Future of Work: TMF’s Secure AI Ecosystem

post-img

Saurabh Gugnani
Senior Director, Global Head - Information Security Engineering, Architecture & Projects, TMF group

 

TMF Group is approaching the AI era with a deliberate focus on responsible adoption, workforce enablement, Navigating the frontier of AI requires a proactive stance on compliance, security, and human oversight. To ensure technology acts as a catalyst for secure growth rather than a liability, TMF has established an ecosystem for responsible AI deployment. This framework bridges international regulatory standards with practical, day-to-day employee guidelines, ensuring innovation and accountability coexist seamlessly.

 

Harnessing AI Responsibly
At the foundation of our approach is a formal AI Governance Framework, aligned with leading standards such as the NIST AI Risk Management Framework, the EU AI Act, ISO 42001, and GDPR. This framework establishes clear principles, accountability, and lifecycle controls for all AI use cases across TMF, ensuring employees understand when and how AI can be used, and where human oversight is required.

To translate governance into day‑to‑day behaviour, TMF has implemented Generative AI Platform Guidelines applicable to all employees. These guidelines clearly define acceptable use, data handling expectations, and risk considerations when using GenAI tools for tasks such as content creation, analysis, translation, and coding. Employees are explicitly guided on avoiding the input of sensitive, client, or personal data, helping reduce privacy, security, and intellectual property risks while still enabling productivity gains.

Workforce readiness is further strengthened through structured use‑case identification and risk‑based classification. Employees are encouraged to propose AI use cases aligned to business outcomes, which are then assessed for data sensitivity, ethical impact, and security risk before approval. This ensures teams can innovate without bypassing controls or creating “shadow AI” risks.

In parallel, TMF has embedded security, privacy, and identity controls into AI adoption. This includes defined requirements for access management, logging, monitoring, vendor assurance, and post‑deployment reviews, ensuring employees interact with AI systems in a controlled and auditable manner throughout their lifecycle.

By combining clear governance, practical guidance, and strong security foundations, TMF is equipping its workforce to harness AI responsibly—enabling innovation and efficiency while maintaining trust, compliance, and accountability as AI becomes an integral part of how work gets done.