Stephen Sennett

Stephen Sennett

Principal Forward-Deployed Engineer - Applied AI

V2 AI

Regulated Doesn't Mean On Rails: what compliance actually asks of your engineers

See all speakers

Regulated Doesn't Mean On Rails: what compliance actually asks of your engineers

We spent three months rebuilding a regulated enterprise's development lifecycle around agents, then worked out how much of the governance we had added was doing real compliance work. Less than we assumed.

Across APRA's prudential standards, the ISM, SOC 2 and ISO 27001, the same four obligations recur: traceability, change management, testing proportionate to change, and independence between whoever makes a change and whoever approves it. Not one says how an engineer should get to a change.

A specification records what you intended, not what happened. The trace already exists — the session, the tool calls, the commit that carries them — and unlike a document, an auditor can re-run it.

I will show what we kept, what we tore out, and the thing nobody has solved: every separation-of-duties rule I can find governs "persons". An agent that implements and approves its own change breaches it today.

Stephen Sennett

Stephen Sennett is a cloud technology leader, content creator, educator, and speaker. He worked in the industry for over a decade across in a variety of roles, currently as a Principal Forward-Deployed Engineer specialising in Applied AI and Cloud with V2 AI. He holds high-level certifications across multiple technologies, has been recognised as an AWS Community Hero, spoken at events around the world, and authors technical content with A Cloud Guru (a Pluralsight company).

Outside work, he is a dedicated volunteer across numerous organisations, primarily in the Emergency Management sector, serving around the country during several major national disasters.