Stephen Sennett
Principal Forward-Deployed Engineer - Applied AI
V2 AI
Regulated Doesn't Mean On Rails: what compliance actually asks of your engineers
Regulated Doesn't Mean On Rails: what compliance actually asks of your engineers
We spent three months rebuilding a regulated enterprise's development lifecycle around agents, then worked out how much of the governance we had added was doing real compliance work. Less than we assumed.
Across APRA's prudential standards, the ISM, SOC 2 and ISO 27001, the same four obligations recur: traceability, change management, testing proportionate to change, and independence between whoever makes a change and whoever approves it. Not one says how an engineer should get to a change.
A specification records what you intended, not what happened. The trace already exists — the session, the tool calls, the commit that carries them — and unlike a document, an auditor can re-run it.
I will show what we kept, what we tore out, and the thing nobody has solved: every separation-of-duties rule I can find governs "persons". An agent that implements and approves its own change breaches it today.
Stephen Sennett
Stephen Sennett is a cloud technology leader, content creator, educator, and speaker. He worked in the industry for over a decade across in a variety of roles, currently as a Principal Forward-Deployed Engineer specialising in Applied AI and Cloud with V2 AI. He holds high-level certifications across multiple technologies, has been recognised as an AWS Community Hero, spoken at events around the world, and authors technical content with A Cloud Guru (a Pluralsight company).
Outside work, he is a dedicated volunteer across numerous organisations, primarily in the Emergency Management sector, serving around the country during several major national disasters.