About Prof. Hernan Huwyler, MBA CPA CAIO
I work where business decisions, technology, risk and accountability meet.
I am Prof. Hernan Huwyler, MBA, CPA, CAIO, an AI governance and GRC executive, professor, auditor and quantitative risk practitioner. My work focuses on helping organizations understand and control the risks created by complex business processes, enterprise technology and increasingly autonomous AI systems.
Over the course of my career, I have worked across audit, internal controls, SOX, SAP, compliance, operational risk, technology risk and business process improvement in multinational organizations and consulting environments. That experience has taken me from financial and SAP controls to cybersecurity, regulatory compliance and AI governance, giving me a practical view of how risks move between business processes, technology and management decisions.
Today, my work increasingly focuses on AI governance and quantitative risk. I study how organizations can move beyond static risk assessments and broad policy statements toward measurable controls, predictive risk models and decision processes that can be tested, monitored and improved. I am particularly interested in the point where AI, corporate governance and audit meet: how to establish accountability for AI systems, how to quantify exposure, and how to turn risk information into decisions that management can actually use.
I created this blog to document and share that work.
The articles bring together practical experience from GRC and audit with research and teaching in AI governance, risk management, SAP controls, SOX, compliance, quantitative risk, business processes and technology. Some articles are deliberately technical, covering SAP transactions, control procedures, audit evidence and implementation issues. Others examine broader questions about how organizations should govern AI, measure risk and design controls for systems that increasingly make or support decisions.
The objective is simple: make difficult risk and compliance problems easier to understand and more useful to the people who have to act on them.
I write primarily for executives, risk and compliance professionals, internal auditors, SAP professionals, technology leaders, academics and students who want practical analysis rather than generic descriptions of frameworks.
The views expressed on this blog are my own and do not represent those of my current or former employers, clients, universities or other organizations with which I am or have been affiliated.
Comments are moderated to keep discussions relevant to the subject of each article. Spam, unrelated promotional material and hateful or abusive content may be removed.
If you would like to reproduce substantial material from this blog, please contact me before doing so.
For my work specifically focused on AI governance, AI risk management and responsible AI, visit my AI Governance and Risk Management site. AI Governance and Risk Management

