Thinkers360
Interested in getting your own thought leader profile? Get Started Today.

Goutama Bachtiar, MAIB, MBA, FRSA, FFIN, FPT, MAICD, TAISE

Industry Advisory Board at EC-Council University

Jakarta, Indonesia

Board Member, Global Advisory Board, Multi-Fellow, Subject Matter Expert.

An accomplished technology advisory leader with over two decades of experience in Governance, Risk and Compliance on IT, Cybersecurity, and Artificial Intelligence.

Awarded as a fellow of multiple global institutes (Royal Society of Arts, Manufactures and Commerce, FINSIA and OneTrust, among others), and recently Cloud Security Alliance Research Fellow, he has over thirty global credentials, is a Global Awards Judge, and an Industry Advisory Board at EC-Council University, International Advisory Board Member at EC-Council, AI CERTs Advisory Board, and Packt Publishing Technology Advisory Board, as well as a Global Blockchain Business Council Regional Ambassador and Accredited Member of Australian Institute of Company Directors. Additionally, he serves as a Subject Matter Expert for ISACA, CompTIA, ISC2, the Open Compliance and Ethics Group, and the Project Management Institute.

In his IT auditing and consulting practices, he's steered 135+ organisations including Fortune 50, 500, Global 500, India 500 & Indonesia 100 companies. He has co-managed multi-million-dollar enterprise IT projects - 20,000 portfolio, program and project hours.

He has been delivering 320+ sessions to a total audience of 13,500+ people, racking up 6,800+ hours as a chairperson, moderator, jury, (keynote) speaker, panellist, trainer, and lecturer, in-person and online, notably for World CIO 200 Summit, Asia Finance Forum, ASEAN-JIF, BIG Awards and ACFE International Fraud Awareness Week.

As a co-author of three books, one Body of Knowledge (ITABoK), inventor of two pending patents, reviewer of major book publishers and Scopus Q1 + WOS journal manuscripts, creator of 55 courseware, notably for O'Reilly, Springer, Wiley, Elsevier, IASA, BJET, Packt, and Manning.

With a portfolio of 350+ articles, white papers, and manuscripts for 30+ media and organisations, he has written and reviewed for ISACA, COBIT, PMI, PMBOK, CSA, TAISE, CCSK, SSRM, OCEG, AECT, ICEM, ZDNet Asia, and e27.co.

Been featured and quoted by O'Reilly, Cloud Security Alliance, CoinTelegraph, FutureCIO, OrtusClub, BusinessWeek ID, CNBC ID, CNN ID, and Routledge.

Available For: Advising, Authoring, Consulting, Influencing, Speaking
Travels From: Jakarta, DKI Jakarta, Indonesia
Speaking Topics: AI GRC, Cybersecurity, and Data Privacy

Speaking Fee $1,500 (In-Person), $1,200 (Virtual)

Goutama Bachtiar, MAIB, MBA, FRSA, FFIN, FPT, MAICD, TAISE Points
Academic 325
Author 139
Influencer 192
Speaker 140
Entrepreneur 1075
Total 1871

Points based upon Thinkers360 patent-pending algorithm.

Thought Leader Profile

Portfolio Mix

Featured Videos

AFF23 | How Indonesia and SEASIA can win the carbon-free energy quest to fuel AI data centres
December 28, 2025
Cyber Security and Internal Control for a Safer Tomorrow
December 28, 2025
Serangan Siber Kian Canggih, Perkuat "Cybersecurity" Jadi Kunci
December 28, 2025

Featured Topics

Company Information

Company Type: Service Provider
Minimum Project Size: N/A
Average Hourly Rate: N/A
Number of Employees: 5,001-10,000
Company Founded Date: 2003
Media Experience: 15 years
Last Media Interview: 07/29/2025

Areas of Expertise

Agentic AI 31.29
Agile 30.73
AI 32.01
AI Ethics 52.63
AI Governance 75.23
AI Infrastructure 43.38
Analytics 30.35
Big Data 30.20
Blockchain 35.97
Business Continuity 35.93
Business Strategy 34.66
Careers 33.27
Cloud 33.98
Coaching 30.24
Cryptocurrency 41.23
Cybersecurity 43.20
Data Center 30.30
DevOps 35.74
Digital Disruption 30.76
Digital Transformation 30.88
EdTech 32.12
Education 32.49
Emerging Technology 32.01
Entrepreneurship 31.95
Finance 63.80
FinTech 31.72
Generative AI 30.69
GovTech 32.21
GRC 49.77
Healthcare 43.05
HealthTech 30.12
HR 32.40
Innovation 35.44
IT Leadership 48.76
IT Operations 100
IT Strategy 67.83
Leadership 37.59
Management 42.64
Marketing 30.01
NFT 34.14
Predictive Analytics 30.10
Privacy 39.26
Project Management 33.82
Retail 30.20
Risk Management 45.13
Security 36.37
Social 33.32
Startups 30.96
Venture Capital 58.74

Industry Experience

Consumer Products
Federal & Public Sector
Financial Services & Banking
Healthcare
High Tech & Electronics
Higher Education & Research
Insurance
Manufacturing
Media
Professional Services
Retail
Telecommunications

Publications & Experience

3 Academic Awards
Best Paper Award. Journal of Infrastructure Policy and Management (JIPM), Vol. 8 No. 2
Indonesia Infrastructure Guarantee Fund Institute
November 15, 2025

See publication

Tags: AI Ethics

Reviews of Submissions for AECT DDL Crystal Award (2016)
Association for Educational Communications and Technology (AECT)
June 09, 2016
To recognise innovative and outstanding multimedia-based distance learning courses (online, CD-ROM/DVD or video-based) and distance learning projects (single modules, lessons, workshops, or something less than an entire course) from July until August 2016.

See publication

Tags: EdTech

Reviews of Submissions for AECT DDL Crystal Award (2015)
Association for Educational Communications and Technology (AECT)
June 15, 2015
To recognise innovative and outstanding multimedia-based distance learning courses (online, CD-ROM/DVD or video-based) and distance learning projects (single modules, lessons, workshops, or something less than an entire course) from July until August 2015.

See publication

Tags: EdTech

5 Academic Fellow / Scholars
Fellow
The International Institute of Directors and Managers (IIDM Global)
November 11, 2024
Accredited as FIIDM.

See publication

Tags: IT Leadership, Leadership, Management

Fellow for Institute of Consulting
Chartered Management Institute (CMI) Institute of Consulting (IoC)
January 16, 2023

See publication

Tags: Business Strategy, Leadership, Management

Fellow
Financial Services Institute of Australasia (FINSIA)
October 28, 2022
For senior executives who have made significant contributions to the industry over their careers and are looking to shape the future of the industry.

See publication

Tags: Blockchain, Finance, Leadership

Fellow
The RSA (The royal society for arts, manufactures and commerce)
October 17, 2022
Awarded as FRSA

- Recognises the contributions of exceptional individuals from across the world who have made a significant impact, especially those who improve other people's lives. Notable fellows include Adam Smith, Karl Marx, Stephen Hawking, and Tim Berners-Lee.

See publication

Tags: Innovation, Leadership, Social

Fellow
The Learning and Performance Institute (FLPI)
October 10, 2022
For a recognised and acknowledged expertise within Learning and Performance community and beyond, continuous maintenance on high professional standards, significant contribution to advancement of the profession.

See publication

Tags: HR, Leadership, Management

8 Advisory Board Memberships
AICT Advisory Board Member
AI CERTs
November 10, 2025
Provided strategic advisory services on:
- Market positioning and competitive landscape
- Go-to-Market strategy and partnership development
- Investor readiness and fundraising strategy
- Product-market fit analysis and key initiatives
- Executive hiring guidance and organisation structure
- Strategic introductions to industry professionals, investors, and partners
- Branding, messaging, and external communications

See publication

Tags: AI, AI Ethics, AI Governance

Industry Advisory Board
EC-Council University
November 01, 2025
Advised the university on policies, procedures, programs and practices related to:
- Degree programs
- Academic policies and procedures
- Curricular development
- Program and course assessment
- Recruitment of faculty
- Business policies and procedures
- Marketing and recruiting strategies

See publication

Tags: Cybersecurity, GRC, Leadership

International Advisory Board for CPENT
EC-Council
November 04, 2024
- Collaborated with prominent industry leaders and professionals to shape the C|PENT program
- Provided guidance in developing new initiatives for Penetration Testing
- Contributed to the advancement of penetration testing practices globally

See publication

Tags: Cybersecurity, Risk Management, Security

International Advisory Board for CCISO
EC-Council
October 07, 2024
- Collaborated with prominent industry leaders and professionals to shape the C|CISO program
- Provided guidance in developing new initiatives for Information Security Management
- Contributed to the advancement of cybersecurity practices globally

See publication

Tags: Cybersecurity, Leadership, Security

Technology Advisory Board
Packt Publishing
September 09, 2024
Provided consultations on essential technologies and tools for job role development, identified trends and gaps in the market, offered feedback on book outlines, and reviewed research reports.

See publication

Tags: Emerging Technology, Leadership, Management

Advisory Board Member for Binus Industrial & Information Business Club (BIIBC)
Binus Industrial & Information Business Club (BIIBC)
January 20, 2014
Gave direction to top level management (President Director, Vice President, and the other Directors), advice as well as feedback on the organization's policy and its annual program plan.

See publication

Tags: Business Strategy, Leadership, Management

Advisor
Guidepoint Global
May 17, 2013
Served as an advisor within the company's global consulting network of subject matter experts to deliver consultancy on the Technology industry through qualitative research and on-demand interactions.

See publication

Tags: IT Leadership, IT Operations, IT Strategy

Advisor for Global Innovations and Technology Platform
Global Innovations and Technology Platform (GITPx)
January 13, 2013
Delivered consultancy and advisory services to the company for its investment activities, including performing IT Due Diligence.

GITP is a Corporate Angel Investor that invests in start-up & seed companies across China, India, Singapore, Indonesia, Vietnam, other Asian countries and beyond.

-Being the speaker on 'International Forum For Business Incubator on Developing Co-Incubation in Asia Pacific' hosted by Indonesia Menakertrans, Bandung, June 2013
-Being the resource Person on 'ASEAN Workshop on SME Business and Technology Incubator', hosted by ASEAN Secretariat along with Indonesian Ministry of Cooperatives and SME, Bogor, June 2013

See publication

Tags: Entrepreneurship, Innovation, Venture Capital

1 Ambassador
Regional Ambassador
Global Blockchain Business Council
January 15, 2024
In the 2024 - 2026 cohorts, I was nominated and appointed as the Ambassador of Indonesia.

GBBC is the largest, leading industry association for the blockchain technology and digital assets community, headquartered in Switzerland, with 500+ institutional members, and 301 Ambassadors from 117 jurisdictions and disciplines.

Notable duties are:
- Be a trusted local point of contact and/or domain expert for the GBBC network
- Present the GBBC Executive team with a general strategic view of local jurisdiction/discipline, given circumstances and blockchain ecosystem maturity

Involved in the Global Standards Mapping Initiative Working Group as well.

See publication

Tags: Blockchain, Cryptocurrency, Innovation

4 Author Newsletters
ZDNet Asia Contributor
ZDNet
June 17, 2013
Op-Eds and News for ZDNet Asia. Held the responsibility until end of 2013.

See publication

Tags: Emerging Technology, Innovation, IT Strategy

TechWireAsia Contributor
TechWireAsia
January 23, 2012
From early 2012 through the third quarter of the year, I wrote about Enterprise, mobile, gadget, app, social, and technology investments across Asia.

See publication

Tags: Emerging Technology, Innovation, IT Strategy

Regular Contributor for Detikinet's Telematika Column
DetikInet
October 24, 2011
From October 2011 until December 2016, I regularly contributed to the IT column in Detikinet.com

One example is https://inet.detik.com/cyberlife/d-1993395/menjejaki-konsepsi-web-3-0

See publication

Tags: IT Leadership, IT Operations, IT Strategy

Senior Contributing Writer for e27.co (formerly e27.sg)
Optimatic Pte Ltd (e27.co)
March 20, 2011
From early 2011 through the second quarter of 2014, I wrote about mobile, gadget, app, social, and technology investments across Asia. One example is https://sg.news.yahoo.com/meetdoctor-wants-improve-healthcare-user-engagement-014838769.html

See publication

Tags: Innovation, IT Strategy, Startups

2 Award Judges
Judge for Business Intelligence Group (BIG) Awards for Innovation 2026
Business Intelligence Group (BIG)
January 15, 2026
Selected as an international judge to evaluate and score innovation across global industries. Handpicked by the organisation to identify trailblazers who are redefining the future of technology and business excellence. Part of a curated panel overseeing 159 global winners, including industry giants like Alcon and Starkey.

See publication

Tags: Innovation

Judge for Business Intelligence Group (BIG) Awards for Business 2025
Business Intelligence Group (BIG)
November 25, 2025
Selected as an international judge to evaluate and score innovation across global industries. Handpicked by the organisation to identify trailblazers who are redefining the future of technology and business excellence. Part of a curated panel overseeing more than a hundred of global winners.

See publication

Tags: Innovation

4 Board Memberships
Member
Australian Institute of Company Directors (AICD)
September 02, 2022
Accredited as MAICD.

See publication

Tags: Business Strategy, Leadership, Risk Management

Advisory Board Member for Indonesia Security Summit 2018
Tradepass
September 04, 2018
Served as Advisory Board Member and Program Management Consultant for Indonesia Security Summit 2018, providing strategic input on agenda design, speaker curation, and program governance.

See publication

Tags: Cybersecurity, GRC, IT Leadership

Vice Chairman and Acting Chairman for Internet Society (ISOC) Indonesian Chapter
Internet Society (ISOC) Indonesian Chapter
May 10, 2004
Oversaw the takes on a variety of programs and activities, such as educational events, community programs, public policy, and networking events, from 2004 until 2005.

See publication

Tags: GovTech, Leadership, Management

Executive Board Member
Indonesian Association of Training and Development (IATD)
January 19, 2004
Sit as one of the board members taking care of the operational activities of the first Training and Development association in Indonesia.

See publication

Tags: HR, Leadership, Management

4 Book Chapters
Book chapter: Designing Trustworthy Neuro-Symbolic AI: From Ethical Principles to Policy Implementation
Elsevier
October 01, 2026
Part of a book titled Neuro-Symbolic AI: Bridging the Gap Between Neural Networks and Symbolic Reasoning.

The editors are Prof. Pascal Hitzler, Prof. Houbing Herbert Song, Assistant Prof. Sarika Jain, and Assistant Prof. Sonika Malik.

See publication

Tags: AI, AI Ethics, AI Governance

Book chapter: Building Trustworthy AI Systems in Southeast Asia: A Governance Framework in Regional Regulatory and Institutional Contexts
Springer Nature
August 10, 2026
Part of a book titled Algorithmic Trust and Governance in Asia.

See publication

Tags: AI Governance, GRC, Risk Management

Co-Author for IT Architecture Body of Knowledge (ITABoK) version 2
IASA Global
September 05, 2015
As co-author with over than 20 high-caliber architect folks for ITABoK v2 Capacity Development Model.

See publication

Tags: IT Leadership, IT Operations, IT Strategy

Book: Bunga Rampai Pelatihan dari Profesi HR/Training untuk Indonesiaku
Indonesian Association of Training & Development (IATD)
January 08, 2005
A chapter on e-learning "E-Learning sebagai Media Pembelajaran"

See publication

Tags: Education, HR, Innovation

7 Book Reviews
Book: Practical AI Security
Packt Publishing
July 01, 2026
Spearheaded as one of the Technical Reviewers. Authored by Kris Kimmerle and David Okeyode.

See publication

Tags: AI Governance, Cybersecurity, Generative AI

Book: Agentic AI for Offensive Cybersecurity
Packt Publishing
June 09, 2026
Spearheaded as one of the Technical Reviewers. Authored by Orhan Yıldırım.

See publication

Tags: Agentic AI, Cybersecurity, Generative AI

Book: Jailbreaking LLMs
Manning
April 15, 2026
Spearheaded as Manuscript Reviewer.

Provided feedback to help the editor and the author on the writing, technical content, examples, source code, Table of Contents, and even offered my opinion on the state of the technology or the reader's needs.

Authored by Priyanka Neelakrishnan.

See publication

Tags: AI Governance, Cybersecurity, Generative AI

Power BI for Finance
Packt Publishing
February 09, 2026
Spearheaded as one of the Technical Reviewers

See publication

Tags: Analytics, Finance, Predictive Analytics

Book titled Quick Start Guide to Audit Programs
ISACA
November 09, 2015
Spearheading as an Expert Reviewer with some fellows. Based on the COBIT 5 Assurance approach.

See publication

Tags: GRC, IT Leadership, Risk Management

Book Review on Privacy Principles and Program Management Guide
ISACA
January 09, 2015
Spearheading as Expert Reviewer with some fellows.

See publication

Tags: GRC, Privacy, Risk Management

COBIT 5: Enabling Information
ISACA
November 03, 2013
Sitting as an Expert Reviewer with 19 fellows. A reference guide for structured thinking about information and typical information governance and management issues, addressing the information model attributes and life cycle that are introduced in the COBIT 5 framework.

See publication

Tags: GRC, IT Strategy, Risk Management

2 Citations
My JIPM Paper Cited by Journal Inspektorat on AI-Enabled Whistleblowing Systems
Jurnal Inspektorat
December 15, 2025
My paper for JIPM, titled "Embedding Ethical AI in Digital Public Infrastructure: Strategic Governance Pathways for Indonesia," was cited by a paper titled "Integration of Artificial Intelligence in Digital Whistleblowing Systems to Enhance the Effectiveness of Internal Government Supervision" in the Jurnal Inspektorat.

See publication

Tags: AI Ethics, AI Governance, AI Infrastructure

My article was quoted in a book titled Public Policymaking in Hong Kong: Civic Engagement and State-Society Relations in a Semi-Democracy
Routledge
February 11, 2013
The book was authored by Eliza W. Y. Lee and published by Routledge.

My article itself was titled China world's biggest mobile subscriber population, but still has plenty of room to grow', published by TechWireAsia, 29 February 2012.


See publication

Tags: Digital Disruption, Emerging Technology, Innovation

6 Conference Publications
Conference paper: The Dual Persona of AI: Mapping the Intellectual Scape of Algorithmic Governance, Financialization, and Ethical Gaps in Strategic ESG Research (2015-2025)
IEEE Explore
January 19, 2026
Presented at the International Conference of Informatics, Multimedia, Cyber, and Information Systems (ICIMCIS) 2025 held on December 3rd and 4th, 2025.

See publication

Tags: AI Ethics, AI Governance, Finance

Conference Paper: AI-Powered Decision Support Systems for SME Innovation: A Bibliometric Mapping of Strategic Entrepreneurship (2020–2025)
International Conference on Creative Communication & Innovative Technology 2026
January 13, 2026

See publication

Tags: AI Ethics, AI Governance, Innovation

Reviews of Submissions for AECT Annual International Convention (2016–2017)
Association for Educational Communications and Technology (AECT)
February 05, 2016
Reviewed Organisational Training and Performance, System Thinking and Learning Technologies proposals from February 2016 until March 2017.

See publication

Tags: EdTech, Education, Innovation

Reviews of Submissions for PMI EMEA Global Congress
Project Management Institute
October 05, 2015
Reviewed more than 20 proposals, white papers and presentation materials from October 2015 until January 2016.

See publication

Tags: Leadership, Management, Project Management

Reviews of Submissions for PMI EMEA Global Congress
Project Management Institute
April 09, 2015
Reviewed more than 30 proposals, white papers and presentation materials from April 2015 until September 2015.

See publication

Tags: Leadership, Management, Project Management

International Organizations: Roadmap For Collaboration
63rd Annual Conference of the International Council for Educational Media (ICEM) 2003
October 12, 2013
Presented at the 63rd Annual Conference of the International Council for Educational Media (ICEM) 2003. Published by IEEE Explore and indexed by Scopus.

A remarkable collaboration has evolved over the past half-century of international organisations dedicated to the wise use of technology in education. The road toward collaborative efforts has not always been easy, especially given the changing political, economic, social, and educational challenges. This presentation examines selected organisations and their ongoing role in bringing diverse international entities together toward a common goal: global education. The result has been a series of conferences, publications, seminars, and personnel exchanges over the years, transcending cultural differences, languages, and locations, extolling unique benefits that have accrued for all participants. What follows is the story of one man's journey across seven continents, multiple languages, diverse arrays of transport, housing, cuisine, beverages, and customs, acclimating to all where possible.

See publication

Tags: EdTech, Education, Innovation

2 Corporate Partners
Partner for Global Learning System (GLS) for Binus University, School of Accounting
Binus University, School of Accounting
January 21, 2026
Integrated real-world industry insights into courses through discussion, assignment, and collaborative learning via BINUSMAYA e-learning platform.

See publication

Tags: Emerging Technology, GRC, Risk Management

Partner for Global Learning System (GLS)
Binus Business School, Faculty of Management
September 09, 2024
Integrated real-world industry insights into courses through discussion, assignment, and collaborative learning via BINUSMAYA e-learning platform for Binus Business School, Faculty of Management.

See publication

Tags: Cybersecurity, Digital Transformation, Privacy

13 Coursewares
Delving into Fintech
Goutama Bachtiar
October 15, 2019
The document provides an agenda and overview of a workshop on understanding fintech. The workshop agenda covers 9 sessions that will discuss topics like e-payment systems, peer-to-peer lending, risk management, regulations, and future trends in fintech. The document also provides background information on key concepts in fintech, including defining fintech, categories of fintech systems, and the benefits of fintech for consumers, firms and countries. Examples of popular fintech systems in Indonesia are also mentioned.

See publication

Tags: Blockchain, Finance, FinTech

Crypto Currency, Bitcoin and Blockchain
Goutama Bachtiar
August 01, 2019
This document discusses a course on crypto currency, Bitcoin, and blockchain. The course agenda covers 7 sessions that explore topics like cryptography, crypto currencies, blockchain technology, Bitcoin, Ethereum, and smart contracts. The schedule lists the daily timing of the 4 sessions over the course duration. Cryptography concepts like encryption, decryption, symmetric and asymmetric keys, hash functions, and SHA are also summarized.

See publication

Tags: Blockchain, Cryptocurrency, Finance

Blockchain Essentials - Harnessing the Technology for Banking Industry
Goutama Bachtiar
October 24, 2018
The document outlines an agenda for a blockchain essentials workshop, including four sessions: exploring blockchain components; leveraging blockchain benefits; implementing blockchain in banking; and understanding key challenges. It then provides details on the first session, exploring blockchain and its components, defining blockchain, its distributed ledger system, and key cryptographic components such as public/private keys, digital signatures, proof of work, and hash functions. It also discusses the relationship between blockchain and cryptocurrency.

See publication

Tags: Blockchain, Cryptocurrency, Finance

Leveraging Agile Project Management with Scrum
The TEH Group
October 19, 2018
This courseware outlines a workshop agenda for leveraging agile project management with Scrum. The 14-module agenda covers topics like the Waterfall model, the Scrum framework, Scrum roles and artefacts, requirements management, estimation, execution, monitoring, adoption challenges, success factors, documentation tools, and more. Ground rules for the workshop are also provided, including participating actively and asking questions.

See publication

Tags: IT Leadership, IT Strategy, Project Management

PMBOK 6th vs 5th Edition
Goutama Bachtiar
October 08, 2018
The deck compares the 5th and 6th editions of the Project Management Body of Knowledge (PMBOK). Key differences include additions of adaptive and iterative practices, including Agile, the PMI Talent Triangle, and three new processes. Revisions include renaming processes and associating processes with different knowledge areas. The 6th edition also emphasises strategic/business knowledge and consists of an appendix on agile practices.

See publication

Tags: IT Leadership, IT Strategy, Project Management

Dealing with Fraud in E-Banking Sphere
Goutama Bachtiar
October 13, 2017
The courseware discusses the prevalence and impact of fraud in the electronic banking sector, outlining definitions, types, and trends. It highlights the significant costs of fraud, estimated at $72 billion annually, with a notable portion attributed to internal actors. Key areas of focus include the types of fraud occurring, methods of detection and investigation, and the importance of robust anti-fraud measures for organisations.

See publication

Tags: Finance, GRC, Risk Management

Conducting Digital Forensics against Crime and Fraud
Goutama Bachtiar
May 03, 2017
This courseware outlines an agenda for a 3-day workshop on digital forensics. Day 1 introduces digital forensics, including its definition, objectives, importance, trends and challenges. It also discusses the types of digital forensics, as well as the phases and activities involved. Day 2 will provide more details on implementing digital forensics through case studies, forensic types, phases and activities, and tool demonstrations. Day 3 focuses on case studies, best practices, standards, and regulations.

See publication

Tags: Cybersecurity, GRC, Risk Management

Managing IT Risks in Internet Banking
Goutama Bachtiar
May 03, 2017
This courseware discusses managing IT risks in internet banking. It covers several topics:

1. Understanding user behaviours and expectations, such as their focus on speed, security and ease of use of internet banking services.

2. Acquiring and developing internet banking services, including following a system development life cycle and outsourcing management practices.

3. Comprehending information security and privacy risks like cyber attacks, and how to respond through human resources management practices around access controls, segregation of duties and training.

See publication

Tags: Cybersecurity, Finance, Risk Management

Courseware on Governance and Management of Enterprise IT with COBIT 5 Framework
Goutama Bachtiar
May 05, 2016
This courseware discusses the importance of governance and management of enterprise IT using the COBIT 5 framework, emphasising that practical information and technology management is crucial for achieving business objectives. It outlines the need for a control framework due to increasing complexities, regulatory pressures, and the importance of managing IT risks while delivering stakeholder value. COBIT 5 provides a structured approach that helps organisations align IT with business goals, improve audit processes, and maintain compliance.

See publication

Tags: GRC, IT Leadership, Management

Electronic Payment Fundamentals: When Tech Embracing Payment Industry
Goutama Bachtiar
October 05, 2015
This courseware document outlines an agenda for an e-payment fundamentals workshop held in October 2015. The workshop covers various topics over two days, including understanding electronic payment systems and how they work, exploring e-payment methods such as e-cash, e-wallets, smart cards, and credit cards, and examining security and infrastructure aspects. Diagrams and graphics are provided to illustrate concepts such as how payment gateways and service providers facilitate electronic transactions between customers, merchants, and banks.

See publication

Tags: Digital Transformation, Finance, FinTech

State of Cyber Crime in Banking Sector Today: Threats and Solutions
Goutama Bachtiar
August 10, 2015
The courseware outlines a training agenda for a cybersecurity conference held in August 2015. Day 1 covers topics such as cybercrime, the current situation in Indonesia and globally, and identifying threats and vulnerabilities. Day 2 focuses on information security strategies across organisations and envisioning the future state. Several sessions explore defining cybercrime, common attack types such as viruses and denial-of-service attacks, and who commits cybercrime.

It also discusses trends like the growing cybercrime marketplace, risks to mobile devices, larger attacks on retailers and banks, and more advanced targeted threats.

See publication

Tags: Cybersecurity, Finance, GRC

Implementing Enterprise Risk Management with ISO 31000:2009
Goutama Bachtiar for TUV Rheinland Indonesia
December 16, 2013
This courseware was intended for a two-day training program for implementing enterprise risk management in line with ISO 31000:2009, led by Goutama Bachtiar, who has extensive experience in advisory and consulting. The training agenda spans three days, focusing on understanding ISO 31000, exploring risk assessment techniques, and managing enterprise risk through workshops and discussions. It highlights the importance of risk management in achieving organisational objectives and provides insights into the principles, framework, and processes detailed in the ISO standard.

See publication

Tags: Leadership, Management, Risk Management

Information Technology Project Management
Goutama Bachtiar
April 22, 2013
This courseware covers topics in project management, including scope management, time management, cost management, quality management, and related areas. It provides information on objectives, project selection, challenges, justification and charters. Methods and steps are outlined for writing project charters, scope statements, scope management plans, work breakdown structures, schedules, and change control.

See publication

Tags: Leadership, Management, Project Management

1 eBook
E-Book on .NET Technology in 'Project Otak'
Indonesia .NET Developer Community (INDC)
January 12, 2007
A chapter on VB. NET in the Indonesian language.

See publication

Tags: Innovation, IT Operations, IT Strategy

2 Executives
IT Advisory Director at Grant Thornton Indonesia
Grant Thornton Indonesia
October 01, 2021
Since October 2021.

- Delivered IT Consulting, Audit, Review, and Assessment services by:
+ Leveraging Agile and Lean methodology on a daily basis
+ Incorporating DEI into all deliverables
+ Collaborating with other member firms (GT NZ, JP, US, and PH) in delivering the engagement
- Slated as Advisory Industry Leader for Banking along with Technology, Media and Telecommunications
- Responsible for product management, business development, pre-sales, Go-To-Market strategy, Project, Program and Portfolio Management, service delivery, strategic collaboration, resource management, revenue, P&L, and budget responsibility, client satisfaction and relationship
- Participated in GTIL Blockchain Working Group, Cyber Community, and Global Milestone Coach Network. Served as Group Coach at GTIL ELP 2024
- Clients included: Fortune (50, 500, Global 500, India 500, Indonesia 100), and Forbes Global 2000

See publication

Tags: Cybersecurity, GRC, Risk Management

Vice President, Head of IT Consulting, Roligio Group Indonesia
Roligio Group Indonesia
May 23, 2013
In charge of identifying, selecting, deploying, implementing, overseeing and maintaining tech-based products, services and platforms within lean, highly interactive and agile systems in place until December 2018.

See publication

Tags: IT Operations, IT Strategy, Leadership

5 Industry Awards
Excellence in Digital Innovation from DigiBank Summit & Awards 2024 Indonesia Edition 2024
CCM Group
July 24, 2024

See publication

Tags: Digital Transformation

1st Winner GTIL ELP APAC 2024's Client Challenge Pitches (Group Coach)
Grant Thornton International Ltd
May 17, 2024

See publication

Tags: Leadership

Fellow
OneTrust
October 14, 2022
Designated as FPT (Fellow of Privacy Technology)

See publication

Tags: Privacy

Subject Matter Expert for Project Management Institute
Project Management Institute
March 12, 2020

See publication

Tags: Project Management

Subject Matter Expert for Project Management Institute
Project Management Institute
February 15, 2016

See publication

Tags: Project Management

3 Industry Badges
Trusted AI Safety Expert (TAISE) Contributor
Cloud Security Alliance
October 23, 2025

See publication

Tags: AI, AI Ethics, GRC

Endorsed Technical Reviewer – Cloud Native Application Protection Platforms (O’Reilly)
O'Reilly
September 10, 2024
Officially acknowledged and quoted in the book for contributing practitioner insight that strengthened the technical rigour and real-world applicability of the content.

See publication

Tags: Cloud, Cybersecurity, GRC

Certificate of Cloud Security Knowledge (CCSK) Contributor
Cloud Security Alliance
July 05, 2024

See publication

Tags: Cloud, Cybersecurity, IT Operations

41 Industry Certifications
AI+ Finance
AI CERTs
December 29, 2025

See publication

Tags: AI, Blockchain, Finance

AI+ Cloud
AI CERTs
December 23, 2025

See publication

Tags: Agentic AI, AI, Cloud

Chief AI Officer
AI CERTs
December 21, 2025

See publication

Tags: Agentic AI, AI Governance, Generative AI

Certificate of Competence in Zero Trust (CCZT)
Cloud Security Alliance
December 06, 2025

Credential ID 9c3b4102-4f1c-49dd-9439-4fa85494c4c5

See credential

See publication

Tags: Cloud, Cybersecurity, GRC

Trusted AI Safety Expert (TAISE)
Cloud Security Alliance
November 27, 2025

Credential ID 1f4a910c-08b0-4035-850a-760a57c3f91d

See credential

See publication

Tags: AI, AI Ethics, GRC

Certificate of Cloud Security Knowledge (CCSK)
Cloud Security Alliance
October 24, 2025

Credential ID 155f99b9-4825-4a1b-a47b-702acf3c0aca

See credential

See publication

Tags: Cloud, Cybersecurity, IT Operations

AI+ Healthcare
AICERTs (www.aicerts.ai)
August 11, 2025

Issued Aug, 2025 – Expires Aug, 2026

Credential ID 615b0d785159

See credential

See publication

Tags: AI, AI Governance, HealthTech

AI+ Ethics
AICERTs (www.aicerts.ai)
July 27, 2025

Issued Jul, 2025 – Expires Jul, 2026

Credential ID e5f84de0c44d

See credential

See publication

Tags: AI, AI Ethics, GRC

AI+ Executive
AI CERTs
June 21, 2025
Has successfully completed the Evernote Certified Consultant training and is a full member of the Evernote Certified Consultant program for the dates listed below, with all rights and responsibilities therein.

Issued Jun, 2025 – Expires Jun, 2026

Credential ID d909d8446c69

See publication

Tags: AI, IT Strategy, Management

Integrated Compliance & Ethics Professional (ICEP)
OCEG (Open Compliance and Ethics Group) and GRC Certify
October 27, 2024

Issued Oct, 2024 – Expired Oct, 2025

Credential ID ICEP-119967523

See credential

See publication

Tags: GRC, Leadership, Risk Management

AI Security and Governance
Securiti.ai
September 29, 2024

Issued Sep, 2024 – Expires Sep, 2026

Credential ID 1275FC7A8-1275FC617-3217A50

See publication

Tags: AI Governance, Cybersecurity, GRC

Integrated Risk Management Professional (IRMP)
OCEG (Open Compliance and Ethics Group) and GRC Certify
August 15, 2024

Issued Aug, 2024 – Expired Aug, 2025

Credential ID IRMP-112368052

See credential

See publication

Tags: GRC, Management, Risk Management

OneTrust Certified Privacy Professional
One Trust
September 09, 2023
Earners of the OneTrust Certified Privacy Professional badge understand best practices to effectively establish and maintain privacy, security, and governance programs using OneTrust technology and tools. Course participants have a strong working knowledge of OneTrust’s core modules, including Assessment Automation, Data Subject Requests, Vendor Management, Data Mapping, Cookies, Consent, and Incident Management, and also understand privacy laws, including the GDPR, CCPA, and LGPD.

Issued Sep, 2023 – Expired Sep, 2024

Credential ID 2ffc412f-7d78-4dda-a6d5-c5a2458a330d

See credential

See publication

Tags: Cybersecurity, GRC, Privacy

Certified Master SOC 2 Implementer
Scytale SOC 2 Academy
April 29, 2023

Credential ID tstosel2vv

See credential

See publication

Tags: Cybersecurity, GRC, Security

AWS Certified Cloud Practitioner (ACCP)
Amazon Web Services Training and Certification
December 30, 2022
Earners of this certification have a fundamental understanding of IT services and their uses in the AWS Cloud. They demonstrated cloud fluency and foundational AWS knowledge. Badge owners can identify the essential AWS services needed to set up AWS-focused projects.

Credential ID 0cc07d82-ea5c-43ab-be5a-a13fa7f7d877

See credential

See publication

Tags: Cloud, DevOps, IT Strategy

OneTrust Certified ESG Professional
OneTrust
December 28, 2022
Earners of the OneTrust Certified ESG Professional badge have achieved an understanding ESG terminology, frameworks, metric groups, reports, and multiple other tools for both streamlining and centralizing data collection to assist in the prioritization, tracking, and creation of continued sustainability goals. Course participants have a strong working knowledge of how to implement and track their ESG programs within the OneTrust’s ESG Program Reporting & Disclosures module.

Issued Dec, 2022 – Expired Dec, 2024

Credential ID 7f093196-113a-4b4f-8605-39d2e0d1af86

See credential

See publication

Tags: GRC, Risk Management, Social

Integrated Data Privacy Professional (IDPP)
OCEG (Open Compliance and Ethics Group) and GRC Certify
December 17, 2022

Issued Dec, 2022 – Expired Dec, 2023

Credential ID IDPP-64676099

See credential

See publication

Tags: GRC, Privacy, Risk Management

ISO 22301 Business Continuity Risk Manager
SkillFront
September 24, 2022
Demonstrated knowledge and outstanding skills in the subject matter expertise of this professional certification.

Credential ID 23429502883192

See publication

Tags: Business Continuity, GRC, Risk Management

ISO 22301 Business Continuity Lead Implementer
SkillFront
September 24, 2022
Demonstrated knowledge and outstanding skills in the subject matter expertise of this professional certification.

Credential ID 48462062525843

See publication

Tags: Business Continuity, GRC, Risk Management

ISO 22301 Business Continuity Lead Auditor
SkillFront
September 24, 2022
Demonstrated knowledge and outstanding skills in the subject matter expertise of this professional certification.

Credential ID 89828053596469

See publication

Tags: Business Continuity, GRC, Risk Management

ISO 22301 Business Continuity Internal Auditor
SkillFront
September 24, 2022
Demonstrated knowledge and outstanding skills in the subject matter expertise of this professional certification.

Credential ID 98512290390039

See publication

Tags: Business Continuity, GRC, Risk Management

ISO/IEC 27001 Information Security Risk Manager
SkillFront
September 21, 2022
Demonstrated knowledge and outstanding skills in the subject matter expertise of this professional certification.

Credential ID 09572212999571

See publication

Tags: Cybersecurity, Risk Management, Security

ISO/IEC 27001 Information Security Lead Auditor
SkillFront
September 21, 2022
Demonstrated knowledge and outstanding skills in the subject matter expertise of this professional certification.

Credential ID 86641101507008

See publication

Tags: Cybersecurity, Risk Management, Security

ISO/IEC 27001 Information Security Internal Auditor
SkillFront
September 21, 2022
Demonstrated knowledge and outstanding skills in the subject matter expertise of this professional certification.

Credential ID 04168901855123

See publication

Tags: Cybersecurity, Risk Management, Security

OneTrust Certified GRC Professional
One Trust
August 17, 2022
Earners of the OneTrust Certified Privacy Professional badge understand best practices to effectively establish and maintain privacy, security, and governance programs using OneTrust technology and tools. Course participants have a strong working knowledge of OneTrust’s core modules, including Assessment Automation, Data Subject Requests, Vendor Management, Data Mapping, Cookies, Consent, and Incident Management, and also understand privacy laws, including the GDPR, CCPA, and LGPD.

Issued Aug, 2022 – Expired Oct, 2024

Credential ID b43cc36f-67b2-4c1c-935d-4dfaf72f0c26

See credential

See publication

Tags: Cybersecurity, GRC, Risk Management

24 Industry Council Members
Trusted AI Safety Expert (TAISE) Contributor from Cloud Security Alliance
Cloud Security Alliance
December 18, 2025
Recognised for contributing technical review feedback on the TAISE training and certification materials. Demonstrated AI safety, security, and governance expertise.

See publication

Tags: AI Governance, Cybersecurity, GRC

Judging Panel for Business Intelligence Group (BIG) Awards
Business Intelligence Group
October 21, 2025
Appointed as a jury member for the BIG Innovation Awards, evaluating breakthrough innovations, business impact, and execution excellence across global industry submissions.

See publication

Tags: Business Strategy, Innovation, Leadership

Technical Reviewer for AI+ Certification Courses
AI CERTs
October 08, 2025
Elected and served as Subject Matter Expert for one month to perform technical review for both the training and certification courses for the participant and the trainer in the following subjects:
- AI+ Security (Level 1)
https://www.aicerts.ai/certifications/security/ai-security-level-1/
- AI+ Healthcare
https://www.aicerts.ai/certifications/specialization/ai-healthcare/
- AI+ Project Manager
https://www.aicerts.ai/certifications/business/ai-project-manager/

See publication

Tags: AI, AI Governance, Cybersecurity

Research Fellow from Cloud Security Alliance
Cloud Security Alliance
September 11, 2025
The Research Fellow is the highest honour and distinction awarded to a volunteer who recognises the subject matter expertise, tireless effort, and long-term dedication, who has truly made an impact in the future of cloud security.

See publication

Tags: AI, Cloud, Cybersecurity

International Judging Council Member of World CIO 200 Summit 2025 Grand Finale (Egypt Edition)
Global CIO Forum
July 17, 2025

See publication

Tags: Business Strategy, Innovation, IT Leadership

Award Jury Committee and Moderator for NXT CX - DX Summit & Awards, Jakarta
Scribe Minds & Media
February 11, 2025

See publication

Tags: Digital Transformation, Innovation, Leadership

Subject Matter Expert for ISC2
ISC2
November 11, 2024
Collaborated with other SMEs in Exam Content Development for the organisation's certification

See publication

Tags: Cybersecurity, Leadership, Security

Technical Reviewer for Book Titled A Guide to CNAPPs and the Foundations of Comprehensive Cloud Security
O'Reilly
September 10, 2024
- Spearheaded as one of the Technical Reviewers. Authored by Russ Miles, Taylor Smith, and Stephen Giguere. The Development Editor is Jill Leonard.

See publication

Tags: Cloud, Cybersecurity, GRC

Cloud Security Knowledge (CCSK) Contributor from Cloud Security Alliance
Cloud Security Alliance
August 29, 2024
Contributed to the development of the CCSK v5 courseware. Demonstrated expertise in cloud security principles and domains.

See publication

Tags: Cloud, Cybersecurity, GRC

Subject Matter Expert: Security+
CompTIA
July 16, 2024
Collaborated with experts from other regions to ensure the Security+ exam remains up-to-date and relevant and continues to be a reliable certification worldwide.

See publication

Tags: Cybersecurity, Leadership, Security

Contributor
Enterprise Ethereum Alliance
June 17, 2024
Co-developed Ethereum Industry Census and Index

See publication

Tags: Blockchain, Cryptocurrency, NFT

GRC Capability Model 3.5
OCEG (Open Compliance and Ethics Group)
May 16, 2023
Spearheading as the Review Committee member with other fellows.

See publication

Tags: GRC, Risk Management

Advisory Council
Association of Certified Fraud Examiners (ACFE)
June 06, 2022
Provided expert opinion and feedback on the growth and improvement of the organisation.

See publication

Tags: GRC, Risk Management, Security

Working Group for IT Architecture Body of Knowledge (ITABoK)
IASA
June 06, 2022
Served as a Working Group Member for the development of the IT Architecture Body of Knowledge

See publication

Tags: IT Leadership, IT Strategy, Management

Global Insights Panel for MIT Technology Review
MIT Technology Review
August 16, 2021
An exclusive forum of thought leaders, innovators, and executives. Members are invited to take part in research and gain valuable insights into today’s technology trends.

See publication

Tags: Emerging Technology, Leadership, Management

Advisory Council for Harvard Business Review
Harvard Business Review
August 09, 2021
Provided insight to shape Harvard Business Review's content and help chart the organization future direction.

See publication

Tags: Business Strategy, Leadership, Management

Subject Matter Expert
Cloud Security Alliance
April 08, 2019
Involved in below Working Groups:
1. Zero Trust
2. Artificial Intelligence
a. Governance & Compliance
b. Technology & Risk
c. Control Framework
3. Cloud Control
4. CCSK version 5
5. Trusted AI Safety Knowledge Review

Activities:
Reviewed the Shared Security Responsibility Model (SSRM) guideline, CCSK v5 Self-Paced Course, TAISE Training & Exam Materials & AICM Guidelines

See publication

Tags: AI Governance, Cloud, Cybersecurity

Organizsing Comittee for Discuss Agile Jakarta 2016
Indo Indians
June 05, 2016
As the organising committee for a community-run event (conference and training) sponsored and supported by Scrum Alliance, we host numerous speakers on Agile and Scrum from June 2016 until July 2016.

See publication

Tags: Agile, Leadership, Project Management

PMI Professional Awards – Eric Jenett Award Evaluator
Project Management Institute
April 12, 2015
Honoured individual who has made an outstanding contribution to the project management profession's practice, leadership, initiative and advancing the concepts, techniques, or theories.

See publication

Tags: Leadership, Management, Project Management

Journal Article Reviewer for ISACA Journal
ISACA
August 06, 2014
Served as Journal Article Reviewer in Research Publications Development during 2013 - 2014 administrative term.

See publication

Tags: Cybersecurity, GRC, Risk Management

Expert Reviewer on Configuration Management: Using COBIT 5
ISACA
September 20, 2013

See publication

Tags: Cybersecurity, GRC, Risk Management

Advisor, Council Member and ITDM Panel
Gerson Lehrman Group
June 10, 2013
Provided advisory services on technology issues through in-person meetings, roundtable discussions, seminars, surveys, presentations, reports and phone calls.

See publication

Tags: IT Leadership, IT Operations, IT Strategy

Subject Matter Expert, Working Group and Program Mentor
ISACA
April 15, 2013
- Was elected and served as SME for COBIT 5 Configuration Management, COBIT 5 Enabling Information, COBIT 5 for Business Benefits Realisation, Risk Scenarios with COBIT 5 for Risk, as well as Big Data Privacy Risk and Control.
- Selected and served as a mentor in ISACA’s Young Professionals Subcommittee and as a Working Group member in CSX Tools Development.

See publication

Tags: Cloud, GRC, Privacy

Subject Matter Expert and Program Evaluator
Project Management Institute
January 11, 2010
Elected and served as SME sitting in a panel of reviewers for Standard for OPM, Professional Award Program, Project Management Excellence Award Program, North America Global Congress and Virtual Congress. Member since 2010.

See publication

Tags: Leadership, Project Management, Risk Management

1 IP Asset
Copyrighted Courseware on Digital Asset and Cryptocurrency
Directorate General of Intellectual Property (DGIP), Indonesia
August 30, 2024
Consists of:
1. Practical Technical Knowledge
2. Security and Risk in Crypto Assets
3. Smart Contracts
4. Decentralised Finance
5. How to Invest
6. More on Investment and Trading
7. Case Study and Future Trends
8. Practice and Evaluation

See publication

Tags: Blockchain, Cryptocurrency, Finance

7 Journal Publications
Governance-by-Design for Autonomous AI Agents in Regulated Financial Systems: A Control-Based Safety Framework
Springer Nature
May 31, 2026
Submitted to the AI and Ethics Journal. Collection Title: AI Agents: Ethics, Safety, and Governance.

See publication

Tags: Agentic AI, AI Ethics, AI Governance

When Consent Fails. Rethinking Digital Rights Enforcement in the Age of Large Language Models
Cambridge University Press
January 30, 2026
Submitted for the Data & Policy journal. Call for Papers: Emerging Data and Policy Challenges to Digital Rights.

See publication

Tags: AI Ethics, AI Governance, Privacy

Embedding Ethical AI in Digital Public Infrastructure: Strategic Governance Pathways for Indonesia
Indonesia Infrastructure Guarantee Fund Institute
November 15, 2025
A single-authored, peer-reviewed paper. Served as both the primary and corresponding author.

See publication

Tags: AI Ethics, AI Governance, AI Infrastructure

Editorial Reviewer for ISACA Journal 2014: Volume 1 - 6
ISACA
January 05, 2014
Spearheading as Editorial Reviewer with other fellows until present. The journal focuses on Data Privacy, IT Audit Transformation and Big Data.

See publication

Tags: Big Data, GRC

Reviewer Panel for British Journal of Educational Technology (BJET)
British Educational Research Association (BERA)
September 11, 2013
Reviewed manuscripts from November 2013 until December 2015 submitted by researchers worldwide, contributing to the journal's rigorous editorial process and its position as one of the most influential journals in educational technology.

Online ISSN: 1467-8535 and Print ISSN: 0007-1013. Indexed by Scopus Quartile Q1 and Web of Science (Social Sciences Citation Index). Published by Wiley & Sons.

See publication

Tags: EdTech, Education, Innovation

Editorial Reviewer for ISACA Journal 2013: Volume 4–6
ISACA
August 07, 2013
Spearheading as Editorial Reviewer with 45 fellows. The journal focuses on Language of Cyber Security, Integrated Business Solutions, Security and Compliance.

See publication

Tags: Digital Transformation, GRC, IT Leadership

Journal Reviewer for TechTrends
Association for Educational Communications & Technology (AECT)
January 14, 2013
Reviewed manuscripts submitted by experts worldwide and contributed to the journal's rigorous editorial processes in the field of educational technology for one year.

Print ISSN: 8756-3894 and Online ISSN: 1559-7075. Indexed by Scopus Quartile Q1 and Web of Science (Emerging Sources Citation Index) with an Impact Factor of 3.8.

See publication

Tags: EdTech, Education, Innovation

2 Keynotes
Keynote Speaker for DigiBank Summit & Awards Indonesia Edition 2024
10dX Summit
July 14, 2024

See publication

Tags: Digital Transformation, Finance, Leadership

Keynote Speaker on Seminar
Progrez
June 12, 2024
Titled Exploring Atlassian Cloud Regulations in the Financial Sector

See publication

Tags: Cloud, Finance, GRC

5 Media Interviews
Exposes Blind Spots in Bank Security
NewinAsia.com
July 29, 2025

See publication

Tags: AI, Cybersecurity, GRC

CTO Chats with Goutama Bachtiar, IT Advisory Director, Grant Thornton
Ortus Club
July 08, 2025

See publication

Tags: AI, GRC, Leadership

ExecOpinion: Translating governance into workable frameworks
FutureCIO
January 07, 2025

See publication

Tags: AI Ethics, AI Governance, Privacy

Cyber Resilience
SWA Magazine
June 07, 2023

See publication

Tags: Cybersecurity, Digital Transformation, GRC

Artificial Intelligence
SWA Magazine
February 24, 2023

See publication

Tags: AI, Digital Transformation, IT Strategy

3 Mentors
Mentor for Institute of Consulting
Chartered Management Institute (CMI) Institute of Consulting (IoC)
January 16, 2023

See publication

Tags: Business Strategy, Leadership, Management

Senior Mentor
Financial Services Institute of Australasia (FINSIA)
October 28, 2022
Shaped the future of the industry. Inspired, encouraged, and supported the mentee on their professional and personal development.

See publication

Tags: Careers, Finance, Leadership

Mentor for The Royal Society for Arts, Manufactures and Commerce (RSA)
The Royal Society for Arts, Manufactures and Commerce (RSA)
October 17, 2022
Provided support tailored to the mentee's specific goals, as well as shared expertise and experiences to benefit the mentee.

See publication

Tags: Careers, Leadership, Management

18 Panels
Moderator, CyberSecIndonesia Conference 2025, Jakarta
Escom Events
July 09, 2025

See publication

Tags: AI, Cybersecurity, Privacy

Moderator, Corinium CISO Indonesia 2025, Jakarta
Corinium Global Intelligence
May 28, 2025

See publication

Tags: AI, Cybersecurity, Privacy

Moderator, Indonesia Cloud & Datacenter Convention 2025, Jakarta
W.Media
May 15, 2025

See publication

Tags: AI Infrastructure, Cloud, Data Center

Moderator, 10DX Summit Indonesia 2025, Jakarta
PMG Events Group
April 29, 2025

See publication

Tags: Digital Disruption, Digital Transformation, Innovation

Panellist and Moderator, SECURE Indonesia, Jakarta
Scribe & Minds
February 12, 2025
Speaking in the Panel Discussion "Encouraging Global Cooperation in Cyber Governance" that consists of:
- The government's responsibility in establishing cyber standards
- The significance of National and International Legal Frameworks in Cyber Governance
- Evaluating the Effectiveness of Capacity Building and Educational Programs

See publication

Tags: Cybersecurity, GovTech, GRC

Panel Moderator CISO Indonesia Conference 2024
Corinium Global Intelligence
December 03, 2024
Moderating a Panel Discussion titled Empowering Cybersecurity Leadership: Nurturing Skills, Culture, and Resources consists of:
- Addressing the cybersecurity skills gap and strategies to bridge the shortage of skilled professionals
- Cultivating a strong cybersecurity culture and fostering a culture where security is ingrained in everyday practices
- Allocating resources for cybersecurity initiatives to ensure robust measures and responses

See publication

Tags: Cybersecurity, GRC, Leadership

Panelist, CyberSecID Conference
Escom Events
July 18, 2024
A panel titled Integration of AI, ML, and Cybersecurity In the Era of Digital Transformation

The panel on 'Integration of AI, ML, and Cybersecurity in the Era of Digital Transformation' examines how Artificial Intelligence (AI) and Machine Learning (ML) are reshaping cybersecurity strategies during the digital transformation era. Experts discuss leveraging AI/ML to detect and respond to cyber threats faster, enhance predictive analytics, and fortify defences against evolving security challenges in a rapidly changing digital landscape.

See publication

Tags: AI, Cybersecurity, Digital Transformation

Session Chair for DigiBank Summit & Awards Indonesia Edition 2024
10dX Summit
July 14, 2024
Panel Session titled Breaking Barriers: Strategies to Drive Financial Inclusion
Main Talking Points
 Beyond mobile money: New approaches to boost financial inclusion
 Rural banking: Designing products that connect, not exclude.
 Bridging the gender gap: How can digital banking empower Indonesian women?
 Fintech & NGOs: How can partnerships unlock financial access for all?

See publication

Tags: Digital Transformation, Finance, Leadership

Panelist, GT x IAIB CAE Forum on Digital Maturity Assessment for Banking Industry
Grant Thornton Indonesia and Ikatan Audit Intern Bank
June 06, 2024

See publication

Tags: Digital Transformation, Finance, GRC

Panelist, 2nd Indonesia Retail & E-Commerce Summit 2024
Scribe Minds & Media
February 28, 2024
A Panel Discussion titled Understanding the strengths and challenges of the retail and e-commerce sector in Indonesia:
- Rapid urbanisation and adoption of modern retail formats
- Digitalisation across the entire spectrum and across business models
- With a diverse topography, how is Indonesia stamping its authority on a seamless supply chain

See publication

Tags: Cybersecurity, Digital Transformation, Marketing

Panelist, Compnet Security Solution Day, Denpasar
Compnet
January 18, 2024

See publication

Tags: Cybersecurity, Digital Transformation, Finance

Panelist for The Tech Capital Asia Finance Forum 2023
The Tech Capital
December 07, 2023
The panel is titled "Investing In Indonesia: How Indonesia And Seasia Can Win The Carbon-Free Energy Quest To Fuel Ai Data Centres And The Needed Crucial Deal Structures"

See publication

Tags: AI Infrastructure, Data Center, Finance

Panelist, Cybersecurity & Data Privacy in Practice: GT Indonesia x BEI Joint Seminar, Jakarta
Grant Thornton Indonesia and Indonesia Stock Exchange
December 04, 2023

See publication

Tags: Cybersecurity, Privacy, Risk Management

Panelist, Cloud/Data Security & Compliance discussion in Global Data Center & Cloud Summit Indonesia, Jakarta
Escom Events
November 23, 2023
A Panel Discussion title: Cloud-Native Security: Protecting Applications and Data in Dynamic Environments

Moderator:
- Dea Saka Kurnia Putra, Founder, Blockchain Founders Club, Belajar Blockchain, & Indonesia Blockchain Forum
Panelists:
- Goutama Bachtiar, Director of IT Advisory, Grant Thornton Indonesia
- Hendro, Cyber Risk Director, Deloitte
- Budi Winarno, Independent Information Security Professional
- Ichsan Rahardianto, VP of Infrastructure & Security, tiket.com

See publication

Tags: AI Infrastructure, Cloud, Cybersecurity

Panelist, Evolving Landscape of Security in Financial Sector in World Cloud Show Indonesia, Jakarta
Trescon Global
November 07, 2023

See publication

Tags: Cloud, Cybersecurity, Finance

Panelist, Financial Services discussion in CyberSecAsia Indonesia, Jakarta
Escom Events
July 27, 2023
Panel session title: The Changing Threat Landscape for Financial Services: Challenges and Innovations

See publication

Tags: Cybersecurity, Finance, GRC

Speaker, Data Resilience in Hyper-Connected World, InfoKomputer Innovate, Jakarta
IBM, Multipolar Technology and InfoKomputer
May 26, 2023

See publication

Tags: Cybersecurity, Privacy, Risk Management

Speaker on IT Audit referred to the latest POJK, IT Governance hybrid seminar, YPIA, Jakarta
Yayasan Pendidikan Internal Audit (YPIA) and Grant Thornton Indonesia
September 07, 2022

See publication

Tags: Cybersecurity, Finance, GRC

2 Patent Pendings
Automated AI Model Governance Framework (AIMGF)
Directorate General of Intellectual Property (DGIP), Indonesia
February 16, 2026
An AI governance architecture that automates fairness analysis, model drift monitoring, explainability scoring, regulatory compliance validation, and audit trail generation for AI systems deployed in financial sectors.

See publication

Tags: AI Governance, Finance, GRC

Quick Ethical Risk Assessment Method for AI Outputs
Directorate General of Intellectual Property (DGIP), Indonesia
November 25, 2025
A method for rapidly assessing ethical risk in AI model output using a selected ethical parameter-based approach.

See publication

Tags: AI Ethics, AI Governance, Risk Management

1 Podcast
Guest Speaker on Roti Manis Podcast: The Landscape of IT Risk in 2025: The Role of Internal Audit in Mitigating Technology Threats
IAIB
March 14, 2025

See publication

Tags: Cybersecurity, GRC, Risk Management

5 Quotes
Quoted Thought Leader on AI Safety and Governance – Cloud Security Alliance (TAISE)
Cloud Security Alliance
October 22, 2025
Quoted by Cloud Security Alliance in their official TAISE web page, highlighting perspectives on AI safety, governance frameworks, and responsible AI leadership.

See publication

Tags: AI Governance

Tackling Cybercrime Threats, Collaboration in Telecommunications Sector is Increasingly Important
Kompas.com
September 29, 2024

See publication

Tags: Cybersecurity

Cyber Threats Getting More Serious, What About Personal Data Protection?
Liputan6.com
July 25, 2024

See publication

Tags: Privacy

Why Rising Cybercrime Requires Stronger Data Protection Awareness
Kompas
July 23, 2024

See publication

Tags: Cybersecurity

Public-Private Partnership in Strengthening Cyber Security
Kompas.com
July 10, 2024

See publication

Tags: Cybersecurity

19 Speaking Engagements
Cyber Risk Exposure Management,
TEH Group on behalf of Trend Micro Indonesia
December 04, 2025
As the roundtable discussion facilitator. My session title is “Bridging the Gap: Aligning Cybersecurity with Business Objectives”

This session will bring together industry leaders to discuss how organisations can strengthen cross-functional alignment, enhance cyber risk visibility, and translate security strategies into measurable business outcomes.

See publication

Tags: AI, Cybersecurity, Risk Management

DX Leaders Indonesia 2025
EDx Events
November 19, 2025
As the Roundtable Discussion Facilitator for the session titled "Digital trust as the new currency: Securing identity, data & confidence"

See publication

Tags: AI, Cybersecurity, GRC

Guest Speaker on CNBC Indonesia: The Risk of AI-Based Cyberattacks. Is Indonesia Ready?
CNBC Indonesia
May 08, 2025
Transformasi digitalisasi yang terus berkembang turut mendorong peningkatan implementasi teknologi Artificial Intelligence (AI) atau kecerdasan buatan diberbagai sektor.

Teknologi AI digunakan untuk mendorong produktivitas dan meningkatkan efisiensi dalam berbagi aspek termasuk bagi sektor industri. Meski demikian, kemajuan teknologi AI ini juga mendorong meningkatnya ancaman serangan siber berbasis AI mulai dari deepfake hingga ancaman keamanan dan privasi.

IT Advisory Director Grant Thornton Indonesia, Goutama Bachtiar menyebutkan saat ini berbagai organisasi sudah banyak yang mengadopsi AI sejak 5-10 tahun lalu. Selain digunakan untuk meningkatkan kualitas layanan publik, AI juga dimaksudkan untuk mendorong produktivitas hingga memberikan "costumer experience"

Dalam menghadapi berbagai serangan siber AI, diperlukan perang pemerintah untuk memperkuat panduan etis dalam implementasi AI sebagai penguat bagi regulasi untuk mengatur penggunaan AI.

See publication

Tags: AI, Cybersecurity, Risk Management

Speaker, CyberAttack Indonesia - The Offsite Retreat
TEH Group
February 20, 2025
Delivered a speaking session titled Personal Data Protection: Ensuring Compliance and Operation Readiness

See publication

Tags: Cybersecurity, GRC, Privacy

Personal Data Protection: Ensuring Compliance and Operation Readiness
The TEH Group
February 05, 2025
This deck, presented in February 2025 to 70+ cybersecurity executives and industry leaders, explores Indonesia’s Personal Data Protection Law (PDPL), outlining key compliance obligations, data subject rights, sanctions, and industry-specific requirements. It also highlights OJK’s digital maturity controls and upcoming regulations, offering practical guidance for organisations to strengthen data governance, ensure operational readiness, and align with international best practices.

See publication

Tags: GRC, Privacy, Risk Management

Guest Speaker, Seminar “Professional Certification: Bridging Industry Needs”
Bina Nusantara University
July 02, 2024

See publication

Tags: Careers, Management, Project Management

Resource Person for Binus Business School Undergraduate Program in Management
Binus Business School
May 14, 2024
The seminar title was Professional Certification: Bringing and Bridging What Industry (Really) Needs.

See publication

Tags: Careers, Leadership, Project Management

Guest Speaker on CNBC Indonesia: Strategy to Strengthen Cybersecurity in the Digital Disruption Era
CNBC Indonesia
January 13, 2024

See publication

Tags: Cybersecurity, GRC, IT Strategy

Speaker on Cyber Security in Indonesia, an IT Seminar, Ukrida, Jakarta
Universitas Kristen Krida Wacana (UKRIDA)
April 17, 2019

See publication

Tags: Cybersecurity, GRC, Security

Speaker at IS/IT Audit seminar for Airlangga University
Airlangga University, Banyuwangi
April 11, 2017

See publication

Tags: Cybersecurity, Finance, GRC

Speaker on Pencegahan Fraud E-Channels di Perbankan: Skimming, Carding and Cyber Crime
BSMR
October 04, 2016
Delivered in person in Jakarta and Surabaya.

See publication

Tags: Cybersecurity, Finance, Security

Speaker at Information Systems Seminar, Binus Event Festival
Binus University, Jakarta
May 02, 2016

See publication

Tags: Cybersecurity, GRC, Risk Management

Speaker on Pencegahan Fraud E-Channels di Perbankan: Skimming, Carding and Cyber Crime
BSMR
February 13, 2016
Delivered in person in Jakarta and Surabaya.

See publication

Tags: Cybersecurity, Finance, Security

Guest Speaker on 'BYOD: Bring Your Own Device or Danger?'
Rotaract Semanggi, Jakarta
July 22, 2013

See publication

Tags: IT Leadership, IT Operations, IT Strategy

Angel Investor View on ASEAN Common Fund for Startup
Goutama Bachtiar
June 03, 2013
The deck outlines a Singapore-based corporate angel investment platform focused on funding startups across Asia, particularly in the technology and innovation sectors.

The platform follows a 'high risk-high return' investment philosophy, aiming to provide initial funding of $100k to $300k, along with follow-on investments, through a collective investment scheme known as a common fund. The document outlines the advantages, criteria, and challenges associated with the standard fund structure, emphasising the benefits of co-investment, diversification, and reduced investment risks.

See publication

Tags: Entrepreneurship, Innovation, Venture Capital

Seminar on Bringing Indonesia Tech Startup Forward at Swiss German University
Swiss German University Master and Undergraduate Program
April 16, 2013

See publication

Tags: Entrepreneurship, Innovation, Venture Capital

Presenter on APCO-Incubation, Business Matching, AIBI, Bandung
University of Indonesia
January 07, 2013

See publication

Tags: Finance, Startups, Venture Capital

Moderator on IT Security Seminar 'C:\> Who Let the Hacker in?'
Binus University, Jakarta
February 05, 2007

See publication

Tags: Cybersecurity, GRC, Risk Management

Speaker on IT Security Seminar 'Ethical Hacking'
Universitas Tarumanagara, Jakarta
May 08, 2006

See publication

Tags: Cybersecurity, GRC, Risk Management

3 Trainings
Group Coach, GTIL APAC Emerging Leaders Programme, Kuala Lumpur
Grant Thornton International Limited
May 27, 2024

See publication

Tags: Coaching, IT Leadership, Leadership

Executive-level Corporate Training on Fintech for Mandiri Bank
BPlus
November 27, 2019
It covers the trends in digital banking, fintech and its ecosystem, e-commerce, bank and fintech players' collaboration, applicable regulations, and recommended practices delivered in a two-day executive-level in-house training program.

See publication

Tags: Blockchain, Finance, FinTech

Executive-level Corporate Training on Blockchain for BNI
Multimatics Group Indonesia
November 01, 2018
Conducted an intensive two-day corporate training titled Blockchain Essentials - Harnessing the Technology for the Banking Industry for a Tier-1 Indonesian bank.

It covers exploring blockchain components, leveraging blockchain benefits, implementing blockchain in banking, and understanding key challenges. It then provides details on the first session, exploring blockchain and its components, defining blockchain, its distributed ledger system, and key cryptographic components such as public/private keys, digital signatures, proof of work, and hash functions. It also discusses the relationship between blockchain and cryptocurrency.

See publication

Tags: Blockchain, Cryptocurrency, Finance

29 Visiting Lecturers
Guest Lecture for Binus School of Accounting
Binus School of Accounting
April 21, 2026
The session title was Data Analytics and Data Visualisation

See publication

Tags: Analytics, Big Data, Predictive Analytics

Guest Lecture for Western Sidney University Indonesia
Western Sidney University Indonesia, School of Computer, Data, Mathematics Science
April 01, 2026
The Guest Lecture titled "The Future of Secure Computing: AI, Cloud, and Big Data"

See publication

Tags: AI, Cloud, Cybersecurity

Guest Lecture for Binus Business School
Binus Business School
January 19, 2026
The session title was AI Ethics, delivered from January to April 2026.

See publication

Tags: AI Ethics, AI Governance, GRC

Guest Lecture for Binus Business School Undergraduate Program in Management
Binus Business School
September 24, 2025
The session title was Digital Initiatives - Lessons Learned from Indonesia Use Cases.

See publication

Tags: AI, Data Center, Digital Transformation

Guest Lecture for Binus Business School Undergraduate Program in Management
Binus Business School Undergraduate Program in Management
February 26, 2025
The session title was Privacy and Data Protection in E-Business delivered on February 26 and 27th, 2025

See publication

Tags: Cybersecurity, Privacy, Risk Management

Guest Lecture for Binus Business School Undergraduate Program in Management
Binus Business School Undergraduate Program in Management
February 19, 2025
The session title was Privacy and Data Protection in E-Business delivered on February 19th and 20th, 2025.

See publication

Tags: Cybersecurity, Privacy, Risk Management

Guest Lecturer on Protecting Financial Data Integrity: The Role of Audit and Assurance in Mitigating Cyber ​​Risk
Islamic University of Indonesia
January 30, 2025
Delivered for the Accounting Major, Faculty of Economics and Business (online).

See publication

Tags: Cybersecurity, Finance, GRC

Guest Lecturer, AI for Cybersecurity
Bina Nusantara University, Master of Management in Digital Business
December 17, 2024

See publication

Tags: AI, Cybersecurity, GRC

Guest Lecturer, AI for Cybersecurity for Bina Nusantara University's Master of Management in Information Systems
Bina Nusantara University, Master of Management in Information System
July 16, 2024
Delivered the session online titled When AI Meets Cybersecurity: The Double-Edged Sword.

See publication

Tags: AI, Cybersecurity, GRC

Guest Lecture for Binus Business School Undergraduate Program in Management
Binus Business School
October 02, 2023
The session title was Cybersecurity in Indonesia: Current State, Challenges and Opportunities, delivered on October 2nd and 5th, 2025.

See publication

Tags: Cybersecurity, Digital Disruption, Risk Management

Guest Lecture for Binus Business School Undergraduate Program in Management
Binus Business School
September 25, 2023
The session title was The Importance of Privacy and Data Protection in E-Business: Indonesia's Context, delivered on September 25th and 27th, 2025.

See publication

Tags: Cybersecurity, Privacy, Risk Management

Guest Lecture for Binus University School of Information System
Binus University School of Information System Undergraduate Program
April 04, 2016
The course name was M1022 – Advanced Topic in Information Systems. Delivered on April 4th, May 16th, and June 13th, 2016.

See publication

Tags: IT Leadership, IT Operations, IT Strategy

Guest Lecture for University of Indonesia's Master Program in Computer Science
University of Indonesia
January 18, 2015
The session title: A Case Study on Business Process Management

It discusses the importance of Business Process Management (BPM) in enhancing organisational efficiency, particularly in the financial sector, and outlines strategies for effective regulatory compliance. Additionally, it details the challenges and learning experiences encountered during a complex SAP implementation at Hewlett-Packard and provides insights into process management and communication strategies for successful project deployment.

See publication

Tags: Business Strategy, IT Leadership, IT Strategy

Guest Lecture for Petra Christian University: International Business Accounting Program
Petra Christian University
November 20, 2014
The session title: Valuing Information Management and IT Architecture

It discusses the critical aspects of information management and IT architecture, emphasising their importance for improving decision-making, predictions, and compliance while reducing costs and risks. It highlights the goals and challenges of information management, the significance of IT architecture for long-term business alignment. It showcases a case study on Hewlett-Packard's global supply operation deployment. Additionally, the document addresses the roles of cloud computing, virtualisation, and the essential characteristics of IT infrastructure.

See publication

Tags: IT Leadership, IT Operations, IT Strategy

Guest Lecture title Indonesia Digital Spaces Competitiveness
University of Indonesia
May 25, 2014
The session was delivered for University of Indonesia's Faculty of Economics and Business's International Undergraduate Program.

See publication

Tags: Digital Disruption, Digital Transformation, IT Leadership

Guest Lecture for Binus Business School's Undergraduate Program in Management
Binus Business School:
May 24, 2014
The session title: Crafting and Delivering an Effective Business Pitch to Investors

It provides tips for effectively pitching a business or product idea. It emphasises that a pitch should clearly explain the problem being solved and the proposed solution in 2-3 short sentences. Pitches should be concise yet compelling, avoiding jargon, and focus on the customer benefits and value rather than features. Effective pitches include information on traction, product, team, and social proof and are practiced extensively to perfect timing and delivery.

See publication

Tags: Finance, Startups, Venture Capital

Guest Lecture at Padjajaran University on Reinforcement of Information Privacy and Security Nowadays
Goutama Bachtiar for Padjajaran University, Faculty of Communication Science, Library Science
May 23, 2014
This document provides a profile of an expert presenter, including their extensive experience in IT advisory, consulting, auditing, training, and project management spanning 16 years. The presenter has advised 6 companies, served as an international subject-matter expert for ISACA, developed certification exams, reviewed publications, audited and consulted with over 30 companies, delivered over 200 training sessions to over 7,000 attendees, and written over 300 articles. The document then outlines the presenter's upcoming session on information privacy and security which will discuss definitions, taxonomies, expectations, types of information collected, standards, challenges, and lessons learned.

See publication

Tags: Cybersecurity, GRC, Privacy

Guest Lecture for University of Indonesia's Master Program in Computer Science
University of Indonesia
April 15, 2014
The session title: The State of ERP in Indonesia: Trends, Opportunities and Challenges

It discusses revisiting ERP systems, including their scope, characteristics, objectives, benefits, trends, and implementation and post-implementation challenges. It also provides advice on building an ERP system internally if a company decides not to purchase a commercial package.

See publication

Tags: Business Strategy, IT Leadership, IT Strategy

Guest Lecture title Commencing Business Incubation and Investment Program
Binus Business School, Undergraduate Program in Management
April 10, 2014

See publication

Tags: Entrepreneurship, Innovation, Venture Capital

Guest Lecture for Binus University School of Information System
Binus University School of Information System Undergraduate Program
April 08, 2014
The session topic was Information System Concept titled Payroll Process and Fixed Asset Procedures.

It discusses the payroll system and its related documents. Key points covered include the functions within the payroll system, including personnel, timekeeping, payroll processing, accounting, and finance. It also explains various documents used, such as decrees, attendance records, payroll registers, and pay envelopes.

See publication

Tags: Business Strategy, IT Operations, IT Strategy

Guest Lecture at Bogor Agricultural University's Master in Management CEO and Entrepreneurial Development Forum
Goutama Bachtiar for Bogor Agricultural University
March 18, 2014
The deck outlines key considerations for starting a consulting firm, highlighting the importance of understanding consulting requirements, targeting specific industries, and developing necessary skills. It emphasises the need for proper planning, including business structure, marketing strategies, and maintaining client relationships. Additionally, it discusses the importance of continuous learning and adapting to client needs in the consulting field.

See publication

Tags: Business Strategy, Careers, Leadership

Guest Lecture for Binus Business School: Master in Management
Binus Business School:
January 21, 2014
The session title: Strategic Communication for Organisation Growth

It discusses the strategic role of communication in organisational growth, highlighting its impact on ROI, employee turnover, and overall financial performance. It outlines key elements of strategic communication, including organisational variables, audience needs, messaging, and channels, while providing case studies to illustrate effective communication strategies. The emphasis is on enhancing communication for better alignment with organisational objectives and adapting to modern digital and social media landscapes.

See publication

Tags: Business Strategy, Leadership, Management

Guest Lecture for Binus University Undergraduate Program, School of Information System
Bina Nusantara Online Learning
October 11, 2013
The session title: Web 2.0 and Social Networks for Enterprise.

The document is a guest lecture presented by Goutama Bachtiar at Bina Nusantara University on the role and evolution of Web 2.0 and social networks in enterprises. It covers various aspects, including the characteristics of Web 2.0, its impact on education, the importance of social media in enterprise marketing and communications, and critical success factors for leveraging social networks effectively. Additionally, the lecture discusses strategies for managing these platforms, including in-house versus outsourcing considerations, and emphasise the need for key performance indicators in measuring success.

See publication

Tags: IT Leadership, IT Operations, IT Strategy

Guest Lecture for Binus University School of Information System
Binus University School of Information System Undergraduate Program
October 11, 2013
The session topic was Information System Concept titled Payroll Process and Fixed Asset Procedures.

It discusses the payroll system and its related documents. Key points covered include the functions within the payroll system, including personnel, timekeeping, payroll processing, accounting, and finance. It also explains various documents used, such as decrees, attendance records, payroll registers, and pay envelopes.

See publication

Tags: Business Continuity, IT Operations, IT Strategy

Guest Lecture for Bandung Institute of Technology's Undergraduate Program, School of Business and Management
Bandung Institute of Technology
October 08, 2013
The session title: The Importance of Logic in Business.

The deck presents a comprehensive overview of logical thinking and its critical role in business decision-making. It discusses various thinking methodologies, including necessary, strategic, lateral, and programmatic thinking, and emphasises the importance of understanding logic for effective problem-solving and strategic management. The content also highlights how logic links actions and consequences, serving as a foundation for successful business practices.

See publication

Tags: Business Strategy, Leadership, Management

4 Webinars
Seeing the Unseen Enemies: Crucial Role of Whistleblowers in Detecting and Preventing Cyberfraud
Institute of Compliance Professional Indonesia (ICoPI) and Centre for Risk Management Sustainability Indonesia (CRMS Indonesia)
November 22, 2024
As a Resource Person in an Online Coffee Talk as part of ACFE International Fraud Awareness Week

See publication

Tags: Cybersecurity, Finance, GRC

Speaker on Digital Transformation in Banking Industry, webinar
BSMR
August 21, 2023

See publication

Tags: Digital Disruption, Digital Transformation, Finance

Speaker on Sector Solution/LED Expertise Industri Startup, webinar
Mandiri University
August 20, 2023

See publication

Tags: Finance, Innovation, Startups

Speaker on Sector Solution/LED Expertise Industri E-Commerce, webinar
Mandiri University
September 15, 2022

See publication

Tags: Innovation, Retail, Startups

5 Whitepapers
Author for "Zero Trust Cybersecurity for Healthcare" IEEE Industry Recommendation Paper
IEEE Standards Association Industry Connections
March 31, 2026
Authored Section 18 on Standards Alignment and IEEE Integration, providing a principles-based harmonisation framework integrating Zero Trust architecture with major healthcare and cybersecurity standards (NIST, ISO 27001, HL7 FHIR, HITRUST).

See publication

Tags: Cybersecurity, GRC, Healthcare

Reviewer for AICM Auditing Guidelines
Cloud Security Alliance
September 03, 2025
The AI Control Matrix (AICM) auditing guidelines emphasise role-specific accountability across the AI supply chain, requiring tailored evaluation for model providers, application developers, orchestrators, platforms, and customers. Key focus areas include AI-aware change management, structured exception handling, rollback readiness, and rigorous quality testing.

Spearheaded as one of the reviewers.

See publication

Tags: AI Governance, AI Infrastructure, GRC

Reviewer for CCM SSRM Guidelines
Cloud Security Alliance
June 03, 2024
The Shared Security Responsibility Model (SSRM) guideline extends the Cloud Security Alliance's Cloud Controls Matrix (CCM) v4 framework to educate cloud customers on their security responsibilities within shared cloud infrastructure.

Spearheaded as one of the reviewers.

See publication

Tags: Cloud, Cybersecurity, GRC

Reviewing Standard for Organizational Project Management (OPM) Draft
Project Management Institute
September 11, 2017
Reviewed and commented on the exposure draft of Standard for Organizational Project Management (OPM) before the publication in mid-2018.

See publication

Tags: Leadership, Management, Project Management

Reviewing ISACA White Paper on Privacy and Big Data
ISACA
October 19, 1201
Spearheading as Expert Reviewer with three other fellows. The white paper is available in English, Spanish, French and Portuguese.

See publication

Tags: Big Data, GRC, Privacy

8 Workshops
Roundtable Discussion’s Facilitator, Cyberattack Nexus Retreat Indonesia
The TEH Group
February 21, 2024
The roundtable titled Modernizing Your SOC: Detecting Application Layer Attacks and Democratizing Security for xOps Teams

See publication

Tags: Cloud, Cybersecurity, GRC

Panelist on Cybersecurity: Best Practices for Risk Mitigation & Compliance, Britcham
British Chamber of Commerce in Indonesia
January 15, 2024

See publication

Tags: Cybersecurity, GRC, Risk Management

Executive-level Corporate Workshop on Agile User Stories for Mandiri Bank
Knowledge Hut
May 06, 2019

See publication

Tags: Agile, Management, Project Management

Executive-level Corporate Workshop on Agile and Scrum for BNI
Knowledge Hut
August 01, 2018

See publication

Tags: Agile, Management, Project Management

Executive-level Corporate Workshop on Project Management for Big Banks in Indonesia
Knowledge Hut
May 14, 2018

See publication

Tags: Agile, Management, Project Management

Executive-level Corporate Workshop on Business Case Writing for MNC in Indonesia
Knowledge Hut
March 20, 2017

See publication

Tags: Business Strategy, Management, Project Management

Executive-level Corporate Workshop on Agile and Scrum for Commonwealth Indonesia Bank
Knowledge Hut
March 03, 2016

See publication

Tags: Agile, Management, Project Management

Executive-level Corporate Workshop on Business Case Writing in Thailand
Knowledge Hut
October 03, 2014
Delivered in Bangkok for a full-day training for Thailand MNCs and local conglomerates.

See publication

Tags: Business Strategy, Management, Project Management

Thinkers360 Credentials

39 Badges

Radar

Blog

3 Article/Blogs
Before AI Agents Start Talking: Who's Listening at Board Level?
Thinkers360
February 02, 2026

Walk into any boardroom today, and you will most likely find executives and directors still debating ChatGPT's fair use policies. On the other hand, their rivals might have already deployed autonomous AI agents that allocate budgets, negotiate contracts, execute transactions, or reconfigure production planning and inventory systems. Without human approval. Without oversight committees. Without anyone noticing, until the regular review.

The agent-to-agent economy has arrived. It was there whilst we were drafting guidelines for generative AI. Right now, procurement agents are haggling with supplier bots over pricing. Compliance systems are triggering remediation workflows across cloud infrastructure. Trading algorithms are staking cryptographic credentials to access market data feeds. All of this happens at machine speed, in the gaps between human attention spans.

Most boards haven't grasped the shift yet. They're applying last year's governance frameworks to this year's autonomous systems. It's like trying to regulate supersonic jets with rules written for hot air balloons.

When Devices Stop Waiting for Permission

Throwback to how we interacted with AI around twenty-four months ago. You'd type a prompt into ChatGPT. Review the response. Decide whether to use it, edit it, or bin it entirely. Give them feedback. Humans stayed in the loop at every decision point. Comforting. Controllable. Safe.

Agentic AI is slightly different. It does work by setting their own goals, breaking problems into steps, coordinating with other agents, and executing activities and tasks across our entire technology stack. Indeed, they don't generate suggestions and wait for our approval. They act, then report back what they've done. By the time you're reading the log files, thousands of decisions might have already been executed.

One of the gigantic financial institutions discovered that its expense approval agent had been in place for three months with an outdated vendor whitelist. No one noticed because the agent processed requests faster than human oversight. Five million transactions. Zero human reviews. This considers regular operation in an organisation racing toward autonomous systems.

In short, the governance landscape has changed moderately, but most of us still use the old playbook.

Content Risk Was Just the Warm-Ups

GenAI could hallucinate facts, perpetuate biases, or accidentally plagiarise copyrighted material. Serious concerns, absolutely. But manageable because humans still have their grips on the outputs. You could catch the mistake before it reached the users, customers, regulators, or the media.

In the case of Agentic AI, autonomy risk operates differently. The AI doesn't wait for your review. It books the vendor meeting, updates your ERP system, notifies stakeholders across three departments, and moves on to the next task. When agents execute forty thousand decisions per second, your quarterly risk committee isn't reviewing decisions anymore. You're reading history, well, ancient history, by AI standards.

Traditional governance assumed you'd have time to evaluate one decision before the next one needed attention. That worked fine when humans made all the calls. Now? The gap between action and oversight is permanent. You can't close it by hiring more compliance officers or scheduling extra committee meetings. The velocity gap is structural, not staffing.

Instead of asking "What did our AI do?", boards need to ask, "What prevents our AI from doing things it shouldn't?" The distinction matters more than most executives realise.

Humans Haven't Been Eliminated. They've Been Repositioned

Effective Agentic AI’s governance moves humans from approvers to exception handlers, from bottlenecks to overseers. You’re absolutely right! We still exist in the loop.

Human-in-the-Loop (HITL) architecture establishes clear escalation paths for scenarios involving high-risk or ambiguous processes, actions, activities, and tasks. Routine decisions run autonomously, and edge cases are flagged for human judgment. A compliance agent might scan 10,000 transactions overnight; nevertheless, it will dispatch five that exceed risk tolerance for further follow-up and investigations, as necessary.

Agents operate within strict boundaries around organizational policy compliance, cost and budget limits, and risk appetite and risk tolerance. Technical safeguards enforce them. Furthermore, rate limiting prevents any single agent from executing thousands of operations without triggering oversight. Tool access restrictions specify exactly which APIs, databases, and systems each agent can interact with. Session timeouts stop indefinite execution that could enable multi-day attack scenarios.

In the case of security, it can't be an afterthought grafted onto agentic systems post-deployment. It must be embedded in the agent's design from the very beginning. The magic mantra is governance as architecture, not as documentation.

So, What Board-Level Oversight Actually Looks Like?

Agentic AI governance demands cross-functional coordination with decision authority sitting at the board level. Your Chief Compliance Officer can't fix this alone. Setting up Agentic Governance Councils that consist of reps from Technology, Business, Security, Legal, Risk, and Compliance units is an ideal pathway to move this forward. Monthly board meetings, quarterly reports, and direct authority over agent registries, data access policies, privilege allocation, and control implementation are the must-have tools, techniques, and deliverables.

A respective personnel or team that creates and maintains the complete list of registered agents operating in your environment: what they do, which data they access, the privileges they have, the ownership, responsibility, accountability, and the controls that govern them should be formed or appointed. Pretty similar to the risk register; it is a foundation for auditability. When regulators investigate a breach, they'll want to trace exactly which agent acted, under what authority, using what data, with which human ultimately accountable for the expected outcome.

Boards themselves need to stay relevant. They need AI literacy, whether by recruiting directors with technical backgrounds, establishing advisory relationships with AI experts, or enrolling them in the related executive education programs. Technology moves too fast and carries too much risk for boards to rely entirely on management reports. You don't need every director to hold a PhD in machine learning. You do need adequate collective understanding to ask critical questions and spot gaps in management's governance proposals.

Full lifecycle governance matters. Still. Development, commissioning, deployment, operation, monitoring, controlling, transfer, decommissioning, and retirement. Each phase has its own challenges and constraints.

A deep dive into the development stage requires identifying agent objectives, impediments, and constraints so engineers can deploy what we call “enforceable boundaries”. Deployment involves granting appropriate access rights and privileges without exposing security vulnerabilities. Operation, furthermore, demands continuous monitoring and speedy anomaly detection. Lastly, retirement ensures agents don't exist merely as "zombie processes" with orphaned access rights wandering your technology infrastructure.

The Missing Part

Boards fixate on what individual agents can do. So, the next question is what happens when multiple agents interact without human referees. Agent-to-Agent Communication Protocols (A2A) will enable autonomous systems to collaborate, negotiate, and transact value at machine speed. These protocols are extremely helpful because they standardise how agents coordinate complex workflows, resolve conflicts quickly and dynamically, and route tasks across the organisation's distributed tech stacks.

However, the governance’s complexity arises when those interactions cross organisational boundaries. Your procurement agent negotiates pricing with a supplier's sales agent, and both operate autonomously. Meanwhile, neither organisation has visibility in the other's governance framework. Then, when things go sideways, who should be held accountable? What happens if one agent stakes AgentBound Tokens whilst the other operates without cryptoeconomic accountability? Can your compliance systems even detect when external agents violate agreed protocols?

So, here we go. Welcome to the agent-to-agent economy of trust. It requires decentralised governance, allowing AI agents to interact and exchange value autonomously whilst preserving human oversight through progressive decentralisation. Centralised control certainly won't scale across organisational boundaries. The afterthought is that governance must be embedded in the communication protocols agents use, not layered on top after the deployment ends.

Why Your Risk Framework Stopped Working

Enterprise Risk Management practice categorises threats by likelihood and impact, then identifies their risk action strategies. That model assumes risks are identifiable, measurable, and relatively manageable from time to time. Agentic AI unsurprisingly breaks all these assumptions.

Autonomous agents create emergent behaviours. System-level outcomes come from agent interactions that weren't programmed into any individual agent. Let’s have a simple example. Your expense approval bot optimises for cost reduction. Your supplier relations agent optimises vendor satisfaction. Your compliance agent optimises policy compliance. Deploy all three and watch them inadvertently conspire to approve invoices from vendors whose contracts lapsed last month. Nobody expected that outcome, given that it emerged from the interaction dynamics.

We might be aware that static approval processes can't govern dynamic systems. Agentic AI demands real-time feedback loops, automated escalation matrices, and real-time intervention capabilities. It makes our regular risk reviews historical exercises. Therefore, continuous assurance models in which compliance monitoring processes continuously run, gather time-stamped evidence, and trigger remediation workflows without waiting for the next committee meeting are a must-have magic pill.

It's an operational necessity driven by evolving laws and regulations. The EU's Digital Operational Resilience Act requires financial institutions to conduct ongoing ICT risk monitoring. In addition, the EU AI Act mandates post-market surveillance for high-risk AI systems. We are witnessing the regulators’ expectation that automated systems must continuously demonstrate compliance, not periodic attestations that everything was alright three or six months ago.

Big Five Questions Our Board Should Ask

Let’s stop debating whether (or not) to deploy agentic AI. Our competitors already did. Start asking better questions:

  1. Do we really know every autonomous agent deployed in our environment? Indeed, unknown agents are ungoverned agents. You can't control what you can't see, right?
  2. Can we trace each agent’s action back to a human who owns the outcome? Autonomous doesn't mean unaccountable. Someone has to answer when regulators come knocking on our doors.
  3. Have we built escalation paths for high-risk scenarios into the agent architecture? Agents shouldn't go live until they know precisely when to stop and ask for help.
  4. Are our agents cryptoeconomically bound to compliance standards through staked collateral? Well, if accountability relies on trust rather than enforceable mechanisms, the hard truth is, our governance is aspirational fiction.
  5. Does our oversight operate at machine speed? If we review agent decisions quarterly whilst they're executing continuously, we're managing historical data, not controlling our current risks.

Getting From Here to There

You’re right. Nobody's transforming agentic AI governance in a single board meeting. It requires big (re)thinking about how control, accountability, and oversight function when decisions occur faster than humans can process them.

Key success factors, the first and foremost, are that we should treat governance as system architecture rather than solely policy documentation. The shift-left approach is implemented by embedding related controls in agent design, adoption of cryptoeconomic accountability frameworks that align agent incentives with organisational values through programmable stakes and automated consequences. Continuous assurance replaces periodic audits with real-time monitoring. Cross-functional governance councils with board-level authority and clear decision rights that don't get bogged down in turf battles.

Most critically, they recognise the shift from generative to agentic AI as a governance discontinuity rather than an incremental evolution. Applying yesterday's frameworks to tomorrow's technology doesn't just create risk; it also creates opportunity.

The agent-to-agent economy stopped being science fiction sometime last year. It's an infrastructure thing right now. The machines are talking, negotiating, and transacting. The strategic question for boards isn't whether to participate. We're already there, whether we realise it or not. So, the question is: are we going to govern those conversations at the right speed, with frameworks tailored to machine velocity, before autonomous interactions reshape entire processes faster than human governance can respond?

Our oversight gap isn't a future threat. It's a present vulnerability. Closing it requires admitting that human-speed governance became obsolete the moment we granted machines autonomy. The rest is history.

See blog

Tags: Agentic AI, AI Ethics, AI Governance

Why Your AI Ethics Policy is Most Probably a Paper Tiger
Thinkers360
January 12, 2026

Today, I remembered a conversation I recently had in a pretty cold corner of a private lounge in South Jakarta. The hum of the city’s relentless traffic felt far away, but the tension inside the room was palpable. Across from me sat a commissioner of one of Indonesia’s largest family-owned conglomerates. Between sips of an over-extracted black coffee, he pointed to a thick, glossy binder on the table, the company’s brand-new "AI Ethics and Governance Framework."

"We’ve spent six months on this with a top-tier consultancy," he said, looking genuinely relieved. "Every value is there. Transparency. Fairness. Inclusivity. We’re fully covered, aren’t we?"

I was looking out at the afternoon gridlock on Sudirman Street and thought about a hot chocolate teapot. The binder was sophisticated. It was posh. It looked fantastic in the annual report. And during a real technological crisis, it was utterly useless. It was a classic case of “CEO’s New Clothes." In the rush to look "AI-ready," many of our CxOs in Jakarta and beyond are walking into a digital storm stark naked, draped only in the fine silk of PR-friendly buzzwords.

Sudirman Scramble: Speed vs. Substance

Let’s be brutally honest. Most AI ethics policies in our country today are what I call "Paper Tigers." Designed by marketing and legal teams to appease shareholders and regulators, not by GRC (Governance, Risk, and Compliance) experts to manage the messy, unpredictable reality of machine learning. We are currently in the middle of a digital gold rush in Indonesia. From Fintech startups in the Mega Kuningan area to legacy banking giants in Thamrin, everyone wants a piece of GenAI pie. But in this scramble for the "first-mover advantage," safety is often treated like a seatbelt in a Jakarta online taxi. Present for appearance, but rarely actually clicked into place.

The problem? Agentic AI doesn't care about your decks or your vision and mission statement. When you make a bold move from simple chatbots and start deploying autonomous agents, systems that can execute trades, manage customer databases, or negotiate with vendors without a human in the loop, you aren't just "upgrading your tech." You are delegating your corporate authority to an algorithm. And if your governance framework is purely aspirational, you have essentially handed the keys of the company’s multi-decade reputation to a black-box system that doesn't understand the concept of a "fiduciary duty."

"Sungkan" Factor: Silent Killer of (IT) Governance

In Indonesia, we have a cultural nuance often called "sungkan" a.k.a “gak enakan”. A deep-seated reluctance to challenge authority, deliver bad news, or "correct" a superior’s vision. In the boardroom, this translates to a dangerous, expensive silence. When the CTO, CIO, or a flashy external vendor says the new AI model is "fully optimised and ready for deployment," very few Directors have the technical confidence or cultural "permission" to ask uncomfortable questions.

I saw this play out recently with a multinational retail banking giant. They had implemented an AI model to "predict" customer creditworthiness and automate loan approvals. Technically speaking, it was a masterclass of operational efficiency. They were cooking. In reality, the model had developed a subtle bias against applicants from certain rural provinces outside Java. Simply not due to the developer’s team being unconsciously biased, but because the training data fed was from old-school credit gatekeeping and regional economic disparities.

Because of the "sungkan" culture, the junior tech resources who noticed the drift didn't feel empowered to stop the launch. The human reviewers, lulled into a false sense of security by the "trusted" AI, were rubber-stamping the machine’s output. This is what we call Automation Bias, and it is a GRC nightmare. It took a massive spike in non-performing loans and a brewing PR scandal for them to call for a deep-dive audit finally. It required a hard-coded intervention. A recalibration of the risk logic and a complete overhaul of their data governance.

Anatomy of a Real AI Audit: Five Pillars for C-Suite

If you are a commissioner or a director, you should stop looking at high-level checklists and start demanding "live" audits. In my experience, a robust AI audit must rest on these five non-negotiable pillars:

1. Data Lineage and Provenance ("Where" and "Why")

In Indonesia’s corporate world, data is often a "rojak" of fragmented legacy systems. If you don't know exactly where the data originated, and whether it was obtained ethically and legally, you cannot govern the AI. An AI is only as honest as its training data.

2. Adversarial Red Teaming

You need to hire people whose only job is to be "naughty." They should try to break your AI, trick it into leaking confidential board minutes, or bypass safety filters. If a bored teenager can trick your corporate chatbot into giving away trade secrets by using a clever "jailbreak" prompt, your 40-page Ethics Policy isn't worth the paper it’s printed on.

3. Localised Bias Testing

Global AI models are often trained on Western datasets. They don't understand the nuances of Indonesian culture, our varied dialects, or our socio-economic realities. Testing for "fairness" in a London or San Francisco context is functionally useless for a business operating in Surabaya, Medan, or Makassar.

4. Explainability (XAI Factor)

If the AI rejects a customer’s application or flags a transaction as fraudulent, can your staff explain the "Why"? A "black box" that says "Trust Me" is a legal and regulatory liability that no Director should ever sign off on.

5. Model Drift and Continuous Monitoring

AI is not a "set and forget" asset like a laptop or a desk. It is more like a living organism. It changes as it interacts with new data. You need something like a permanent pulse check. A dashboard that shows the "health" of the AI in real-time. Not just a one-off certificate from a vendor.

The Shadow AI Pandemic: Beat the Traffic, Breach the Data

While you are sitting in committee meetings debating high-level strategy, your staff are already using AI in ways that would make your Chief Risk Officer have a heart attack. This is the "Shadow AI" pandemic.

Think about the typical overworked analyst in a Kuningan office. They want to beat the 5 PM Jakarta traffic. To save three hours of work, they copy-paste a messy, confidential Excel sheet containing sensitive, or confidential client data into a free, public version of ChatGPT to "clean it up and summarise." It feels harmless. Their productivity boosts. It feels efficient.

But that data is now part of a global, public training set. Your company’s intellectual property has just been leaked into the wild, and you don't even have a record of it happening. Cybersecurity in 2026 isn't just about firewalls and antivirus; it’s about Data Sovereignty. It’s about creating "Walled Gardens". Secure, enterprise-grade AI environments where your employees, all of them, including you, can be productive without leaking the "crown jewels." If you don't provide the tools, your employees will go over the fence to find them.

Cloud Computing: "Shared Responsibility" Trap

I often hear a continuous, almost charmingly naive myth in Jakarta’s boardrooms: "We’ve moved to the Cloud (AWS, Google, or Azure), so security and compliance are now their problem."

This is a dangerous lie that has led to some of the most significant data breaches in recent history. In the industry, we call it the Shared Responsibility Model. In short, the cloud provider is responsible for the "security of the cloud" (the hardware, data centres, and physical pipes). You, on the other hand, as the cloud consumer, are responsible for "security in the cloud" – the data, access logs, and AI agents you utilised included.

Therefore, if you integrate an AI agent into your “cloud stack” without a solid, firm Identity and Access Management (IAM) policy and procedure, you, truthfully, leave your back door wide open. Having seen the case in which a poorly configured AI agent, designed to "optimise" cloud costs, accidentally granted itself administrative privileges and deleted a backup server because it deemed it "redundant." A cyber-attack from outside? Absolutely, no. A governance failure from the inside, it is.

Agentic AI and Kill-Switch Culture

As we move toward Agentic AI, as the systems that have the "agency" to act on our behalf, the concept of a "Kill-Switch" becomes paramount. We are talking about AI that can book flights, move funds between accounts, or change a manufacturing blueprint in a factory in Cikarang.

The question for the Board is: Who has the finger on the button and wants to roll up their sleeves?

First and foremost, IT Governance must evolve to accommodate Human-in-the-Loop or, at the very least, Human-on-the-loop approaches for high-stakes and or strategic decisions. Wouldn't you hire a procurement officer and give them a 1-billion-rupiah credit limit without their first line manager’s signature? Then, why would we provide a similar authority to an algorithm that doesn't feel the weight of responsibility? Accountability? We need to foster a "Kill-Switch Culture" where stopping vague, ambiguous processes is celebrated as much as launching a new feature.

AGI: Preparing for Final Frontier

The conversation inevitably turns to Artificial General Intelligence (AGI). While some dismiss it as "sci-fi faffing," the rapid trajectory of Agentic AI suggests we are closer to the "Ghost in the Machine" than many are comfortable admitting. For a policymaker or a commissioner, AGI is the ultimate governance challenge because it represents a shift from "Narrow AI" (doing one thing well) to "General AI" (doing everything as well as, or better than, a human).

If we cannot govern a simple chatbot that occasionally hallucinates legal advice today, how on earth do we expect to govern a system that matches human intelligence across every domain?

The preparation for AGI doesn't start with futuristic laws; it starts with fixing your GRC basics today. It begins with cleaning up your data silos. Start with Data Governance. Then continue with a Cybersecurity posture that "assumes breach" rather than "hopes for the best." And most importantly, it starts with a culture of Informed Scepticism. We need Directors who aren't afraid to look like the "slowest" person in the room by asking for a technical explanation of how a decision was reached.

Indonesian Context: Leading or Following?

As a nation, Indonesia has a choice. We can either be a "testing ground" or merely a market for global AI companies, taking their black-box models and hoping for the best, or we can put ourselves in the global Trusted AI maps.

Our regulators are watching. OJK and Indonesian Central Bank increasingly focus on digital operations, not only on transformation but also on resilience. The organisations that will thrive in this new era are those that can demonstrate their AI is safe, ethical, and governed. In the global marketplace, Trust is the new currency. If you can’t prove your AI won't hallucinate a fake financial report or leak customer data, nobody will want to do business with you.

Final Thoughts: Putting Paper Tigers Away

So, as you head into your following strategic review or board meeting in one of those sleek Sudirman towers, I challenge you to look at your AI Ethics policy with fresh eyes.

Is it a living, breathing part of your GRC framework, integrated into your Cybersecurity response plan and your IT Governance protocols? Or is it just "corporate wallpaper"? Something that looks nice and reassuring but doesn't actually hold anything up when the wind starts to blow.

"CEO’s New Clothes" is a cautionary tale about the dangers of vanity and the fear of appearing "un-hip" or "un-tech." But in the world of high-stakes corporate leadership, that vanity can lead to a multi-million dollar fine, a destroyed reputation, and a permanent loss of customer trust.

Time to put away the paper tigers. Time for some proper, international-standard rigour. At the end of the day, when the regulators come knocking, and the algorithms start acting up, "we meant well" simply won't make the cut.

Let’s stop the faffing. Let’s get to work. Keep going and keep building secure and innovative AI.

See blog

Tags: AI Ethics, AI Governance, GRC

The Ethical Compass: Why Indonesia Must Move Beyond AI Slogans Before It’s Too Late
Thinkers360
December 29, 2025

Imagine an algorithm deciding you are ineligible for a loan. No explanation provided. No procedure to appeal. This is the looming risk we face when Artificial Intelligence (AI) evolves without an ethical compass.

From chatbots mimicking the voices of public figures to algorithmic credit scoring and recruitment systems, AI is permeating the nuances of our daily lives at an extraordinary pace. Amidst this rapid influx, a critical question arises: where does ethics stand?

The Global Landscape vs. The Indonesian Context

In regions like the European Union, the United States, and Singapore, the discourse on AI ethics has already produced relatively established frameworks. Benchmarks such as the EU AI Act, OECD AI Principles, and the NIST AI Risk Management Framework serve as foundational pillars, emphasising fairness, transparency, accountability, and explainability.

In contrast, the conversation in Indonesia is still in its infancy. While there are emerging initiatives, such as the Financial Services Authority’s (OJK) ethical guidelines for fintech and banking, and the Ministry of Communication and Digital Affairs’ (Komdigi) circular on ethical values, the landscape remains fragmented. 8Without binding regulations and integrated coordination, AI ethics in Indonesia risks becoming a mere slogan rather than a functioning support system.

Why It Matters

The absence of an AI ethical framework is not just a legal vacuum; it is a lack of a moral guide to protect human interests. This gap has the potential to erode public trust, trigger economic losses, and widen social inequality. Whether it is the use of AI in public services without clear accountability or automated loan denials without fair recourse, the stakes are high.

Ethical governance for AI has become an urgent necessity. Put simply: ethics must guide AI, while the law follows closely behind.

A Collective Responsibility

AI ethics is not a purely technical matter reserved for machine learning experts, deep learning specialists, or AI engineers. It is a collective endeavour spanning sectors and generations, touching upon law, human rights, economics, education, and national values. Consequently, we cannot leave AI governance entirely to the market, private corporations, or foreign technology providers. We need an approach rooted in local wisdom, national values, and sovereignty.

A Roadmap for Action

To tackle these challenges, I propose three strategic steps:

  1. Establish a National Forum for AI Ethical Governance: The government should convene a multi-stakeholder body involving regulators, academics, industry practitioners, civil society, and the tech community. This forum would be responsible for drafting ethical principles, implementation standards, and oversight mechanisms. Principles such as non-discrimination, data protection, and social justice must be at the heart of every AI adoption.
  2. Prioritise Digital Ethics Education: We must instil ethical awareness early on, not just for students, but for developers and policymakers as well. True AI literacy goes beyond knowing how to use technology; it is about understanding how to use it rightly, fairly, and humanely.
  3. Mandate AI Impact Assessments: Any entity developing or deploying AI, particularly in the public and financial sectors, should be required to conduct an AI Impact Assessment. Similar to an environmental impact study, this mechanism would focus on evaluating algorithmic risks to individual rights and social structures.

The Path Forward

Indonesia has a significant opportunity to become a pioneer in ethics-based AI governance in Southeast Asia, provided we move beyond being passive consumers of foreign technology. The key lies in a contextual approach that respects our national principles (Pancasila), social justice, and societal diversity.

In the digital age, ethics is not an "optional extra." It is the very foundation of trust and sustainable innovation. We must build this foundation today, or we will pay a heavy price tomorrow through a crisis of confidence, social loss, and the dominance of foreign technology. It is time to place ethics at the centre of every AI policy, ensuring it remains the compass that keeps AI aligned with humanity.

See blog

Tags: AI Ethics, AI Governance, GRC

Opportunities

2 Writing & Editings
Courseware Development for Professional and Executive Education

Location: Virtual (Global)    Fees: 6000

Service Type: Service Offered

I design and develop executive-level and policy-grade courseware on Ethical AI Governance, AI Risk Management, AI Safety, and Digital Trust.

The courseware is tailored for regulators, boards, senior executives, and higher-education institutions, combining global standards with local regulatory and institutional contexts.

Deliverables include structured curricula, learning objectives, case studies, assessment materials, and facilitator guides suitable for executive education, certification programs, and policy capacity-building initiatives.

Respond to this opportunity

Policy-Grade White Papers on AI Governance, Ethics, and Risk

Location: Virtual (Global)    Fees: 5000

Service Type: Service Offered

Developing policy-grade white papers on Ethical AI Governance, AI risk management, and digital trust for regulators, boards, and senior executives.

My work translates complex regulatory, ethical, and technological issues into clear, decision-ready documents that inform policy, strategy, and governance frameworks.

Typical engagements include national AI governance frameworks, board-level position papers, regulatory consultation documents, and thought leadership white papers for global platforms.

Respond to this opportunity

Events

2 Online Events
EC-Council CyberTalks

Location: Remote    Date : March 13, 2026 - March 13, 2026     Organizer: EC-Council

The webinar title is Navigating Security in DeFi: Protecting Decentralised Finance Platforms.

See Event

Cloud Security Alliance Security Update Podcast

Location: Remote    Date : January 16, 2026 - January 16, 2026     Organizer: Cloud Security Alliance

An hour recorded podcast hosted by John A DiMaria, CSSBB, AMBCI, HISP, MHISP, CERP, Director of Operations Excellence at Cloud Security Alliance. The topic is how to balance automation with human oversight in cloud security.

See Event

Contact Goutama Bachtiar, MAIB, MBA, FRSA, FFIN, FPT, MAICD, TAISE

Book Goutama Bachtiar, MAIB, MBA, FRSA, FFIN, FPT, MAICD, TAISE for Speaking

Book a Video Meeting

Media Kit

Share Profile

Contact Info

  Profile

Goutama Bachtiar, MAIB, MBA, FRSA, FFIN, FPT, MAICD, TAISE

   Address

Jakarta, Indonesia


Latest Activity

Latest Opportunities

Latest Member Blogs

Upcoming Member Events

Search
How do I climb the Thinkers360 thought leadership leaderboards?
What enterprise services are offered by Thinkers360?
How can I run a B2B Influencer Marketing campaign on Thinkers360?