Ramya Amballa
Thirteen years across PwC, Wells Fargo, JPMorgan Chase and Viatris, now advising boards and regulators on AI and technology governance.
Ramya Amballa built her governance judgment inside enterprise technology risk, cyber risk, GRC, third-party risk and audit readiness functions, the disciplines she now applies to AI governance for boards, CISOs and government steering committees.
Where This Judgment Comes From
Ramya Amballa spent thirteen years inside the governance, risk and audit functions of PwC, Wells Fargo, JPMorgan Chase and Viatris, running enterprise technology risk, cyber risk, GRC, third-party risk and audit readiness programmes across banking, professional services and life sciences. At JPMorgan Chase, that meant global KYC and sanctions operations across multiple jurisdictions. At Wells Fargo and Viatris, it meant third-party risk governance for hundreds of vendor relationships, through the part of the relationship most programmes stop watching once onboarding is signed off. At PwC, it meant testing controls across 300+ business-critical applications and cutting residual risk exposure by 35% in a single programme.
AI governance turned out to be the same discipline wearing a faster clock. The organisations asking for it were rarely short of frameworks. What they lacked was what those thirteen years had actually been about: a named owner for every decision, evidence maintained as a matter of course rather than assembled after an incident, and controls tested against what a system does in production, not what a policy says it should do.
AI governance is not a separate discipline. It is governance, applied to a new generation of decisions.
It fails for the same reasons governance has always failed: assumed ownership, retrospective evidence, and controls nobody tested against how the system actually behaves.
Why OPERA Exists
OPERA is what came out of applying that judgment consistently. It sequences five decisions, from the opportunity behind a governance requirement to the assurance evidence that outlasts it, developed from running this kind of programme inside four different regulated environments before it had a name.
- O
Opportunity
Approved use case
- Use case intake
- Business objectives
- Stakeholder identification
- P
People
Named ownership
- Ownership assignment
- Accountability model
- Governance roles
- E
Evaluation
Risk visibility
- Risk assessment
- Control analysis
- Regulatory mapping
- R
Response
Controlled deployment
- Decision process
- Documentation
- Evidence generation
- A
Assurance
Audit-ready assurance
- Monitoring
- Metrics
- Governance review
Background
Certifications: NIST AI RMF, CAISR, EU GDPR Practitioner, Microsoft AI Transformation Leader
Sectors: Government & Public Sector, Energy & Critical Infrastructure, Financial Services, Enterprise SaaS
Experience
AI for U&I · Independent Advisor
Feb 2026 – Present
PwC India · Cyber Security Consultant, Governance
Aug 2024 – Feb 2026
Viatris · Deputy Manager, Global Compliance
Aug 2023 – Feb 2024
Wells Fargo · Operational Risk Consultant, TPRM
Mar 2020 – Jul 2023
JPMorgan Chase · Team Lead, Operations
Aug 2017 – Mar 2020
How Engagements Work
- Starts with a working conversation about a specific problem, not a scoping questionnaire
- Run using the OPERA methodology, scaled to what the organisation needs rather than applied wholesale
- Sized to fit: a focused advisory engagement, an operating model redesign, or a longer programme
- Ends with something the organisation owns and can run without outside help: an operating model, not a report that sits on a shelf
She does not take on work where the goal is a compliance document rather than a governance structure people will actually use, or where accountability cannot be clearly assigned inside the organisation.
Discuss a governance challenge
Most engagements begin with a working conversation about a specific problem, not a formal proposal.