Q&A: Insights from The Savvy CIO Podcast with Dr. Plumb of IBM

0
As organizations rush to implement AI, many CIOs are grappling with a difficult question: How can you innovate with AI while remaining compliant, secure and audit-ready?

Few people are better positioned to answer that question than Dr. Radha Plumb, Vice President of AI-First Transformation at IBM and former Chief Digital and Artificial Intelligence Officer at the U.S. Department of Defense. In July 2026, Dr. Plumb was the guest on the first episode of The Savvy CIO podcast from Park Place Technologies. Her timely comments on AI governance, risk management, auditability and what CIOs need to do today to prepare for an AI-powered future are summarized below in this Q&A from her conversation with host Bradd Busick.

Busick: Tell us about your background and what led you to AI transformation.

Dr. Radha Plumb: I’m actually an economist by training—though not the kind most people think of. My background is in applied econometrics, which was essentially “big data” before we called it that. Throughout my career, I’ve focused on understanding how organizations use data to make meaningful decisions.

That foundation carried through roles in government and industry, and it’s why I’m so interested in AI today. At its core, much of the AI conversation is really a conversation about data—how we manage it, govern it and use it responsibly to drive outcomes.

Busick: You’ve worked across academia, Big Tech, government and now IBM. What’s the common challenge you’ve seen across large organizations?

Dr. Plumb: It usually comes down to understanding risk.

Organizations often say they can’t move forward because something feels risky—whether it’s a security concern, compliance issue or auditability challenge. The key is breaking that risk down into something tangible.

Ask: What is the actual risk? What mitigations are available? Who owns the risk? Is the trade-off worth it?

When risk remains vague and undefined, progress stalls. But once you clearly identify and assign ownership of the risk, organizations can make informed decisions and move forward.

Busick: Many leaders see governance as something that slows innovation. Is that the wrong mindset?

Dr. Plumb: Absolutely. I often use the analogy that better brakes make faster trains. Trains were able to move faster because braking systems improved. AI governance works the same way.

Governance isn’t about slowing innovation—it’s about ensuring AI systems are doing what you want them to do and avoiding what you don’t want them to do. When governance is built into the process from the start, organizations can move faster with greater confidence.

Busick: Why are large language models (LLMs) so challenging from an audit perspective?

Dr. Plumb: Traditional systems produce deterministic outcomes. You provide structured inputs, apply known logic and receive predictable results.

LLMs work differently. They combine massive amounts of data and context with inferential reasoning, creating outputs that may not be fully predictable.

The value of LLMs is their ability to generate novel insights and connections. The challenge is that you can’t always clearly trace every step that led to a specific output. Organizations need to be deliberate about where they use generative AI versus deterministic systems. The future isn’t all LLMs. It’s about combining both approaches through an orchestration layer that delivers the right balance of creativity and predictability.

Busick: What’s the first compliance challenge CIOs should address when adopting AI?

Dr. Plumb: The first question auditors will ask is straightforward: Who has access to what data? Role-based access controls, identity management, and data governance remain foundational. But what’s new is what happens after data enters the AI ecosystem.

Organizations need what I call an orchestration layer—or an AI operating system—that determines how information flows between various models, workflows, reports, dashboards and business functions.

Every company will need to define its own approach. Financial data, for example, should be governed differently than branding guidelines. The orchestration strategy needs to reflect business priorities and risk tolerance.

Busick: Where do most organizations struggle with AI governance today?

Dr. Plumb: The biggest challenge sits at the intersection of technology and process. There’s a belief that AI can fix poorly designed or overly complicated processes. It can’t. Organizations first need to define how work should happen. Then they can determine where AI fits and how technology supports those processes.

At IBM, we’ve worked on agentic workflows in finance that compare budget forecasts to actuals. The technology can identify deviations, but the business still needs to define which deviations matter. That’s a business decision, not a technology decision. Successful AI deployments require business processes and technology controls to work together.

Busick: How should organizations think about data governance versus model governance?

Dr. Plumb: They are related but distinct. Data governance focuses on access controls, metadata, authoritative systems and data quality. That’s the foundation. Model governance starts after the data reaches the AI system. It involves understanding:

  • What data the model is accessing
  • How the model is performing
  • Whether bias is emerging
  • How outputs are generated
  • How the model behaves over time

The challenge is that we don’t yet have universally accepted methods for evaluating LLMs. Because of that, transparency becomes critically important. Organizations need visibility into how models operate and where inference is happening so they can better understand outcomes and identify potential problems.

Busick: Are organizations prepared when auditors ask how their AI systems are governed?

Dr. Plumb: Some are, but many still have work to do. For highly regulated decisions, organizations should be able to clearly identify the bounded data sources a model can access. That’s a strong starting point. They should also implement governance tools that provide transparency into model behavior, data access patterns and decision-making processes.

Agentic workflows require another layer of visibility. Organizations should be able to explain:

  • Which actions an agent can take
  • What triggers those actions
  • What thresholds govern decisions
  • That level of transparency will satisfy many audit requirements. However, there are still some decisions that simply should not be fully automated. Human oversight remains essential in certain highly regulated areas.

Busick: Is it possible to achieve both speed and security with AI?

Dr. Plumb: Not only is it possible, it’s necessary. The key is shifting security conversations to the beginning of the process. At IBM, my first conversations about any AI initiative are with our CISO and security teams. If security requirements aren’t considered from day one, deployment becomes much harder later.

Security by design creates a positive flywheel:

Security by design → Compliant outcomes → Faster deployments → More innovation

Organizations that embed security early can move faster than those that treat it as a final checkpoint.

Busick: What’s the most important thing CIOs should do right now to prepare for an AI-driven future?

Dr. Plumb: Understand your workflows. Many leaders think the answer will be a new technology platform. In reality, the biggest opportunity is understanding how work gets done across the organization.

At IBM, we’ve mapped our business into enterprise workflows and activity sets. That provides a framework for evaluating where AI can create value. When new AI capabilities emerge, we can quickly identify where they fit, bring together the right stakeholders, and test them in real business scenarios. The upfront work of documenting workflows may feel tedious, but it dramatically accelerates AI adoption later.

According to Dr. Plumb, the organizations that succeed with AI won’t be those that deploy the fastest. They’ll be the ones that build the right controls, governance frameworks, and workflows to scale AI responsibly.

To learn more about The Savvy CIO podcast from Park Place Technologies, visit the website here.

Related News:

IBM and AMD Partner with Zyphra on Next-Gen AI Infrastructure

CoreWeave and IBM Partner to Launch AI Supercomputer for Granite Models

Share.

About Author

A former IT administrator, Olivia is a passionate student of technology innovation with a particular enthusiasm for pioneering IoT, AI and security products and strategies. Olivia is also an avid cyclist and a closet artist.