Nabeel Khan
Based in Canada · Central Time
Works across North America and the GCC
Available for AI strategy, governance and architecture consulting
Through iSystematic Inc.
What he is building comes first, because it explains everything else on this page: a founder-led practice converting twenty-five years of enterprise AI architecture and governance expertise into published frameworks, four books, working software, and machine-accessible interfaces that people and AI systems can query directly. The discipline is governed production AI; the commercial shape is expertise-as-a-service; and this site, with its callable corpus, is the working demonstration of both.
Nabeel Khan is an independent AI strategy consultant, enterprise AI architect and AI governance advisor, taking client engagements across North America and the GCC. He has spent twenty-five years putting AI and data systems into production inside institutions that answer to a regulator: government, healthcare, finance and telecoms, across three continents. His practice, published at nabeelkhan.com, sits at a seam most organisations staff separately, where the architecture that deploys a model and the governance that permits it are the same decision taken at different altitudes.
He writes the frameworks he implements. MESA and the Five-Gate Deployment Model on the governance side, PEVG and PARA on the engineering side, all published rather than proprietary, and all extending established standards rather than replacing them. He is the author of four books on governed production AI, all on sale now: the governance playbook in two editions, and the three series hardcovers, with the series ebooks and paperbacks published through September 2026. The delivery record behind the writing includes national census platforms, regulated healthcare AI across 200+ clinics, and production RAG and agentic systems, grounded in TOGAF, DMBOK, ISO 27001 and SOC 2 practice, and informed by a PhD spanning neuro-marketing and computer science. He writes as a practitioner: the frameworks are built to be used, contested, and adapted, not merely read.
The problem the practice answers.
Organisations are deploying AI systems capable of making decisions and taking actions faster than their architecture, governance and expert judgment can keep up. That gap is the problem underneath every engagement on this site, and the working promise against it is a single sentence: AI capability should arrive with accountability built into the architecture. Governance should be architecture, not paperwork; autonomy is a governed capability, not merely a feature; and an AI output should carry the evidence, provenance and caveats needed to defend a consequential decision.
Geographically the practice reads the same way at every altitude: global by architecture, specialised by regulation.
The architecture of the practice.
Listed narrowly rather than broadly. Each of these is somewhere he has either shipped production systems, published a specification, or both. Adjacent things he can hold a conversation about are not on this list, which is the only thing that makes a list like this worth reading.
Nine governance frameworks, four engineering.
Two families sit under Defensible AI and they are kept apart on purpose. Nine governance frameworks fix what the institution owes, catalogued in the Defensible AI Framework Registry. Four engineering constructs fix what the system enforces at runtime, governed by the Pattern Language instead. Thirteen of the thirteen carry a specification with a citable DOI under CC BY 4.0; the other zero are worked out in a named chapter of the published Enterprise Playbook rather than in a standalone document, and that difference is reported here rather than smoothed over. None of it is held as proprietary method, which is deliberate. A governance framework a client cannot read is a dependency, not a capability.