Jonas Adam Mohamed Osman Abdelghafour — Chief Risk Officer, Risk & Compliance Director, Governance and Financial Risk Expert
A consolidated profile of the practice: focus areas, credentials, services and published analysis for boards, risk committees and compliance leaders.
Who he is
Jonas Adam Mohamed Osman Abdelghafour — also published as Jonas Osman Abdelghafour, Yonas Osman Abdelghafour, Jonas Osman and Yonas Osman — is a Chief Risk Officer (CRO), Risk & Compliance Director and governance and financial risk expert working with regulated institutions in banking, insurance and financial services. His practice integrates governance, risk management and regulatory compliance as a single decision-making system at executive and board level.
Focus areas
Governance, risk and compliance framework design; anti-money laundering and financial crime controls; enterprise and operational risk; independent model validation and model risk management; AI governance in regulated decisions; and the quantitative disciplines behind credit, market and liquidity risk. He also supports regulatory change programmes, compliance monitoring, and the design of risk appetite and internal control frameworks.
How he works
Analytical, evidence-based and proportionate. Frameworks are only useful when they change what actually happens in underwriting, onboarding, capital allocation, model deployment and escalation. Deliverables are written to be used by boards and risk committees: focused management information, clearly framed options and recommendations tied to strategy, capital and conduct outcomes.
Background and evidence
Full biography on the about page; credentials and evidenced qualifications on the qualifications page; engagement formats on the services page; and published analysis in insights. Only work that can be substantiated is described on this website.
Current compliance writing
Recent analysis on the live regulatory agenda across financial crime, sanctions, AI governance and compliance operating models.
- Customer due diligence in 2026: what the FCA review signals
- Customer risk methodology in AML
- AI hallucinations as a compliance risk
- Human judgement in AI-assisted compliance
- AI, deepfakes and synthetic identity in AML
- Mobile fraud, deepfakes and fraud-as-a-service
- Fraud and AML convergence
- Sanctions circumvention: ownership, control and trade flows
- Complex corporate structures and beneficial ownership
- AMLA and the EU single rulebook
- FCA crypto authorisation in 2026
- Compliance by design in innovation projects
- The GRC function of 2030: skills and strategic influence
Governance & GRC
- DORA, NIS2 and the UK Regime: One Control Set, Three Rulebooks
Groups operating across the EU and UK face three overlapping operational resilience regimes with different scopes, thresholds and vocabularies. Running them as three programmes is expensive and produces inconsistent evidence.
- The Oversight Framework for Critical ICT Third-Party Providers
DORA does something unprecedented: it gives European supervisors direct oversight powers over technology companies that are not financial institutions. Here is how designation and oversight work, and what it means downstream.
- Designing a DORA Testing Programme That Proves Something
DORA requires a risk-based testing programme covering all critical ICT systems at least annually. Most programmes test what is easy to test rather than what would actually fail.
- The Register of Information: DORA's Hardest Operational Deliverable
Every in-scope entity must maintain a register of all contractual arrangements for ICT services, submitted to its competent authority. Assembling it once is achievable. Keeping it accurate is the real obligation.
- DORA Incident Reporting: Classification, Clocks and the Initial Report
Major ICT-related incidents trigger a three-report sequence against tight deadlines. The hard part is not the reporting — it is deciding, under pressure and without full information, whether the threshold is met.
AML & Financial Crime
- AI and Deepfakes in AML: How Synthetic Identity Changes Customer Verification
Deepfakes and synthetic identity weaken single-signal digital verification and increase the importance of evidence triangulation across identity, device, behaviour and transaction data.
- FCA Crypto Authorisation in 2026: What Compliance Teams Should Prepare Before the Gateway Opens
FCA crypto authorisation requires a coherent operating model connecting permissions, governance, financial crime controls, outsourcing and evidence rather than a policy-heavy application pack.
- Mobile Fraud, Deepfakes and Fraud-as-a-Service: Why Financial Crime Controls Must Converge
Mobile fraud, deepfakes and fraud-as-a-service are collapsing the traditional separation between fraud prevention, AML intelligence and customer protection.
- Customer Due Diligence in 2026: What the FCA Review Signals for Compliance Leaders
The FCA’s 2026 customer due diligence review raises the standard from policy completion to demonstrable control effectiveness across customer risk assessment, onboarding, enhanced due diligence and ongoing monitoring.
- AML and sanctions compliance in marine insurance: what underwriters and risk teams need to know
Maritime sanctions have turned marine insurance into an instrument of economic statecraft. How OFAC guidance, EU packages and the oil price cap reshape underwriting compliance.
CRO & Compliance Leadership
- What the Board Owns Under DORA — and How to Evidence It
DORA places ultimate responsibility for ICT risk on the management body and makes it non-delegable. The obligations are specific, and most of them are evidenced in minutes rather than in policy.
- Who Actually Owns the Model? Professional Roles and Accountability in UK and US Financial Services
Ask five professionals who is accountable when a model fails and you get five incompatible answers. A role-by-role map of model accountability across UK SM&CR and the US collective-responsibility model.
- ICA vs CRMA vs PMI-RMP vs CRM: which risk qualification fits a GRC or AML career
A practitioner comparison of four risk and compliance qualifications — ICA, IIA CRMA, PMI-RMP and The National Alliance CRM — mapped to the roles, evidence expectations and career paths they actually serve in GRC and financial crime.
- What an effective Chief Risk Officer operating model looks like
The structural components of a CRO operating model that produces real second-line challenge without duplicating first-line functions.
- The Risk and Compliance Director's annual governance calendar
A structured annual calendar for a Risk and Compliance Director that anchors framework, appetite, ORSA/ICAAP, EWRA, resilience and supervisory dialogue.
AI Governance
- AI Hallucinations Are Now a Compliance Risk: Governance Lessons for Boards and Control Functions
Generative AI errors become compliance failures when they enter regulated decisions, submissions, investigations, customer communications or board material.
- The AI Rulebook That Isn't: UK Principles vs US Patchwork in Financial Services
Two jurisdictions reached the same place by opposite routes: no AI rulebook for financial services. What the Consumer Duty, SM&CR, SR 26-2 and the NAIC Model Bulletin actually require of AI programmes.
- The EU AI Act for insurers: what it means for pricing, underwriting and model governance
Life and health pricing AI is named high-risk under Annex III. What the deferred timeline changes, and how to fold AI Act duties into model risk management.
- From principle to proof: bias testing in AI underwriting and claims
Regulators no longer ask whether insurers oppose AI bias — they ask for evidence. A layered, defensible bias-testing program for underwriting and claims.
- When AI governance meets cyber defense: the convergence banks can't ignore
NIST's AI cybersecurity profile gives banks one vocabulary for a risk that used to fall between two org charts. One program, not two.