Blackbox

Blackbox — Remote

Automate your business

Free tools to help you identify areas in your business you can automate, measure your AI risk exposure and check your website.

My name is Alison King. I have twenty-five years' experience in turning complex technology into commercial outcomes — across insurance technology, financial systems and regulated delivery. I can support you in assessing and implementing change in your organisation.

I work at the point where commercial intent meets technical reality. I find the opportunity, make it coherent, and lead it into delivery — then increasingly build it myself. The result is judgement grounded in both: a programme leader who ships code, and a product builder who understands margin, risk and adoption.

Open to contract engagements — 12 months, rate on application
Scroll to enter

Digital transformation starts with what you cannot see.

Selected impact

Zero

SOC 2 Type II exceptions

Applied Systems Europe — assurance programme led across five products through both Type I and Type II examinations; each concluded with no exceptions noted

c. £8m

Digital transformation led

Towers Watson — legacy Pension Self-Administration platform technical transformation programme

40+

Cross-functional teams directed

Engineering, operations, actuarial and client-facing functions

$2m

Regulatory programme delivered

American Express — Consumer Credit Directive, to quality, time and budget

Capability

Three disciplines, one person.

Most organisations buy these separately and then pay for the gaps between them. I have been fortunate enough to have had the professional freedom to use my natural curiosity to evolve multiple disciplines. The environments have been complex enough, and carried enough unknowns, that managing delivery alone was never sufficient — every role has demanded analysis alongside it: finding what the plan does not yet account for, rather than delivering with the gaps still hidden. I have worked alongside some brilliant engineers and have acquired knowledge along the way that has enabled me to work on my own technical projects, using AI tooling to expedite them.

01

Analyst

Both halves — the business problem, and the system underneath it.

Requirements are the cheapest place to fix anything. Root cause analysis comes first: take burdensome processes apart, separate the symptom from the cause, and find where change would genuinely create impact. That work runs in two directions at once — commercially, tying every decision back to margin, cost-to-serve, capacity, customer value and risk; and technically, into data, integrations, system design and the test criteria that prove it worked. Analysing one without the other is how programmes ship the wrong thing correctly.

  • Systems analysis
  • Process & data modelling
  • Requirements & test design
  • Technical debt reduction
  • Commercial modelling

02

Programme leader

Twenty-five years of regulated delivery, including the difficult ones.

I have recovered failing services and delivered programmes that had fallen behind. Plans built on assessed risk, with assumptions logged, verified and tracked, and resource measured rather than guessed. Governance models that provide the right amount of gateways to ensure nothing slips through, without becoming overly burdensome. My approach is to keep moving, keep measuring, and judge it on outcomes.

  • Programme recovery
  • Regulated delivery
  • PRINCE2 / AgilePM
  • Governance & assurance
  • Vendor & stakeholder management

03

Builder

Products that solve complex problems.

Full-stack applications built and deployed end to end — Next.js on Vercel, Supabase and PostgreSQL, Stripe, n8n for orchestration, APIs and webhooks across multiple authentication models. I work in agentic AI build, test and fix loops, delivering what used to take a team to build.

  • Next.js / React
  • Supabase / PostgreSQL
  • Vercel
  • n8n
  • Stripe
  • APIs & webhooks
  • Claude Code

The differentiator

AI that can survive an audit.

Most AI delivery fails the second question, not the first. I build governance in from the start, framed around ISO/IEC 42001, the AI management systems standard — human-in-the-loop gateways at the points that matter, security hardening as a default rather than a phase, and a decision trail that stands up when someone asks who approved what, and why. I have taken a control environment through external examination and out the other side: a SOC 2 assurance programme across five products, led from control design through evidence and remediation to auditor engagement, and carried through both Type I and Type II. The Type II matters — it tests whether controls actually operated over a period, not whether they looked right on paper. Each examination concluded with no exceptions noted.

Human-in-the-loop gateways

Automation stops for a person where the consequence justifies it.

Controlled AI operating practice

Skills repositories, reusable instruction sets and managed model context, so AI-assisted delivery is a governed process rather than individual improvisation.

Evidence that survives examination

Control design, evidence collection and auditor engagement run as a programme — proven through SOC 2 Type I and Type II examinations, each completed with no exceptions noted.

Proportionate governance

Controls sized to actual risk, so the framework gets used instead of circumvented.

Security hardening

Authentication, secrets handling and least-privilege access designed in, not retrofitted.

Decision traceability

An auditable record of what the system did, what a human did, and on what basis.

Selected work

Positions held and impact made.

Applied Systems Europe

Oct 2021 — present

Brighton / remote

Senior Project Manager from Sep 2023

Senior Project Manager / Systems Analyst & Programme Lead

  • Works directly with the CEO to identify commercially valuable opportunities, build the case for change and drive it into delivery.
  • Leads the flagship technical transformation of Applied Connect — improving resilience, efficiency, customer value and capacity for future change.
  • Led the SOC 2 assurance programme across five products, through both Type I and Type II examinations — control design and implementation, evidence collection, remediation and external auditor engagement. Each concluded with no exceptions noted.
  • Leads identification and prioritisation of AI opportunities across the portfolio, balancing value, feasibility, adoption and risk against technical debt, manual effort and cost-to-serve.
  • Designs the AI controls the delivery organisation works within — skills repositories and reusable instruction sets, and the management of same-context and centralised models, so AI-assisted delivery is repeatable, reviewable and safe to scale.
  • Partners with insurers, product and engineering to deliver system improvements, challenging low-value work to protect margin and release capacity.

The workApplied Connect

Blackbox

Jun 2025 — present

Concurrent venture

Founder & Product Builder

  • Builds and commercialises secure, AI-enabled applications end to end — architecture, build, payments, hardening and release.
  • Portfolio spans collectables sourcing and pipeline management, food-grade formulation and compliance, personal financial planning and manufacturing operations.
  • Tests every proposition against need, margin, pricing, adoption and scalability before investing further.

The workTiny Land app

Cosaris

Oct 2025 — Sep 2026

Brighton · Fractional

Head of IT & Delivery, and Fractional Adviser for PMO, AI Governance & Innovation

  • Advised the CEO on high-value applications of AI, data and automation, connecting innovation choices to client service and business outcomes.
  • Introduced proportionate AI governance and stronger use of data — improving decision quality, accountability and investment priorities.

Track record

Tiny Land

2017 — 2025

Founder & Director

Identified an unmet need and built food-grade children’s craft products into an end-to-end e-commerce and manufacturing business. Owned P&L, cash flow, website, payments, data-led marketing, manufacturing and team development — then created repeatable operations that scaled beyond the founder.

The workTiny Land appSussex Express

Towers Watson

2011 — 2016

Head of Project Management

Turned around a struggling project-management service, establishing governance, prioritisation and benefits measurement that restored credibility. Led the c. £8m digital transformation of ePA, the online platform through which scheme members administer their own pensions — a full rewrite off ageing web technology onto Django and Python — directing cross-functional teams of 40+.

The workePA platform

American Express

2010 — 2011

Senior Project Manager (contract)

Delivered a $2m Consumer Credit Directive programme across business and legacy systems to agreed quality, timeline and budget. Directed SEPA/PSD workstreams across technology, legal, finance, tax, compliance and operations.

The workThe Consumer Credit (EU Directive) Regulations 2010

The Pensions Regulator

2009 — 2010

Deputy Programme Manager (contract)

Delivered the 2009 Annual Report and Accounts on time — a first for TPR — while strengthening planning and governance. Coordinated procurement and policy work supporting pensions reform with DWP and HMRC, under what was then the Employer Compliance Regime.

The workPensions Act 2008

Select Service Partner

2006 — 2009

Global Project Manager

Delivered a global MI and data-mining programme improving analysis of operational and commercial performance. Personally fixed the SAP feed into the OPAL data warehouse, repairing a failing reporting service, and led a multi-site workforce-scheduling implementation.

Capita Software Services · 2005 — 2006

Redesigned defect management, cutting outstanding logs by 50%; delivered IVR, online payments and Chip-and-PIN implementations.

Lloyds TSB Group IT · 2004 — 2005

Planned scarce skills across a 200-person retail-banking technology function, protecting critical regulatory delivery.

Cornell Properties · 2002 — 2004

Digitised paper-based accounting and records, improving efficiency and query resolution.

Hewden Hire Centres · 2000 — 2002

Ran the nightly UNIX till-polling that pulled trading data in from the depot network, and produced the reporting and success metrics that showed whether it had landed.

Proof of work

Products.

Everything below was specified, built, hardened and released by me. They exist because the fastest way to stay credible about what software can do is to keep shipping it.

AppShip

Live

iOS build submission and validation for solo developers — signing checks, chunked upload and store readiness.

Open the app

ORLY

In build

Multi-tenant operations platform for collectables sourcing and resale — orders, inventory, sourcing and customer service across marketplaces.

Subtext

Live

On-device language analysis with a privacy-first processing model.

Tiny Land

Live

Formulation and licensing app for food-grade craft recipes — 69 colour formulations, with a Pro licence entitling holders to manufacture and sell under their own brand.

Open the app

Qualifications

2026

ISO/IEC 42001 AI Management Systems — Awareness

AIQI · UKAS

Verify

2025

Cyber Security Diploma

Chichester College

2024

AgilePM Foundation

APMG International

Verify

2010

PRINCE2 Practitioner

APMG International

Common questions

What this looks like in practice.

What is ISO/IEC 42001 and why does it matter for AI delivery?

ISO/IEC 42001 is the international management system standard for artificial intelligence. It asks an organisation to show how AI is governed rather than how clever it is: who is accountable, how risk is assessed, where a human must intervene, and what record exists of decisions. It matters because buyers, insurers and regulators increasingly ask the second question — not "does it work?" but "can you show me how it is controlled?" I frame AI delivery around it so that answer already exists.

Can AI-assisted software delivery survive an audit?

Yes, but only if the practice is governed rather than improvised. That means a controlled operating environment — skills repositories and reusable instruction sets so the same work is done the same way, managed model context so behaviour is predictable, human-in-the-loop gateways at the points where consequence justifies them, and a decision trail showing what the system did, what a person did, and on what basis. I led a SOC 2 assurance programme across five products at Applied Systems Europe, from control design through evidence collection and remediation to external auditor engagement, taking it through both Type I and Type II examinations. Type II is the meaningful one: it tests whether the controls actually operated across a period rather than whether they were well designed at a moment. Each concluded with no exceptions noted.

What does an AI governance engagement actually involve?

Usually three things in sequence. First, finding where AI genuinely creates value against technical debt, manual effort and cost-to-serve — and, just as importantly, where it does not. Second, designing controls proportionate to the actual risk, so the framework gets used rather than circumvented. Third, building the evidence trail as the work happens rather than reconstructing it before an audit. The output is capability the organisation keeps, not a document it files.

What kind of engagements are you available for?

Twelve-month contract engagements as a technical programme manager, systems analyst or AI transformation and governance lead, working remotely across the UK. Also fractional advisory work through Blackbox on AI governance, delivery assurance and product build. Rate on application.

Get in touch

Tell me what you are trying to solve.

Available for contract engagements, fractional advisory work and software builds through Blackbox. I reply to everything that is a real enquiry.

Based
Remote

Elsewhere
LinkedIn

Goes straight to my inbox. Not shared, not added to any list. Privacy Policy