Espacio Vodafone

Torre de Control CISO Federada

Entidades que Requieren Escalamiento

52

52 entidades monitorizadas

Repositorios que Impulsan Exposición

202

1194 repos en patrimonio

Acciones Vencidas

31

Hallazgos y exenciones pasadas de fecha comprometida

Sistemas IA sin Gobernanza

29

204 sistemas IA rastreados

Matriz de Exposición por Entidad

Clasificado por exposición primero. Usa esto como superficie de triaje de portfolio, no la lista de entidades.

12 entidades de mayor presión

Escalamientos de esta semana

Decisiones que necesitan el CISO de grupo, no otra ronda de triaje local.

8 decisiones

Escalate VF AI Framework into group remediation review

Assign central engineering support and freeze unapproved production AI changes for 14 days.

Group CISO
VF AI Framework, Vodafone Finance Platforms, Vodafone Ireland2026-03-26

Reduce Azure OpenAI concentration in high-risk systems

Approve a fallback routing pattern and require review of all customer-facing assistants in the top 10 entities.

AI Governance Lead
Customer care and broadband platforms2026-03-29

Recover stale evidence collectors across the worst repo clusters

Prioritize evidence-collector and repo-scanner remediation in Tier 1 release paths before next steering meeting.

Platform Assurance
Group engineering platforms and regional broadband entities2026-03-28

Close overdue temporary waivers on production AI systems

Force renew, close, or replace all overdue exceptions with explicit compensating controls.

Enterprise Security Governance
High-risk AI systems with missing or conditional approval2026-03-31

Mandate SOC 2 Type II for all Vodafone Egypt subprocessors

Require SOC 2 Type II attestation from every third-party subprocessor handling Vodafone Egypt customer data by end of Q2.

Regional CISO Egypt
Egypt + Africa entities2026-04-05

Review Azure OpenAI data residency compliance for EU entities

Audit all Azure OpenAI deployments across EU operating companies to confirm data residency alignment with GDPR and local DPA requirements.

Cloud Governance
12 EU entities using Azure OpenAI2026-03-30

Extend exception waiver for legacy Vodacom billing system

Grant a 90-day extension on the existing production waiver while the billing platform migration completes Phase 2.

Vodacom CISO
Vodacom South Africa, Vodacom Tanzania2026-04-01

Approve updated AI model risk framework for Tier 1 systems

Ratify the revised model risk framework that introduces mandatory red-teaming, bias testing, and drift monitoring for all Tier 1 AI systems.

AI Governance Board
All entities with high-risk AI2026-04-08

Concentración de Riesgo por Repositorio

Clasificado por puntuación de riesgo del repo para que las peores rutas de release aparezcan primero.

RepoEntidadCriticidadPipelineHallazgosUso de IARemediaciónÚltimo escaneo
vf-gr-18/telemetry-troubleshooting-31

Observability and evidence

Vodafone Finance PlatformsTier 1Failing9/2 criticalCustomer-facingBlocked5 days ago
vf-eu-18/telemetry-troubleshooting-13

Observability and evidence

Vodafone Enterprise EuropeTier 1Failing9/2 criticalInternalBlocked6 days ago
Vodafone CRM PlatformsTier 1Failing9/2 criticalCustomer-facingBlocked2 days ago
vf-eu-9/release-gates-1

Customer-impacting release gates

Vodafone Czech RepublicTier 1Failing9/2 criticalNoneBlocked5 days ago
vf-af-1/release-gates-13

Customer-impacting release gates

Vodacom South AfricaTier 1Failing9/2 criticalNoneBlocked8 days ago

Postura de Gobernanza IA

Los sistemas en producción sin aprobación clara deben aparecer antes de que la experimentación con modelos parezca interesante.

SistemaEntidadProveedorRiesgoAprobaciónProcedenciaRepo propietarioRevisión pendiente
Requirements Copilot

Confluence + Jira

Vodafone UKAzure OpenAIHighMissing96%vf-eu-1/ai-framework-12 days ago
Prompt Evaluation Hub

Confluence + GitHub

Vodafone RomaniaMistralHighMissing89%vf-eu-8/billing-core-8in 5 days
Knowledge Retrieval Assistant

Jira + GitHub Actions

Vodafone Turkey PlatformsPerplexityHighMissing82%vf-eu-15/rag-knowledge-15in 12 days
Regression Prioritiser

GitHub + Confluence

Vodacom TanzaniaAzure OpenAIHighMissing75%vf-af-2/speech-service-12 days ago
Fault Triage Assistant

Confluence + Jira

Vodafone M-Pesa PlatformsMistralHighMissing68%vf-af-9/ai-framework-5in 5 days

Mapa de presión de evidencia

Peores clusters de evidencia obsoleta, clasificados por ratio en vez de conteo bruto de repos.

Abrir evidencia

Vodafone Greece

15 repos obsoletos · 15 repos rastreados

100%

Vodafone Digital Engineering

17 repos obsoletos · 18 repos rastreados

94%

Vodafone Carrier Services

13 repos obsoletos · 15 repos rastreados

87%

Vodacom South Africa

15 repos obsoletos · 18 repos rastreados

83%