ChannelLife New Zealand - Industry insider news for technology resellers
New Zealand
Token appoints former HSBC security chief to board

Token appoints former HSBC security chief to board

Thu, 27th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Token has appointed former HSBC security executive Monique Shivanandan to its Board of Directors as it markets a product aimed at controlling high-risk actions by AI agents.

At HSBC, Shivanandan served as Group Chief Information Security Officer and Chief Data and Analytics Officer. She oversaw security across the bank's global operations and established its AI execution and governance model.

Her appointment adds board-level experience spanning banking, insurance, telecoms and cybersecurity at a time when companies are testing how far autonomous AI systems should be allowed to act without direct human sign-off.

Token is targeting that issue with what it calls AI Agent Gateways. The system is designed to intercept an AI agent's request before it carries out an action, then classify it as allow, gate or deny.

Lower-risk actions can proceed automatically, while higher-consequence actions are halted until an authorised individual approves them with a live fingerprint on a TokenCore device. That approval is tied to both the individual and the specific transaction.

Token argues this approach differs from AI oversight systems that rely on another model or policy layer to review an action. It says those systems remain vulnerable if the same manipulated prompt or poisoned context affects both the original agent and the reviewing system.

Board oversight

The appointment reflects a wider shift in how corporate leaders are approaching AI risk. As AI systems move beyond answering queries and begin handling payments, access controls, data deletion and software changes, questions about accountability are moving from technical teams to boards and audit functions.

Shivanandan brings public and private company board experience in North America and Europe. She sits on the board of Iridium Communications, where she serves on the audit and compensation committees, and is Chair of Sepio Systems.

Her earlier executive roles included Group Chief Information Officer at Chubb, Group Chief Information Officer at Aviva, Group Chief Technology Officer and CISO at Capital One, and Chief Information Officer for the UK and Ireland at BT. She has also served on the boards of Network International and J.P. Morgan Securities plc, and on Fannie Mae's Technology Advisory Board.

Kevin Surace, Chief Executive Officer of Token, said the company is seeing demand from enterprises trying to define where automated decision-making should stop and human responsibility should begin.

"Every enterprise is asking the same question right now: how do we let agents act without letting them act unsupervised," Surace said. "More AI watching AI is useful, but it is still an opinion. Biometric assured identity is an outcome. When an action moves money or changes access, the right human has to be physically present and approve it with a fingerprint - and no prompt, no poisoned context, and no stolen credential can route around that. Very few people have seen this problem from both sides the way Monique has. She ran security for one of the largest banks in the world and built its AI governance model at the same time. Having her on our Board says a great deal about where enterprise security is heading."

Control point

Token's argument is that a verified person, rather than a credential or service account, should be the final control point for sensitive actions. In practice, the company is positioning biometric approval as both an audit and governance tool and an access control mechanism.

Each gated action carries the identity of the person who approved it, creating a record intended to answer a question likely to become more pressing as AI agents are deployed more widely in operational settings: who authorised the action?

Shivanandan said the issue is already reaching boardrooms. "I spent years accountable for both the security of a global bank and the governance of its AI, and those two jobs are converging fast," she said. "Every Board I sit on is now asking the same thing: what happens when an agent is wrong, or manipulated, and who is accountable for the action it took? You cannot answer that with another model's opinion. Token for AI Agent Gateways puts a specific, verified human in the transaction path at the moment the consequence occurs, and it leaves an audit trail identifying that person. That is a control a Board can govern and a regulator can examine. That is why I joined this Board."

Alongside the AI product, Token sells biometric identity tools designed to work with existing identity and access management, single sign-on and privileged access systems. Its TokenCore range includes wearable, portable, node and card-based products that use on-device fingerprint authentication and secure hardware.

The products are intended to sit alongside existing identity infrastructure rather than replace it. That may matter for large organisations seeking added controls over sensitive actions without rebuilding established identity systems.

Shivanandan has spent more than 30 years in technology, security and data leadership roles, advising Chief Executives and boards at Aviva, Chubb and HSBC. She holds a degree in industrial engineering from Lehigh University.