Home
News
Tech Grid
Interviews
Anecdotes
Think Stack
Press Releases
Articles
  • AI

Token Appoints Former HSBC CISO Monique Shivanandan to Board


Token Appoints Former HSBC CISO Monique Shivanandan to Board
  • by: Business Wire
  • |
  • August 26, 2026

Token, the biometric identity assurance company, today announced the appointment of Monique Shivanandan to its Board of Directors. Shivanandan served as Group Chief Information Security Officer of HSBC and Chief Data and Analytics Officer, where she established the bank's AI execution and governance model.

The appointment comes as Token brings Token for AI Agent Gateways to market, making verified human approval the control point for autonomous AI. One of the world's most senior enterprise security executives joins Token's board at a pivotal moment for enterprise AI governance and identity assurance.

Quick Intel

  • Token appoints former HSBC Group CISO Monique Shivanandan to Board of Directors
  • Shivanandan established AI execution and governance model at HSBC and brings 30+ years of enterprise security leadership
  • Appointment supports launch of Token for AI Agent Gateways for securing autonomous AI actions
  • Token for AI Agent Gateways intercepts agent tool calls and requires live biometric approval for high-consequence actions
  • Platform provides deterministic control outside agent reasoning environment to prevent prompt injection bypass
  • Shivanandan currently serves on board of Iridium Communications and chairs cybersecurity company Sepio Systems

Governance Milestone for Biometric Identity Assurance

The appointment is a governance milestone for Token. Shivanandan brings fiduciary board experience across public and private companies on two continents, including a current seat on the board of Iridium Communications where she serves on the audit and compensation committees, and serves as chair of cybersecurity company Sepio Systems. Her arrival is a measure of how seriously the market now takes biometric identity assurance: the executive who spent five years deciding which controls were strong enough to defend a systemically important global bank has chosen to help direct the company building them.

Beyond HSBC, she served as Group Chief Information Officer at Chubb, Group Chief Information Officer at Aviva, Group Chief Technology Officer and CISO at Capital One, and Chief Information Officer for the UK and Ireland at BT. She established technology innovation centers and funds at Capital One and Aviva, and has advised the CEO and Board of Directors at Aviva, Chubb, and HSBC. She previously served on the Boards of Network International and J.P. Morgan Securities plc and on Fannie Mae's Technology Advisory Board.

Securing Autonomous AI with Deterministic Human Approval

Her appointment comes as enterprises confront the defining security question of the agentic era. AI agents no longer simply answer questions — they send money, delete data, change access rights, and push code to production. A bad answer is a quality problem. A wire transfer is a control problem. Oversight agents and policy guardrails reduce how often an agent reaches a harmful action, but they remain probabilistic.

Token for AI Agent Gateways answers that with a deterministic control. The gate intercepts an agent's tool call before it executes and classifies it — allow, gate, or deny. Low-risk calls pass through untouched at machine speed. High-consequence calls stop until the specific authorized human approves with a live fingerprint on a TokenCore device, bound to that transaction. Because the gate sits outside the agent's reasoning environment, it is not a prompt an agent can be talked past.

It is the only control of its kind: Token re-verifies a specific, physically present human at the moment a high-consequence agent action executes, every time it carries consequence. Every gated action carries the identity of the person who approved it — not a service account, not a shared credential.

"Every enterprise is asking the same question right now: how do we let agents act without letting them act unsupervised," said Kevin Surace, CEO of Token. "More AI watching AI is useful, but it is still an opinion. Biometric assured identity is an outcome. When an action moves money or changes access, the right human has to be physically present and approve it with a fingerprint — and no prompt, no poisoned context, and no stolen credential can route around that. Very few people have seen this problem from both sides the way Monique has. She ran security for one of the largest banks in the world and built its AI governance model at the same time. Having her on our Board says a great deal about where enterprise security is heading."

"I spent years accountable for both the security of a global bank and the governance of its AI, and those two jobs are converging fast," said Shivanandan. "Every Board I sit on is now asking the same thing: what happens when an agent is wrong, or manipulated, and who is accountable for the action it took? You cannot answer that with another model’s opinion. Token for AI Agent Gateways puts a specific, verified human in the transaction path at the moment the consequence occurs, and it leaves an audit trail identifying that person. That is a control a Board can govern and a regulator can examine. That is why I joined this Board."

TokenCore Biometric Identity Assurance Platform

Token's cryptographic biometric identity assurance proves the human, not just the credential. Rather than layering factors onto weak credential foundations, Token binds both access and approval to a verified, physically present person through on-device biometric authentication enforced on secure hardware. The TokenCore product suite — TokenCore Wearable, TokenCore Portable, TokenCore Node, and TokenCore Card — integrates with existing IAM, SSO, and PAM infrastructure. It does not replace the identity stack; it completes it.

Shivanandan's appointment follows a period of rapid expansion for Token, including the launch of Token for AI Agent Gateways, biometric-assured protection for Salesforce access, and the addition of senior leadership across engineering, marketing, and revenue.

 

About Token

Token provides biometric-assured identity solutions for enterprises that need to stop credential theft, phishing, social engineering, and account takeover at the point of access. Token products combine biometric fingerprint verification, secure hardware, FIDO2 and WebAuthn authentication, and wireless ease of use to ensure that only the right person can access critical systems. Token protects workforce access across modern enterprise applications, identity providers, and cloud platforms.

Founded in 2014 and backed by Grand Oaks Capital, Token delivers secure, passwordless authentication solutions that help organizations reduce identity-based risk and strengthen workforce security.

  • AI AgentIdentity AssuranceCybersecurity
News Disclaimer
  • Share