Services
GRC consulting for regulated and critical sectors.
AI governance
- ISO/IEC 42001 AI management systems, from gap assessment to implementation
- AI governance assessments against the NIST AI Risk Management Framework
Regulatory compliance
- Mapping which standards and regulations apply to the business
- Gap assessments and adequacy to sector requirements
- Policies, controls and ongoing compliance monitoring
Third-party risk
- TPRM program design: forms, assessment templates and workflows
- Vendor risk assessments at scale, with consolidated reporting and remediation plans
Privacy
- Data Protection Officer as a formal role (LGPD)
- Privacy programs: data mapping, DPIAs, RoPA and data subject requests
Information security
- ISMS and ISO/IEC 27001 alignment, with documentation end to end
- OT/IT and operational risk assessments with prioritized remediation
Risk quantification
- Cyber risk quantification with FAIR (Factor Analysis of Information Risk)
Get in touch
Reach me on LinkedIn. Tell me the problem and roughly when you need it solved. That is enough to start.
The full record: Full curriculum.