Specializing in:
enterprise trust

Turning compliance claims into verifiable evidence.

Technology GRC & AI Governance Analyst specializing in NIST AI RMF, ISO 27001, and SOC 2 alignment. Building audit-ready evidence packages, automated control mapping, and vendor risk frameworks.

Impact DashboardActive

10

governance systems built

15

AI use cases mapped

25

buyer questions standardized

24h

trust snapshot scope

01 / Flagship proof-of-work

One trust system. Three operational layers.

The flagship combines customer assurance, third-party risk and AI governance so a buyer can move from public claim → evidence → residual risk → action without changing tools or vocabulary.

Integrated modules

Module 01 · Customer assurance

Security Control & Evidence Map

A buyer-facing control model that converts broad trust claims into owners, evidence, framework mappings and reviewable remediation decisions.

15

Evidence domains

SOC 2 + ISO

Primary lenses

Traceable

Evidence state

Evidence preview
Simulated portfolio data
DomainBuyer questionEvidencePriority
AccessHow is privileged access controlled?RBAC · MFA · access reviewHigh
EncryptionIs customer data encrypted?TLS · storage · KMS evidenceHigh
IncidentHow are incidents escalated?IR plan · exercise · notice flowHigh
AssuranceWhat audit evidence exists?SOC scope · ISO certificateHigh
Evidence owner
Review date
Framework crosswalk
Buyer impact
Remediation owner

02 / 10 production-grade systems

A portfolio built like an operating model.

Every project answers a real GRC question: what is the risk, what control addresses it, what evidence proves it, who owns it, and what decision comes next?

Filter

03 / Capability matrix

No progress bars. Evidence instead.

Capability is shown through implementation context and a concrete artifact—not a fabricated proficiency percentage.

Technology GRC

GRC & Compliance

Risk, controls, evidence, ownership and remediation workflows.

Evidence · 10-system portfolio

SOC 2

GRC & Compliance

Trust Services Criteria mapped to operational controls and audit evidence.

Evidence · 15-domain control inventory

ISO/IEC 27001

GRC & Compliance

ISMS control architecture, risk treatment and evidence mapping.

Evidence · Control-to-evidence system

Security Questionnaires

GRC & Compliance

Canonical buyer answers with evidence links, owners and review dates.

Evidence · 25-question knowledge base

Control Testing

GRC & Compliance

Population/sample thinking, expected result, exception and retest workflow.

Evidence · Audit operations system

NIST AI RMF

AI Governance

Govern, Map, Measure and Manage applied to operational AI use cases.

Evidence · 15-system AI register

EU AI Act Article 50

AI Governance

Provider/deployer transparency analysis for interactive and synthetic content.

Evidence · 15-use-case register

ISO/IEC 42001

AI Governance

AI management-system governance integrated with risk/evidence workflows.

Evidence · AI Governance OS

AI Risk Registers

AI Governance

Use-case, stakeholder, oversight, testing and residual-risk mapping.

Evidence · AI Governance OS

Shadow AI Governance

AI Governance

Prompt DLP, approved channels, redaction and unsanctioned-use controls.

Evidence · 12-control DLP standard

Third-Party Risk

TPRM & Risk

Criticality tiering, evidence review, findings and treatment decisions.

Evidence · 10-vendor TPRM register

GDPR Article 28

TPRM & Risk

Processor contracts, subprocessors, assistance, deletion and audit rights.

Evidence · 12-clause control set

Vendor Questionnaires

TPRM & Risk

Evidence requests spanning assurance, IAM, crypto, privacy and AI providers.

Evidence · 20-question vendor assessment

Executive Risk

TPRM & Risk

Likelihood, impact, residual risk, appetite, treatment, KRI and escalation.

Evidence · 15-risk executive register

TypeScript / React

Developer Tools & CS Core

Typed component systems and interactive frontend architecture.

Evidence · This portfolio

Next.js App Router

Developer Tools & CS Core

Static-first App Router site with SEO metadata and accessible interactions.

Evidence · This portfolio

Git / GitHub

Developer Tools & CS Core

Version control, repository documentation and CI workflow.

Evidence · Portfolio repository

Python

Developer Tools & CS Core

Data transformation and artifact-generation workflows.

Evidence · GRC evidence workbooks

Data Structures & Algorithms

Developer Tools & CS Core

Computer Science foundations supporting technical risk analysis.

Evidence · BSc Computer Science

Databases / SQL

Developer Tools & CS Core

Data modeling and query fundamentals for control/evidence systems.

Evidence · BSc Computer Science

04 / Trajectory

Fast-track proof, without pretending tenure.

The positioning is deliberately analyst-level: technical enough to be useful immediately, conservative enough to withstand an experienced GRC manager's questions.

2026 · Now

Independent Technology GRC & AI Governance proof-of-work

Built ten operational governance systems spanning customer assurance, AI governance, TPRM, SOC 2/ISO evidence, executive risk, Article 50 transparency, shadow AI, Article 28 and audit operations.

GRCTPRMAI Governance

Aug 2026

Article 50 transparency moved from future readiness to live operations

Mapped interactive and generative AI use cases to the European Commission's Article 50 transparency guidance while keeping legal applicability distinct from generic framework alignment.

EU AI ActNIST AI RMF

2026

Published buyer-facing trust readiness case studies

Produced source-backed public trust assessments that separate observed evidence, public evidence not identified and matters requiring internal verification instead of making unsupported compliance conclusions.

Customer AssuranceEvidence

Current

BSc (Hons) Computer Science · SEGi University

Building the technical foundation behind technology risk work: software engineering, algorithms, databases, systems and disciplined problem solving.

Computer ScienceMalaysia

03 / Framework Coverage Matrix

Standards mapped to practical proof.

Every compliance framework is backed by concrete control mapping, evidence registers, and risk treatment plans—not theoretical compliance claims.

Primary source alignment:NIST AI RMF 1.0, ISO/IEC 27001:2022, and SOC 2 Trust Services Criteria
Updated for 2026 Standards

05 / Hire · Contract · Collaborate

Turn trust friction into evidence.

Open to Technology GRC, Security Compliance, TPRM, Technology Risk and AI Governance roles—and tightly scoped B2B trust-readiness work.

Start a conversation

Micro-offer

24-Hour AI & Security Public Trust Readiness Snapshot

15-point evidence review · buyer-question register · third-party/AI risk observations · five prioritized documentation actions.

Fixed founding-client scope$99