A structured approach to governing risk, implementing controls and generating evidence.
My approach combines governance, risk, compliance, information security and technology regulation to turn complex requirements into decisions, controls and verifiable evidence.
I don't start from preconceived solutions. I first understand the organization's context, its risk exposure, its regulatory obligations and its actual level of maturity. From there, I structure the work into four phases.
I analyze the organization, its processes, assets, systems, third parties, responsibilities and applicable regulatory framework. The goal is to determine what must be protected, what obligations exist and where the main areas of exposure are.
I compare the current situation against applicable requirements — ISO 27001, NIS2, DORA, GDPR, AI Act, ISO/IEC 42001 or other relevant frameworks — to identify gaps, risks, dependencies and priorities.
I define policies, responsibilities, controls, procedures, indicators, evidence and oversight mechanisms. The goal is not to produce isolated documentation, but to establish a governance model that can be sustained and demonstrated.
I direct and support the implementation of the agreed measures, prioritizing actions by risk, impact, effort and criticality. The result must integrate into the organization's daily operations and generate sufficient evidence for audits, clients, management or regulators.
The goal is not just to comply with a standard. It's to build an organization capable of demonstrating how it governs its risks.
Representative professional intervention scenarios. They do not correspond to identifiable clients.