Methodology

From regulatory obligation to verifiable control.

A structured approach to governing risk, implementing controls and generating evidence.

My approach combines governance, risk, compliance, information security and technology regulation to turn complex requirements into decisions, controls and verifiable evidence.

I don't start from preconceived solutions. I first understand the organization's context, its risk exposure, its regulatory obligations and its actual level of maturity. From there, I structure the work into four phases.

01

Discover — Understand the context

I analyze the organization, its processes, assets, systems, third parties, responsibilities and applicable regulatory framework. The goal is to determine what must be protected, what obligations exist and where the main areas of exposure are.

02

Assess — Evaluate risks and gaps

I compare the current situation against applicable requirements — ISO 27001, NIS2, DORA, GDPR, AI Act, ISO/IEC 42001 or other relevant frameworks — to identify gaps, risks, dependencies and priorities.

03

Govern — Design the control model

I define policies, responsibilities, controls, procedures, indicators, evidence and oversight mechanisms. The goal is not to produce isolated documentation, but to establish a governance model that can be sustained and demonstrated.

04

Implement — Put it into operation

I direct and support the implementation of the agreed measures, prioritizing actions by risk, impact, effort and criticality. The result must integrate into the organization's daily operations and generate sufficient evidence for audits, clients, management or regulators.

The goal is not just to comply with a standard. It's to build an organization capable of demonstrating how it governs its risks.

Guiding principles
Risk-based · Evidence-driven · Regulatory-aligned · Business-oriented
Typical deliverables
Gap Assessment Risk Matrix Remediation Roadmap Controls Matrix Policies and Procedures RACI Evidence Register KPIs/KRIs Audit Plan Executive Report
Intervention Scenarios

How the methodology translates into real business situations.

Representative professional intervention scenarios. They do not correspond to identifiable clients.

Fintech
Gaps against DORA · Regulatory exposure and operational risk
Gap assessment, ICT risk management framework, continuity, incident management and third parties
Prioritized DORA compliance roadmap
Technology company
AI systems without a formal governance framework · Regulatory exposure and lack of traceability
System inventory and classification · AI Act + ISO/IEC 42001 gap assessment · Policies, roles, controls and evidence register
AI governance roadmap and readiness for a management system aligned with ISO/IEC 42001
Law firm
Confidential information and insufficient security controls · Exposure in data protection and risk of security incidents
Risk assessment · ISMS based on ISO/IEC 27001:2022 · security controls and privacy alignment
Implementation roadmap and readiness for ISO/IEC 27001 audit