Kuala Lumpur · Open for remote

Governance systems built to move from requirement to decision.

Technology Risk and AI Governance proof of work across control assurance, third-party risk, customer security diligence, AI risk, privacy processor governance and executive reporting.

AI GovernanceTechnology RiskGRCTPRMControl AssuranceRegTech
01Evidence-first

Observed public evidence, unavailable public evidence and reference implementations stay explicitly separated.

02Decision-oriented

Registers resolve into accountable outcomes: approve, remediate, accept, escalate or reject.

03Audit-shaped

Controls connect to owners, evidence cadence, tests, exceptions, remediation and retest state.

Proof of work · 01–10

Ten governance systems, one operating language.

Filter by domain, search by framework or capability, then open any system for its objective, evidence, architecture and source artifact.

10 systems visible

Signature operating model

Traceability is the interface.

Every system is structured so a reviewer can follow the decision lineage without guessing how a policy statement became an operational control.

01Requirement

Regulation, framework criterion, buyer question or internal obligation.

02Control

Named behavior with scope, owner, frequency and expected state.

03Evidence

Artifact or record that demonstrates the control operated.

04Exception

Gap, ambiguity, overdue item or failed test requiring action.

05Residual risk

Risk that remains after treatment, with appetite and ownership.

06Decision

Approve, remediate, accept, escalate or reject with accountability.

Downloadable evidence

Inspect the artifacts behind the interface.

The website is a presentation layer. The workbook, binder, resume and project source documents remain directly accessible.

Direct conversation

Need governance that can survive scrutiny?

Open to remote opportunities across Technology Risk, GRC, TPRM, AI Governance, AI Risk & Compliance, control assurance and adjacent RegTech work.