Regulation, framework criterion, buyer question or internal obligation.
Kuala Lumpur · Open for remote
Governance systems built to move from requirement to decision.
Technology Risk and AI Governance proof of work across control assurance, third-party risk, customer security diligence, AI risk, privacy processor governance and executive reporting.
Observed public evidence, unavailable public evidence and reference implementations stay explicitly separated.
Registers resolve into accountable outcomes: approve, remediate, accept, escalate or reject.
Controls connect to owners, evidence cadence, tests, exceptions, remediation and retest state.
Proof of work · 01–10
Ten governance systems, one operating language.
Filter by domain, search by framework or capability, then open any system for its objective, evidence, architecture and source artifact.
Signature operating model
Traceability is the interface.
Every system is structured so a reviewer can follow the decision lineage without guessing how a policy statement became an operational control.
Named behavior with scope, owner, frequency and expected state.
Artifact or record that demonstrates the control operated.
Gap, ambiguity, overdue item or failed test requiring action.
Risk that remains after treatment, with appetite and ownership.
Approve, remediate, accept, escalate or reject with accountability.
Downloadable evidence
Inspect the artifacts behind the interface.
The website is a presentation layer. The workbook, binder, resume and project source documents remain directly accessible.
Populated registers and operational tables supporting the project systems.
Download workbook → PDFProduction portfolio binderLong-form portfolio evidence and project documentation.
Open binder → DOCXResumeTechnology Risk, AI Governance, GRC, security compliance and TPRM positioning.
Download resume → MDSource registerReference register for the public sources used throughout the evidence portfolio.
Open register →Direct conversation
Need governance that can survive scrutiny?
Open to remote opportunities across Technology Risk, GRC, TPRM, AI Governance, AI Risk & Compliance, control assurance and adjacent RegTech work.