Most growth-stage technology and infrastructure companies build compliance reactively — a policy drafted after an audit finding, a control implemented after a near-miss, a regulator relationship that only exists because someone had to respond to an inquiry. The result is a compliance function that reports on the past instead of governing the present, and a Board that can't answer a straightforward question: which frameworks are we actually compliant with today, not which ones are on a roadmap.

35+ governance frameworks are already applied in active practice — not studied, deployed — spanning ISO/IEC 42001, NIST AI RMF, ISO 27001, GDPR and DPDP, across 1,100+ asset-owners represented in governance and legal mandates. That GRC depth is paired with hands-on vulnerability analysis experience and multiple global incident mitigations across production products, so compliance reporting is grounded in having actually managed the underlying risk, not just documented it. That GRC depth spans 20+ years across Canada and India, and across legal, technology and compliance domains — a compliance program built by someone who has operated inside all three, not just audited them.

Talk About This Seat →

Usual Responsibilities

RACI Profile

How this role typically sits in a RACI matrix — what it owns, what it's checked against, and who else is in the loop.

Responsible
  • Compliance program design and policy library
  • Regulatory change monitoring
  • Incident investigation oversight
Accountable
  • Overall compliance posture reported to the Board
  • Regulator and auditor relationship
Consulted
  • Legal on contract and litigation exposure
  • Engineering on technical control implementation
Informed
  • Executive leadership and department heads on compliance cadence and findings

Where This Shows Up

Competency Governance Support
Frameworks Frameworks Registry