Focused on:
enterprise trust

I build the evidence behind technology trust.

Computer Science undergraduate focused on Technology GRC, third-party risk, security compliance and AI governance. I turn framework requirements into inspectable risk registers, control maps, questionnaires and evidence workflows—without presenting portfolio work as prior client tenure or certification.

Proof-of-work snapshotInspectable

10

proof-of-work systems

15

AI use cases mapped

25

buyer questions mapped

10

vendors assessed

01 / Flagship proof-of-work

One operating model. Three governance problems.

This portfolio simulation connects customer assurance, third-party risk and AI governance through the same decision chain: requirement → evidence → risk → owner → next action.

Integrated modules

Module 01 · Customer assurance

Security Control & Evidence Map

A portfolio model showing how broad trust claims can be decomposed into owners, evidence, framework references and reviewable remediation decisions.

15

Evidence domains

SOC 2 + ISO

Primary lenses

Traceable

Evidence state

Evidence preview
Portfolio simulation · not client data
DomainBuyer questionEvidencePriority
AccessHow is privileged access controlled?RBAC · MFA · access reviewHigh
EncryptionIs customer data encrypted?TLS · storage · KMS evidenceHigh
IncidentHow are incidents escalated?IR plan · exercise · notice flowHigh
AssuranceWhat audit evidence exists?SOC scope · ISO certificateHigh
Evidence owner
Review date
Framework crosswalk
Buyer impact
Remediation owner

02 / 10 inspectable systems

Proof that can be opened, questioned and reviewed.

Each project turns a real governance problem into a concrete artifact: risk, control, evidence, owner and decision. The work is independent proof-of-work, not a claim of prior client delivery.

Filter

03 / Capability matrix

Evidence over adjectives.

Every capability is paired with the artifact or implementation context where I applied it, so a reviewer can inspect the work instead of trusting a self-rated percentage.

Technology GRC

GRC & Compliance

Risk, controls, evidence, ownership and remediation workflows.

Evidence · 10-system portfolio

SOC 2

GRC & Compliance

Trust Services Criteria mapped to operational controls and audit evidence.

Evidence · 15-domain control inventory

ISO/IEC 27001

GRC & Compliance

ISMS control architecture, risk treatment and evidence mapping.

Evidence · Control-to-evidence system

Security Questionnaires

GRC & Compliance

Canonical buyer answers with evidence links, owners and review dates.

Evidence · 25-question knowledge base

Control Testing

GRC & Compliance

Population/sample thinking, expected result, exception and retest workflow.

Evidence · Audit operations system

NIST AI RMF

AI Governance

Govern, Map, Measure and Manage applied to operational AI use cases.

Evidence · 15-system AI register

EU AI Act Article 50

AI Governance

Provider/deployer transparency analysis for interactive and synthetic content.

Evidence · 15-use-case register

ISO/IEC 42001

AI Governance

AI management-system governance integrated with risk/evidence workflows.

Evidence · AI Governance OS

AI Risk Registers

AI Governance

Use-case, stakeholder, oversight, testing and residual-risk mapping.

Evidence · AI Governance OS

Shadow AI Governance

AI Governance

Prompt DLP, approved channels, redaction and unsanctioned-use controls.

Evidence · 12-control DLP standard

Third-Party Risk

TPRM & Risk

Criticality tiering, evidence review, findings and treatment decisions.

Evidence · 10-vendor TPRM register

GDPR Article 28

TPRM & Risk

Processor contracts, subprocessors, assistance, deletion and audit rights.

Evidence · 12-clause control set

Vendor Questionnaires

TPRM & Risk

Evidence requests spanning assurance, IAM, crypto, privacy and AI providers.

Evidence · 20-question vendor assessment

Executive Risk

TPRM & Risk

Likelihood, impact, residual risk, appetite, treatment, KRI and escalation.

Evidence · 15-risk executive register

TypeScript / React

Developer Tools & CS Core

Typed component systems and interactive frontend architecture.

Evidence · This portfolio

Next.js App Router

Developer Tools & CS Core

Static-first App Router site with SEO metadata and accessible interactions.

Evidence · This portfolio

Git / GitHub

Developer Tools & CS Core

Version control, repository documentation and CI workflow.

Evidence · Portfolio repository

Python

Developer Tools & CS Core

Data transformation and artifact-generation workflows.

Evidence · GRC evidence workbooks

Data Structures & Algorithms

Developer Tools & CS Core

Computer Science foundations supporting technical risk analysis.

Evidence · BSc Computer Science

Databases / SQL

Developer Tools & CS Core

Data modeling and query fundamentals for control/evidence systems.

Evidence · BSc Computer Science

04 / About & trajectory

Early-career by tenure. Evidence-led by design.

I am a Computer Science undergraduate targeting analyst-level Technology GRC, TPRM, Security Compliance and AI Governance work. The portfolio is intentionally explicit about what is simulated, what comes from public evidence, and what would require internal verification.

2026 · Now

Independent Technology GRC & AI Governance proof-of-work

Built ten inspectable proof-of-work systems spanning customer assurance, AI governance, TPRM, SOC 2/ISO evidence, executive risk, Article 50 transparency, shadow AI, Article 28 and audit operations.

GRCTPRMAI Governance

Aug 2026

Article 50 transparency moved from future readiness to live operations

Mapped interactive and generative AI use cases to the European Commission's Article 50 transparency guidance while keeping legal applicability distinct from generic framework alignment.

EU AI ActNIST AI RMF

2026

Published buyer-facing trust readiness case studies

Produced source-backed public trust assessments that separate observed evidence, public evidence not identified and matters requiring internal verification instead of making unsupported compliance conclusions.

Customer AssuranceEvidence

Current

BSc (Hons) Computer Science · SEGi University

Building the technical foundation behind technology risk work: software engineering, algorithms, databases, systems and disciplined problem solving.

Computer ScienceMalaysia

05 / Framework references

Applied with scope. Never presented as certification.

These standards and regulations structure the portfolio work. They are references for analysis—not audit opinions, legal determinations, certifications or proof of prior program ownership.

Primary-source links are provided so reviewers can inspect the framework basis directly.
Scope disclosed
AI risk management
Applied in portfolio

NIST AI RMF 1.0

Voluntary AI risk-management framework used to structure Govern, Map, Measure and Manage activities across the AI proof-of-work.

Portfolio application

GovernMapMeasureManage
Information security
Referenced, not certified

ISO/IEC 27001:2022

ISMS requirements used as a reference for risk treatment, control ownership and evidence mapping. This portfolio does not claim ISO certification.

Portfolio application

ISMS contextRisk treatmentAnnex A reference
SOC 2 criteria
Criteria referenced

AICPA Trust Services Criteria

Trust Services Criteria for security, availability, processing integrity, confidentiality and privacy used to structure control-and-evidence examples.

Portfolio application

Common criteriaLogical accessChange management
AI transparency
Live from 2 Aug 2026

EU AI Act · Article 50

Transparency duties for certain interactive and synthetic AI systems, used here for provider/deployer applicability and disclosure decision examples.

Portfolio application

Interaction disclosureContent markingDeployer notice
Processor governance
Contract controls referenced

GDPR · Article 28

Processor and subprocessor requirements used to structure DPA evidence, assistance, deletion/return and audit-right questions in the TPRM work.

Portfolio application

Documented instructionsSubprocessorsAudit & deletion
AI management system
Referenced, not certified

ISO/IEC 42001:2023

AI management-system requirements and guidance used as a reference for governance, accountability and continual-improvement concepts.

Portfolio application

AI policyAccountabilityContinual improvement

06 / Hiring conversation

Need an analyst who makes risk work inspectable?

I am open to Technology GRC, Security Compliance, Third-Party Risk, Technology Risk and AI Governance opportunities. The fastest way to evaluate fit is simple: review the evidence, scan the resume, then email me with the role and problem you need solved.

Best-fit conversation

Analyst-level Technology GRC & AI Governance

GRC · TPRM · security compliance · AI governance

Kuala Lumpur, Malaysia · open to remote opportunities

Independent proof-of-work available for direct review