Revenue-sensitive assurance
Turn recurring security and compliance questions into governed, evidence-backed answers designed to keep enterprise diligence moving without unsupported claims.
Md. Abdullah Al Owasi · Technology Risk & AI Governance
I turn security, AI and third-party risk requirements into decision-ready operating systems—controls, evidence, ownership, exceptions, remediation, monitoring and executive risk reporting. The result is governance work designed to withstand scrutiny and help the business move with confidence.
10
governance systems architected
15
AI use cases mapped
25
buyer questions systematized
20
vendor-risk questions designed
Core operating logic
Requirement → control → evidence → exception → residual risk → decision.
01 / Executive value
The portfolio is organized around the business problems a Technology GRC or AI Governance function is expected to solve: move diligence, strengthen assurance, govern AI risk and make third-party decisions defensible.
Turn recurring security and compliance questions into governed, evidence-backed answers designed to keep enterprise diligence moving without unsupported claims.
Connect controls to evidence owners, cadence, test logic, exceptions, remediation and retesting so assurance work has a repeatable operating structure.
Translate AI inventories into accountable risk decisions: purpose, data, human oversight, evaluation, monitoring, residual risk and transparency actions.
Prioritize vendor scrutiny by criticality, evidence quality, data exposure, contractual obligations and residual risk—not questionnaire volume alone.
Decision architecture
02 / Flagship architecture
Customer assurance, third-party risk and AI governance are treated as connected operating problems. Each layer follows the same discipline: requirement → control → evidence → exception → residual risk → decision.
Integrated modules
Layer 01 · Control & evidence architecture
A control-to-evidence architecture that decomposes broad trust claims into accountable owners, reviewable evidence, framework references, exceptions and remediation decisions.
15
Evidence domains
SOC 2 + ISO
Primary lenses
Traceable
Operating model
| Domain | Decision question | Evidence path | Priority |
|---|---|---|---|
| Access | Can privileged access be defended? | RBAC · MFA · access review | High |
| Encryption | Is customer data protected in transit and at rest? | TLS · storage · KMS evidence | High |
| Incident | Can escalation and notification be evidenced? | IR plan · exercise · notice flow | High |
| Assurance | What independent or internal evidence supports the claim? | SOC scope · ISO evidence · control record | High |
03 / Selected decision systems
Ten systems spanning assurance, AI governance, third-party risk, audit operations and executive risk. Each is designed around the same standard: explicit ownership, traceable evidence, visible exceptions and a decision at the end.
04 / Capability architecture
Capability is expressed through systems, artifacts, decision logic and implementation context. The emphasis is on what I can structure, analyze, build and defend in a real risk conversation.
Risk, controls, evidence, ownership, exceptions, remediation and assurance workflows.
Applied in · 10-system operating portfolio
Trust Services Criteria translated into control, evidence, testing and assurance structures.
Applied in · 15-domain control inventory
ISMS control architecture, risk treatment, ownership and evidence mapping.
Applied in · Control-to-evidence architecture
Governed buyer answers with evidence paths, accountable owners and review cadence.
Applied in · 25-question assurance knowledge base
Population/sample logic, expected results, exceptions, remediation and retesting.
Applied in · Audit-operations system
Govern, Map, Measure and Manage applied to enterprise AI inventory and risk decisions.
Applied in · 15-use-case AI governance register
Provider/deployer transparency analysis for interactive and synthetic AI use cases.
Applied in · 15-use-case transparency register
AI management-system concepts integrated with accountability, risk and evidence workflows.
Applied in · AI governance operating architecture
Purpose, data, stakeholder, oversight, evaluation, monitoring and residual-risk mapping.
Applied in · AI governance decision register
Approved channels, prompt classification, secret detection, redaction and unsanctioned-use controls.
Applied in · 12-control governance standard
Criticality tiering, evidence review, contractual risk, findings and treatment decisions.
Applied in · 10-vendor TPRM register
Processor instructions, subprocessors, assistance, deletion, audit rights and evidence requirements.
Applied in · 12-clause processor control set
Evidence requests spanning assurance, IAM, cryptography, privacy, resilience and AI providers.
Applied in · 20-question vendor-risk assessment
Likelihood, impact, residual risk, appetite, treatment, KRI and escalation logic.
Applied in · 15-risk executive register
Data transformation and repeatable artifact-generation workflows for governance and evidence operations.
Applied in · GRC evidence workbooks
Typed interfaces for decision systems, interactive evidence views and portfolio tooling.
Applied in · This portfolio
Static-first web architecture, metadata, accessibility and deployment discipline.
Applied in · This portfolio
Version control, change traceability, repository documentation and delivery workflow.
Applied in · Portfolio repository
Structured thinking for evidence inventories, risk registers, ownership and relational decision data.
Applied in · Computer Science + GRC systems
Technical foundation for decomposing governance problems into inputs, states, dependencies and decision logic.
Applied in · BSc Computer Science + operating portfolio
05 / Operating thesis
My work sits where security, compliance, AI and business risk meet. I design governance structures that make ownership explicit, evidence inspectable, exceptions visible and residual risk useful to decision-makers.
Operating principle
I design governance work so every important claim can be traced to a requirement, control, evidence path, accountable owner, exception state and decision. The objective is not documentation volume; it is decision quality under scrutiny.
Enterprise assurance
Customer diligence, audits and executive risk reporting should draw from the same governed evidence system. That reduces contradiction, clarifies ownership and creates a cleaner path from security claim to business decision.
AI governance
My AI governance work connects inventory, purpose, data, stakeholders, human oversight, evaluation, monitoring, transparency and residual risk so governance produces decisions rather than policy theatre.
Technical foundation
Computer Science strengthens the systems side of my GRC work: data structures, software engineering, databases, automation and disciplined decomposition of complex technical problems.
06 / Framework depth
Framework knowledge matters when it changes how controls are designed, evidence is collected, ownership is assigned, exceptions are handled and decisions are made. These are the primary lenses behind the portfolio architecture.
Govern, Map, Measure and Manage provide the primary risk lifecycle used across the AI inventory, oversight, evaluation and monitoring architecture.
Applied in the architecture
ISMS requirements inform risk treatment, accountable control ownership, evidence structure and the relationship between governance intent and operating proof.
Applied in the architecture
Security, availability, processing integrity, confidentiality and privacy criteria inform control-and-evidence structures used in customer assurance and audit operations.
Applied in the architecture
Provider and deployer transparency obligations are translated into applicability, interaction disclosure, synthetic-content marking and communication decisions for relevant AI use cases.
Applied in the architecture
Processor and subprocessor obligations drive DPA evidence requests, assistance duties, deletion/return controls, audit rights and vendor-governance decision points.
Applied in the architecture
AI management-system concepts inform accountability, impact assessment, governance structure and continual-improvement patterns across the AI operating model.
Applied in the architecture
07 / Hiring conversation
I am targeting high-ownership roles across Technology GRC, Security Compliance, Third-Party Risk, Technology Risk and AI Governance. Send the role and the problem you need solved; the systems, artifacts and reasoning on this site make it easy to evaluate how I would approach the work.
Best-fit mandate
Control-to-evidence architecture · TPRM decisioning · AI risk operations
Kuala Lumpur, Malaysia · open to remote and relocation discussions
Executive portfolio binder, evidence workbook and resume available now