Max HumphreyFractional CTO, GRC & PMO
Book a call LinkedIn ↗
Services Experience Case Studies Free Assessment Contact LinkedIn Book a call →
← All services
Governance, Risk & Compliance

Fractional GRC

A fractional GRC lead builds and runs governance, risk, and compliance programs sized to your team — not scaled down from a Fortune 500 department, but built from the ground up around the frameworks that actually apply to you. I own the program the way an in-house GRC director would, without the overhead of a full department.

What this covers

Third-party / vendor risk management program design

Intake, assessment, and ongoing monitoring that scales with your vendor list.

SOC 2, ISO 27001, NIST 800-53 & NIST CSF control mapping

Building controls that hold up to audit, not just checking a box.

Security questionnaires, SIG assessments & residual risk reporting

Handling the volume without sacrificing quality.

Executive and board-level risk reporting

Translating technical risk into language stakeholders can act on.

Policy, process & procedure development

Documentation that's actually followed, not shelfware.

GRC tooling: ServiceNow VRM, OneTrust, RiskRecon, BitSight

Implementation and ongoing administration.

Who this is for

Organizations that need a real GRC program — not a consultant who writes a report and leaves — but don't have the volume of work to justify a full-time hire. Especially useful ahead of an audit, a customer security review, or when a growing vendor list has outpaced your current process.

Let's talk about governance, risk & compliance

I take on a limited number of clients at a time so every engagement gets real attention. Reach out to discuss scope, cadence, and fit.

Book an introductory call