Fractional GRC
A fractional GRC lead builds and runs governance, risk, and compliance programs sized to your team — not scaled down from a Fortune 500 department, but built from the ground up around the frameworks that actually apply to you. I own the program the way an in-house GRC director would, without the overhead of a full department.
What this covers
Third-party / vendor risk management program design
Intake, assessment, and ongoing monitoring that scales with your vendor list.
SOC 2, ISO 27001, NIST 800-53 & NIST CSF control mapping
Building controls that hold up to audit, not just checking a box.
Security questionnaires, SIG assessments & residual risk reporting
Handling the volume without sacrificing quality.
Executive and board-level risk reporting
Translating technical risk into language stakeholders can act on.
Policy, process & procedure development
Documentation that's actually followed, not shelfware.
GRC tooling: ServiceNow VRM, OneTrust, RiskRecon, BitSight
Implementation and ongoing administration.
Who this is for
Organizations that need a real GRC program — not a consultant who writes a report and leaves — but don't have the volume of work to justify a full-time hire. Especially useful ahead of an audit, a customer security review, or when a growing vendor list has outpaced your current process.
Let's talk about governance, risk & compliance
I take on a limited number of clients at a time so every engagement gets real attention. Reach out to discuss scope, cadence, and fit.
Book an introductory call