I will create your risk register and grc documentation

United States

I speak English, Spanish, Yoruba

1 order completed

GRC Analyst

Most GRC documentation sellers write about compliance. I build compliance programs. At the Idowu Ajiri Foundation I designed an active NIST CSF 2.0 program: 9 controls, 11 policies governing US and ...
About this Gig

Your audit window is open. Your documentation is not ready.


An auditor requesting your risk register tests one thing: what you can actually show them. If that document does not exist, or exists as a spreadsheet no one has touched in a year, that conversation ends before fieldwork begins.


I build audit-ready compliance documentation. Not templates. Working documents auditors can test against.


I deliver:

- Risk registers: 5x5 scoring matrix, treatment plans, risk owners, residual risk ratings

- Policy libraries: access control, incident response, change management, vendor management, and more

- Control libraries: mapped to NIST CSF 2.0, ISO 27001:2022, SOC 2, or SOX ITGC with test procedures

- Evidence packages: organized by control area for audit fieldwork


Who orders this: Startups preparing for their first SOC 2 audit. SaaS companies entering enterprise sales. Security teams with controls running but no documentation to prove it.


Before ordering, message me:

- Your compliance state: starting fresh, updating, or audit-prepping

- Your framework: SOC 2, ISO 27001, NIST CSF, or SOX ITGC

- Your audit date if known

- Your organization type: startup, nonprofit, or enterprise

Service type:

Analysis

Language:

English

Delivery style preference

Please inform the freelancer of any preferences or concerns regarding the use of AI tools in the completion and/or delivery of your order.

Academic work to be done for you, is unethical since it violates most schools’ Honor Codes.

Asking sellers to prepare homework/academic works on your behalf is against Fiverr’s Community Standard and may lead to your account being disabled.

My Portfolio