Governance, Risk, and Compliance Projects

AI Governance, Information Security, and Data Protection — ISO 42001, ISO 27001, ISO 27701, GDPR, NIST AI RMF

Projects

Selected GRC work showcasing compliance and risk.

ISO 27001

Developed risk assessments and controls.

GDPR Compliance Policies

GDPR-compliant policies, data maps, and supporting documentation aligned to regulatory requirements.

NIST Framework Project

Applied the NIST Cybersecurity Framework to assess risks, document control gaps, and support risk-based decision-making.

Education & Certifications

Completed professional training in governance, risk, and compliance, including GDPR, NIST, and compliance program fundamentals.

Experience Overview

Focused on GRC roles, I have contributed to ISO/IEC 27001 audits, GDPR compliance checks, and NIST framework implementations.

Skills

Key Competencies
  • Governance, Risk & Compliance (GRC)

  • AI Governance

  • Risk assessments and risk register management

  • Compliance documentation and control design

  • Regulatory compliance (GDPR, ISO/IEC 27001, ISO/IEC 27701& PCI DSS)

  • Policy and procedure development

  • Third-party and vendor risk management

  • Data protection and privacy governance

A professional workspace featuring compliance documents, a laptop displaying risk assessment charts, and certification certificates on the wall.
A professional workspace featuring compliance documents, a laptop displaying risk assessment charts, and certification certificates on the wall.

Technical & Compliance Skills

  • GDPR compliance (DPIAs, RoPA, DSARs, breach response)

  • ISO/IEC 27001:2022 Implementation and documentation

  • ISO/IEC 27701:2025 Implementation and documentation

  • PCI DSS compliance documentation

  • Risk treatment planning and mitigation tracking

  • Compliance frameworks and control checklists

  • Audit preparation and evidence collection

Tools & Working Methods

  • Microsoft Word and PDF documentation

  • Microsoft Excel and Google Sheets for risk registers and tracking

  • Structured compliance and policy templates

  • Documentation aligned with ISO/IEC 27001 and NIST Cybersecurity Framework (CSF)

About Martin Searle

Entry-level GRC and Compliance Analyst with practical experience across ISO/IEC 27001, GDPR, PCI DSS, and privacy frameworks gained through structured projects, training, and real-world business scenarios. Focused on risk assessments, policy development, compliance documentation, and helping organisations strengthen governance and regulatory compliance.

70+ Professional Certificates & Training Achievements

30+ Hands-On GRC Projects

  • AI Governance: ISO/IEC 42001 AI Management System build, EU AI Act risk-tier classification, NIST AI RMF applied assessment

  • ISO 27001: Risk assessments, control mapping, Statement of Applicability (SoA), internal audit preparation

  • ISO 27701: PIMS extension, Controller/Processor determination, Records of Processing Activities (RoPA)

  • GDPR: Data subject rights procedure, breach response plan, data protection assessments

  • NIST CSF / NIST AI RMF: Cybersecurity and AI framework mapping and gap assessments

  • Third-Party Risk: Vendor assessments and due diligence exercises

  • Information Security: Policy reviews and security governance activities

Covering Governance, Risk & Compliance (GRC), ISO standards, GDPR, cybersecurity, information security, privacy, and emerging technologies. Includes training from Skillsoft, GRC Mastery, Mastermind Assurance, and NCFE.

Contact

A clean, minimal desk setup with a laptop and a notepad, symbolizing professional communication.
A clean, minimal desk setup with a laptop and a notepad, symbolizing professional communication.

Reach out to discuss governance, risk, or compliance opportunities.

© 2026 Martin Searle.All Rights Reserved. Certain graphics on this website were created using AI tools. References to the NIST Cybersecurity Framework (CSF) are provided for informational purposes only and do not imply endorsement by NIST or the U.S. Government.

© 2025. All rights reserved.