Skip to main content
Back to case files

FinRisk-GRC

FinRisk-GRC project preview

Problem

A simulated AWS-hosted fintech SaaS platform needed a structured risk assessment covering cloud, vendor, access, privacy, and insider risk — with treatments traceable to recognized frameworks rather than an unstructured list of concerns, and defensible under PCI DSS and India's DPDP Act.

Approach

Ran a NIST SP 800-30 risk assessment across the environment, producing a 14-risk register scored on a 5×5 likelihood/impact matrix. Mapped each risk's treatment to ISO 27001:2022 Annex A controls and NIST CSF 2.0 functions, evaluating control effectiveness and residual risk, and formalized mitigate, accept, and transfer decisions as risk acceptance records.

Stack

  • NIST SP 800-30
  • ISO 27001:2022 Annex A
  • NIST CSF 2.0
  • PCI DSS
  • DPDP Act
  • 5×5 Risk Matrix
  • Risk Register

Outcome

Turns a fintech environment's scattered risk concerns into a 14-entry risk register with scored severity, mapped controls, and documented accept/mitigate/transfer decisions — a defensible, audit-ready GRC artifact instead of ad hoc notes.

View on GitHub