FinRisk-GRC

- NIST SP 800-30
- ISO 27001:2022
- NIST CSF 2.0
- PCI DSS
- DPDP Act
Problem
A simulated AWS-hosted fintech SaaS platform needed a structured risk assessment covering cloud, vendor, access, privacy, and insider risk — with treatments traceable to recognized frameworks rather than an unstructured list of concerns, and defensible under PCI DSS and India's DPDP Act.
Approach
Ran a NIST SP 800-30 risk assessment across the environment, producing a 14-risk register scored on a 5×5 likelihood/impact matrix. Mapped each risk's treatment to ISO 27001:2022 Annex A controls and NIST CSF 2.0 functions, evaluating control effectiveness and residual risk, and formalized mitigate, accept, and transfer decisions as risk acceptance records.
Stack
- NIST SP 800-30
- ISO 27001:2022 Annex A
- NIST CSF 2.0
- PCI DSS
- DPDP Act
- 5×5 Risk Matrix
- Risk Register
Outcome
Turns a fintech environment's scattered risk concerns into a 14-entry risk register with scored severity, mapped controls, and documented accept/mitigate/transfer decisions — a defensible, audit-ready GRC artifact instead of ad hoc notes.