22-Day GRC Practical Simulation
Every day: a real scenario, a real deliverable, real critique. This is the hands-on companion to Srida IT’s flagship 22-Day GRC Program — you produce the artefacts a working GRC professional produces in the first 22 days on the job, and get an AI-partner review against the criteria a Srida partner would apply.
Programme structure
Week 1
Days 1-4
Governance, Risk & Compliance Foundations
Week 2
Days 5-9
ISMS · ISO 27001 build-out
Week 3
Days 10-14
PCI DSS scoping + implementation
Week 4
Days 15-18
ITGC · SOX + SOC 2 audit readiness
Week 5
Days 19-22
DPDPA implementation + Capstone
Every day, one deliverable
Map an organisation's GRC landscape
NimbusStack is a ₹200 cr Indian SaaS company (500 employees, HQ Hyderabad, remote-first).
Build a risk register from 12 asset scenarios
You've just completed a rapid asset-discovery workshop at NimbusStack.
Framework mapping — NIST CSF → ISO 27001 → SOC 2
NimbusStack's biggest US customer is asking for SOC 2 Type II.
Design an audit charter for a first-time engagement
Board wants NimbusStack's very first internal audit.
Define ISMS scope + boundary for SwiftLend NBFC
SwiftLend (₹500 cr AUM NBFC, RBI-regulated) has decided to pursue ISO 27001 certification.
Draft the Information Security Policy (ISMS-POL-01)
SwiftLend's Scope Statement (Day 5) has been ratified by the Board.
Risk assessment on 3 information assets
SwiftLend needs a formal ISO 27001-aligned risk assessment.
Select applicable Annex A controls + build the SoA
Based on your Day 7 risk assessment, you must now produce the ISO 27001:2022 Statement of Applicability (SoA).
Plan an ISMS internal audit + build the checklist
SwiftLend's ISMS is now 6 months old.
Scope a PCI DSS assessment — identify the CDE
SwiftLend has just launched a co-branded credit-card product.
Segmentation strategy for a hybrid architecture
You've scoped the CDE (Day 10) at SwiftLend.
Map PCI DSS 12 requirements to your controls
Your QSA has asked you to produce a Requirement Coverage Matrix — showing that every PCI DSS v4.
SAQ selection + evidence collection plan
Based on your scoping (Day 10), SwiftLend qualifies for SAQ A-EP (some page controls exist, PAN not stored server-side).
Draft the Report on Compliance (ROC-lite summary)
You've completed the SAQ (Day 13).
Design an access review checklist (SOX-aligned)
KaizenMotors (auto-parts, mid-size, ₹300 cr revenue, US-listed parent) requires quarterly access reviews for all financial-system users under SOX ITGC.
Change management control test for a SaaS platform
KaizenMotors runs a customer-facing SaaS (parts-catalogue).
Build a segregation-of-duties matrix
KaizenMotors' Finance function has 12 roles: 1.
ITGC evidence pack for SOC 1 audit
KaizenMotors' external auditor arrives in 4 weeks for the annual SOC 1 audit.
DPDPA gap assessment for KaizenMotors
KaizenMotors currently has no DPDPA programme.
Draft privacy notice + consent mechanism
KaizenMotors is launching a customer portal — allowing dealers to check part availability, pricing, warranty status.
DPIA for an AI-based feature
KaizenMotors wants to launch an AI-powered dealer credit-scoring feature.
CAPSTONE — Board presentation on year-1 compliance roadmap
You've spent 22 days on this programme.
Access the daily labs
Full access is included with enrolment in the 22-Day GRC Program or Cohort 2026 candidature. Preview any day’s scenario above — submission & AI review require an active enrolment.