Day 1 of 22Governance, Risk & Compliance· ~45 min

Map an organisation's GRC landscape

Scenario

NimbusStack is a ₹200 cr Indian SaaS company (500 employees, HQ Hyderabad, remote-first). They serve BFSI + healthcare customers in India + UAE + Singapore. They have never had a formal GRC programme. The CEO just hired you. On Day 1 you're handed: no policies, no risk register, no compliance calendar. You have the ERP admin, the InfoSec lead (1 person), and a founder-CTO who ships fast. Board is asking for a 'GRC maturity assessment' in 30 days.

Your role

You are the newly appointed Head of GRC at NimbusStack.

Your task

Produce a one-page GRC Landscape Map that identifies: 1. All regulatory obligations that apply (Indian + international) 2. Stakeholders + accountability RACI (top 5 roles) 3. Top 5 governance decisions needed in the first 90 days 4. Recommended reporting cadence to the CEO and Board

Deliverable format: Markdown document, ~400-800 words, with a RACI table

Toolkit

  • Regulatory list: DPDPA (India), SOC 2 (US customers), PCI DSS (if payments), GDPR (EU exposure via APAC customers?), ISO 27001 (customer contracts require it)
  • RACI template: Rows = decisions/tasks; Columns = CEO, CTO, CISO, GRC Head, Legal
  • Board reporting frequency benchmarks: quarterly GRC summary, monthly risk dashboard

Success criteria (what the AI grades against)

  • All 5-7 relevant regulations correctly identified (missing DPDPA = fail)
  • RACI has clear Accountable + Responsible split (not the same person)
  • First-90-day decisions include: hire a DPO or vCISO, adopt a framework, run a baseline risk assessment
  • Board cadence proposed with quarterly + one exception-based trigger
  • Practical Indian context (mentions DPDP Board, CERT-In 6-hour rule)

Log in to submit your deliverable for AI review.

Log in / Register