Map an organisation's GRC landscape
Scenario
NimbusStack is a ₹200 cr Indian SaaS company (500 employees, HQ Hyderabad, remote-first). They serve BFSI + healthcare customers in India + UAE + Singapore. They have never had a formal GRC programme. The CEO just hired you. On Day 1 you're handed: no policies, no risk register, no compliance calendar. You have the ERP admin, the InfoSec lead (1 person), and a founder-CTO who ships fast. Board is asking for a 'GRC maturity assessment' in 30 days.
Your role
You are the newly appointed Head of GRC at NimbusStack.
Your task
Produce a one-page GRC Landscape Map that identifies: 1. All regulatory obligations that apply (Indian + international) 2. Stakeholders + accountability RACI (top 5 roles) 3. Top 5 governance decisions needed in the first 90 days 4. Recommended reporting cadence to the CEO and Board
Deliverable format: Markdown document, ~400-800 words, with a RACI table
Toolkit
- Regulatory list: DPDPA (India), SOC 2 (US customers), PCI DSS (if payments), GDPR (EU exposure via APAC customers?), ISO 27001 (customer contracts require it)
- RACI template: Rows = decisions/tasks; Columns = CEO, CTO, CISO, GRC Head, Legal
- Board reporting frequency benchmarks: quarterly GRC summary, monthly risk dashboard
Success criteria (what the AI grades against)
- All 5-7 relevant regulations correctly identified (missing DPDPA = fail)
- RACI has clear Accountable + Responsible split (not the same person)
- First-90-day decisions include: hire a DPO or vCISO, adopt a framework, run a baseline risk assessment
- Board cadence proposed with quarterly + one exception-based trigger
- Practical Indian context (mentions DPDP Board, CERT-In 6-hour rule)
Log in to submit your deliverable for AI review.
Log in / Register