Portrait of Shubham Arora

Shubham Arora · Senior GRC Lead, Security Assurance

GRC, engineered.

I built a GRC program from the ground up, then engineered it to run itself. Almost.

How I scaled GRC

Automation first.
Headcount last.

When I started, there was no SOC 2, no policies, no vendor risk assessments and no risk management. I’m still the only person running GRC, so I treated it as an engineering problem: build each process once, then automate it.

Where I startedThe business needed SOC 2. There was no program.

No SOC 2, no policies, no vendor risk assessments, no risk management. Everything on this page started from zero.

What I builtThree frameworks, 119 controls, one platform.

Drata set up from scratch with every integration built myself. SOC 2 and PCI DSS v4 run side by side with no duplicate work, plus an ISO 42001 gap analysis for AI.

What it changedA clean first SOC 2 Type 2. No findings.

Automation cut manual compliance effort by over 60%. That’s how I, still the only person in GRC, run SOC 2, PCI DSS, AI governance, vendor risk, risk management and policy.

01Map once, comply manyOne control set mapped across SOC 2 and PCI DSS, so each control is evidenced once.
02Automate the evidenceEligible controls evidenced and monitored automatically, with failures sent to Slack.
03One front doorEvery vendor request lands in one system, with an AI draft ready before review.
04Write for the readerPolicies rewritten in plain language, with a human approving every change.
05Make risk visibleA top 10 view leadership reads in a minute and owners act on.

The program

Built from the ground up.

Two years building a GRC program from zero, and automating it as it grew.

Clean auditSOC 2 Type 2

First-ever audit, built from zero. No findings.

CompliantPCI DSS v4

SAQ taken from non-compliant to compliant. No stored cardholder data.

AI managementISO 42001

Gaps identified and priorities aligned

Vendors65+

Risk assessments completed.

Policy23

Policies and procedures rewritten.

Controls119

Controls mapped to policies.

Evidence100%

Of eligible controls evidenced and monitored automatically.

Vendor Risk Assessment. Automated.

Every vendor.
One front door.

I built a single front door for vendor risk. Requests come in through Slack or the web, an AI draft is ready before anyone opens it, and approvals run in parallel.

Vendor Management System portfolio view

Live and clickable, on sample data. Approve a gate, rescan a vendor, or ask the AI. Tap to open the live app. It’s built for larger screens. Open full screen ›

RequestSlack or web form
AI assessmentTrust center, docs, DOCX
ManagerConfirms the need
Four reviewsSecurity, Finance, Legal, IT
DrataSynced, monitored, renewed
60%Less time per vendor assessment
42Security requirements across 11 domains
T1–T3Vendor tiers that set review depth
AI assessment brief
Posture map
Ask AI

Risk management

Risk you can see.

I turned the Drata risk register into a view leadership reads in a minute and owners act on.

Risk dashboard overview

The real dashboard, on a sample register. Tap to open the live dashboard. It’s built for larger screens. Open full screen ›

RegisterRisks, owners, treatments in Drata
SnapshotCaptured daily for trends
Executive viewTop 10, severity, untreated
Owner reviewEach owner sets a treatment
Monthly reviewRegister refreshed and signed off
Top 10Enterprise risks, live for leadership
DailySnapshots power the trend lines
MonthlyRegister review and sign-off
Top 10 risks
Controls & monitoring
Owner review

Agentic Policy management. With humans in the loop.

Policies people
actually read.

I rewrote 23 security policies in plain language, using AI agents with people approving every change. Commitments stay in the policy.

Before

“The following requirements shall be adhered to by all staff members of [the company] with respect to the utilization of mobile computing devices in a manner that ensures compliance with organizational security protocols and applicable regulatory frameworks:”

  • “Mobile computing devices must be protected with a password required at the time the device is powered on.”
  • “Wireless encrypted security and access protocols shall be used with all wireless network connections used by devices connecting to [company] environments.”
After
  • Devices must require a passcode or biometric to unlock.
  • Only use encrypted wireless connections when accessing company systems.
01FetchPull every policy from Confluence
02RewriteAgents apply one template and glossary
03TraceEvery sentence logged in a change record
04MapChecked against mapped controls
05AuditCross-policy conflicts flagged
06ApproveSecurity, stakeholders, VP
07PublishLive in Drata for attestation

Nothing gets lost.

From the Cryptography Policy change record. All 15 “should” statements were resolved one by one.

OriginalCallPublished
The same encryption keys should not be used between production and non-production environments.must notProduction and non-production environments must not share encryption keys.
Encryption keys used in production environments should be rotated at least once per year.mustEncryption keys in production must be rotated at least once per year.
Key management should be fully automated.procedureMoved to the Cryptography Procedure as operational guidance.
23Policies rewritten
33Cross-policy flags triaged
748Acknowledgements synced to Drata automatically using a Cron Job

Continuous compliance

Evidence that
collects itself.

I built five pipelines that connect Drata to Coalition, Lattice and CircleCI, cutting manual evidence collection by over 60%. They run on a schedule, with no human intervention needed.

Change management

Every production change evidenced, with approvals.

100% of changes
Policy acknowledgements

Signed policies flow into Drata automatically.

Continuous
Security training

Completion tracked from a service account.

Continuous
Access provisioning

New-hire access tied to helpdesk tickets.

Daily check
Performance reviews

Annual review completion verified per employee.

Annual
Privacy requests

Inbox monitored. Deletion SLAs tracked.

Daily
Vulnerability reports

Pulled from the scanner on schedule.

Automatic
Control failures

A failing check sends a Slack alert.

Real time

AI governance

Ready for AI.

I wrote the framework for how the company adopts AI, and built the vendor checks to back it up.

01AI risk management frameworkSign-off
02ISO 42001 gap analysisDone
03AIMS requirements registerDone
04AI regulatory landscape mapDone
05TPRM policy with AI controlsDone
06AI checks in every vendor reviewLive

The journey

Two years, step by step.

  1. SOC 2 kickoffGap assessment and roadmap
  2. Policies into DrataTemplate and policy lifecycle
  3. Risk programRegister, annual risk assessment
  4. GRC platform liveDrata go-live, control owners assigned
  5. AI vendor reportsAssessment reports drafted by AI
  6. PCI DSS gap assessmentData flows, training, deliverables
  7. Tier 1 & 2 vendors assessedEvery critical vendor reviewed
  8. Risk dashboardTop 10 risks for leadership
  9. Vendor management systemIntake to offboarding
  10. Control monitoringFailures send a Slack alert
  11. SOC 2 policy refreshApproved and published
  12. Posture scanningEvery vendor graded weekly

What’s next

Agentic GRC.

Next, I’m making the program check itself.

About me

13 years in risk and audit.

I started out writing code, then spent six years at Deloitte leading SOX, SOC 1, SOC 2 and NIST work before running GRC in-house. I’m also the author of three bestselling books, which is why my policies read the way they do.