GRC and Information Security, based in Dubai, UAE
AI Governance · ISO 42001 · EU AI Act · NIST AI RMF · Open-source GRC toolkits
I'm Ankit, a GRC and information security professional based in Dubai, UAE, working in this field since 2017. Most of the job is working out what an organisation's real risks actually are, and then building something that addresses them.
Right now I'm GRC Lead at PureHealth Group, covering SEHA, Daman, SSMC, SKMC, SEHA Clinic, Rafeed and Riayati, against 6,800+ controls. The result I'd point to is KPI breach rates coming down from 40% to 3%, which was mostly process redesign and a lot of conversations with people who had good reasons to be sceptical.
Before this I worked at Oman Arab Bank, Equifax, Deloitte and PwC, across banking regulation, fintech audit and consulting.
Lately most of my attention is on AI governance. ISO 42001 has been published since 2023 and the EU AI Act timeline keeps moving, but the harder problem is that very few organisations have a workable path from the text of either standard to something a team can actually run. That gap is what I work on, in my day job and in the open-source toolkits below.
| Period | Role | Where | What I did |
|---|---|---|---|
| 2025 to present | GRC Lead | PureHealth Group, Abu Dhabi | Risk assessments and compliance across SEHA, Daman, SSMC, SKMC, SEHA Clinic, Rafeed and Riayati, run through RSA Archer; KPI breach rates from 40% down to 3%; project delivery up 35% |
| 2024 to 2025 | IT Assurance & Compliance Manager | Oman Arab Bank, Muscat | Built audit tracking dashboards; closed 60% of aging high-risk findings; reported to the CTO, CISO and Board |
| 2024 | Information Security Manager | Equifax, Bangalore | Drove ISO 42001 readiness alongside ISO 27001 and RBI audit readiness in four months; embedded Gemini in the control workflow, cutting documentation effort by 30% |
| 2022 to 2024 | Deputy Manager | Deloitte, Bangalore | Led SOC 2 (Telenor Norway), ISO 27001, ISO 22301, ITGC and NIST audits end to end; supervised four senior consultants |
| 2021 to 2022 | Assistant Manager | PwC, Bangalore | Risk and controls across oil and gas, fintech, retail, e-commerce and automotive |
Earlier, 2017 to 2021: Control Case International (InfoSec Consultant), Sikraft Infotech (ISO IMS Auditor), RSM International (Sr. Officer, Operations Consulting), Merieux NutriSciences (Technical Auditor).
A free browser-based assessment that maps AI exposure across ISO 42001, the EU AI Act, NIST AI RMF and 15+ other frameworks, with regulator-level detail for the UAE, EU, India, Singapore and three more jurisdictions. Twelve risk domains, about four minutes, no signup, nothing leaves your browser.
Three more live tools sit on my portfolio rather than here: the AI Governance Hub (ISO 42001, NIST AI RMF and the EU AI Act cross-mapped clause by clause), the UAE AI GRC platform (one control library across 8 UAE and international frameworks), and the AI Model Card Whiteboard. See them on ankituniyalprofile.com →
Each one pairs templates with something you can run.
| Repository | Area | What's inside |
|---|---|---|
| iso-42001-ai-governance-toolkit | AI management systems | Gap assessment, risk register, controls mapping, Python script that checks assessment currency across an AI inventory |
| eu-ai-act-compliance-toolkit | EU AI Act | Risk classification, conformity assessment checklist, FRIA template, technical documentation, incident reporting |
| shadow-ai-scanner | Shadow AI discovery | Endpoint-local inventory of AI tools, agents, extensions and credentials, with risk-scored GRC-ready reports |
| iso-27001-isms-toolkit | Information security | Gap assessment, risk register, SoA covering all 93 Annex A controls, implementation roadmap |
| iso-27701-pims-toolkit | Privacy | ISO 27701:2025 edition, DPIA, TIA, privacy by default, joint controller guidance |
| iso-27017-27018-cloud-security-toolkit | Cloud security | Cloud risk register, SoA with extended controls, PII protection in public clouds |
| grc-automation-toolkit | GRC operations | Policy management, control testing, evidence collection, asset inventory, access reviews, vendor risk |
| ServiceNow-IRM-Toolkit | Tooling | Modules, workflows, GlideRecord scripts and audit queries for ServiceNow IRM |
| DORA-Implementation-Toolkit | Financial services | Digital operational resilience implementation material |
| UAE-AI-Compliance-Guide | UAE banking and fintech | CBUAE Responsible AI Guidance Note, CBUAE Model Management Standards, UAE AI Charter |
| AI-Risk-Program-UAE-Europe | Programme design | Governance, policies, risk taxonomy, assessment methodology, vendor management, controls |
Most AI governance material is written by lawyers and regulators, for lawyers and regulators. The people who actually build and deploy AI systems are rarely the intended audience, and it shows when you hand them a framework and ask them to comply with it.
So I try to pair every policy template with something executable: a checklist that can be run, a script that automates part of the monitoring, a decision tree that returns an answer instead of more questions. That is what GRC engineering means to me. Policy meets code.
A fair amount of what is in these repos is a first attempt, and this is not the only reasonable way to approach it. Corrections and pull requests are welcome.
Frameworks: ISO 27001 · ISO 42001 · ISO 27701 · ISO 27017/27018 · ISO 22301 · EU AI Act · NIST CSF 2.0 · NIST AI RMF · SOC 2 · PCI DSS · GDPR · COBIT 2019 · NCA ECC · DORA · CBUAE Responsible AI
Tools: RSA Archer · ServiceNow GRC · OneTrust · Power BI · Python · Excel
Certifications: CISA · CRISC · CISM · AAISM · ISO 27001 Lead Auditor
If you are working on AI governance, standing up a GRC programme, or trying to work out what the EU AI Act actually requires of your organisation, feel free to reach out. Happy to compare notes, and just as happy to be told where I have got something wrong.
📧 [email protected] | 🌍 Dubai, UAE 🇦🇪 | LinkedIn | Portfolio


