Governance, Risk and Compliance Expertise — Jonas Osman Abdelfour
Integrated GRC frameworks that connect strategy, risk appetite, controls, accountability and regulatory expectations into a single decision-making system.
Governance, risk and compliance is most valuable when it is structured as one framework rather than as three parallel administrative functions. Jonas Osman Abdelfour designs and assesses GRC frameworks so that risk ownership, control design, compliance monitoring and executive reporting reinforce each other — and connect to how capital, conduct and strategy are actually managed.
Why integrated GRC matters
Fragmented GRC produces overlapping obligations registers, duplicated controls, and management information that neither the board nor regulators can trust. An integrated framework anchors everything to a common risk taxonomy, a defined risk appetite, and clearly assigned accountabilities under the three-lines model.
What this work covers
A representative — not exhaustive — set of areas addressed in engagements of this type.
- GRC framework design
- Governance structures and accountability
- Three-lines model implementation
- Risk ownership and RACI
- Policy and control frameworks
- Risk and control self-assessments (RCSAs)
- Compliance risk assessments
- Regulatory obligations registers
- Control testing methodology
- Compliance monitoring plans
- Issue and action management
- Risk reporting and management information
- Board and committee governance
- Regulatory change management
- Operational resilience integration
- Third-party risk management
- Conduct risk oversight
- Risk culture assessment
How it operates in practice
Engagements typically begin with a diagnostic of the current framework: taxonomy, appetite statements, RCSA quality, control libraries, monitoring plans, issue backlogs and the flow of management information to executive and board committees.
From that baseline, target-state design focuses on where the framework is expected to make decisions: escalation thresholds, control ownership, dependencies on data quality, and the interface with internal audit and the second line. The goal is a framework that reduces surprise, sharpens accountability and gives the board a defensible view of the firm's risk profile.
Documentation, terms of reference and reporting packs are calibrated to the size and complexity of the institution. Proportionality is central: controls exist to mitigate specific risks, not to be layered defensively.
Related insights
All insights →- Governance & GRCHow to design an effective GRC framework
A practical model for integrating governance, risk and compliance around a common taxonomy, appetite and reporting architecture.
- Governance & GRCCommon failures in governance structures
Where board and committee governance most often breaks down — and how to design out the common failure modes.
- Governance & GRCRisk ownership and accountability under the three-lines model
Practical guidance on assigning risk ownership so that the three-lines model produces accountability rather than paperwork.
- Governance & GRCWhat good board risk reporting looks like
Design principles for board risk reporting that focuses committees on decisions rather than description.