Shola Hassan, MBA, CISM
Cybersecurity, Privacy & AI Governance
I help organizations reduce cyber and compliance risk while supporting secure business growth.
CISM · ISO 27001 LA · ISO 27701 LA · ISO 42001 LA · CySA+ · Security+
Available for GRC, security governance and advisory opportunities
Cybersecurity & GRC
Governance frameworks, control mapping, and audit readiness across ISO 27001, SOC 2 and PCI DSS.
Privacy Governance
Privacy management-system readiness aligned to ISO 27701, built around real data flows, not just policy.
AI Governance
Practical AI risk and governance readiness aligned to ISO 42001 — beyond a one-page AI use policy.
Vendor risk assessment, criticality tiering, and due-diligence life cycles (including ServiceNow TPRM).
Third-Party Risk
Vendor risk assessment, criticality tiering, and due-diligence life cycles (including ServiceNow TPRM).
Assurance & Audit Readiness
Evidence coordination and control alignment to get organizations audit-ready, not just policy-ready.
ISO 27001
ISO 27701
ISO 42001
Integrated governance across information security, privacy and AI risk

I'm Shola Hassan, a Calgary-based cybersecurity GRC and risk professional with an MBA and CISM certification. My work spans information security governance, privacy management, third-party risk, and AI governance — helping organizations align controls to ISO 27001, ISO 27701, ISO 42001, SOC 2, and PCI DSS. I bring an auditor's rigor as a Lead Auditor across all three of those management-system standards, translating technical risk into decisions business leaders can act on.
Hiring?
Need GRC support?





