top of page
Shola Hassan, MBA, CISM

Cybersecurity, Privacy & AI Governance

I help organizations reduce cyber and compliance risk while supporting secure business growth.

CISM · ISO 27001 LA · ISO 27701 LA · ISO 42001 LA · CySA+ · Security+

Available for GRC, security governance and advisory opportunities

Cybersecurity & GRC

Governance frameworks, control mapping, and audit readiness across ISO 27001, SOC 2 and PCI DSS.

Privacy Governance

Privacy management-system readiness aligned to ISO 27701, built around real data flows, not just policy.

AI Governance

Practical AI risk and governance readiness aligned to ISO 42001 — beyond a one-page AI use policy.

Vendor risk assessment, criticality tiering, and due-diligence life cycles (including ServiceNow TPRM).

Third-Party Risk

Vendor risk assessment, criticality tiering, and due-diligence life cycles (including ServiceNow TPRM).

Assurance & Audit Readiness

Evidence coordination and control alignment to get organizations audit-ready, not just policy-ready.

Professional Networking Platform - GRC & Compliance Review

Regulatory Compliance Program Build - Digital Health Technology Company

Global Retailer – Third-Party Risk Management

Vulnerability Risk Intelligence & Compliance Assurance

ISO 27001

ISO 27701

ISO 42001

Integrated governance across information security, privacy and AI risk

Headshot-Shola-Hassan
I'm Shola Hassan, a Calgary-based cybersecurity GRC and risk professional with an MBA and CISM certification. My work spans information security governance, privacy management, third-party risk, and AI governance — helping organizations align controls to ISO 27001, ISO 27701, ISO 42001, SOC 2, and PCI DSS. I bring an auditor's rigor as a Lead Auditor across all three of those management-system standards, translating technical risk into decisions business leaders can act on.

Hiring?

View Professional Résumé

Need GRC support?

Discuss an Engagement
bottom of page