Expertise

Governance, Risk and Compliance Expertise — Jonas Osman Abdelfour

Integrated GRC frameworks that connect strategy, risk appetite, controls, accountability and regulatory expectations into a single decision-making system.

Governance, risk and compliance is most valuable when it is structured as one framework rather than as three parallel administrative functions. Jonas Osman Abdelfour designs and assesses GRC frameworks so that risk ownership, control design, compliance monitoring and executive reporting reinforce each other — and connect to how capital, conduct and strategy are actually managed.

Why integrated GRC matters

Fragmented GRC produces overlapping obligations registers, duplicated controls, and management information that neither the board nor regulators can trust. An integrated framework anchors everything to a common risk taxonomy, a defined risk appetite, and clearly assigned accountabilities under the three-lines model.

What this work covers

A representative — not exhaustive — set of areas addressed in engagements of this type.

  • GRC framework design
  • Governance structures and accountability
  • Three-lines model implementation
  • Risk ownership and RACI
  • Policy and control frameworks
  • Risk and control self-assessments (RCSAs)
  • Compliance risk assessments
  • Regulatory obligations registers
  • Control testing methodology
  • Compliance monitoring plans
  • Issue and action management
  • Risk reporting and management information
  • Board and committee governance
  • Regulatory change management
  • Operational resilience integration
  • Third-party risk management
  • Conduct risk oversight
  • Risk culture assessment

How it operates in practice

Engagements typically begin with a diagnostic of the current framework: taxonomy, appetite statements, RCSA quality, control libraries, monitoring plans, issue backlogs and the flow of management information to executive and board committees.

From that baseline, target-state design focuses on where the framework is expected to make decisions: escalation thresholds, control ownership, dependencies on data quality, and the interface with internal audit and the second line. The goal is a framework that reduces surprise, sharpens accountability and gives the board a defensible view of the firm's risk profile.

Documentation, terms of reference and reporting packs are calibrated to the size and complexity of the institution. Proportionality is central: controls exist to mitigate specific risks, not to be layered defensively.

Related insights

All insights →