- Developed risk treatments and controls by analysing recurring trends and interdependencies.
- Led QSRA and QCRA workshops, providing P50 and P80 values to support scope and funding decisions.
- Drove the end-to-end risk and control self-assessment process and monitored control effectiveness.
Governance, risk & compliance
Turning complex risk into clear, practical action.
I am Ifeanyi Udokwu, a risk and compliance professional with experience spanning enterprise risk, cybersecurity frameworks, project delivery, privacy and control assurance.
Profile
Risk-led thinking, grounded in delivery.
My background brings together project management, governance, risk, compliance and IT services. I help teams identify uncertainty, strengthen controls and keep delivery aligned with business objectives.
I have worked with stakeholders across utilities, rail, finance, healthcare and oil & gas, supporting risk decisions, assurance activity, policy development and practical remediation.
- Utilities
- Rail
- Finance
- Healthcare
- Oil & gas
Experience
A career across risk, compliance and delivery.
Selected responsibilities and outcomes from the supplied CV.
- Conducted risk assessments and compliance audits across ISO 27001, PCI DSS, GDPR and NIST CSF.
- Implemented third-party risk processes and developed remediation plans to improve audit readiness.
- Supported DPIAs, DSARs, security awareness training and internal control reviews.
- Conducted PCI DSS gap analyses, risk assessments and security audits.
- Supported cardholder-data security, incident documentation and cybersecurity training.
- Delivered a care progression programme within budget and stakeholder requirements.
- Developed PMO processes and led early planning across scope, constraints, risks and deliverables.
- Tracked schedules, monitored subcontractor activity and maintained RAID and daily activity logs.
- Prepared weekly and monthly project progress reports.
- Used process simulation software to assess production methods and support improvements.
- Assessed safety and environmental issues and supported compliance with health and safety legislation.
Skills
Frameworks, tools and working practices.
Capabilities listed in the supplied CV.
Governance & compliance
- NIST CSF
- ISO 27001
- PCI DSS
- GDPR
- COBIT
- Audit preparation
Risk & control
- ISO 31000
- ISO 27005
- NIST 800-30
- RCSA
- Third-party risk
- Business continuity
Tools & analysis
- Archer
- OneTrust
- ServiceNow GRC
- ARM
- Predict
- @Risk
- Primavera Risk Analysis
Project delivery
- PRINCE2
- Microsoft Project
- Jira
- Primavera P6
- Workshop facilitation
- Stakeholder management
Selected work & learning
Where experience meets continued development.
A concise view of established practice and current professional focus.
Enterprise risk & controls
Experience developing risk treatments, facilitating quantitative risk workshops and managing risk and control self-assessments.
Security, privacy & assurance
Practical work across security frameworks, compliance audits, data protection impact assessments and third-party risk.
Digital & AI risk focus
Developing a focus on how established governance, risk and compliance methods can support accountable digital and AI use.
Professional development
Qualifications and current learning
- International Certificate in Enterprise Risk Management
- ISO 27001 Lead Implementer
- PRINCE2 Foundation
- NEBOSH General Health & Safety
- Value Management Foundation Course
- Digital Risk Management Certificate — in progress
Contact