Skip to content
View Ankit-Uniyal's full-sized avatar
:atom:
:atom:

Block or report Ankit-Uniyal

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Ankit-Uniyal/README.md
Typing SVG

LinkedIn Portfolio AI Risk Navigator Email Profile Views


🛡️ About Me

I'm Ankit — a GRC and Information Security professional based in Dubai, UAE. I've spent the last decade helping organisations figure out what their real risks are (not just what looks good on a dashboard), and building systems to actually do something about them.

Right now I'm the GRC Lead at PureHealth Group — the UAE's largest healthcare platform. That means overseeing compliance across 100+ hospitals and 4,000+ controls, which sounds impressive until you're the one responsible for making it actually work. The thing I'm most proud of there is bringing KPI breach rates down from 40% to 3%. That took a lot of persuasion, process redesign, and more than a few late nights.

Before PureHealth, I worked at Oman Arab Bank, Equifax, Deloitte, and PwC. Each was a different challenge — banking regulations, fintech audit, Big 4 consulting. What they had in common was that compliance was often treated as a box-ticking exercise. I've always pushed back on that.

Lately I've been going deep on AI Governance. ISO 42001 just dropped and the EU AI Act is becoming real — and most organisations have no idea how to actually implement either. That's the gap I'm trying to close, both in my day job and through some open-source work here on GitHub.


📊 Career in Brief

Period Role Where What I actually did
2025–Present GRC Lead PureHealth Group, Abu Dhabi Reduced KPI breaches from 40% → 3%; built compliance programme across 100+ SEHA facilities
2024–2025 IT Assurance & Compliance Manager Oman Arab Bank, Muscat Built AI-powered dashboards for audit tracking; resolved 60% of high-risk findings; reported to Board
2024 Information Security Manager Equifax, India Got to ISO 27001/42001/RBI readiness in 4 months; integrated Google Gemini for compliance workflows
2022–2024 Deputy Manager Deloitte, India Led SOC 2, ISO 27001, ISO 22301, NIST audits; managed a team of 4 senior consultants
2021–2022 Assistant Manager PwC, India Covered risk and controls across Oil & Gas, Fintech, and Retail

🚀 What I'm Building

AI Risk Navigator

A free tool for assessing AI risk without needing to read 500-page frameworks first. Four questions, about five minutes, plain-language results. It covers ISO 42001, the EU AI Act, NIST AI RMF, and a few others — and works whether you're a beginner trying to understand what's at risk, or an auditor who needs structured outputs.

Try it here →

ISO 42001 AI Governance Toolkit (this repo)

Practical templates and checklists for implementing ISO 42001 — the new international standard for AI management systems. Gap assessments, risk registers, controls mapping, and a Python automation script that checks assessment currency across your AI inventory.

EU AI Act Compliance Toolkit

Same approach applied to the EU AI Act. Risk classification guide, conformity assessment checklist, FRIA template, technical documentation template, incident reporting procedure — all the stuff you actually need to operationalise the regulation, not just read about it.


🤖 The AI Governance angle

I've been thinking about this for a while: most AI governance frameworks are written by lawyers and regulators for lawyers and regulators. The actual teams building and deploying AI systems — the engineers, the risk managers, the business owners — can't use them.

My view is that governance has to be engineered, not just documented. That's why I pair every policy template with something executable: a checklist you can actually run, a script that automates the monitoring, a decision tree that gives you an answer rather than more questions.

That's what GRC Engineering means to me. Policy meets code.


🧰 Tools & Frameworks I Work With

Frameworks: ISO 27001 · ISO 42001 · EU AI Act · NIST CSF 2.0 · NIST AI RMF · SOC 2 · PCI-DSS · GDPR · NCA ECC · DORA

Tools: ServiceNow GRC · Archer · Power BI · Python (for automation) · Excel (yes, still)

Certifications: CISA · CRISC · CISM (in progress) · ISO 27001 Lead Auditor


📈 GitHub Activity

GitHub Stats Top Languages


💬 Let's talk

If you're working on AI governance, building a GRC programme, or just trying to figure out what the EU AI Act actually requires your organisation to do — feel free to reach out. I'm always happy to compare notes.

📧 ankituniyal619@gmail.com  |  🌍 Dubai, UAE 🇦🇪  |  LinkedIn

Popular repositories Loading

  1. iso-42001-ai-governance-toolkit iso-42001-ai-governance-toolkit Public

    A practical implementation toolkit for ISO/IEC 42001:2023 AI Management Systems — gap assessment checklists, risk register templates, controls mapping, and implementation roadmap for GRC profession…

    Python 2

  2. Ankit-Uniyal Ankit-Uniyal Public

    GitHub profile of Ankit Uniyal — Information Security & GRC Professional | AI Governance | Dubai, UAE

    1

  3. generative-ai-for-beginners generative-ai-for-beginners Public

    Forked from microsoft/generative-ai-for-beginners

    21 Lessons, Get Started Building with Generative AI 🔗 https://microsoft.github.io/generative-ai-for-beginners/

    Jupyter Notebook 1

  4. awesome-security-GRC awesome-security-GRC Public

    Forked from Arudjreis/awesome-security-GRC

    Curated list of resources for security Governance, Risk Management, Compliance and Audit professionals and enthusiasts (if they exist).

    1

  5. awesome-compliance awesome-compliance Public

    Forked from getprobo/awesome-compliance

    A curated list of tools, frameworks, and resources for IT compliance, security standards, and regulatory requirements

    Astro 1

  6. verifywise verifywise Public

    Forked from verifywise-ai/verifywise

    Complete AI governance and LLM Evals platform with support for EU AI Act, ISO 42001, NIST AI RMF and 20+ more AI frameworks and regulations. Join our Discord channel: https://discord.com/invite/d3k…

    TypeScript 1