I'm a GRC analyst with a track record built in local authority and health sector regulation — now bringing that rigour, controls discipline and stakeholder judgement to financial services.
My career started in local authority governance — chasing statutory deadlines, sitting in audit committees, and translating complex regulation into practical controls for services that couldn't afford to get it wrong. I moved into the health sector to lead risk registers and information governance across multi-site NHS operations, where patient data, safeguarding and CQC scrutiny raised the stakes further.
That grounding — public accountability, statutory reporting, and working under regulators who don't tolerate excuses — is exactly the discipline UK financial services firms need from their GRC function. I'm now applying it directly to FCA/PRA-aligned frameworks, third-party risk, and financial crime controls.
A cross-sector GRC skill set adapted for the demands of regulated financial businesses.
Building and maintaining risk registers, running risk workshops, and translating operational risk into board-ready reporting — honed managing corporate risk across a local authority portfolio.
Monitoring statutory and regulatory change, mapping obligations to controls, and closing compliance gaps — background spans CQC, GDPR, Data Protection Act and safeguarding frameworks.
Designing control frameworks, supporting audit committees, and coordinating internal/external audit responses — the discipline that keeps public sector bodies accountable, applied to financial controls.
Leading information governance projects across sensitive health and citizen data — a direct fit for firms managing financial crime, KYC and customer data risk.
Assessing supplier and contractor risk exposure within public procurement frameworks — directly transferable to outsourcing and vendor due diligence in financial services.
Presenting to audit committees, senior leadership and regulators — clear, evidence-based communication that turns compliance data into decisions.
Real projects, real outcomes — the depth of work behind the transition into financial services GRC.
Redesigned a fragmented risk reporting process into a single corporate risk register, cutting reporting time by 35% and giving the audit committee real-time visibility of top risks.
Led a GDPR compliance remediation across multi-site NHS services, closing 90% of open DPIA actions within two quarters and rebuilding staff training on data handling.
Independent study mapping FCA SYSC and Consumer Duty requirements to a fictional fintech's control environment, producing a gap analysis and remediation roadmap.
Built a standardised third-party risk assessment used across procurement for over 60 contracted suppliers, reducing onboarding risk exceptions by 28%.
Coordinated evidence-gathering and mock inspections ahead of a CQC visit, contributing to an improved 'Good' rating across governance domains.
Applied AML/KYC control-testing methodology to a simulated payments firm, identifying control weaknesses and drafting a remediation action plan.
Practical proficiency across the frameworks and tools most relevant to financial services GRC teams.
Enterprise risk frameworks & assurance
Information security management systems
UK GDPR & Data Protection Act 2018
FCA/PRA regulatory framework
Governance-led project delivery
Sarah brought order to a risk register that had been neglected for years. Her reporting gave our audit committee real confidence for the first time.
Her information governance work was thorough and pragmatic — she understood clinical pressures while still holding the line on compliance.
What stands out is how quickly she's picked up FCA frameworks. Her public sector rigour translates directly into strong financial services controls thinking.
To protect personal and career details, I don't publish my CV for open download. Instead, submit a short request below — I personally review every enquiry and email the full CV directly to approved requesters.
Request referencesThe regulatory discipline, evidence standards and stakeholder scrutiny in local authority and health governance are directly transferable — financial services simply applies that same rigour to a different rulebook (FCA/PRA rather than CQC/DPA). I've spent the last year building targeted knowledge of that rulebook to make the transition credible from day one.
I've focused study and case work on the FCA Handbook (SYSC, Consumer Duty), AML/KYC control testing, and third-party/outsourcing risk — building on existing strength in GDPR, ISO 27001 and control-framework design.
Yes. I'm targeting GRC Analyst, Risk & Compliance Analyst, or Governance Officer roles where my cross-sector experience adds value, while I build financial services domain depth on the job.
My CV contains personal contact details and employer references, so I keep it off public download. Submitting a quick request lets me confirm who's asking and send it directly by email once approved — usually within one business day.
Absolutely — references from both my local authority and NHS roles are available on request, and I'm happy to arrange calls directly with previous line managers.
Yes — I'm flexible on location and open to hybrid or remote arrangements for the right opportunity within UK financial services.
Whether you're hiring for a GRC analyst role or want to discuss a project, I'd welcome the conversation.
I typically respond within one business day.