Transitioning into UK Financial Services GRC

Governance, risk & compliance thinking, proven where it matters most.

I'm a GRC analyst with a track record built in local authority and health sector regulation — now bringing that rigour, controls discipline and stakeholder judgement to financial services.

GRC analyst reviewing business reports on a laptop, holding compliance papers
6+Years in regulated roles
40+Risk & audit projects
3Sectors covered
Scroll to explore ↓
Sector background: Local Authority NHS & Health Sector Now targeting: Financial Services & Fintech ISO 27001 · GDPR · FCA Handbook
Portrait of Sarah Whitfield, GRC analyst, smiling in a grey suit
Chartered IRM & ISACA affiliated
About

Regulatory judgement forged in the public sector, ready for financial services

My career started in local authority governance — chasing statutory deadlines, sitting in audit committees, and translating complex regulation into practical controls for services that couldn't afford to get it wrong. I moved into the health sector to lead risk registers and information governance across multi-site NHS operations, where patient data, safeguarding and CQC scrutiny raised the stakes further.

That grounding — public accountability, statutory reporting, and working under regulators who don't tolerate excuses — is exactly the discipline UK financial services firms need from their GRC function. I'm now applying it directly to FCA/PRA-aligned frameworks, third-party risk, and financial crime controls.

  • Risk registers & control frameworks
  • Statutory & regulatory reporting
  • Information governance & GDPR
  • Internal audit liaison
  • Policy design & rollout
  • Stakeholder & board reporting
What I do

Core areas of expertise

A cross-sector GRC skill set adapted for the demands of regulated financial businesses.

01

Risk Management

Building and maintaining risk registers, running risk workshops, and translating operational risk into board-ready reporting — honed managing corporate risk across a local authority portfolio.

Risk registersRCSAHeat maps
02

Regulatory Compliance

Monitoring statutory and regulatory change, mapping obligations to controls, and closing compliance gaps — background spans CQC, GDPR, Data Protection Act and safeguarding frameworks.

FCA HandbookGDPRPolicy mapping
03

Governance & Controls

Designing control frameworks, supporting audit committees, and coordinating internal/external audit responses — the discipline that keeps public sector bodies accountable, applied to financial controls.

Control testingAudit liaisonISO 27001
04

Information Security & Data

Leading information governance projects across sensitive health and citizen data — a direct fit for firms managing financial crime, KYC and customer data risk.

Data classificationDPIAsAccess controls
05

Third-Party & Supply Chain Risk

Assessing supplier and contractor risk exposure within public procurement frameworks — directly transferable to outsourcing and vendor due diligence in financial services.

Due diligenceVendor riskSLAs
06

Stakeholder Reporting

Presenting to audit committees, senior leadership and regulators — clear, evidence-based communication that turns compliance data into decisions.

Board packsMI dashboardsCommittee papers
Track record

Selected case studies

Real projects, real outcomes — the depth of work behind the transition into financial services GRC.

Local Authority Wooden letter tiles spelling Regulation, representing a compliance framework project

Council-wide risk register overhaul

Redesigned a fragmented risk reporting process into a single corporate risk register, cutting reporting time by 35% and giving the audit committee real-time visibility of top risks.

Sector: Public Sector18-month programme
Health Sector Wooden letter tiles forming the word Compliance on a rustic background

Information governance remediation

Led a GDPR compliance remediation across multi-site NHS services, closing 90% of open DPIA actions within two quarters and rebuilding staff training on data handling.

Sector: HealthNHS Trust
Financial Services (Applied) Analyst reviewing stock market charts on a laptop while on the phone

FCA-aligned controls mapping (portfolio project)

Independent study mapping FCA SYSC and Consumer Duty requirements to a fictional fintech's control environment, producing a gap analysis and remediation roadmap.

Sector: FinTechSelf-directed
Local Authority Financial documents, charts and laptop organised on a desk

Supplier due diligence framework

Built a standardised third-party risk assessment used across procurement for over 60 contracted suppliers, reducing onboarding risk exceptions by 28%.

Sector: Public Sector12-month rollout
Health Sector Wooden letter tiles arranged to spell Rules on a textured background

Safeguarding & CQC audit readiness

Coordinated evidence-gathering and mock inspections ahead of a CQC visit, contributing to an improved 'Good' rating across governance domains.

Sector: HealthAudit cycle
Financial Services (Applied) Professional analysing stock markets on a digital tablet

Financial crime control review (case study)

Applied AML/KYC control-testing methodology to a simulated payments firm, identifying control weaknesses and drafting a remediation action plan.

Sector: PaymentsSelf-directed
6+Years across public & health sector governance
40+Risk, audit & compliance projects delivered
90%Reduction in open DPIA actions (case study)
3Professional certifications in progress/held
Capability

Skills built for regulated environments

Practical proficiency across the frameworks and tools most relevant to financial services GRC teams.

Risk Assessment & Registers92%
Regulatory Compliance Mapping88%
Data Protection & GDPR90%
Internal Audit Liaison82%
FCA / Financial Services Frameworks74%
GRC Tooling & Reporting Dashboards80%
Certifications

Qualifications & memberships

IRM

Institute of Risk Management — Certificate in Risk Management

Enterprise risk frameworks & assurance

27K

ISO 27001 Lead Implementer (in progress)

Information security management systems

GDP

Practitioner Certificate in Data Protection

UK GDPR & Data Protection Act 2018

FCA

CISI — Fundamentals of Financial Services Regulation

FCA/PRA regulatory framework

PM

APM Project Fundamentals Qualification

Governance-led project delivery

What colleagues say

Trusted by managers and audit committees

Sarah brought order to a risk register that had been neglected for years. Her reporting gave our audit committee real confidence for the first time.

Portrait of a smiling man in formal attire
James OkaforHead of Internal Audit, Local Authority

Her information governance work was thorough and pragmatic — she understood clinical pressures while still holding the line on compliance.

Portrait of a confident woman in an orange blazer
Priya AnandInformation Governance Lead, NHS Trust

What stands out is how quickly she's picked up FCA frameworks. Her public sector rigour translates directly into strong financial services controls thinking.

Portrait of a smiling professional woman in a grey suit
Michael TurnerCompliance Consultant, Mentor
Documents

Request my CV & supporting profile

To protect personal and career details, I don't publish my CV for open download. Instead, submit a short request below — I personally review every enquiry and email the full CV directly to approved requesters.

Request references
Requests are sent to me for review — I don't auto-send the CV. Once approved, I'll email it directly to the address provided.
FAQ

Common questions

Why move from public sector into financial services GRC?+

The regulatory discipline, evidence standards and stakeholder scrutiny in local authority and health governance are directly transferable — financial services simply applies that same rigour to a different rulebook (FCA/PRA rather than CQC/DPA). I've spent the last year building targeted knowledge of that rulebook to make the transition credible from day one.

What financial services frameworks are you most familiar with?+

I've focused study and case work on the FCA Handbook (SYSC, Consumer Duty), AML/KYC control testing, and third-party/outsourcing risk — building on existing strength in GDPR, ISO 27001 and control-framework design.

Are you open to entry-level or analyst-level GRC roles?+

Yes. I'm targeting GRC Analyst, Risk & Compliance Analyst, or Governance Officer roles where my cross-sector experience adds value, while I build financial services domain depth on the job.

Why do I need to request the CV instead of downloading it?+

My CV contains personal contact details and employer references, so I keep it off public download. Submitting a quick request lets me confirm who's asking and send it directly by email once approved — usually within one business day.

Can you provide references from previous roles?+

Absolutely — references from both my local authority and NHS roles are available on request, and I'm happy to arrange calls directly with previous line managers.

Are you open to relocation or hybrid/remote roles across the UK?+

Yes — I'm flexible on location and open to hybrid or remote arrangements for the right opportunity within UK financial services.

Let's talk about your GRC needs

Whether you're hiring for a GRC analyst role or want to discuss a project, I'd welcome the conversation.

PhoneAvailable on request
📍
LocationUnited Kingdom — open to relocation

Send a message

I typically respond within one business day.

🔒 PREVIEW — built with Zurum. Publish to remove this banner & put it on your own domain.