I turn the Microsoft 365 you already licence into a working GRC system — risk registers, incident reporting, WHS, audits and policy. For small businesses and not-for-profits across Australia. No new platform to buy.
Most GRC consultants hand you a framework and leave you to run it in spreadsheets. Most Microsoft consultants have never maintained a register or fronted a board with an overdue action list. I do both — which is why what I build still gets used after I leave.
I build inside the Microsoft 365 your organisation already licences. No new subscription, no per-user fee, no migration project.
Eleven years in risk, compliance and governance. I have maintained the registers, led the audits, and answered to the board.
Based in Hobart, working with organisations right across Australia. On site where that genuinely helps, remote where it does not.
Your risk register lives in a spreadsheet one person owns and nobody reads. I rebuild it in SharePoint, Lists and Power Automate — tools your licence already includes.
Learn more →Approvals chased by email, reminders nobody sends. Workflows that route, escalate and report on their own — with AI used only where it genuinely helps.
Learn more →Policy reviews that quietly lapse; audit evidence gathered in a panic. Frameworks and procedures built to your obligations, then implemented — not handed over as a PDF.
Learn more →Nothing about your compliance requirements changes. What changes is whether the record is current on the day someone asks.
AI can take real work off a stretched team — summarising incident reports, drafting policy updates, triaging hazards. It can also introduce privacy, accuracy and record-keeping risks nobody has assessed.
I keep current with the National AI Centre and work to the Australian Government’s Guidance for AI Adoption, so what we put in place is defensible to your board — not just impressive in a demo.
What that means for a small organisation →Tell me what you are running now and where it is breaking down.
Start a conversation