Who’s on this one
Mishael Moodley — GRC Specialist at McDonald’s, and a lead auditor across ISO 27001, 9001, 14001 and 45001. That combination is the whole reason for this episode: he works in the security standards our audience lives in and the quality standards most of them have never opened.
Sid Roper — VP of Customer Solutions, Compyl. 24 years in cybersecurity and GRC, spent replacing manual chaos with automated trust and scalable compliance.
Daniel Tangney — Host, GRC Radio.
Who should be in the room
- GRC and compliance managers — if you are writing the same corrective action twice, this is the session about why.
- CISOs and security leaders — the case for treating internal audit as a standing programme rather than a pre-audit sprint.
- Anyone running 27001 or SOC 2 — no quality-management background needed. That is the point.
Run of show
Forty-five minutes. Roughly 35 of conversation, 10 of your questions. No slides.
- Auditing both worlds — what Mishael sees in a 9001 audit that never comes up in a 27001 one.
- Corrective action, done properly — root cause, containment, and the effectiveness check almost nobody runs.
- Management review that earns its hour — what goes in, what comes out, and who has to be there.
- The internal audit programme you don’t have — how quality teams schedule and staff this, and what that would look like for security GRC.
- Borrow one thing — where to start this quarter if you only change a single process.
- Live Q&A — open floor.
