Compyl
Sponsored by:
The Conversation Starts in....
Days
Hours
Minutes
Seconds

Why the Same Findings Keep Coming Back

Who’s on this one

Mishael Moodley — GRC Specialist at McDonald’s, and a lead auditor across ISO 27001, 9001, 14001 and 45001. That combination is the whole reason for this episode: he works in the security standards our audience lives in and the quality standards most of them have never opened.

Sid Roper — VP of Customer Solutions, Compyl. 24 years in cybersecurity and GRC, spent replacing manual chaos with automated trust and scalable compliance.

Daniel Tangney — Host, GRC Radio.

Who should be in the room

  • GRC and compliance managers — if you are writing the same corrective action twice, this is the session about why.
  • CISOs and security leaders — the case for treating internal audit as a standing programme rather than a pre-audit sprint.
  • Anyone running 27001 or SOC 2 — no quality-management background needed. That is the point.

Run of show

Forty-five minutes. Roughly 35 of conversation, 10 of your questions. No slides.

  • Auditing both worlds — what Mishael sees in a 9001 audit that never comes up in a 27001 one.
  • Corrective action, done properly — root cause, containment, and the effectiveness check almost nobody runs.
  • Management review that earns its hour — what goes in, what comes out, and who has to be there.
  • The internal audit programme you don’t have — how quality teams schedule and staff this, and what that would look like for security GRC.
  • Borrow one thing — where to start this quarter if you only change a single process.
  • Live Q&A — open floor.
When
October 1, 2026
Time
2:00 pm –
2:45 pm
Why the same findings keep coming back. With Sid Roper, VP of Customer Solutions at Compyl, and Mishael Moodley, GRC Specialist at McDonald's. October 1, 2026 at 2:00 PM ET.

We will cover:

  • What corrective action looks like as a real discipline — root cause, containment, and an effectiveness check that actually gets done
  • Why management review is more than a slide deck once a year, and what a useful one produces
  • How to run an internal audit programme instead of a scramble three weeks before the external auditor arrives
  • What quality management does about repeat findings that 27001 and SOC 2 programmes almost never do
  • Where to start if you’re only going to borrow one thing this quarter
  • How to make findings stay closed without adding headcount you won’t get

"(Required)" indicates required fields

Name(Required)
Monitoring thousands of environments daily
By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies