Building a governance, risk, and compliance function from zero is one of the hardest challenges in cybersecurity leadership. There is no team, no framework, no existing policy. Every decision you make in the first 90 days shapes the program for years.
When I took on this role at Solutions by stc, a telecom subsidiary with 500+ employees operating cloud, connectivity, IoT, CCTV, and enterprise IT services, I started with nothing. No policies. No control framework. No compliance processes. I built the team from zero, hired and assigned the members myself, and grew it into a unit of 10 to 12 senior professionals managing continuous compliance across multiple certifications.
Start with Ownership, Not Policy
The instinct is to write policies first. Resist it. Policies without owners are shelf documents. The first month was spent mapping every operational process to a responsible team. Who owns change management? Who approves vendor access? Who reviews firewall rules?
This mapping exercise surfaces two things immediately. First, you discover processes that have no owner at all. These are your highest-risk areas. Second, you discover processes with multiple owners, which means no one is accountable. Both problems must be resolved before writing a single policy.
I mapped every platform, data flow, and third-party integration to a specific team and individual. This took weeks. It saved months of rework later.
Pick Your Frameworks, Then Unify Them
ISO 27001 provides structure. NCA provides regulatory requirements. PCI-DSS provides payment-specific controls. HIPAA provides health information protection. None of them map perfectly to your organization as-is.
We needed ISO 27001 and PCI-DSS certifications and HIPAA compliance simultaneously while maintaining NCA compliance. The mistake would have been to treat them as separate projects. Instead, we built a single control framework and tagged each control with the standards it satisfied. One control could satisfy requirements across multiple frameworks simultaneously. This reduced the total control count by roughly a third.
The key was cross-mapping. When you lay out every requirement side by side, you find that access management, incident response, change management, and a dozen other domains appear in every framework. One evidence package, tagged correctly, satisfies all of them. This cut the overhead on operational teams significantly. Instead of producing the same firewall review evidence three separate times, they produced it once.
Build a Compliance Calendar
With 10 to 12 senior professionals and a constant rotation of certification renewals and audits, the schedule was always full. We were either renewing a certification or preparing for an audit at any given time.
The hardest part of audits is not the audit itself. It is arranging the operational teams, collecting evidence, and making sure the right people are available for auditor interviews. Without planning, teams get blindsided and scramble.
The compliance calendar solved this. At the start of each year, I mapped every audit and certification renewal to specific months and shared it across the organization. Operations teams knew months in advance when each audit would happen. They could prepare evidence, clear schedules, and assign points of contact. The difference between a calm audit and a chaotic one is almost always how much notice the operational teams received.
Embed Governance into Existing Workflows
The fastest way to kill a GRC program is to make it a separate process that competes with operations for attention. Governance must live inside the workflows people already use.
We embedded compliance checks into the change management system. Every change request automatically triggered a governance review. No separate form. No additional meeting. We integrated security assessments into the vendor onboarding process. Before any vendor received access to our platforms, they passed through a standardized risk assessment. The procurement team managed the process. The GRC team provided the criteria and reviewed results.
Navigate Resistance with Patience
Not every department welcomed governance with open arms. Some leaders in other departments saw GRC as overhead, not value. The approach that worked was consistent: explain that GRC exists to help them make informed decisions. It is there to align their operations with laws, regulations, and certification requirements. Frame it as a support function, not an enforcement function.
Over time, once teams saw that governance reduced audit surprises and simplified their evidence workload through cross-mapping, the resistance faded. The compliance calendar in particular built trust because it respected their time.
The 90-Day Priority
If you are building a GRC function from scratch, focus on three deliverables in the first 90 days. Map ownership for every critical process. Build a unified control framework that covers all applicable regulations. Embed one governance checkpoint into an existing operational workflow. Everything else can wait.
This approach delivered zero critical audit findings across all certification cycles for over four consecutive years at Solutions by stc, serving a portfolio of managed services for 500+ employees. The framework did not eliminate risk. It made every risk visible, owned, and tracked to closure.