IT Governance, Risk, Compliance and Audit Readiness
A 12-week, hands-on programme in IT governance, risk management, compliance, and audit readiness. Trainees build portfolio-ready work, such as risk registers, policies, audit reports, and governance frameworks, for GRC jobs and freelance work.
Course Introduction
Learning Outcomes
Explain IT governance principles and the business value of governed IT decisions, using COBIT 2019 and ISO/IEC 38500
Map IT objectives to business strategy with Balanced Scorecard and OKRs, and design a governance structure with escalation paths
Draft and evaluate IT policies (acceptable use, access management, data governance) against control objectives
Build a risk register and map controls using ISO 31000 and the NIST Cybersecurity Framework
Assess compliance against a legal checklist with Pakistan-specific context (PECA, Data Protection Bill, SBP requirements)
Evaluate IT service performance with ITIL 4 and design a governance KPI and maturity dashboard
Simulate an IT audit engagement and produce an audit report
Identify governance gaps in cloud, AI, IoT, and shadow IT, and map a response to a simulated cyber-incident
Apply proposal writing, pricing, and client communication skills to win GRC freelance work on Upwork and Fiverr
Design, document, present, and defend a complete governance framework or audit model as a capstone
Target Audience
- group *ICT and Computer Science graduates
- group *Freelancers and independent consultants
- group *Early-career ICT professionals
- group *Women graduates (10% minimum enrolment target)
- group *Youth in merged and underserved KP divisions
Certification Criteria
- check Attend at least 80% of scheduled sessions
- check Complete all practical assignments, quizzes, and the Final Written Exam
- check Score at least 80% overall across the weighted components
- check Present and defend the capstone successfully
Assessment Strategy
12 Duration.
Course Modules
12 weeks · 4 sessions per week · 144 contact hours
Governance Foundations & Frameworks
Governance landscape; fundamentals and business value; COBIT 2019; ISO/IEC 38500 and ITIL 4 overview; framework selection
Strategic Alignment & Governance Structures
Balanced Scorecard and OKRs; stakeholder mapping; boards, committees and roles; governance charter
Policies & Controls
Acceptable use and access management; data governance and BYOD; AI-assisted policy drafting; Quiz 1
Risk Management & Compliance
Risk registers (ISO 31000); control mapping (NIST CSF); PECA, GDPR and data protection; compliance gap report
IT Service Management & Performance
ITIL 4 service value chain; SLA/OLA design; governance KPIs and maturity models; dashboard design
Emerging Tech Governance & Midterm
Cloud and shadow IT; AI, IoT and BYOD governance; integrated case; Quiz 2 and Midterm
Audit & Cyber Resilience
IT audit lifecycle; audit simulation and findings; incident response, DRP/BCP; breach notification and tabletop
Freelance & Career Pathways
GRC gig platforms; proposal writing and pricing; client communication; ISACA/ISO certification roadmap
Final Exam & Capstone Planning
Exam review; Final Written Exam; problem scoping; charter and stakeholder matrix
Capstone Execution & Portfolio I
Governance documentation draft; risk and control design; mentor review; Upwork profile
Capstone Finalisation & Portfolio II
Performance and compliance mapping; peer feedback; before/after document pair; presentation rehearsal
Capstone Defence & Certification
Panel defence; soft skills and interview prep; employability database; closing and next steps
Frameworks & Tools
Governance Frameworks: COBIT 2019, ISO/IEC 38500, ITIL 4, ISO 31000, NIST Cybersecurity Framework
Design & Diagramming: Lucidchart, Miro, Microsoft Visio
Risk, Audit & Data: Excel, Google Sheets, audit workpaper templates (AuditBoard trial where available), GDPR/ISACA policy templates
Dashboards: Power BI Desktop, Google Sheets
AI & Freelance: ChatGPT, Gemini, Upwork, Fiverr, Freelancer.pk, LinkedIn, LMS
“Design a Governance Framework or Audit Model for an IT Service Organization.” Trainees choose a real or fictional governance challenge. They design a governance structure (COBIT or ISO/IEC 38500), build a risk register, policy set, and performance model, or run a full mock audit. They present it to a panel in Week 12. It must use at least two frameworks. Themes include University IT Governance, SME Data Protection Audit, Clinic IT Risk Register, Government Incident Response Plan, ISO 27001 Documentation Package, and Vendor Risk Assessment.
One-Page Governance Problem Brief
Framework & Control Map Diagram
Working Artefact (policy set, risk register and control matrix, or audit report)
Plain-Language Governance Guide (one page)
Portfolio Walkthrough (recorded or live)
Live Panel Presentation & Defence
Ready to lead the Digital Revolution?
Join the next cohort and master the technologies shaping the future of global enterprise.