Summary
Overview
Work History
Education
Skills
Certification
Timeline
Generic

Santhosh Kapalavai

Associate Manager - Governance, Risk & Compliance (GRC)

Summary

Dedicated and accomplished GRC Manager with nearly 9 years of experience, distinguished for driving excellence in governance, risk, and compliance. Leveraging a robust skill set including ISO 2700/9001 Lead Auditor,GRCP,CC, CSOE, CRCMP, and multiple other certifications, I possess a profound understanding of industry standards, audit methodologies, and governance frameworks. Developed efficient audit methods and managed external audits for ISO and CMMI certifications, leading the team to achieve ISO 27001, 9001, 27701, 22301, and CMMI Level 5 certifications. Additionally, oversaw SOC2 report preparation, ensuring stakeholder confidence in our controls. Created a comprehensive risk management framework and proactively monitored risk indicators for informed decision-making, while managing IT General Controls (ITGC) assessments to ensure strong control environments. I am committed to maintaining operational integrity, safeguarding assets, and optimizing performance

Overview

8
8
years of professional experience
7
7
years of post-secondary education
9
9
Certifications

Work History

Associate Manager - GRC

Dexian
09.2023 - Current
  • Developed efficient audit methods, overseeing internal audits for smoother operations.
  • Managed external audits with firms for ISO and CMMI certifications
  • Led the team to achieve ISO 27001, 9001, 27701, 22301, and CMMI Level 5 certifications
  • Oversaw SOC2 report prep, ensuring stakeholder confidence in our controls
  • Created a risk management framework, producing detailed reports for leadership
  • Proactively monitored risk indicators for informed decision-making
  • Managed IT General Controls (ITGC) assessments, ensuring strong control environments
  • Lead audit follow-up activities, ensuring that corrective action plans are defined, tracked, and effectively implemented to address identified weaknesses and enhance process efficiency
  • Foster a culture of compliance awareness by providing guidance and training to internal teams and vendors on risk management, controls, and best practices

Risk and Compliance lead

Accenture Solutions Pvt. Ltd
07.2018 - 09.2023
  • Lead and oversee a skilled team of auditors responsible for conducting comprehensive 1st and 2nd party audits, specializing in supply chain operations like Order-to-Cash (O2C), Procure-to-Pay (P2P), and Record-to-Report (R2R)
  • Strategically incorporate ITGC controls, including Access Management, Change Management, and Incident Management, into the audit process to ensure the integrity and security of IT systems supporting supply chain functions
  • Collaborate with cross-functional teams to define audit scope, objectives, and key performance indicators, employing a risk-based approach to ensure robust audit planning
  • Effectively manage audit planning activities, including scheduling, resource allocation, and the development of audit test plans, ensuring a structured and efficient audit process
  • Conduct opening and closing meetings with internal teams and vendor partners, setting clear expectations, and establishing open lines of communication
  • Utilize comprehensive walkthrough calls to gain insights into processes and controls, facilitating a thorough understanding of supply chain operations
  • Apply professional skepticism and analytical skills to review and analyze audit findings, drawing actionable insights and providing comprehensive recommendations to improve internal controls and compliance
  • Cultivate strong relationships with vendors and internal stakeholders, serving as the primary point of contact for audit-related inquiries and communication
  • Collaborate with legal, procurement, and relevant departments to ensure contractual agreements reflect necessary compliance and risk management clauses
  • Provide mentorship, guidance, and professional development opportunities to audit team members, nurturing their growth and expertise.

Senior Representative

Indian Airforce - SRK Aviacom (I) Pvt.Ltd
02.2017 - 07.2018
  • Served as a primary point between client and customer, effectively addressing concerns, providing updates, and building strong relationships
  • Collaborated with cross-functional teams to align quality goals and maintain consistency in aircraft maintenance operations
  • Conducted regular audits of maintenance procedures, documentation, and facilities to identify areas for improvement and ensure adherence to standards
  • Led client audits to demonstrate adherence to quality and safety standards, addressing questions and concerns while building confidence in services provided
  • Acted as a liaison between clients and customer internal teams, translating technical information into accessible terms and ensuring clear communication throughout projects
  • Supported the certification and airworthiness process by verifying compliance with regulatory requirements and manufacturer specifications.

Quality Maintenance Engineer

Vision Group of Aviation
02.2016 - 01.2017
  • Conducted thorough inspections and audits of aircraft components, systems, and maintenance procedures to ensure compliance with industry standards and regulations
  • Collaborated with cross-functional teams, including engineers, technicians, and maintenance crews, to resolve quality issues and implement corrective actions
  • Led root cause analysis investigations to identify and rectify defects, ensuring minimal impact on aircraft operations and safety
  • Participated in the review and approval of maintenance documentation, such as maintenance manuals, repair procedures, and technical bulletins.

Education

Post Graduate Diploma in Management (Supply Chain) -

PRIN. L. N. WELINGKAR INSTITUTE OF MANAGEMENT DEVELOPMENT & RESEARCH
01.2018 - 04.2020

Bachelor's (Hons.) Mech (Aircraft Engines & Power Plant) - undefined

NATIONAL AEROSPACE UNIVERSITY - KHAI - KHARKOV, UKRAINE
01.2011 - 04.2015

Skills

undefined

Certification

ISO 27001:2022 Lead Auditor

Timeline

Associate Manager - GRC

Dexian
09.2023 - Current

Risk and Compliance lead

Accenture Solutions Pvt. Ltd
07.2018 - 09.2023

Post Graduate Diploma in Management (Supply Chain) -

PRIN. L. N. WELINGKAR INSTITUTE OF MANAGEMENT DEVELOPMENT & RESEARCH
01.2018 - 04.2020

Senior Representative

Indian Airforce - SRK Aviacom (I) Pvt.Ltd
02.2017 - 07.2018

Quality Maintenance Engineer

Vision Group of Aviation
02.2016 - 01.2017

Bachelor's (Hons.) Mech (Aircraft Engines & Power Plant) - undefined

NATIONAL AEROSPACE UNIVERSITY - KHAI - KHARKOV, UKRAINE
01.2011 - 04.2015
Santhosh KapalavaiAssociate Manager - Governance, Risk & Compliance (GRC)