Governance, Risk & Compliance (GRC)

Our Governance, Risk & Compliance (GRC) practice partners with organizations as they continue to deal with the dynamic governance, risk, and compliance landscape and navigate today’s complex business environment. We seek to prepare business leaders and their teams to identify and manage risks, strengthen governance across levels, drive end-to-end compliance, design and test internal controls, anticipate and assess any disruptions, and help build business resilience. We help to deploy platforms aimed at digitization, automation, and AI-enablement of an organization’s GRC functions.

Our Services

Enterprise Risk Management
Organizational Resilience Framework
Internal Audit
Policies and Procedures
Compliance
Internal Controls Design & Testing

Enterprise Risk Management (ERM) is a comprehensive and systematic process, applied in a strategic fashion across the enterprise. It is designed to identify potential events that may affect the entity and measure and manage risks against its most critical objectives. ERM enables management to effectively deal with uncertainty and associated risks and opportunities. When deployed correctly, this process enhances leaders’ ability to protect and build value.

Organizational Resilience (OR) refers to an organization’s ability to anticipate, prepare for, respond to, and adapt to various disruptions or changes in its internal and external environment. 

 

It involves the capacity to withstand and recover from adverse situations, while maintaining core business functions and adapting to emerging challenges.

 

Resilient organizations are better equipped to navigate uncertainties, crises, and disruptions, ensuring continuity and sustainability. Implementing OR enables an organization to foster long-term sustainability.

Traditionally, internal audit has been viewed as a compliance-focused function, responsible for ensuring controls are effective, policies are followed, and risks are managed. However, its role is evolving — in the face of rapid digital transformation, increasing regulatory complexity, and shifting business risks, internal audit is now emerging as a strategic enabler.

 

At Uniqus, we help organizations redefine Internal Audit as a forward-looking enabler of trust and resilience. With global perspective and local insight, we enable Internal Audit functions to move from hindsight to foresight, creating lasting value and sustainable impact. Guided by the Institute of Internal Auditors (IIA) Global Internal Audit Standards (GIAS) and powered by data analytics, AI, and deep domain expertise, our multidisciplinary teams deliver agile, technology-driven assurance across compliance, sustainability, financial controls, operations, IT audits, capital projects, and special investigations.

Clear, effective policies and procedures (financial, operational, governance, etc.) are critical for smooth operation of any organization. They ensure consistency, mitigate risks, and help maintain compliance with industry standards and regulation. We specialize in developing and refining policies and procedures tailored to an organization’s unique needs. Our goal is to help you establish a strong operational framework that promotes efficiency, accountability, and a culture of compliance. 

Compliance management ensures that organizations operate within legal, regulatory, and ethical boundaries while mitigating compliance risks. A strong compliance framework fosters a culture of integrity and accountability. We support clients in developing comprehensive compliance programs, conducting compliance risk assessments, documenting compliance compendium/ obligation registers and implementing monitoring mechanisms to ensure adherence to evolving regulatory landscapes.

Internal Controls are processes effected by an entity’s board of directors, management, and other personnel. They are designed to provide reasonable assurance around the achievement of objectives relating to operations, reporting and compliance. We assist our clients in designing best-in-class internal controls, and management testing of the controls. Our expertise spans diverse frameworks including Sarbanes-Oxley in the USA, ICOFR requirements in the Middle East and Internal Financial Controls in India.

Risk UniVerse is our cutting-edge GRC platform designed to streamline an organization’s compliance requirements through centralized data, automated workflows, and interactive dashboards — delivering enhanced visibility and audit readiness across the enterprise.

Our platform leverages the power of AI through its Controls AI features. Built-in AI-driven Control Testing automation moves organizations from manual, time-consuming assurance processes to smart, automated, and scalable testing. Complementing this, our AI-powered Document Management and Testing Intelligence engine converts transcripts, call recordings, into structured Process narratives & flow diagrams and Risk Control Matrices (RCMs).

Why Us?

Our leadership and deep expertise

Nagaraj Uchil, who leads our GRC practice, has over 20 years of experience in internal controls and SOX, ERM, OR, compliance, governance and IPO readiness, and has worked with clients across the globe. This unique blend of experience gives us the ability to understand your requirements, both strategically and practically, and deliver excellence. Nagaraj is supported by experienced local leaders in each of the markets we operate in.

Deep and diverse talent pool and globally integrated delivery model

Our partners and other leaders in our GRC practice have significant experience working with the enterprise risk management, organizational resilience, corporate governance, compliance, internal financial controls, and technology practices of the Big 4 and other large consulting and technology organizations globally. Our talent pool is globally integrated, working across our key markets of the USA, India, and the Middle East. Leveraging our offshore talent pool, combined with substantial onsite presence, we deliver significant cost efficiencies while maintaining timely, high-quality delivery.

Our AI and Technology-led approach

Our technology-led approach helps organizations modernize and scale their GRC functions. Our technology solutions are AI-powered which accelerate manual control testing, automate documentation, and transform transcripts, recordings, and narratives into structured process documentation, risk and control matrices (RCMs), and process flow diagrams (PFDs). Combined with our deep functional expertise, our proprietary Risk UniVerse product, and strategic technology partnerships, we help organizations address automation, data management, and controls challenges while delivering an efficient, scalable, and audit-ready approach to governance, risk, and compliance.

Agility and responsiveness

Our team embodies the essence of agility and responsiveness, fostering a dynamic environment where adaptability and quick responses are integral to our operations. Free from auditor independence requirements, we can seamlessly support our clients without the friction, delays, or restrictions caused by independence considerations. Our agility and responsiveness is enhanced by a high degree of partner/director involvement on projects.

Case Study

Driving SOX Compliance for an Online Travel Company

Case Study

Testing Internal Controls for a Leading Beauty and Personal Care Company

Driving Change: Client Success Stories

Our Leaders

Nagaraj Uchil

Partner, Global Head of GRC | Dubai, UAE

Ankur Gupta

Partner, GRC | Pune, India

Sabri S. Soufan

Partner, GRC | Riyadh, Kingdom of Saudi Arabia

Srikrishnan Soundararajan

Partner, GRC | Chennai, India

Vishal Hegde

Associate Partner, Qatar

Matt Solomon

Managing Director, GRC | California, USA

Ahmed Moussa

Director, GRC | Abu Dhabi, UAE

Dhruv Dossa

Director, GRC | Dubai, UAE

Guruprassad Kannan 

Director, GRC | Chennai, India

Kiran Kumar

Director, GRC | Mumbai, India

Mangesh Ulman

Director, GRC | Dubai, UAE

Mostapha Beydoun

Director, GRC | Riyadh, Kingdom of Saudi Arabia

Namrata Agarwal

Director, GRC | Bangalore, India

Priyal Nagori

Director, GRC | Gurugram, India
x

Nagaraj Uchil

Partner, Global Head of GRC

Nagaraj is an MBA in finance and has over 18 years of experience in Internal Controls, Enterprise Risk Management, Business Continuity Management, and IPO Readiness for organizations.

Prior to joining Uniqus, Nagaraj was leading Internal Controls, IPO Readiness, Enterprise Risk Management (ERM) and Business Continuity Management (BCM) for KPMG, Lower Gulf.

His sectoral experience includes Oil & Gas, Power & Utility, Real Estate & Construction, Sovereign funds, Travel and Tourism, Public Sector, Technology, and Retail & Consumer Durables.

x

Kiran Kumar

Director, GRC

Kiran is a Chartered Accountant with over 20 years of experience in Internal Controls, Sarbanes Oxley Compliance and controls monitoring across several large MNCs in India and the Middle East. Kiran joins us from Philips Global Business Services where he was part of Group Internal Controls team. Prior to Philips, Kiran has also worked with Petroleum Development Oman and Shell.

x

Priyal Nagori

Director, GRC

Priyal is a Chartered Accountant with over 12 years of experience. She comes with extensive experience in SOX, Reporting, Risk Mitigation, Controls, and Process standardization. Priyal joins us from Revolut, where she was a Risk Manager for Finance and Treasury. Prior to Revolut, Priyal has also worked with KPMG & Goldman Sachs.

x

Sabri S. Soufan

Partner, GRC

Sabri brings over a decade of leadership experience in GRC and Internal Audit, with a strong track record in growing consulting practices, leading transformation projects, and advising senior stakeholders. A Certified Internal Auditor (CIA), Certified Fraud Examiner (CFE), and Licensed International Financial Analyst (LIFA), he offers deep technical expertise and a forward-looking perspective to addressing today’s evolving governance and risk landscape in Saudi Arabia and the Middle East region.
Prior to joining Uniqus, Sabri held key roles at PwC and Deloitte, delivering large-scale initiatives for a diversified portfolio of prestigious entities in KSA and the Middle East region, spanning governmental entities, capital projects, real-estate, financial services and family business.
x

Dhruv Dossa

Director, GRC

Dhruv comes with over 15 years of experience in supporting a diverse range of clients with Governance, Risk and Compliance services. Dhruv has extensive experience in Internal Controls, Enterprise Risk Management, IPO Readiness, IFC / SOX, Policies & Procedures, and Internal Audits across industries. Prior to joining Uniqus, he was associated with KPMG Lower Gulf.
x

Namrata Agarwal

Director, GRC

Namrata is an Indian Chartered Accountant, Certified Internal Auditor (IIA), and Certified Sarbanes Oxley Expert (SOXCPA) possessing over 13 years of professional experience broadly into Statutory Audits, Financial Reporting, Accounting Advisory Services, Risks, Internal Controls and Compliances. She developed and implemented robust internal controls for various companies across industries (including Hospital, Pharmaceutical, Transportation & Logistics, Home Furnishings, Retail, etc) ensuring compliance with regulatory requirements and industry best practices (including COSO framework). She developed Finance Processes, Local Operating Procedures and assisted in development of Accounting Manual for a global company in India. She conducted risk assessments to identify key control gaps and develop strategies for mitigating risks and improving overall operational efficiency for the global furniture company.

x

Ahmed Moussa

Director, GRC 

Ahmed has over 17 years of experience in Internal Audit, Risk Advisory, Internal Controls over Financial Reporting (ICOFR), Assurance, Anti-Fraud, Corporate Governance, Due Diligence, and Business Advisory. Throughout his career, he has led numerous high-impact initiatives to strengthen governance frameworks, internal audit functions, risk management systems, and financial and operational controls, advising senior leadership on optimizing performance and driving sustainable excellence. He is a Fellow of the ACCA (UK) and holds global certifications including CFE (US) and CISA (US). Prior to joining Uniqus, Ahmed held key roles at KPMG, Deloitte, and Protiviti, successfully managing large-scale transformation projects across the GCC and Europe.

x

Mostapha Beydoun

Director, GRC

Mostapha has over 15 years of experience in Governance, Risk Management, and Compliance, serving clients across the Middle East and North Africa. He has advised organizations in the public sector, financial services, construction, and sovereign-backed entities. He has led high-impact projects in KSA, optimizing internal controls and strengthening risk and compliance frameworks. Before joining Uniqus, he held a leadership role at a major private organization, where he drove strategic governance and risk initiatives. He holds an MBA in Finance and a degree in Artificial Intelligence.

x

Mangesh Ulman

Director, GRC

Mangesh brings over 17 years of experience in the resilience domain, with a strong focus on strategic risk management, business continuity management, crisis management, and supply chain risk management. He has worked across multiple sectors, including energy, metals, mining and manufacturing, ports and logistics, and aviation, with experience spanning the Middle East, Europe, the USA, and India. He has collaborated closely with national oil companies ano organizations responsible for managing national critical infrastructure to build, strengthen, and continuously enhance their risk and resilience capabilities.

Mangesh specializes in supporting organizations to develop technology-enabled risk and resilience programs that empower management to make informed, confident decisions.

x

Matt Solomon

Managing Director, GRC

Matt brings over 15 years of experience and specialises in Enterprise and Strategic Risk Management, helping organizations understand, manage, and benefit from their unique risk profiles. He has extensive experience in designing and implementing program that integrate ERM, resilience, cyber, and compliance risk capabilities, enabling organizations to effectively manage the risks and opportunities that matter most.

Prior to joining Uniqus, Matt was at Deloitte, where he advised clients across a wide range of industries, including aviation and automotive, energy, technology, industrials, and mining.

x

Guruprassad Kannan 

Director, GRC

Guru brings over 13 years of experience in Governance, Risk, and Compliance (GRC), with expertise across risk solutions including internal audit and controls, enterprise risk management (ERM), business process management, and risk analytics. He has led large, complex engagements across sectors such as manufacturing, automotive, logistics, and IT/ITES, including SaaS, working with organizations across India and global markets in the US, Europe, and Asia.

Prior to joining us, Guru was with EY India.

x

Vishal Hegde

Associate Partner, GRC

Vishal is an Internal Audit, Risk, and Compliance leader with over 20 years of experience across international markets and all three lines of defense, with a focus on banking and financial services. His expertise includes risk governance frameworks, non-financial risk, enterprise risk management, data privacy, third-party risk management, cybersecurity resilience, and incident management.

He brings domain experience across liquidity and cash management, asset management, private banking, global markets, and securities services. Prior to joining us, he held senior Internal Audit and governance roles at HSBC, leading assignments and teams across multiple geographies and supporting regulatory reviews by organizations such as Prudential Regulation Authority, Central Bank of the UAE, Saudi Central Bank, Hong Kong Monetary Authority, and Monetary Authority of Singapore.

x

Ankur Gupta

Partner,
Governance, Risk & Compliance

Ankur is a seasoned risk professional with almost 16 years of experience with Governance Risk and Compliance, and has serviced clients across multiple sectors including manufacturing, consumer products, IT, metals & mining, and FS. He has led risk consulting engagements like Internal audit, Internal Controls, SOX, Forensic reviews, Risk transformation, Enterprise Risk Management, Regulatory compliance engagements.

Prior to joining Uniqus, Ankur was an Associate Partner at KPMG and was previously a Director in the Business Consulting – Risk function at EY.

x

Srikrishnan Soundararajan

Partner,
Governance, Risk & Compliance

Sri is a Chartered Accountant and Certified Fraud Examiner with over 17 years of experience advising corporates on designing robust risk operating models, leading complex cross-border investigations, and driving analytics-led anti-fraud solutions.

Prior to joining Uniqus, he was a Director at EY, where he led high-stakes mandates spanning white-collar investigations, fraud risk assessments, and governance transformation initiatives, delivering strong, actionable outcomes for clients.

Download the pdf of this publication


This will close in 0 seconds