16+ Years · Big 4 Trained · Delhi-Based

Risk Intelligence
& Compliance
Excellence

Fortifying Trust Through Risk Intelligence and Compliance Excellence.

Empowering organizations across India, US, APAC, and Europe with robust risk governance, SOX/ITGC compliance, and regulatory advisory tailored for high-growth industries.

IATGRC
16+ Years Experience
11+ Years SOX/ITGC
8+ Industries
About IATGRC

Built on Decades of
Global Audit Excellence

Ridhi Nahata, Founder of IATGRC, is a seasoned professional with over 16 years of experience. She is a Risk Advisory and Internal Audit leader with 11+ years of experience in SOX 404, ITGC, ICFR, enterprise risk management, and ERP control frameworks.

She has a proven record of leading global audit programs across the US, APAC, and Europe. Ridhi is experienced in Oracle Cloud ERP controls, IPO readiness, regulatory compliance, and Audit Committee reporting.

Trained at a Big 4 firm, Ridhi also serves as an active trainer for Internal Audit and SOX programmes — bringing Big 4 methodology and global perspective to organizations of all sizes.

CISA Qualified
ISO 27001 Certified
Masters in Finance
Semi-Qualified Company Secretary
Big 4 Trained
SOX 404 Specialist
IIA Member
ITGC / ERP Expert

"Building resilient enterprises through integrated audit, risk, and governance — with precision, trust, and a commitment to lasting value."

Ridhi Nahata
Founder, IATGRC · Risk & Compliance Consultant
Trust Every engagement is anchored in transparency and ethical practice aligned with IIA standards.
Innovation Leveraging Power BI, IDEA analytics, and Zero Trust frameworks for modern risk intelligence.
Precision Meticulous RCM development, board-level reporting, and audit coordination that delivers results.
Meet the Founder

Profile, Credentials
& Contact

Ridhi Nahata
Ridhi Nahata
Founder, IATGRC
📞
✉️

Ridhi Nahata is a Risk Advisory and Internal Audit leader with 16+ years of experience across SOX 404, ITGC, ICFR, enterprise risk management, information security, and regulatory compliance — combining Big 4 methodology with practical, business-first execution.

Certifications & Qualifications

CISAISACA
ISO 27001Lead Auditor / Lead Implementor
LLBLaw Graduate
CSExecutive Level
MBAFinance
M.ComInternational Business
AI EnthusiastApplying AI tools to audit, risk, and compliance workflows

Consulting & Contractual Services

Available for engagements ranging from short-term advisory sprints to ongoing contractual retainers — covering GRC transformation, SOX/ITGC assurance, information security, and specialized project-based support for organizations of all sizes.

Project-Based Consulting Contractual / Retainer Engagements Interim & Fractional Roles Independent Advisory
On-Demand Talent

Resources
Availability

Vetted, engagement-ready professionals available through IATGRC for short and long-term assignments.

🧭

Independent Director

Board-level governance oversight and independent perspective for companies seeking regulatory board composition.

📑

SOX Consultants

Experienced consultants for SOX 404, ICFR documentation, control testing, and remediation support.

🔍

Internal Auditor

Skilled internal audit professionals for fieldwork, risk assessments, and audit programme execution.

🛡️

Cyber Security Auditor

Specialists in ISO 27001, ITGC, and cybersecurity control audits across IT and cloud environments.

Our Expertise

Ten Pillars of
Risk & Compliance

Comprehensive advisory solutions built around your industry's unique regulatory and operational landscape.

01
🏛️

Enterprise Risk Governance

Board-level risk assessment and reporting, Risk Control Matrix (RCM) development, IPO readiness advisory, and comprehensive governance frameworks for complex organizations.

Risk Assessments Board Reporting IPO Readiness RCM Development
02
⚙️

Risk Management Frameworks

ERM frameworks based on COSO principles, ITGC and ERP controls advisory for Oracle Cloud/SAP environments, and Zero Trust security architecture consulting.

COSO / ERM ITGC Oracle Cloud / SAP Zero Trust
03
📋

Regulatory Compliance

SOX 404/ICFR readiness, NBFC regulatory compliance, GDPR and ISO 27001 advisory, data protection audits, and comprehensive external audit coordination.

SOX 404 ICFR GDPR ISO 27001 NBFC
04
📊

Financial Advisory

O2C/P2P process optimization, advanced data analytics using Power BI and IDEA, external audit coordination, and Company Secretary services for corporate compliance.

O2C / P2P Power BI IDEA Analytics Company Secretary
05
🎓

Training & Industry Development

Internal Audit & SOX training using Big 4 methodology, ITGC/ERP workshops, ERM masterclasses, Data Analytics for Auditors, and Regulatory Compliance bootcamps.

SOX Training ITGC Workshops ERM Masterclass Data Analytics
06
🤖

Consulting with AI Tools

AI-assisted audit analytics, intelligent risk scoring, automated control testing, AI-powered anomaly detection, and AI integration into GRC/ERP environments.

AI Audit Analytics Risk Scoring Auto Control Testing GRC AI Integration
07
🔐

DPDP Implementation

End-to-end Digital Personal Data Protection Act (DPDP) 2023 implementation — gap assessments, consent frameworks, data mapping, and grievance redressal mechanisms.

DPDP Act 2023 Gap Analysis Consent Frameworks Data Mapping
08
🛡️

ISO 27001 — Lead Auditor & Lead Implementor

Certified Lead Auditor and Lead Implementor services for Information Security Management Systems — from ISMS design through certification audit readiness.

Lead Auditor Lead Implementor ISMS Design Certification Readiness
09
📘

Policies & Procedures

Design, drafting, and implementation of organization-wide policies and standard operating procedures aligned to regulatory and governance requirements.

Policy Drafting SOPs Governance Alignment
10
⚖️

POSH Services

Prevention of Sexual Harassment (POSH) compliance — Internal Committee setup, policy drafting, employee training, and inquiry advisory support.

Internal Committee Setup POSH Policy Employee Training Inquiry Advisory
Service Pillar Key Offerings Target Industries
Enterprise Risk Governance Risk assessments, RCM development, Audit Committee reporting, IPO readiness NBFC, Banks, Manufacturing
Risk Management Frameworks ERM (COSO), ITGC/ERP controls (Oracle Cloud/SAP), Zero Trust advisory ITES, Healthcare, FMCG
Regulatory Compliance SOX 404/ICFR, NBFC regulations, GDPR/ISO 27001, data protection audits Hospitality, Banks, NBFC
Financial Advisory O2C/P2P optimization, Power BI/IDEA analytics, Company Secretary services All Industries & More
Training & Industry Development Internal Audit & SOX training (Big 4 methodology), ITGC/ERP workshops, ERM masterclasses, Data Analytics for Auditors, Regulatory Compliance bootcamps All Industries · Finance & Audit Professionals
Consulting with AI Tools AI-assisted audit analytics, intelligent risk scoring, automated control testing, AI-powered anomaly detection, AI integration into GRC/ERP environments ITES, FMCG, NBFC, Banks & All Industries
DPDP Implementation Gap assessments, consent frameworks, data mapping, grievance redressal mechanisms Healthcare, ITES, Financial Services
ISO 27001 — Lead Auditor & Lead Implementor ISMS design, implementation support, internal/external audit, certification readiness All Industries
Policies & Procedures Organization-wide policy drafting, SOP design, governance alignment All Industries
POSH Services Internal Committee setup, policy drafting, employee training, inquiry advisory All Industries
Training Programmes

Learn from a
Big 4 Trained Expert

IATGRC delivers world-class internal audit and compliance training grounded in 16+ years of real-world Big 4 and global corporate experience. Both corporate batches and individual enrolments are welcome.

Why Train with IATGRC?

Big 4 trained methodology — the same rigour used at global firms, delivered accessibly.
Global perspective spanning US, APAC, and European audit environments.
Practical toolkits, templates, and real-world case studies included.
Corporate group batches and individual professional enrolments available.
Covers emerging areas: AI in audit, data analytics, and ERP controls.
📑

SOX 404 & ICFR Training

End-to-end SOX compliance: scoping, RCM design, control testing, deficiency classification, and Audit Committee reporting. Ideal for first-time filers and growing companies.

🖥️

ITGC & ERP Controls

Hands-on training on IT General Controls, Oracle Cloud, and SAP access/change management controls. Covers audit evidence, testing, and remediation approaches.

🌐

Enterprise Risk Management

COSO ERM framework, risk appetite setting, risk register design, board-level risk communication, and integrating ERM with strategic planning cycles.

🔍

Internal Audit Fundamentals

IIA standards, audit planning and risk assessment, fieldwork techniques, finding management, audit report writing, and Audit Committee interaction best practices.

📈

Data Analytics for Auditors

Power BI dashboards for audit, IDEA data analytics, automated exception testing, continuous monitoring frameworks, and visualizing audit results for stakeholders.

⚖️

Regulatory Compliance Masterclass

NBFC/RBI regulations, GDPR, ISO 27001, data protection frameworks. Practical compliance programme design and integration with internal audit activities.

Training Track Record

Corporate Trainer, Industry Faculty & Guest Lecturer

NetSuite GRC Training Hands-on training on NetSuite's GRC module for risk and controls management.
Audit Directory Training Structured training programmes delivered via Audit Directory for audit professionals.
ISO 27001 Guest Lecture Invited guest sessions on ISMS design, implementation, and audit practices.
Internal Audit Trainer (Big 4) Delivered internal audit training programmes within a Big 4 firm environment.
Industry Expert — Christ College Guest lectures on GRC, risk, and audit topics for students at Christ College.
Industry Expert — Eithraj College Guest lectures bringing industry perspective on compliance and audit to Eithraj College.

"Invest in knowledge that pays dividends across your entire career — and your organization's resilience."

Request Training
Training Enquiries

Request a
Training Programme

Fill in the form to enquire about any training programme. We accommodate individual professionals and corporate batches. We'll get back to you within 24 hours.

📞

Training Request Form

Industries We Serve

Sector-Specific
Risk Intelligence

IATGRC delivers tailored governance and compliance solutions across eight high-complexity industries — with custom advisory for emerging sectors.

🛒

FMCG

Supply chain risk assessments, operational audit optimization, and procurement controls for fast-moving consumer goods enterprises.

🏥

Healthcare

Data privacy compliance, HIPAA-aligned financial controls, and regulatory advisory for hospitals, diagnostics, and health-tech firms.

💻

ITES

Cybersecurity governance, ERP implementation controls (Oracle Cloud/SAP), and IT general controls for technology and outsourcing companies.

🏭

Manufacturing

Global entity audits, Lean process improvements, operational risk frameworks, and multi-jurisdiction compliance management.

🏦

NBFC & Banks

RBI regulatory filings, ICFR readiness, credit risk frameworks, and internal audit transformation for NBFCs and scheduled banks.

🏨

Hospitality

Revenue cycle audits, fraud risk assessments, F&B controls, and compliance advisory for hotel chains and hospitality groups.

Emerging Sectors

Specialized SOX/ITGC for EV charging, fintech, and renewable energy companies scaling towards IPO or international listings.

🔧

And More

Custom risk governance and compliance solutions for unique industry requirements. Let's build the right framework for you.

Thought Leadership

Resources &
Insights

Actionable GRC intelligence from the frontlines of enterprise risk governance and compliance advisory.

Newsletter

GRC Trends 2026: What Boards Need to Know

Emerging frameworks, AI-driven audit tools, and regulatory shifts reshaping enterprise risk governance across high-growth industries.

Read on LinkedIn →
Newsletter

SOX Compliance in Hybrid Cloud Environments

How organizations can maintain SOX 404 and ICFR integrity as workloads migrate to multi-cloud and hybrid infrastructure.

Read on LinkedIn →
Newsletter

Cyber Risk Communication for Corporate Boards

Translating technical ITGC and cybersecurity findings into actionable board-level risk reporting that drives governance decisions.

Read on LinkedIn →
Free Download

Risk Control Matrix (RCM) Template

A ready-to-use RCM template developed from 16+ years of SOX and ITGC engagements. Fully customizable for your organization.

Request via Consultation →
Free Download

SOX 404 Readiness Checklist

Step-by-step checklist for ICFR documentation, control testing, and deficiency remediation — ideal for first-time SOX filers.

Request via Consultation →
Subscribe

IATGRC Newsletter on LinkedIn

Get the latest insights on GRC, Internal Audit, SOX, ITGC, and regulatory compliance directly in your LinkedIn feed.

Subscribe Now →
Client Testimonials

Trusted Across
Engagements & Industries

What clients say about working with Ridhi across SOX, DPDP, ISO 27001, NBFC, and ECL engagements.

"

Ridhi demonstrated exceptional ownership throughout our SOX transformation initiative. Beyond delivering high-quality Business Finance and ITGC control documentation, she proactively identified process gaps and recommended practical improvements that enhanced our overall control environment. Her ability to coordinate across multiple stakeholders, manage challenging timelines, and consistently deliver beyond the agreed scope made her a trusted advisor. She combines technical expertise with strong project management skills, ensuring that every deliverable adds measurable value to the organization.

SOX Project for US Fortune 500 Company (2025–2026) Role: Consultant – Business Finance & ITGC (6-Month Engagement) Client: Confidential | US Fortune 500 Organization
"

Working with Ridhi on our DPDP Act readiness assessment was an outstanding experience. She went beyond a standard compliance review by providing actionable recommendations, prioritization of risks, and practical implementation guidance tailored to each subsidiary. Her structured approach, proactive communication, and ability to simplify complex regulatory requirements enabled our leadership team to make informed decisions. Her commitment to delivering value far exceeded the original engagement scope.

DPDP Act Impact Analysis Role: Lead Consultant – DPDP Impact Assessment Client: Confidential | European Multinational Group (Three Indian Subsidiaries)
"

Ridhi led our ISO 27001 implementation with remarkable professionalism and attention to detail. She not only established the required Information Security Management System but also introduced operational improvements that strengthened our governance practices. Her proactive engagement with different business functions, disciplined project management, and willingness to provide additional guidance whenever required ensured a smooth implementation journey. She consistently delivered more than what was contractually expected.

ISO 27001 Implementation Role: Lead Implementation Consultant Client: Confidential | Accounting & Taxation KPO
"

Ridhi played a key role in designing our compliance and policy framework with a practical, business-oriented approach. Her understanding of regulatory expectations, governance principles, and operational realities helped us develop policies that were both compliant and implementable. She demonstrated excellent planning, stakeholder management, and proactive problem-solving throughout the engagement. Her recommendations extended well beyond the original scope, creating long-term value for our organization.

NBFC Policy & Compliance Framework Design Role: Governance, Risk & Compliance Consultant Client: Confidential | Non-Banking Financial Company (NBFC)
"

Ridhi contributed significantly to the development of our Expected Credit Loss (ECL) solution by bringing together regulatory expertise, risk management knowledge, and practical business insights. She consistently anticipated challenges, proposed innovative enhancements, and ensured that the product aligned with industry expectations. Her collaborative approach, strong analytical capabilities, and commitment to quality made her an invaluable strategic partner. She continually added value beyond her assigned responsibilities and helped shape a stronger end product.

Expected Credit Loss (ECL) Product Development Role: Consulting Partner – Product Strategy & Development Client: Confidential | Financial Services Technology Initiative
Get in Touch

Start Your Risk
Transformation

Whether you need SOX readiness, a full ERM framework, or regulatory compliance advisory — IATGRC delivers with precision and expertise. Reach out for a confidential consultation.

📞
📍
Location New Delhi, India
Serving US · APAC · Europe
📰
Newsletter IATGRC on LinkedIn

Book a Consultation

✓ Request sent! We'll be in touch within 24 hours.