Worked examples¶
Fully built example artefacts, end to end. See what a finished checklist, document inventory or control mapping looks like before you build your own.
Third-party (ICT) risk assessment, start to finish
The full DORA Chapter V assessment lifecycle, from deciding whether a function is critical or important through to a tested exit. Comes with a downloadable, CIF-driven assessment workbook and a process document with flowchart and RACI.
sameerkhairkar.comDPIA + AI Act FRIA, done as one assessment
GDPR Article 35 and AI Act Article 27 as a single exercise: one scope, one risk register, two legal lenses. A cross-mapping of every required element from both regimes, a joint process flow, a worked example, and a self-contained interactive assessor.
sameerkhairkar.comThe supplier register, with the check nobody builds in
A supplier and third-party risk register for NIS2 and ISO 27001 that refuses to be a filing cabinet: a plain-language intake form, five-axis tiering, twenty-one stop signals between the request and the approval, and the sanctions and ownership screening almost every register leaves out. Twelve-step walkthrough, worked example, downloadable workbook and slide deck.
sameerkhairkar.comProtection needs, and how criticality is inherited
Why you never rate a server on its own merits. BSI-Standard 200-2 §8.2 and ISO/IEC 27005:2022 Annex A.2 side by side: the six damage scenarios, inheritance down to every supporting asset, the maximum, cumulation and distribution effects, and risk propagating back up. Comes with an interactive protection-needs model and maximum calculator, and an editable asset-inheritance diagram.
More on the way
New worked examples get announced on the blog.