Skip to content

Worked examples

Fully built example artefacts, end to end. See what a finished checklist, document inventory or control mapping looks like before you build your own.

sameerkhairkar.com

Third-party (ICT) risk assessment, start to finish

The full DORA Chapter V assessment lifecycle, from deciding whether a function is critical or important through to a tested exit. Comes with a downloadable, CIF-driven assessment workbook and a process document with flowchart and RACI.

sameerkhairkar.com

DPIA + AI Act FRIA, done as one assessment

GDPR Article 35 and AI Act Article 27 as a single exercise: one scope, one risk register, two legal lenses. A cross-mapping of every required element from both regimes, a joint process flow, a worked example, and a self-contained interactive assessor.

sameerkhairkar.com

The supplier register, with the check nobody builds in

A supplier and third-party risk register for NIS2 and ISO 27001 that refuses to be a filing cabinet: a plain-language intake form, five-axis tiering, twenty-one stop signals between the request and the approval, and the sanctions and ownership screening almost every register leaves out. Twelve-step walkthrough, worked example, downloadable workbook and slide deck.

sameerkhairkar.com

Protection needs, and how criticality is inherited

Why you never rate a server on its own merits. BSI-Standard 200-2 §8.2 and ISO/IEC 27005:2022 Annex A.2 side by side: the six damage scenarios, inheritance down to every supporting asset, the maximum, cumulation and distribution effects, and risk propagating back up. Comes with an interactive protection-needs model and maximum calculator, and an editable asset-inheritance diagram.

More on the way

New worked examples get announced on the blog.