INDEPENDENT TECHNOLOGY RISK & GRC CONSULTANCY
Build the control once.
Let it hold when the rules change.
Resilient Control designs technology risk, cyber and compliance frameworks for financial institutions engineered to absorb regulatory change on their own — so you stop paying to re-explain the same control every time a rule moves.
THE PROBLEM WITH THE USUAL APPROACH
You don't call your driving instructor every time a speed limit changes. Your compliance shouldn't need a Big 4 team every time a regulation does.
Big 4 engagements are built to repeat. A framework gets designed, a fee gets paid, a regulation shifts eighteen months later, and the same engagement starts again — because the framework was never built to adjust itself.
Resilient Control designs it differently. The frameworks I build are engineered to absorb regulatory change at the point it happens, not at the point someone gets re-engaged to notice it.
Same rigor. Delivered by someone who has actually run these controls inside a bank — at a fraction of the ongoing cost, because the ongoing cost mostly disappears.
WHERE THE FRAMEWORK ANCHORS
Six disciplines. One resilient structure.
Each anchors independently, and holds the others steady when one of them shifts.
CYBER / CISSP
Cybersecurity Leadership
CISSP-certified security governance — control design, third-party and cloud risk, and incident response built from direct, hands-on practice inside regulated banks.
GRC
Governance, Risk & Compliance
End-to-end GRC framework design — policy, risk appetite, control ownership — built to run without a standing consulting retainer behind it.
TECH RISK
Technology Risk Control
First-line technology risk ownership: control-by-design embedded directly into engineering and delivery, not bolted on after the fact.
DORA
Operational Resilience
DORA-aligned resilience governance, Important Business Services mapping and scenario testing, implemented inside a bank under live supervision.
RCSA
Risk & Control Self-Assessment
RCSA frameworks designed for genuine self-assessment — not a spreadsheet exercise repeated every audit cycle.
TPRM
Third-Party Risk Management
Vendor and supplier risk governance across the full lifecycle — onboarding, due diligence, ongoing monitoring and exit.
Every engagement includes technical programme and project management — someone has to actually deliver the framework, not just design it.
BIG 4 VS RESILIENT CONTROL
The same rigor. A structurally different cost curve.
The Retainer Model
- Framework re-explained at every engagement
- Junior teams rotate through your account
- Billed by the hour, scoped to expand
- Re-engagement required for every regulatory update
Resilient Control
- Framework engineered to adapt on its own
- One practitioner, 25+ years inside the institutions you're securing
- Fixed-scope delivery, built to hand over
- Regulatory changes absorbed without a new SOW
WHO'S BUILDING IT
Twenty-five years inside the institutions you're securing against.
- CertificationCISSP · PMP
- EducationExecutive MBA, Univ. of Tsukuba
- Experience25+ years
- InstitutionsSMBC · AT&T · Citigroup
- Regulators engagedPRA · FCA · BaFin
Resilient Control is built and run by Sainul Hossain, a CISSP-certified technology risk executive who has spent 25+ years inside regulated financial institutions — most recently leading Technology Risk Control at SMBC Group, and before that in senior infrastructure and governance roles at AT&T and Citigroup.
He has built compliance and control functions from the ground up three times over — including a technology risk and controls function created from nothing as SMBC moved through a live transition to enhanced ECB supervision — and has engaged directly with the PRA, FCA and BaFin on live regulatory examinations.
That's the practitioner difference: frameworks designed by someone who has owned the control, not reviewed it from the outside.
START THE CONVERSATION
Book a no-obligation intro call.
Based in London. Working with financial institutions across the UK and Europe.