Risk owner
Mo KhanjiFGIA
Governance, risk & compliance.
I’m a commercially minded GRC leader with experience across financial services, cyber assurance and applied AI. I’m comfortable with new and emerging technology and take a practical approach to risk. I believe good GRC should help a business grow and take informed risks, not slow it down with red tape.
View the register01 / Professional experience
The register.
| ID | Period | Role / Organisation | Context | Controls / Contribution | Evidence / Outcome |
|---|---|---|---|---|---|
| MK–01 | Jun 2021 — Present |
Senior Manager, GRCGridware Cybersecurity ↗Governance, Risk & Compliance |
Cybersecurity consultancy. Lead the GRC team and internal risk management, reporting to the CEO and leadership team. |
|
Clearer leadership oversight and accountability. vCISO is now a core source of GRC revenue. Control records ↓ |
| MK–02 | Feb 2026 — PresentConcurrent |
Manager, Special ProjectsWedgeX ↗Gridware innovation |
AI projects, client tooling and reporting alongside continuing GRC leadership. |
|
Client portal and reporting delivered. Desktop AI: past pilot, ready for staff-wide launch. For penetration testing and security analysis. |
| MK–03 | Jan 2020 — Jun 2021 |
Manager, Risk & ComplianceHUB24 ↗ |
Second-line risk and compliance for superannuation and investment platforms. Reported to the Head of Risk. Portfolio context +Platforms with more than $50 billion in funds under management during my tenure. |
|
Compliance management, platform assessments and audit work. |
|
2011–2020 / Within the Link Group of companies
Progressed from financial advice and compliance leadership within Link Advice, a group subsidiary, into Link Group’s second-line risk and compliance function. Link Group is now MUFG Pension & Market Services. Company links below open the current group profile. | |||||
| MK–04 | Jul 2017 — Jan 2020 |
Senior Compliance Manager, Managed FundsLink Group ↗Group second line |
Group-level second-line role with a primary remit for Link Fund Solutions, covering registry, accounting and custody services, and supporting other Link Group AFSLs. |
|
Board-level assurance findings. Compliance testing and group privacy support. |
| MK–05 | Nov 2014 — Jul 2017 |
Manager, Risk & ComplianceLink Advice ↗Advice subsidiary |
Led the subsidiary’s risk and compliance function, supporting digital, scaled and comprehensive financial advice. |
|
Electronic compliance system designed and rolled out. AFSL and dispute-resolution oversight. |
| MK–06 | Aug 2011 — Nov 2014 |
Financial Adviser → Compliance OfficerLink Advice ↗ |
Licensed financial advice, followed by a move into compliance in January 2013. |
|
Quarterly CEO Award, Q2 2014, for FoFA implementation work. |
02 / Selected work
Control records.
Selected examples, with the supporting detail.
01Leadership & governanceA clearer way to lead.Establishing the leadership committee and running internal risk.Gridware
Context
A small cybersecurity consultancy, where leadership and delivery responsibilities often overlap.
My contribution
Established the leadership committee. Maintain the organisational risk register, set policy and report to the CEO and leadership team.
What changed
Clearer oversight and accountability for goals and performance, with a forum for leaders to discuss issues and support each other.
02Consulting & assuranceFrom an offering to the first clients.Developing vCISO and Essential Eight services.Gridware
Context
Developing consulting services alongside the established ISO assurance work.
My contribution
Developed the vCISO and Essential Eight offerings, including the pitches that secured the first clients.
What changed
vCISO is now a core source of GRC revenue. Essential Eight secured work with regulated Australian organisations, including government entities.
03Special projects / Applied AIPutting specialist AI within reach.Leading the design and rollout of a desktop AI application.Gridware / WedgeX
Purpose
Give staff, particularly penetration testers, access to specialist cybersecurity models for security analysis and authorised testing.
My contribution
Led the application’s design and rollout, from the technical stack and provider risk assessment to hands-on configuration and development. Integrates multiple providers, including sovereign options, through LiteLLM.
Stage
Past pilot and ready for staff-wide launch.
03 / Qualifications & credentials
Supporting controls.

FGIAFellow 
ISO/IEC 27001Lead Auditor 
Essential EightWorking knowledge 
CIS Controls v8Working knowledge 
GDPRWorking knowledge 
NIST CSF 2.0Working knowledge
- Credentials
- Fellow & Certificate in Governance and Risk Management — Governance Institute of Australia ISO/IEC 27001 Lead Auditor — Exemplar Global · ISMS Lead Auditor — PwC Training Academy
- Working knowledge
- Tools & delivery
- Security clearance
- Level available on request
04 / Contact the owner
Let’s talk.
Sydney, Australia