MKWorking risk registerMo Khanji / Sydney

Risk owner

Mo KhanjiFGIA

Governance, risk & compliance.

I’m a commercially minded GRC leader with experience across financial services, cyber assurance and applied AI. I’m comfortable with new and emerging technology and take a practical approach to risk. I believe good GRC should help a business grow and take informed risks, not slow it down with red tape.

View the register

01 / Professional experience

The register.

Full CV
Career register: roles, context, contributions and evidence. Current responsibilities followed by earlier experience.
IDPeriodRole / OrganisationContextControls / ContributionEvidence / Outcome
MK–01 Jun 2021
— Present

Senior Manager, GRC

Gridware Cybersecurity ↗Governance, Risk & Compliance

Cybersecurity consultancy. Lead the GRC team and internal risk management, reporting to the CEO and leadership team.

  • Maintain the risk register, set policy and work with leaders to manage their risks.
  • Established the leadership committee and developed the vCISO and Essential Eight offerings, including pitches to the first clients.
  • Lead ISO 27001 implementation and audit work, SOC 2 readiness and business continuity exercises. Present findings to boards and executive teams.

Clearer leadership oversight and accountability.

vCISO is now a core source of GRC revenue.

Control records ↓
MK–02 Feb 2026
— PresentConcurrent

Manager, Special Projects

WedgeX ↗Gridware innovation

AI projects, client tooling and reporting alongside continuing GRC leadership.

  • Delivered the client portal and automated reporting; coordinated initial client and pilot onboarding.
  • Led the design and rollout of a desktop AI application integrating specialist cybersecurity models and sovereign providers through LiteLLM.
  • Responsibilities span the technical stack, provider risk assessment and hands-on configuration and development.

Client portal and reporting delivered.

Desktop AI: past pilot, ready for staff-wide launch.

For penetration testing and security analysis.
MK–03 Jan 2020
— Jun 2021

Manager, Risk & Compliance

HUB24 ↗

Second-line risk and compliance for superannuation and investment platforms. Reported to the Head of Risk.

Portfolio context +

Platforms with more than $50 billion in funds under management during my tenure.

  • Oversaw the compliance management system and assessed operations against Corporations Act, APRA and ASIC obligations.
  • Conducted audits and compliance assessments, working with Legal and Compliance on regulatory obligations.

Compliance management, platform assessments and audit work.

2011–2020 / Within the Link Group of companies

Progressed from financial advice and compliance leadership within Link Advice, a group subsidiary, into Link Group’s second-line risk and compliance function.

Link Group is now MUFG Pension & Market Services. Company links below open the current group profile.
MK–04 Jul 2017
— Jan 2020

Senior Compliance Manager, Managed Funds

Link Group ↗Group second line

Group-level second-line role with a primary remit for Link Fund Solutions, covering registry, accounting and custody services, and supporting other Link Group AFSLs.

  • Rolled out the compliance testing plan for Link Fund Solutions.
  • Audited a robo-advice tool against ASIC RG 255, presenting findings to the Link Group Board.
  • Delivered privacy awareness training following the 2018 data breach reporting changes and supported the group’s GDPR data protection policy.

Board-level assurance findings.

Compliance testing and group privacy support.

MK–05 Nov 2014
— Jul 2017

Manager, Risk & Compliance

Link Advice ↗Advice subsidiary

Led the subsidiary’s risk and compliance function, supporting digital, scaled and comprehensive financial advice.

  • Led the design and rollout of the Link Electronic Compliance System (LECS).
  • Managed AFSL obligations: responsible manager changes, licence conditions, regulatory lodgements and audit preparation.
  • Managed external dispute resolution matters.

Electronic compliance system designed and rolled out.

AFSL and dispute-resolution oversight.

MK–06 Aug 2011
— Nov 2014

Financial Adviser → Compliance Officer

Link Advice ↗

Licensed financial advice, followed by a move into compliance in January 2013.

  • Provided licensed financial advice.
  • Worked on the Future of Financial Advice implementation project.

Quarterly CEO Award, Q2 2014, for FoFA implementation work.

02 / Selected work

Control records.

Selected examples, with the supporting detail.

01Leadership & governanceA clearer way to lead.Establishing the leadership committee and running internal risk.Gridware

Context

A small cybersecurity consultancy, where leadership and delivery responsibilities often overlap.

My contribution

Established the leadership committee. Maintain the organisational risk register, set policy and report to the CEO and leadership team.

What changed

Clearer oversight and accountability for goals and performance, with a forum for leaders to discuss issues and support each other.

02Consulting & assuranceFrom an offering to the first clients.Developing vCISO and Essential Eight services.Gridware

Context

Developing consulting services alongside the established ISO assurance work.

My contribution

Developed the vCISO and Essential Eight offerings, including the pitches that secured the first clients.

What changed

vCISO is now a core source of GRC revenue. Essential Eight secured work with regulated Australian organisations, including government entities.

03Special projects / Applied AIPutting specialist AI within reach.Leading the design and rollout of a desktop AI application.Gridware / WedgeX

Purpose

Give staff, particularly penetration testers, access to specialist cybersecurity models for security analysis and authorised testing.

My contribution

Led the application’s design and rollout, from the technical stack and provider risk assessment to hands-on configuration and development. Integrates multiple providers, including sovereign options, through LiteLLM.

Stage

Past pilot and ready for staff-wide launch.

03 / Qualifications & credentials

Supporting controls.

Credentials
Fellow & Certificate in Governance and Risk Management — Governance Institute of Australia ISO/IEC 27001 Lead Auditor — Exemplar Global · ISMS Lead Auditor — PwC Training Academy
Working knowledge
  • ISO 27001
  • Essential Eight
  • CIS Controls v8
  • GDPR
  • SOC 2 readiness
  • NIST CSF 2.0
  • ISO 31000
  • ASD ISM
  • APRA
  • ASIC
  • AFSL compliance
  • Privacy Act & APPs
Tools & delivery
  • Vanta
  • Drata
  • Hyperproof
  • 6clicks
  • Secureframe
  • Jira
  • Confluence
  • Power BI automation
  • Python automation
Security clearance
Level available on request

04 / Contact the owner

Let’s talk.

Sydney, Australia