From zero knowledge to confident practitioner
A structured path through governance, risk and compliance, no jargon, no prerequisites. Start with the foundations and progress to jurisdiction deep dives and certification preparation.
Four tracks, built to stack
Track 01 · Foundation
What governance, risk and compliance actually is, plain-language grounding in risk, controls, policy and assurance. No prerequisites.
Track 02 · Privacy core
The principles every privacy law shares, lawfulness, purpose limitation, minimisation, accuracy, retention, security and accountability.
Track 03 · Jurisdiction
Deep dives by regime, GDPR, DPDP Act, CCPA, PIPL and ASEAN laws, each with worked implementation examples.
Track 04 · Certification
ISO/IEC 27001, 27701 and 42001, clause-by-clause walkthroughs, control design, internal audit technique and evidence packs.
Learn in a logical order
Start from the foundations
No background needed. Track 01 assumes nothing and builds the vocabulary.
Apply to a real regime
Choose the jurisdiction you answer to and work through implementation examples.
Prepare for certification
Clause walkthroughs and evidence packs for ISO 27001, 27701 and 42001.
Who it's for
Boards and executives, engineers and product teams, HR and procurement, legal and, above all, anyone starting a career in GRC from zero.
Your first GRC role starts here
Guide newcomers, or become one. The Academy is open to practitioners in every jurisdiction we cover.
Browse the Academy