Skip to content
View lbhatti-risk's full-sized avatar
  • Joined May 1, 2026

Block or report lbhatti-risk

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
lbhatti-risk/README.md

Layla Bhatti — Digital Audit and IT Risk Professional

I specialise in technical risk at the intersection of Identity Governance (IGA) and emerging regulations, specifically DORA and the EU AI Act. My work focuses on helping organisations transition from legacy manual controls to robust, audit-ready automated environments.

Current Technical Focus

IGA and PAM Migrations

Auditing the transition from manual spreadsheet-based reviews to automated security platforms such as CyberArk and Veza. I am particularly interested in the logic required to maintain population integrity during these migrations.

DORA Compliance

Developing control-mapping frameworks for ICT Third-Party Risk and Operational Resilience. I focus on how the Digital Operational Resilience Act redefines the audit requirements for critical technology service providers.

AI Governance

Developing audit programmes for Artificial Intelligence 'Identity and Access' to ensure model integrity and control over training data access.

Repository Contents

The IGA Migration Toolkit

Risk-based audit programmes designed for automated identity tools, focusing on IPE (Information Produced by Entity) and query logic validation.

DORA Readiness Crosswalks

Mappings of NIST and ISO standards to the requirements of the Digital Operational Resilience Act, specifically focusing on the third-party risk pillar.

AI Audit Artefacts

Synthetic model cards and access logs used for auditing Artificial Intelligence environments to demonstrate control over model weights and data sensitivity.

A Note on Confidentiality

All materials in this repository have been fully anonymised, restructured, and utilise synthetic data. No content originates from a live client engagement or proprietary internal system. These documents represent my personal methodologies and professional viewpoint on industry best practices.

Connect with me

Pinned Loading

  1. IGA-Migration-Audit-Toolkit IGA-Migration-Audit-Toolkit Public

    Audit frameworks for IGA and PAM migrations (CyberArk, Veza). Includes risk matrices for manual-to-automated control transitions, IPE integrity validation, and SoD conflict mapping.

  2. a-grc a-grc Public

    This repository provides digital tools for risk and compliance management. It helps teams track audit results and automate control testing. The project supports a modern approach to digital assurance.

  3. audit-workpaper-automator audit-workpaper-automator Public

    An AI-powered CLI tool designed to automate the documentation of IT General Controls (ITGC) Design & Implementation (D&I) reviews. Utilises Claude’s multimodal vision to analyse evidence, perform g…

    Python

  4. aws-security-assurance-toolkit aws-security-assurance-toolkit Public

    An automated AWS security assurance framework designed for Digital Audit professionals to evaluate control effectiveness, capture raw evidence strings, and generate formal audit workpapers for clou…

    Python 1