Course 2: Audit-Ready GRC Portfolio Builder
Course 2: Audit-Ready GRC Portfolio Builder

Learn How GRC Analysts Execute β€” and Build the Audit-Ready Portfolio That Proves It.

In Course 1, you built TechFlow's Risk Register. In Course 2, you build the policies, controls, vendor assessments, and evidence that prove every risk in that register is being managed β€” the way a SOC 2 Type II auditor needs to see it.

Over 6 weeks, you take TechFlow Solutions from β€œrisks identified” to β€œaudit-ready.” You produce 22 operational artifacts across 6 modules: scope and data documentation, policies, controls and evidence, vendor risk, incident response, and audit readiness.

You leave with proof that you can build, document, and defend an operational GRC program β€” not just describe one.

Best for: GRC professionals and serious career changers ready to show employers operational depth, not just conceptual understanding.

Timeline6 Weeks
OutcomeAudit-Ready Portfolio Deliverables
SupportWeekly Live Sessions
PathAudit β†’ Controls β†’ Evidence β†’ Readiness

Led by Dr. Rose Shumba, PhD Β· 20+ years in cybersecurity education Β· Former NSA/DHS Center of Academic Excellence Director Β· Featured in The New York Times Β· 500+ career transitions supported

Start Here

Welcome from Dr. Rose Shumba

Start with this welcome video to understand how Course 2 continues the TechFlow case study and what audit-ready operational GRC work means.

Course Overview

See How Course 2 Builds the Audit-Ready Portfolio

This overview walks you through the Course 2 structure, the TechFlow SOC 2 readiness scenario, and the operational artifacts you will build across the course.

The Hiring Reality

Course 2 Podcast: What Audit-Ready GRC Work Looks Like

A short industry conversation on why policies, controls, evidence, vendor risk, and audit-readiness matter in operational GRC roles.

Press play to listen
What Audit-Ready GRC Work Looks Like
Listen before you review the Course 2 portfolio artifacts.
Podcast
The Problem

You do not need more theory. You need work you can show.

Many people study GRC but still struggle when it is time to explain what they can actually do.

"Can you walk me through a control library you built?"
"How would you organize evidence for an audit?"
"How would you document vendor risk?"

They can define controls. They can name frameworks. They can talk about SOC 2.

But when a hiring manager asks them to show and explain the work, that is where many candidates get stuck.

This course helps close that gap. You will build the work.

The Promise

By the end, you will have an operational GRC portfolio.

You will work through TechFlow, a healthcare technology company preparing for its first SOC 2 Type II audit.

What You Will Build

Artifact 01

Scope, Asset, and Data Documentation

Artifact 02

Security and Vendor Risk Policies

Artifact 03

SOC 2 Control and Evidence Documentation

Artifact 04

Vendor Risk and Customer Assurance Materials

Artifact 05

Incident Response and Tabletop Documentation

Artifact 06

90-Day Audit Readiness Plan

Who This Is For

This course is for you if you are ready to move from studying GRC to building GRC work.

Course 1 Completers Ready for the Next Level

You have already started building GRC portfolio proof and now want to go deeper into audit-ready work, controls, evidence, policies, vendor risk, and operational documentation.

Students Preparing for Operational GRC Roles

You want to move beyond basic risk concepts and learn how GRC work shows up inside audit preparation, evidence collection, vendor reviews, control documentation, and customer assurance.

Professionals Who Need Audit and Evidence Skills

You may come from IT, compliance, audit, healthcare, operations, project management, or another adjacent field. This course helps you organize and explain audit-ready work in a way employers can evaluate.

Enrollment

Choose Your Course 2 Option

Start Course 2 after completing Course 1 and build your audit-ready GRC portfolio.

Independent option Β· June Cohort

Self-Paced Course

Best for learners who want to complete the course independently.

$397
Course Price

Includes full course access for independent completion.

Enroll Self-Paced β€” $397
Certificate of Completion and Reference Letter from Dr. Rose Shumba awarded upon completing all required coursework and deliverables.

All courses are digital products. No refunds. All sales are final.

Frequently Asked Questions

Questions before you enroll?

Yes. You must complete Course 1: GRC Portfolio Builder before enrolling in this course. Course 2 builds directly on the work you create in Course 1.
Course 1: GRC Portfolio Builder focuses on risk analysis, framework awareness, security gaps, and the risk register. Course 2: Audit-Ready GRC Portfolio Builder focuses on operational GRC artifacts: policies, controls, evidence tracking, vendor risk, incident response, SOC 2 readiness materials, and audit support.
No. This is a hands-on portfolio-building course.
Yes. Students who complete all required coursework and deliverables receive a Certificate of Completion and a Reference Letter from Dr. Rose Shumba.
That is why the course uses a realistic case study. You build the work in a guided environment and learn how to explain it clearly.
The June cohort is a 6-week program. Students will move through the TechFlow audit-readiness case study with a structured weekly focus on controls, evidence, policies, vendor risk, incident response, and audit readiness.
$497 is the June cohort price for the hybrid version of Course 2. The regular hybrid price is $697. This pricing is available for the current June enrollment period only.
$297 is the June cohort price for the self-paced version of Course 2. The regular self-paced price is $397. This pricing is available for the current June enrollment period only.

Ready to Build Your Audit-Ready Portfolio in 6 Weeks?

Join the June cohort and build the operational GRC documents, controls, evidence trackers, and audit-readiness materials hiring managers want to see.

Practical portfolio work. Built around the TechFlow SOC 2 readiness case study.

Have you completed Course 1? If not, start there first.

Go to Course 1: GRC Portfolio Builder β†’
© 2026 Dr. Rose Shumba Β· Course 2: Audit-Ready GRC Portfolio Builder
Kudzai Edu Group