Johnny Vaughan, LLC — Chesapeake, Virginia

GRC delivery capacity for regulated businesses and the firms that serve them.

Third-party risk assessments, compliance readiness, and security documentation. Fixed scopes, defined deliverables, exclusions in writing before work starts.

CRISCCTPRP8+ years GRC and IT audit40+ vendor assessmentsFinancial services, healthcare, federal

Who this is for

Two situations, one gap

A customer sent a security questionnaire, a contract added a compliance requirement, or an insurer asked questions you cannot currently answer. You need the work done correctly the first time, without hiring a full-time compliance function.

Or you are a consultancy with signed compliance work and more of it than your team can deliver this quarter. You need someone who can execute inside your methodology without training.

The work below is grounded in eight years of practice across financial services, healthcare, and federal environments, including Big Four technology risk consulting and federal authorization documentation under NIST SP 800-53.

Service 01

Third-party risk and vendor assessments

I have performed more than 40 vendor security assessments end to end: intake, scoping, questionnaire and SIG review, SOC report and evidence analysis, control evaluation, risk rating, findings, and remediation validation.

Single vendor review

Questionnaire analysis, evidence review, documented risk rating, and findings for one vendor.

Fixed quote based on criticality and evidence volume

Assessment overflow

Execution inside your existing methodology and tooling, with weekly capacity agreed in advance.

Hourly, quoted per inquiry

TPRM program diagnostic

Review of intake, tiering, assessment, and remediation processes with a prioritized improvement roadmap.

Fixed quote after scoping

Sample deliverable: Third-party risk assessment report (PDF)
Built on synthetic data. Illustrates structure, analysis depth, and reporting format.

What this is not

This is risk assessment and advisory, not an audit opinion, a certification, a penetration test, or a legal determination. Assessments rely on the evidence the vendor provides. I document evidence gaps rather than work around them.

Service 02

Compliance readiness and audit evidence

I assess organizations against NIST SP 800-53, NIST CSF, ISO 27001, SOC 2, SOX ITGC, PCI DSS, GLBA, FFIEC, and HIPAA. The difference from a checklist exercise is that I evaluate the evidence itself, the way an assessor will.

Readiness diagnostic

Control-gap analysis against your target framework, evidence-quality review, and a remediation roadmap prioritized by risk and implementation effort.

Fixed quote based on framework and system scope

Audit evidence sprint

PBC tracking, evidence collection and indexing, control narratives, and issue-response support through fieldwork.

Fixed quote per sprint

Access review execution

User and privileged access reviews, entitlement reconciliation, exception investigation, and a complete audit evidence package.

Fixed quote per review cycle

What this is not

This is audit support and readiness advisory, not independent assurance or attestation. Framework, systems in scope, evidence population, and exclusions are defined in writing before any fixed price is quoted. Production system changes remain with your administrators.

Service 03

Policies, procedures, and federal documentation

Generic templates fail evidence review because they describe an organization that does not exist. I write documentation from interviews with the people who perform the work, validated against how the process actually operates.

Federal experience includes System Security Plans, FIPS 199 categorizations, privacy documentation, and NIST SP 800-53 control statements through the Revision 4 to Revision 5 transition.

Individual policy, SOP, or procedure

Built from process-owner interviews and validated against current practice.

Quoted per document

Policy suite

A scoped set covering a framework's documentation requirements, sequenced so each document references the others correctly.

Priced by document count after scoping

Federal RMF and FedRAMP documentation support

SSP and control-statement updates, artifact quality review, evidence mapping, and POA&M maintenance for integrators and subcontractors.

Hourly, quoted per inquiry

What this is not

I do not resell templates as tailored work. For federal engagements: I am not a 3PAO, do not hold assessor-of-record authority, and do not represent clearance status. Support is documentation and evidence quality, not authorization decisions.

Background

How I work

Fixed scope where the work permits, hourly where it does not. Every engagement starts with the deliverable, the quote, and the exclusions in writing. I would rather decline work I cannot deliver defensibly than produce a report that fails review.

I also build compliance automation in Python and Terraform. That work is public, along with a longer record of my background.

Portfolio and project source: portfolio.johnnyvaughanllc.com
Certifications: CRISC (ISACA), CTPRP (Shared Assessments)
President, Norfolk chapter, GRC Engineering Club

Contact

Start with the requirement

Describe what you are facing, the framework if you know it, and the deadline. I respond within two business days with a scoped approach.