668: Michael Thomsen of Origin 84, Part Two - Reusable Compliance Policies, ISO 27001 Audits, and Building a Fractional GRC/Strategy Bench
/In this Command Control Power episode, host Joe and guests discuss standards, policies, certification, and compliance with Michael Thomsen of Origin 84 in Sydney, continuing an ISO 27001 deep dive. Michael explains how policies are written to solve specific control problems (e.g., MFA) and can be reusable, while areas like data classification require tailoring based on a clientโs industry, legislation, contracts, and workflows; key discovery questions include where data is stored and shared, and what obligations contracts impose. The conversation contrasts frameworks (NIST, Essential Eight) and notes auditors verify that policies drive processes and are followed, emphasizing continual improvement through audits, risk/incident tracking, and iterative remediation. Jerry and Sam share healthcare/SOC 2 experiences and discuss shifting solo consultants from tactical support to higher-value strategic advisory/account management, using fractional roles and partners. Michael outlines Origin 84โs fractional model (financial controller, HR, strategy officer, plus legal/CFO) and sourcing via professional networks, LinkedIn, and conferences like ACEs, where Michael will present on account management.
00:00 Welcome and Recap
00:45 Reusable Policies vs Tailoring
02:20 Data Classification Nuances
03:33 Discovery Questions That Matter
06:18 Building Trust Without Conflict
07:30 Insurance as the Trigger
08:47 SOC 2 and Framework Reality
10:50 Audits and Continuous Improvement
12:48 Breaking Down Compliance Work
14:07 Jerryโs Healthcare SOC 2 Case
15:49 Fractional Support Models
17:13 Move Up to Strategic Advisor
19:16 Agency and Stakeholder Dynamics
20:41 Consulting Revenue Mindset Shift
23:26 Hand Off Tactics, Lead Strategy
24:21 Healthcare Provider Experiences
24:30 Compliance Strategy Calls
25:16 Subcontracting Specialist Help
25:55 Scaling With Key Hires
28:18 Fractional Finance And HR
30:03 Fractional Strategy Officer
31:26 Outsourced Regional Support
32:31 Finding Fractional Talent
36:55 Networking At ACEs
39:41 Account Management Matters
41:51 Wrap Up And Farewell
