CV

Technology Risk and Operations professional with over ten years' experience across Big 4 consulting, global organisations, and independent business operations. I specialise in IT governance, ITGC, SOX, systems implementation support, cloud risk and controls, and operational resilience, with a practical focus on embedding control into complex service operations. I am especially interested in mission-led organisations, education, and roles where strong governance supports meaningful social impact.

Garry Costin-Davis ~ MSc, BSc, CISA, CFAB, MCMI ~ garry@costindavis.com

Core strengths

Risk & Assurance

IT audit & controls assurance, SOX and ITGC governance, cloud risk and controls, operational resilience, risk management, programme assurance, governance and compliance coordination.

SOX ITGC COBIT NIST ISO27001

Delivery & Stakeholders

Multi workstream organisation, documentation quality, stakeholder engagement, reporting, team leadership and coaching.

Systems Implementation Leadership Communication

My background spans governance, assurance, compliance coordination, data accuracy, process improvement, stakeholder communication, and multi-workstream organisation.

Professional experience

Founder / Director ~ GNAW Resources

Mar 2024 ~ Present

Operating and managing a consultancy and gaming services business delivering systems implementation support, IT controls and governance advisory, digital operations, facilitation, and client-facing gaming services.

Supporting implementation of a new payroll and HR system within an independent school environment, while providing advisory input on IT controls, governance, and ISO review activity.

Managing online and in-person service operations, digital platforms, invoicing, client coordination, branded materials, digital content, and community engagement initiatives.

IT Platforms SOX Manager ~ Vodafone

Jan 2020 ~ Mar 2024

Accountable for global IT SOX governance across Vodafone's IT Operations estate, overseeing control design, operating effectiveness, remediation strategy, and executive reporting across multi-region environments.

Led ITGC and Security control oversight for a large scale Google Cloud Platform migration, embedding cloud aligned access, change, and data controls globally and establishing control-by-design principles across DevSecOps and platform engineering teams.

Oversaw multiple concurrent transformation workstreams, ensuring controls were embedded early and remained aligned with regulatory and operational requirements, while supporting assurance strategy and regulatory readiness as an SME across IT governance.

Analysed large control datasets across multiple systems to identify inconsistencies, validate control effectiveness, and strengthen reporting accuracy; coordinated external audit engagements across global IT operations, contributing to improved audit outcomes and year-on-year reduction in control deficiencies.

Internal Audit Manager ~ IT Audit & Data Analytics (Reckitt Benckiser)

Mar 2019 ~ Dec 2019

Led delivery of IT audit engagements across financial, operational, and technology domains within a global FMCG environment.

Introduced data analytics into audit testing, increasing coverage and enabling deeper insight into control performance and risk areas; assessed IT, security, and data controls against COBIT, ISO27001, and NIST frameworks.

Delivered risk based reporting to senior stakeholders, linking technical findings to business impact and supporting prioritised remediation; identified operational and strategic technology risks across complex enterprise systems and managed stakeholder relationships across global business units to support continuous improvement.

Senior Consultant ~ Technology Risk (Ernst & Young)

Aug 2016 ~ Feb 2019

Managed end to end delivery of technology risk and IT assurance engagements across multiple clients, including planning, scoping, budgeting, and execution.

Led IT audit and digital risk assignments, coordinated cross border delivery across multi location teams, and delivered programme risk management and security review work for transformation initiatives.

Developed data analytics tools, supported innovation initiatives, and contributed to the development of graduate and junior consultants through training, coaching, and mentoring.

Global Client Data Solutions Supervisor ~ BCD Travel

Jun 2015 ~ Sep 2015

Analysed and managed large volumes of global client and operational data, improving reporting quality and supporting business decision making.

Developed and maintained data structures to improve consistency and usability across systems; delivered stakeholder reporting with a focus on clarity, accuracy, and actionable insight; led coordination across global teams to maintain data quality and meet client requirements.

System & Data Coordinator ~ Kenwood Travel

Dec 2011 ~ Jan 2015

Developed IT processes and IT service management practices; delivered training and team management; led system and data update programmes; implemented governance and lifecycle processes for reservations and controlled system usage.

Earlier career includes sales, hospitality management, customer service, and operational leadership roles. (Details on request, or in a condensed "Earlier career" section below.)

Earlier career (condensed)

Travel sales & account management

2007–2011

Tailor-made travel consulting and account management, supplier negotiation, and client relations across multiple roles.

Operations & hospitality management

2001–2007

Unit and multi site management with staffing, training, P&L responsibility, and delivery during operational change.

Education & certifications

Education

MSc — Software Engineering (Oxford Brookes University, 2016)

BSc — Mathematics and Statistics (London Metropolitan University, 2015)

Certifications & professional training

CISA (ISACA, 2018) · CFAB (ICAEW, 2017) · PRINCE2 (2015)

TQUK Level 3 Award in Supporting Teaching and Learning in Schools (2025)

Community & volunteering

I support community organisations through volunteering, including schools and local support services.

Examples include: Cheshire East Libraries, Marlfields Primary Academy, MENCAP, Reading Voluntary Association, Micklands Primary School, and RSPCA.

Skills & competencies

Organisational risk

ITGC & SOX, technology risk management, IT audit & assurance, GRC, cloud risk & controls, COBIT / ISO27001 / NIST, risk assessment & control testing, DevSecOps controls, technology transformation assurance, third-party risk, and data analytics.

Professional competencies

Stakeholder engagement, risk, audit and delivery teams, risk based decision making, operational resilience, governance and assurance, cross functional communication, and pragmatic leadership in complex, regulated environments.

Interests

Travel · Volunteering · Tabletop Gaming · 3D Printing · Game Design