Twenty years of audits, from both sides of the table

Highpoint Risk Management Consulting is an independent practice. One principal, direct engagement, no bench.

Background

Hovsep G. Iskikian has spent roughly twenty years in governance, risk and compliance, most recently as a director of GRC and cybersecurity at a regulated fintech, where he owned audit programs and led compliance teams across PCI DSS, SOC 1 and SOC 2, SOX IT general controls and ISO 27001.

That means the work here comes from having run these programs under real deadlines with real auditors, not from having read the standards. Having sat on the management side of an assessment changes what you look for: which findings an assessor will actually pursue, which evidence holds up under sampling, and which remediation plans are realistic for a team that also has a day job.

Credentials

CISA

Certified Information Systems Auditor, ISACA. The audit credential external auditors and audit committees recognize.

PCI ISA

PCI Internal Security Assessor, PCI Security Standards Council. Formal PCI DSS assessment training, which is what makes ISA-led gap work meaningful rather than a checklist review.

  • PCI DSS
  • SOC 1
  • SOC 2
  • SOX ITGC
  • ISO/IEC 27001:2022
  • NIST CSF
  • NIST AI RMF
  • EU AI Act
  • TPRM

The name

Highpoint reflects the standard the work aims at: getting a compliance program to its highest point, and keeping it there. Certification is a moment. Staying certified is a program.

What this practice does not do

It is worth being explicit, because the boundary protects you.

No attestation. Highpoint RMC does not issue SOC reports, PCI Attestations of Compliance or ISO 27001 certificates. It is not a CPA firm, a QSA company or a certification body. Advising you and then attesting to your compliance would compromise both.

No penetration testing or managed security. Where an engagement needs those, you get a referral, not a scope extension.

No legal advice. Regulatory interpretation that carries legal consequence belongs with your counsel. The work here is building the controls and evidence that support whatever position counsel takes.

The entity

Highpoint Risk Management Consulting, LLC is a California limited liability company formed in June 2026, based in the San Francisco Bay Area and serving clients across the United States. Certificates of insurance and standard contracting documents are available on request during vendor onboarding.

Work with me directly

The person you talk to first is the person who does the work.

Start an inquiry