About Hosmak Solutions

An independent advisory practice in AI governance, technology GRC, and internal controls — built on twenty-five years inside the financial services institutions our clients answer to.

To put the governance and risk-management standard of a major financial institution within reach of the smaller firms now held to it.

The gap

Why this firm exists

Canada’s financial services sector has a structural gap. Institutional-grade governance expertise concentrates inside large banks, insurers, and the Big 4 firms that serve them — priced and scaled accordingly. Meanwhile, the firms facing the fastest-growing expectations are the smaller ones: credit unions, portfolio managers, fintechs, MGAs, and the vendors who supply regulated institutions. They face the same questionnaires, the same regulatory rulers, and the same board questions, with none of the internal machinery.

Hosmak Solutions exists to close that gap: the standard of a major institution’s risk function, sized and priced for organizations that will never need — and should never buy — a bank’s program.

In his own words

Founder’s note

Bunmi Makinde, founder of Hosmak Solutions

I’ve spent my career on every side of the table this work is done at.

I started in audit at Coopers & Lybrand in Lagos in 1995, and spent my first decade in public practice and then leading a bank’s internal IT audit unit — writing findings, and learning early that a finding nobody acts on is just paperwork with a date on it.

Then eleven years in Big 4 advisory, at PwC in Lagos and Vancouver and EY in Toronto, delivering more than fifty technology governance, risk and controls engagements for financial services clients. That’s where I learned what good looks like across many organizations — and how often frameworks are built to impress the person assessing them rather than to be operated by the people who own them.

Then nearly a decade inside one of Canada’s five largest banks, building enterprise technology risk governance from the inside: the process, risk and control framework, the risk appetite statement and KRI suite, the issue management routines, and the technology risk reporting that went to executive and board risk committees. I sat in the meetings where remediation owners explained slipped dates. Sometimes I was the one asking why. That decade taught me the thing consulting alone never could: which parts of governance actually get used, and which parts quietly die the week the consultant leaves.

I founded Hosmak Solutions because the firms that most need that experience are the ones least able to buy it at institutional prices.

It’s a privilege to put all of that to work for the small and medium-sized institutions building and strengthening their technology governance, risk and controls practices.

— Bunmi Makinde, Founder

Career

The path here

Career timeline
Years Role
1995–1998 Senior Financial Auditor, Coopers & Lybrand, Lagos
1998–2001 Assistant Audit Manager & Branch Manager, BDO
2001–2005 Head, IT Audit Unit, Keystone Bank
2005–2011 Manager, Systems & Process Assurance, PwC — Lagos, then Vancouver
2011–2016 Manager, Risk Assurance Advisory, EY, Toronto
2016–2026 Senior Risk Manager, then Associate Director, Technology & Operations Risk — one of Canada’s five largest banks, Toronto
2026– Founder, Hosmak Solutions, Toronto

Operating principles

How we work

Fixed scope, agreed first

Written scope, deliverables, timeline and fee before work begins. If the scope needs to change, that’s a conversation and a signature, not an invoice surprise.

You own what we build

Working documents in editable form, walked through with your team before we close the file. A framework you can’t maintain without us is a dependency, not a deliverable.

Sized for your organization

Proportionality is a design principle, not an excuse for less. The right framework for a firm of forty is different in kind from a bank’s — not a photocopy at reduced opacity.

We don’t review our own work

Where we’ve built something in an advisory capacity, we don’t then provide the independent review of it. We’ll flag the conflict before you see it.

Plain answers

If we’re not the right fit, we’ll say so in the first conversation and point you somewhere better.

Qualifications

Credentials and affiliations

Designations

  • FCA (Nigeria) — see designation note — Institute of Chartered Accountants of Nigeria
  • CISA — ISACA
  • CRISC — ISACA
  • AAIR — ISACA
  • CFSA — Institute of Internal Auditors
  • COBIT 5 Accredited

Frameworks and standards

  • COBIT 5
  • COSO Internal Control and ERM
  • NIST CSF and AI RMF
  • ISO/IEC 42001
  • IIA Global Internal Audit Standards
  • OSFI B-10, B-13, E-23
  • SOX 404 / ICFR

Continuing education: Harvard Business School Online — certificates of completion in Organizational Leadership and Management Essentials.

Practical details

Based in
Toronto · serving clients across Canada
Working model
Remote-first, with on-site fieldwork where the engagement requires it
Delivered under
Hosmak Solutions Canada Inc. — a federal corporation, registered to carry on business in Ontario

The first conversation is the useful one

Thirty minutes, no cost. Bring the question you’re actually facing — the board ask, the questionnaire, the finding — and you’ll leave with a straight view of what answering it takes.

Book a 30-minute consultation

Or email hello@hosmaksolutions.ca