Compliance & Integrity
We help organisations translate legal, regulatory and ethical expectations into clear responsibilities, proportionate controls, reliable evidence and management information.
When organisations call us
- Growth has outpaced the compliance system — policies are scattered, ownership is unclear and evidence of control execution is thin.
- Entry into a new market, product or regulated activity changes which obligations actually apply.
- An investor, bank, insurer or major counterparty expects a credible compliance framework — soon.
- An incident, internal report or inspection finding requires a structured, documented response.
- Compliance, AML, data protection, cyber and AI duplicate processes instead of sharing one architecture.
Questions we help answer
- Which obligations genuinely apply to us — and who owns each of them?
- Is our compliance programme proportionate to our risk profile, or a shelf of documents?
- Which controls are critical, and how do we prove they are performed?
- How should the board receive information about breaches, trends and remediation?
How we can support
- Obligations map — regulatory requirements, contractual commitments and internal standards in one prioritised view.
- Compliance risk assessment — methodology, workshops, register and priorities.
- Operating model — roles, mandates, reporting lines, escalation and, where appropriate, a three-lines model.
- Policy architecture — a coherent hierarchy of principles, policies, procedures, registers and evidence.
- Third-party integrity — risk segmentation, due diligence, clauses, monitoring and escalation.
- Speak-up and investigations governance — receiving, qualifying and overseeing reports, with clear boundaries of role.
- Monitoring and assurance — second-line control plans, testing, indicators and findings management.
- Board and management reporting — decision-ready dashboards, escalation thresholds and review cycles.
Typical work products
Obligations and owners map, compliance risk profile, target operating model, RACI matrix, documentation architecture, code of conduct, third-party assessment methodology, control and evidence register, monitoring plan, board reporting pack, remediation plan, role-based training materials.
We describe our reviews as gap assessments, maturity or readiness reviews — not as statutory audits or certification, which remain reserved for authorised bodies.
Bring clarity to the next decision.
A first conversation is free of charge, confidential and without obligation.