What we do

Compliance & Integrity

We help organisations translate legal, regulatory and ethical expectations into clear responsibilities, proportionate controls, reliable evidence and management information.

When organisations call us

  • Growth has outpaced the compliance system — policies are scattered, ownership is unclear and evidence of control execution is thin.
  • Entry into a new market, product or regulated activity changes which obligations actually apply.
  • An investor, bank, insurer or major counterparty expects a credible compliance framework — soon.
  • An incident, internal report or inspection finding requires a structured, documented response.
  • Compliance, AML, data protection, cyber and AI duplicate processes instead of sharing one architecture.

Questions we help answer

  • Which obligations genuinely apply to us — and who owns each of them?
  • Is our compliance programme proportionate to our risk profile, or a shelf of documents?
  • Which controls are critical, and how do we prove they are performed?
  • How should the board receive information about breaches, trends and remediation?

How we can support

  • Obligations map — regulatory requirements, contractual commitments and internal standards in one prioritised view.
  • Compliance risk assessment — methodology, workshops, register and priorities.
  • Operating model — roles, mandates, reporting lines, escalation and, where appropriate, a three-lines model.
  • Policy architecture — a coherent hierarchy of principles, policies, procedures, registers and evidence.
  • Third-party integrity — risk segmentation, due diligence, clauses, monitoring and escalation.
  • Speak-up and investigations governance — receiving, qualifying and overseeing reports, with clear boundaries of role.
  • Monitoring and assurance — second-line control plans, testing, indicators and findings management.
  • Board and management reporting — decision-ready dashboards, escalation thresholds and review cycles.

Typical work products

Obligations and owners map, compliance risk profile, target operating model, RACI matrix, documentation architecture, code of conduct, third-party assessment methodology, control and evidence register, monitoring plan, board reporting pack, remediation plan, role-based training materials.

We describe our reviews as gap assessments, maturity or readiness reviews — not as statutory audits or certification, which remain reserved for authorised bodies.

Bring clarity to the next decision.

A first conversation is free of charge, confidential and without obligation.

Discuss a challenge