01
We help organisations translate legal, regulatory and ethical expectations into clear responsibilities, proportionate controls, reliable evidence and management information.
- Compliance risk assessment that reflects the real business
- Policies, controls and evidence that hold up under scrutiny
- Third-party integrity and speak-up governance
Explore the area →
02
We support organisations in designing and improving risk-based financial crime frameworks that connect customer risk, controls, data, escalation and management oversight.
- Business-wide risk assessment that matches the real model
- KYC/CDD, screening and monitoring that scale
- AMLR readiness before July 2027
Explore the area →
03
We help organisations identify, govern and evidence the responsible use of AI across strategy, procurement, development, deployment and oversight.
- AI inventory, ownership and risk classification
- EU AI Act readiness on the post-omnibus timeline
- Vendor assessment and human oversight that works
Explore the area →
04
We help owners, boards and management teams build decision structures, information flows and accountability mechanisms suited to the organisation’s stage, risk and ownership model.
- Decision rights and information flows that fit the stage
- Board packs that support decisions, not archive them
- Related-party and conflict handling that stands up
Explore the area →
05
We help organisations establish practical risk, control and resilience arrangements that support decisions, ownership and recovery — not only reporting.
- Risk registers that actually change decisions
- Operational and ICT resilience (DORA / NIS2 aligned)
- Incident readiness and third-party dependency control
Explore the area →
06
We help organisations understand and strengthen the ownership, contractual, governance and risk foundations of technology, data and intangible assets.
- Chain of title for code, data and work products
- Open-source and licence hygiene before diligence
- Data provenance and rights in AI development
Explore the area →
07
We help investors and growth companies identify material governance, regulatory, IP, data and technology risks before and after investment.
- Red-flag screening before full due diligence
- Investment-ready data rooms and governance
- 100-day post-investment remediation plans
Explore the area →