Consulting
We advise where the disciplines meet.
Legal, regulatory, risk and technology judgement for decisions that run through the whole organisation: from licences to operate to implementing a new rule or validating a model.
Legal and regulatory
The legal framework runs through every area. We build it with you if you are starting, and comply with and update it if you already operate.
Regulatory complianceCompliance programmes, responses to supervisors, personal data protection and remediation plans.
- Compliance programmes
- Supervisory requests
- Data protection
- Remediation plans
- Requirements mapped to the control and the evidence that proves it.
- Responses drafted with the data that backs them.
- Plans with owners and dates, not intentions.
New regulation implementationFrom interpretation to operation, across every area a new rule touches.
- Interpretation
- Gap analysis
- Processes and systems
- Regulatory reporting
- What the rule requires, from whom and from when.
- What changes in processes, systems, models and reports.
- Implementation coordinated with technology and risk.
Internal policiesPolicies for any area: risk, investments, data, third parties, security and conduct.
- Risk and investments
- Data and security
- Third parties and suppliers
- Corporate governance
- Policies short enough to be followed.
- Controls tied to the process that enforces them.
- Reviewed on a calendar, not after the incident.
Contracts and licensingCommercial, corporate and technology contracts, and the licences and authorisations to operate.
- Licences and authorisations
- Corporate structuring
- Technology contracts
- Commercial agreements
- Negotiated by someone who also understands the business and the technology.
- Exit and transition agreed at signing, not at the breakup.
- Coordinated with your legal team and outside counsel.
Risk and models
We quantify risks of every kind and leave models ready to be defended before a committee or a supervisor.
Risk quantification methodologiesMethodologies to measure financial and non-financial risks, from legal to operational.
- Financial risk
- Non-financial risk
- Scenarios and stress
- Methodology documentation
- Methodology written so a third party can reproduce it.
- Explicit assumptions and limits.
- Fitted to the scale and industry of each organisation.
Independent model validationValidation separate from whoever built the model: assumptions, data, performance and documentation.
- Validation
- Backtesting
- Data quality
- Findings report
- Reproducible tests with evidence.
- Findings ranked by impact.
- A report a committee understands, not only an analyst.
Risk appetite and limitsAppetite frameworks, limits and indicators, with reporting to the board and committees.
- Risk appetite
- Limits and indicators
- Committee reporting
- Monitoring
- Limits that can be measured with the data that exists.
- Alerts with thresholds and owners.
- Reports shaped for whoever decides.
Strategy and technology
Architecture, vendor and governance decisions, made before they get expensive.
Technology strategy and architectureArchitecture, roadmap and the decision to build, buy or integrate.
- Architecture
- Build or buy
- Roadmaps
- Costs and risks
- A written recommendation with the trade-offs made explicit.
- Costed options, including the cost of doing nothing.
- We can stay to implement it.
Transformation and vendor selectionTransformation programmes and vendor selection, with technical, legal and risk criteria.
- Transformation
- Vendor selection
- Third-party risk
- Negotiation
- Criteria defined before seeing the offers.
- Vendor risk assessed alongside price.
- Contract aligned with what was assessed.
Technology and data governanceRoles, policies and controls so technology and data are managed in an orderly way.
- IT governance
- Data governance
- Roles and responsibilities
- Controls
- Owners defined by domain.
- Measurable controls.
- Coordinated with the organisation's corporate governance.
Two ways to handle the legal side
Depending on what is at stake, the answer may need a signature or it may need speed.
Signed by a lawyer
Legal counsel
Opinions, contracts and documents signed by licensed lawyers, for formal decisions and filings.
Not a signed opinion
AI-assisted regulatory support
Regulation lookup, summaries, assisted interpretation and first-pass document review, with legal AI tools. It is fast guidance, not a signed legal opinion; when a case needs it, it moves to legal counsel.
Ways of working
Advisory work is agreed case by case. Every model follows the same method.
Diagnostic
A short engagement to understand the situation and decide what to do.
Ends in a report and a roadmap.
Project
A defined scope, with agreed deliverables and dates.
A rule to implement, a policy to design, a model to validate.
Ongoing support
Recurring advice, available when the question comes up.
For those who need judgment on a standing basis.
We work with your advisers
We don't replace your legal team or your outside counsel: we work with them. We bring the regulatory, risk and technology view that is often missing from the table, and we coordinate so decisions are made with everything in sight.
Our standardised services are contracted under a master agreement, the published terms of each service and a service order. Consulting engagements are governed by a contract agreed with each client. See Legal
Book a consultation
A cap of 12 months of fees is low for regulated data. Propose a carve-out for data protection breaches.