Services

Support shaped around the file you need.

Each service below is a defined piece of compliance support. You can commission one of them or combine them in a single proposal. None of them is legal advice, an audit opinion, or a guarantee of a third-party decision.

The offer explains how a fee is set. The details explain the working sequence. If you are unsure which line fits, request a scoping note.

A fountain pen lying across a blank lined page of a spiral notebook.
The page stays plain until the scope is named. Then it is written so the owner can follow it.

01

Compliance program design

Purpose

A working structure for who owns compliance topics, how often they are reviewed, and where issues are recorded.

Description

A compliance program, in this practice, is not a binder of every rule that might ever apply. It is the operating map: which topics are in scope, who is accountable, how often the map is reviewed, and how an issue is logged and closed. The design is scaled to the team that will run it. A founder-led company and a multi-site operator do not receive the same map.

The practice facilitates the design and writes it down. The organization remains responsible for running it and for confirming that the topics match its real activity.

Scope

Included: a program outline, a responsibility map, a review calendar, and an issue-log template. Excluded: a legal opinion on whether a license is required, a representation to a regulator, and day-to-day operation of the program unless ongoing coordination is agreed separately.

Process

  1. Confirm the topics the leadership team wants inside the program.
  2. Identify the people who already touch those topics.
  3. Draft the outline, the ownership map, and the review rhythm.
  4. Walk through the draft with the owners and revise it once within the agreed rounds.
  5. Hand over the file and the list of topics deliberately left out.

Deliverables

  • Program outline stating purpose, topics, and limits.
  • Responsibility map with a named owner for each in-scope topic.
  • Review calendar for the coming year.
  • Issue-log template with fields for owner, status, and closure.

Intended customer

A leadership team that knows compliance matters and does not yet have a structure, or a team whose current structure lives in the memory of one person. Organizations in that position are described on the organizations page.

02

Policy and procedure documentation

Purpose

Policies and short procedures written in plain language, each with an owner and a review date.

Description

Policies fail when they describe an imagined company. This service drafts, or rewrites, the policies and the short procedures underneath them so they match the way the organization actually works. The language is plain. Each policy states who owns it, who it applies to, and when it will be reviewed. Procedures are the steps a person follows on a Tuesday, not a restatement of the policy in longer words.

The client supplies the operational facts and confirms them. Where a topic needs a legal reading, the draft marks that question instead of disguising it as settled text. Counsel can review the draft. The practice does not replace that review.

Scope

Included: an agreed list of policies, drafts, one index, and a revision table. The number of policies and the rounds of comment are set in the proposal. Excluded: employment contracts, privacy notices that require a legal opinion, and any filing with an authority.

Process

  1. Collect the documents that already exist and the complaints people have about them.
  2. Agree the list. A topic that is out of list is not drafted for free.
  3. Draft in plain language and mark open questions in the margin of the working file.
  4. Take comments from the named owners.
  5. Issue final versions and the index.

Deliverables

  • The agreed policy set and the related short procedures.
  • A one-page index with owner and review date.
  • A revision table showing what changed from the previous version, where one existed.

Intended customer

Companies whose policies are outdated, contradictory, or stored in a single inbox. Also teams that have no written policy for a topic a customer has just asked about.

03

Obligation mapping and gap review

Purpose

A prioritized map of gaps for the topics you name, based on your documents and how the work is actually done.

Description

A gap review answers a practical question: against the topics you have named, where is the organization exposed because a document, a control, or an owner is missing? The topics might include privacy documentation, workplace conduct, vendor oversight, record-keeping, or the support around financial controls. The map is a working paper. It is not a certificate that you comply with a statute, and it is not a statutory audit.

The practice reads what you provide and speaks with the people you make available. If a source is missing, the gap is recorded as an unknown, not filled with an assumption. Priorities are suggested so a small team can see what to do first. You decide the order.

Scope

Included: the themes named in the proposal, a document review, a limited set of interviews, and a written map. Excluded: a review of themes you did not name, technical security testing, forensic work, and any opinion addressed to a regulator or a bank.

Process

  1. Agree the themes and the questions the map must help you answer.
  2. Read the materials and hold the agreed interviews.
  3. Draft the map with priorities and open questions.
  4. Hold a review meeting and correct factual errors.
  5. Issue the final map.

Deliverables

  • An obligation map for the agreed themes.
  • A gap list with a suggested priority.
  • An open-questions list, separated from confirmed findings.

Intended customer

Teams preparing for diligence, a customer questionnaire, or an internal decision about what to fix first. If the map shows that policies need rewriting, policy documentation can follow under its own scope.

04

Controls and evidence framework

Purpose

A register that ties each in-scope control to the evidence that should exist, where it is kept, and who keeps it.

Description

Policies say what should happen. Evidence shows what did happen. This service builds the link. For each control inside the agreed scope, the practice defines the evidence a reasonable reviewer would expect to see, where that evidence lives, and who is responsible for keeping it. The result is a register the organization can maintain.

The practice designs the framework. It does not operate the controls and it does not attest that they are effective. A register that claims effectiveness without testing would mislead the next reader, so the register does not say that.

Scope

Included: selection of controls from an existing program or gap map, evidence definitions, a register template, and retention notes for the evidence you choose to keep. Excluded: penetration testing, financial statement audit, and a control-effectiveness opinion.

Process

  1. Start from the program or the gap map, not from a blank universal control list.
  2. Select the controls that matter for the stated purpose.
  3. Define the evidence and the keeper for each one.
  4. Walk through the register with the owners.
  5. Hand over the matrix and the template.

Deliverables

  • A control-to-evidence matrix.
  • A register template the team can keep using.
  • Short retention notes for the evidence types you decide to hold.

Intended customer

Operators who already have policies but cannot show a trail when a partner, customer, or board member asks. The framework is often commissioned after a gap review.

05

Vendor and third-party review support

Purpose

A repeatable way to tier suppliers, ask useful questions, and record the decision you make.

Description

Suppliers who touch data, money, or a critical operation need a check that can be repeated, not a fresh improvisation each time a contract renews. This service builds that check: tiers based on the access or dependence involved, a questionnaire that matches the tier, and a log of the decision. The practice can help run a first cycle with a sample of vendors and then leave the method with you.

A completed questionnaire is not a promise that a vendor is safe. It is a record of what was asked, what was answered, and what you decided. Technical security testing, if you need it, is a different profession and is outside this service.

Scope

Included: a tiering note, a questionnaire, a review checklist, and a sample decision log for the vendors named in the proposal. Excluded: negotiating the vendor contract, legal review of liability clauses, and on-site audits of the vendor.

Process

  1. List the suppliers that matter and the reason each one matters.
  2. Define tiers and the questions that belong to each tier.
  3. Review the sample with you and record the decision.
  4. Adjust the checklist where a question proved useless.
  5. Hand over the pack so the next renewal can follow it.

Deliverables

  • Vendor tiering note.
  • Questionnaire and review checklist.
  • Sample decision log for the agreed vendors.

Intended customer

Companies that rely on a handful of suppliers and have so far handled them ad hoc. Particularly relevant when a customer asks how third parties are reviewed.

06

Ongoing coordination

Purpose

A retained rhythm of action logs, review reminders, and short status notes after the documents are in place.

Description

A program goes quiet when nobody keeps the log. Ongoing coordination is the retained service that prevents that. On the cadence in the proposal, the practice updates the action log, prompts owners before review dates, and writes a short status note. It is coordination. It is not a substitute for an in-house officer where a law or a contract requires a named person with specific duties.

The monthly or quarterly shape, the hours, and the meetings are written down before the retainer starts. Extra topics are quoted before they are added. Emergency representation before an authority is not part of the retainer.

Scope

Included: the agreed check-ins, maintenance of the action log, review reminders, and the periodic status note. Excluded: new policy sets, fresh gap reviews, and incident response beyond pointing you to the right adviser. Those can be proposed separately.

Process

  1. Open with a handover from the project file, or from the documents you already have.
  2. Hold the scheduled check-in.
  3. Update the log and send reminders.
  4. Issue the status note on the agreed cadence.
  5. At renewal, look at whether the retainer still matches the work.

Deliverables

  • A maintained action log.
  • Review reminders to the named owners.
  • A periodic status note.

Intended customer

Teams that have finished a design or documentation project and do not want the folder to go quiet, and teams that already have documents but no one whose job includes keeping the calendar. Fees and the retainer shape are explained in the engagement offer.