Service index

Eight ways we help a team show its controls.

Each service below states its purpose, the scope we will accept, the process, the deliverables, and the client it is meant for. Fees are not listed here because they depend on the brief. The engagement offer explains how a price is set. Nothing on this page is a legal opinion.

Close view of a person marking a printed document with a pen
Deliverables are written documents with an owner and a record, not a slide that says the control exists.
01

Regulatory gap assessment

Show the distance between how the organisation works today and the obligations it has already been asked to meet.

A gap assessment is a structured comparison, not a certificate and not a legal opinion. We take an agreed list of expectations — a partner questionnaire, a contract schedule, a checklist from your counsel, or a set of internal rules — and test it against interviews and the records you actually keep. Where the source of an obligation is unclear, the finding says “confirm with counsel” instead of inventing a citation.

Scope

One business line or one topic, such as customer onboarding, record keeping, or vendor contracts. A second line is a separate scope. We do not audit every statute that might touch the company, and we do not issue an assurance opinion.

Process

  1. A scoping call to fix the question and the sources we may rely on.
  2. A document request limited to that question.
  3. Interviews with the people who perform the work.
  4. A comparison note: expectation, current practice, gap, and practical next step.
  5. A findings conversation so the wording matches reality before it is issued.

Deliverables

  • An obligation map with the source of each item named.
  • Gap notes ordered by practical impact, not by a decorative risk score.
  • A sequence of fixes the team can actually staff.
  • A list of questions that still belong to counsel or another adviser.

Who it is for

A founder or operator facing a bank, investor, marketplace, or new-market question who needs an honest picture before drafting a full manual.

02

Compliance program design

Turn informal habits into a program with owners, records, and a rhythm of review.

Program design is for teams that have outgrown “we all know how this works”. We set the governance in proportion to the firm: who approves a policy, who performs the control, who keeps the record, and when someone checks that the record exists. The result is an operating model, not a slogan.

Scope

The topics named in the proposal. A typical first program covers governance, a risk register, a control list, and a review calendar for one or two risk areas. It does not, by itself, include software implementation or a company-wide training tour.

Process

  1. Confirm the risks the leadership team is actually willing to manage.
  2. Draft the operating model and test the role names against real job titles.
  3. Review the draft with the people who will run it.
  4. Revise once for substance and once for clarity.
  5. Hand over the files and the open items.

Deliverables

  • A short program outline.
  • A role note in plain language, close to a RACI but readable.
  • A risk register with causes, existing controls, and the evidence you would show.
  • A control checklist and a review calendar.

Who it is for

Organisations whose current practice lives in inboxes and memory, and who need something a new manager could follow.

03

AML/CFT control support

Help a business that onboards customers, or that moves or holds money, organise identification, records, and escalation.

We write the practical steps for customer due diligence: what you collect, when you refresh it, which cases go to a nominated person, and which records you keep. We do not decide whether your business needs a licence. We do not register you with a supervisor. We do not advise you on how to avoid a reporting duty. If licensing or a suspicious-matter decision is in view, that question is marked for qualified counsel.

Scope

Procedures and templates for the channels named in the proposal. Higher-risk products can be included only if the proposal says so. Transaction-monitoring software is out of scope; we can describe the rule the software would need to reflect.

Process

  1. Map customer types, channels, and who currently says yes.
  2. Draft the due-diligence steps and the evidence to retain.
  3. Write escalation criteria a staff member can apply without guessing.
  4. Prepare a short briefing note so the first users hear the same explanation.

Deliverables

  • A customer due-diligence procedure.
  • An escalation note with examples that match your customers, not a textbook.
  • A record checklist.
  • A staff briefing outline.

Who it is for

Payment-adjacent businesses, agencies, dealers, and professional firms that have been asked to show anti-money-laundering controls and still need their own legal assessment of licensing.

04

Data protection readiness

Organise how personal data is collected, used, stored, and shared so the team can explain it.

We build a data inventory and the internal routines around it, with attention to personal-data rules in the Republic of Moldova and, where you handle information about people in the European Economic Area or the United Kingdom, the duties those regimes are known for. We draft notice text for your counsel to review before you publish it. We do not appoint ourselves as your data protection officer, and we do not represent you before a data authority.

Scope

The systems and teams named in the proposal. A full multi-country transfer opinion is legal work and is out of scope. We will list the transfers we see and the question they raise.

Process

  1. List categories of people, the data, the purpose, and where it sits.
  2. Note who else receives it and how long it is kept.
  3. Draft a retention schedule the business can actually apply.
  4. Draft a privacy notice and an internal request procedure.
  5. Mark every point that counsel should confirm before publication.

Deliverables

  • A data inventory.
  • A retention schedule.
  • A draft privacy notice for counsel’s review.
  • An internal procedure for access, correction, and deletion requests.

Who it is for

Companies with customer, employee, or marketing lists, especially if they sell to people in the EU or use processors outside their own office.

05

Vendor and third-party diligence

Give the team a repeatable way to decide which suppliers need a closer look.

Not every supplier presents the same risk. Stationery is not a payroll platform. We build a tiering model, a questionnaire, and a review record so the decision is written down. Contract wording — security, sub-processing, exit, audit — is listed for your lawyer to negotiate. We do not run disputes and we do not perform forensic audits of a supplier’s network.

Scope

The supplier population you name, or a method you can apply yourselves to future suppliers. On-site audits are out of scope unless a separate proposal prices them, which we rarely recommend as a first step.

Process

  1. Sort suppliers into routine, standard, and heightened tiers.
  2. Draft questions that match the tier, so low-risk firms are not buried in paperwork.
  3. Create a one-page review record: who decided, on what date, and what is still open.
  4. Hand your lawyer a clause checklist rather than a pretend negotiation.

Deliverables

  • A tiering note.
  • A questionnaire set.
  • A review-log template.
  • A clause checklist for counsel.

Who it is for

Operators who rely on outsourced IT, payroll, marketing, logistics, or white-label services, and who have been asked how they supervise those firms.

06

Policy and procedure drafting

Write the documents staff will use, in language they recognise.

This service is the drafting itself, when you already know which documents you need. Each policy states the rule and who owns it. Each procedure is short, numbered, and ends with the record that proves the step. We would rather issue six accurate procedures than a forty-page manual nobody opens.

Scope

The named set only. Translation into another language, design layout, and an intranet build are not included unless the proposal adds them. Standard delivery is in English.

Process

  1. Confirm the real steps with the operator, not only the manager.
  2. Draft in plain language and mark assumptions.
  3. Take two rounds of written comments.
  4. Issue a version table so later edits have a history.

Deliverables

  • The agreed policies.
  • Matching one-page or few-page procedures.
  • A version table and an owner list.

Who it is for

Teams that have been asked to “send the policies” and do not yet have a set that describes the work they do.

07

Staff briefings

Help the people who do the work understand the documents they have just received.

A policy that is only emailed will be skimmed. A briefing walks through two or three real situations from the client’s own week, shows which record to keep, and leaves time for questions. We can lead a remote session when the proposal includes it. We do not issue accredited certificates or claim the session is a regulated training course.

Scope

One session plan per agreed audience, usually managers and the staff who perform the control. Repeating the session for every shift is quoted separately. We do not assess individual employees for disciplinary purposes.

Process

  1. Pick situations from the final procedures, not from a generic slide deck.
  2. Draft a participant sheet with the three actions you want remembered.
  3. Lead the session, or coach the client’s own manager to lead it.
  4. Leave an attendance record template the client completes.

Deliverables

  • A session plan.
  • A participant sheet.
  • An attendance record template.

Who it is for

Teams adopting a new program who want the first explanation to be consistent.

08

Retained advisory

Keep a named reviewer available when a new product, vendor, or country appears.

After a build, questions still come up. A retainer is a monthly hour allotment for written answers and light reviews of drafts you prepare. It is not an emergency hotline and it is not a silent promise to rewrite the program every month. Unused hours do not roll forward unless the proposal says so. New policy suites are quoted as projects.

Scope

The hour cap and the topics named in the proposal. Incident response, investigations, and appearances before an authority are outside a standard retainer.

Process

  1. You send the question with the draft or the facts.
  2. We answer in writing inside the agreed response window.
  3. Hours are recorded against the monthly cap.
  4. A short open-items note closes the month.

Deliverables

  • Written answers.
  • Marked drafts, within the hour cap.
  • A monthly open-items note.

Who it is for

Organisations that have finished a build, or that already have documents and want a careful external reader.