All practice areas

Ahead of regulatory change

Compliance & Risk

Regulatory guidance, risk assessments, and policies that keep your business ahead of change.

How we help

Regulation moves faster than most internal policies. We map the obligations that actually apply to your business and build a compliance program proportionate to your size and risk.

When something goes wrong, we help you respond quickly, document properly, and limit the exposure.

What’s included

  • Regulatory gap analysis and risk assessments
  • Data protection and privacy programs
  • Internal policies, handbooks, and training
  • Anti-bribery and financial crime controls
  • Incident response and regulator correspondence
  • Ongoing compliance monitoring

Case studies

Outcomes we have delivered in compliance & risk

Anonymised examples of recent matters. Details have been changed to protect client confidentiality; the outcomes are real.

Consumer fintech, 200k users

Data breach contained and reported inside the 72-hour window

The challenge
A misconfigured third-party integration exposed customer records on a Friday evening, with no incident plan and conflicting internal accounts of what had been accessed.
What we did
We stood up an incident response over the weekend: scoped the affected records with the engineering team, assessed reportability, drafted the regulator notification and customer communications, and documented the decision trail contemporaneously.
The outcome
The notification was filed within the statutory window with a complete remediation plan attached. The regulator closed the matter with no enforcement action.
  • 48 hours

    Reported within

  • None

    Enforcement action

  • 200k

    Records triaged

Regulated lender

Compliance framework rebuilt after an adverse audit

The challenge
An internal audit found policies that had not been reviewed in four years, no evidence of board oversight, and training records that could not be produced on request.
What we did
We rewrote the policy suite around the current rulebook, built an annual review and attestation calendar, and put a board reporting pack in place so oversight is evidenced as it happens rather than reconstructed later.
The outcome
The follow-up audit closed every finding, and the firm now has an audit trail it can produce on demand.
  • 100%

    Audit findings closed

  • 18

    Policies rewritten

  • Satisfactory

    Follow-up rating

Facing something similar? Tell us about your matter and we will tell you how we would approach it.

FAQs

Questions clients ask about compliance & risk

We are a small company — do we really need a program?
You need a proportionate one. A short, well-documented set of policies you actually follow protects you far better than a large framework nobody uses.
What happens if we receive a regulator inquiry?
Contact us before responding. Early responses set the tone of the whole process, and we can help you gather the right documentation and reply accurately.
Do you handle data protection specifically?
Yes — privacy notices, processing records, vendor terms, and breach response are a core part of our compliance work.
How often should policies be reviewed?
Annually as a baseline, and immediately after a regulatory change, a significant incident, or a shift in what your business actually does. Undated policies are the first thing a regulator picks up on.
What should we do in the first 24 hours of a data breach?
Contain it, preserve the logs, and start a written incident record. Reporting deadlines can be as short as 72 hours, so involve us early — the assessment of whether it is notifiable is itself a legal judgement worth documenting.
Do we need a data protection officer?
Only where you carry out large-scale monitoring or process special-category data at scale. Where you do not, we help you appoint a responsible owner and document why a formal DPO is not required.
How do we manage compliance risk in our supply chain?
Risk-tier your vendors, apply proportionate due diligence, and put the obligations in the contract — data processing terms, audit rights, and anti-bribery warranties — rather than relying on a questionnaire alone.
Do you deliver staff training?
Yes. We run short, role-specific sessions for boards, managers, and front-line teams, with attendance records and refresher materials you can keep as evidence of your program.

Talk to a compliance & risk lawyer

Tell us what you are dealing with and we will come back within one business day with next steps and a clear fee estimate.