PROVABLE Compliance Lean Solutions Talk to an expert
Regulations
Compliance Delivery
Industries
Work
Insights
About
Talk to an expert

Compliance consultancy & delivery

Regulation in.
Evidence out.

Most firms stop at the recommendation. We design the framework, build the controls, run the remediation and — when you need it — operate the function. What you get back is a working compliance capability and the evidence to prove it.

Regulatory obligation Requirements Control Control Control Process Evidence Assurance
AdviseDesignImplementAssureOperate

The gap

Your regulator will
never read the strategy deck.

Compliance programmes rarely fail because nobody understood the legislation. They fail in the translation — when a requirement never becomes somebody's job, a control nobody tests, or evidence nobody can produce on the day it is asked for. That translation is the entire discipline. It is also the part most consultancies leave to you.

The Proof Chain — our method, and the order it has to happen in

01RegulationThe legal text, its scope and what actually applies to you.
02RequirementsObligations broken down into discrete, testable statements.
03RisksWhat fails if the requirement is not met, and how badly.
04ControlsThe specific mechanism that holds the risk down, with an owner.
05ProcessesThe routine that makes the control happen without heroics.
06EvidenceThe artefact proving the control ran, dated and retrievable.
07AssuranceIndependent testing that the whole chain still holds.

Break any link and the programme is decorative. Most regulatory findings trace back to a single missing link — usually five or six.

Service model

Four ways in. One continuous capability.

Engage us at any point in the chain. Most clients start with one and expand.

01 / Advise

Understand what actually applies

Regulatory scope, exposure and maturity — established quickly, with a defensible rationale for what you are and are not in scope for.

  • Applicability & gap analysis
  • Maturity & readiness assessment
  • Risk assessment & ERM
  • Governance & operating model design
  • Board and executive advisory
02 / Design & Implement

Build the capability

Frameworks, policies, controls and the plumbing underneath them — designed to be operated by your people, not by a consultant on retainer.

  • Compliance management systems
  • Risk & control frameworks
  • Policies, procedures, RACI
  • Evidence & monitoring design
  • GRC and RegTech implementation
03 / Test & Remediate

Find out whether it works

Independent testing against the requirement, not against the policy. Then the remediation work to close what the testing finds.

  • Control design & operating effectiveness testing
  • Compliance monitoring programmes
  • Remediation delivery & issue validation
  • Audit and inspection readiness
  • Root cause analysis
04 / Operate & Scale

Run it, or run it with you

Specialists who integrate into your organisation, or a managed capability we operate to an agreed standard. Scale up for the programme, down when it lands.

  • Delivery pods & embedded specialists
  • Fractional compliance leadership
  • Managed monitoring & testing
  • Compliance PMO
  • Ongoing regulatory change management

Compliance delivery

Need capacity,
not another report?

The most common compliance problem is not ignorance. It is that three people are already doing five people's work and a new regulation just landed on top of them. We deploy teams that do the work — inside your organisation, on your systems, to your standards.

Traditional consultancy

Diagnose Recommend Leave

You receive a findings report and an implementation plan. The implementation is yours.

Provable

Diagnose Design Implement Operate Improve

You receive a working control environment, tested, with evidence and named owners. We stay as long as that takes and no longer.

Delivery pods

A multidisciplinary team assembled around one defined compliance objective. Senior lead, real specialists, a project manager who owns the plan. Scales with the programme.

EU AI Act Readiness Pod

8–12 wks
Regulatory Lead AI Governance Specialist Risk & Controls Consultant Business Analyst
Typical outputs
AI system inventoryRisk classification Gap assessmentGovernance model Control frameworkImplementation roadmap

GDPR Programme Pod

10–16 wks
Privacy Lead / fractional DPO Data Protection Specialist Data / Technology Specialist Business Analyst
Typical outputs
RoPALawful basis mapping DPIA methodologyTransfer assessments DSR processBreach playbook

DORA Resilience Pod

12–20 wks
Operational Resilience Lead ICT Risk Specialist Third-Party Risk Specialist Project Manager
Typical outputs
Critical function mappingICT risk framework Register of informationIncident classification Testing programmeContract remediation

AML Remediation Pod

Scales to volume
Financial Crime Lead Remediation Manager KYC / KYB Analysts Quality Assurance Reviewer
Typical outputs
File remediation at volumeQA framework Backlog clearanceIssue validation Regulator-ready reporting

Scope it yourself

Build the team your problem needs

Three choices. We will show you the shape of the engagement we would actually propose — the roles, the duration and what lands on your desk at the end.

Delivery pod configurator

Indicative — not a quote

01 — What are you dealing with?

02 — Where are you now?

03 — How much of it is yours to run?

Indicative engagement

EU AI Act Readiness Pod

Duration8–12 weeks
ModelProject
Team4 specialists
Suggested team
What you would receive

Regulatory capability

Depth where it counts, coverage where you need it.

Two domains we lead with, seven more we deliver in. Open one to see the work, not the legislation.

GDPR is not a policy problem. It is a records problem, a lawful-basis problem and a supplier problem, and it is judged on what you can produce when someone asks. We build privacy programmes that hold up under a supervisory authority's questions.

GDPR implementationRecords of processing (RoPA) Lawful basis & legitimate interest assessmentsDPIA methodology & execution International transfers & TIAsData subject rights operations Breach response & notificationProcessor & sub-processor governance Retention & minimisationPrivacy operating model Fractional DPOPrivacy control testing

Most organisations cannot yet answer the first question the AI Act asks: which systems do you operate, and what risk class is each one in? We start there, then build the governance that makes the answer stay true as the estate changes.

AI system inventory & discoveryRisk classification methodology Prohibited practice screeningHigh-risk obligation mapping GPAI & model provider obligationsAI governance framework Conformity assessment readinessTechnical documentation Post-market monitoringHuman oversight design AI policy & acceptable useGDPR–AI Act interlock

Framework design through to file-level remediation at volume, with the quality assurance layer that makes the output defensible.

AML programme designKYC / KYB operations Transaction monitoring tuningSanctions screening Fraud risk controlsRemediation & backlog clearance

DORA and NIS2 turn resilience into an evidenced discipline with named critical functions and contractual teeth. We map obligations to the controls you already have before proposing new ones.

DORA readiness & implementationNIS2 scoping & controls Critical function mappingRegister of information Third-party ICT contract remediationResilience testing programmes

A risk taxonomy nobody uses is worse than none. We build risk frameworks that produce decisions, not heat maps.

ERM framework designRisk appetite & taxonomy RCSA design & facilitationKey risk indicators Control library & rationalisationIssue & action management

Where product regulation, quality management and data protection collide — and where a software release can quietly become a regulatory event.

EU MDR & IVDRISO 13485 QMS Software as a medical deviceClinical evaluation support Post-market surveillanceHealthTech privacy & HIPAA

Your regulatory perimeter now includes your vendors' vendors. We build the tiering, diligence and monitoring to match.

Third-party risk frameworkVendor tiering & criticality Due diligence operationsContractual control clauses Ongoing monitoring

The programmes that are judged after something has already gone wrong. Built to survive that scrutiny.

Code of conductAnti-bribery & corruption Whistleblowing (EU Directive)Conflicts of interest Third-party integrity diligenceEthics training & testing

Sustainability reporting is now an assurance problem. It needs the same control discipline as financial reporting, and rarely has it.

CSRD readinessDouble materiality assessment Sustainability data controlsESG governance model Assurance preparation

How we work

Six steps. In this order, every time.

The sequence matters more than the speed. Skipping a step is how programmes end up needing a second programme.

01

Discover

The regulation, the business model, the systems and the people. What you do, where, and for whom — because scope is decided by facts, not by preference.

02

Assess

Requirements broken down, current state tested against them, gaps ranked by regulatory and business exposure. You get a defensible position, not a wish list.

03

Design

Framework, controls, operating model and ownership. Designed around how your organisation actually runs, not around a reference model.

04

Implement

Policies live, controls in place, processes embedded, technology configured, people trained. This is the step most engagements never reach.

05

Assure

Independent testing that the controls work as designed, and the evidence pack that proves it — dated, attributable, retrievable.

06

Operate

Where you want it: we run the monitoring, testing or specialist capacity on an ongoing basis, and hand it back whenever you are ready.

Outcomes

What changes in the business.

Deliverables are what we hand over. These are what you keep.

Regulatory readiness reached on a date you can commit to
Every requirement mapped to a named owner
Evidence retrievable in hours, not weeks
Control failures visible before an auditor finds them
Compliance that scales without proportional headcount
Faster entry into regulated markets
Fewer repeat findings from the same root cause
Security and procurement reviews that stop stalling deals
An executive view of exposure that is actually current

Engagement models

Three ways to work with us.

Project

A defined compliance objective with a start, an end and a deliverable set agreed up front.

Best for

Assessments, framework design, implementation programmes and remediation with a clear finish line.

Embedded

Specialists who join your team, work on your systems and report into your governance.

Best for

Capacity gaps, specialist expertise you don't want to hire permanently, and programmes that need continuity.

Managed

We operate a defined compliance capability to an agreed standard, with reporting you can take to a board.

Best for

Ongoing monitoring, control testing, KYC operations and fractional compliance leadership.

Scope of practice

Built as one practice, not a directory of freelancers.

9
Regulatory domains
4
Service lines, one method
6
Step delivery sequence
3
Engagement models

Senior accountability on every engagement. No pyramid staffing, no junior-heavy teams learning the regulation on your budget.

Engagement patterns

What the work looks like in practice.

Representative shapes of engagement, described the way we would scope them.

EU AI Act — Technology

AI governance for a distributed model estate

Situation

Multiple AI systems built by different product teams across several European entities. No central register, no agreed risk classification, no single owner.

Work

Discovery and inventory, a classification methodology the product teams can apply themselves, gap assessment against high-risk obligations, governance model and control framework, sequenced roadmap.

Clear regulatory ownership and an AI programme the engineering organisation can actually run.

GDPR — SaaS scale-up

Privacy that stops blocking enterprise deals

Situation

Enterprise security reviews repeatedly stalling at the privacy questionnaire. No current RoPA, inconsistent lawful basis, transfer position undocumented.

Work

Processing inventory rebuilt from systems rather than interviews, lawful basis and transfer assessments, DPIA methodology, DSR and breach runbooks, processor governance.

A defensible privacy position and an evidence pack that answers procurement in days.

Compliance function — HealthTech

A compliance function built to scale, not to staff

Situation

Rapid European expansion with compliance handled informally by a founder and a part-time adviser. Growing product and data footprint.

Work

Compliance operating model, policy architecture, risk framework, clear responsibilities, monitoring plan, and fractional leadership until an internal hire made sense.

A working compliance function without permanently expanding headcount.

Next step

What compliance problem are you solving?

Tell us what you are dealing with. We will tell you the fastest defensible path from the requirement to the evidence — and whether you need us for all of it or none of it.

Capabilities

Everything between the legal text and the evidence file.

Four service lines that run in sequence or stand alone. Engage us for one assessment or for the whole chain.

01 — Advise

Establish what actually applies, and how exposed you are.

The most expensive compliance mistakes are scoping mistakes — made early, discovered late. This work exists to make the scope defensible before anyone starts building.

Regulatory applicability

Which regimes apply to which entities, products and data flows — with the reasoning written down, so the position survives a change of personnel.

Gap & readiness assessment

Current state tested against decomposed requirements. Findings ranked by regulatory exposure and business impact, not by ease of fixing.

Compliance maturity assessment

Where the function sits today across governance, process, control, evidence and culture — and what the next realistic level costs.

Risk assessment & ERM

Risk taxonomy, appetite, RCSA design and key risk indicators that produce decisions rather than a quarterly colouring exercise.

Governance & operating model

Committees, mandates, three-lines design, decision rights and escalation that match the size you actually are.

Board & executive advisory

Regulatory horizon scanning, change management and the briefing your board needs to discharge its own obligations.

02 — Design & implement

Build the capability, then hand over the keys.

Designed to be run by your people. If a framework only works while we are in the building, we designed it wrong.

Compliance management system

The architecture that holds policies, risks, controls, obligations and evidence together in one traceable structure.

Risk & control frameworks

Control libraries mapped to obligations, deduplicated across regimes so one control can satisfy several requirements.

Policies, procedures & RACI

Documents people can follow, with named accountability rather than departmental fog.

Process mapping & control implementation

Controls embedded into the process where the risk occurs, not bolted on as a quarterly attestation.

Evidence & monitoring design

Deciding up front what proof each control produces, where it is stored and how long it is kept.

GRC & RegTech implementation

Tooling configured around your framework. Technology where it removes work, not where it adds a licence.

03 — Test & remediate

Find out whether it works before someone else does.

Testing against the requirement, not against the policy. A policy can be perfectly followed and still fail the regulation.

Control testing

Design and operating effectiveness testing with sampling that would stand up to an internal audit challenge.

Compliance monitoring

Risk-based monitoring plans, executed on a cycle, reported in a form a board can act on.

Remediation delivery

The programme that closes findings — planned, staffed, tracked and evidenced to closure rather than to a status update.

Audit & inspection readiness

Evidence packs assembled, narratives rehearsed, gaps closed before the notice period runs out.

Issue validation & root cause

Independent confirmation that a fix actually fixed it, and analysis of why it broke, so it stays fixed.

Independent quality assurance

A second line over remediation and operational work at volume, with a documented QA standard.

04 — Operate & scale

Compliance delivery.
People who do the work.

Advisory tells you what to do. Delivery is us doing it — inside your organisation, on your systems, under your governance, for exactly as long as the problem lasts.

The model

A pod is a team, not a pool of CVs.

Staff augmentation sends you people. A pod sends you a team with a lead who owns the outcome, a plan, a quality standard and a defined end state. The difference shows up in month two.

Composition

Built around the objective

A typical pod carries a compliance lead, a regulatory specialist, a risk and controls consultant, a business analyst and a project manager. Data or technology specialists join where the work demands it.

Scaling

Up for the peak, down for the plateau

Remediation needs volume for twelve weeks and two people afterwards. The pod flexes on agreed notice so you are not paying for a peak that has passed.

Accountability

One senior name on the outcome

Every pod has a senior lead accountable for delivery, present throughout. Not a partner at kick-off and a graduate thereafter.

Roles we deploy

Specialists, not generalists with a template.

Compliance analystsRegulatory specialistsRisk & controls specialists Control testersKYC / KYB analystsAML investigators Privacy specialistsFractional DPOAI governance specialists Third-party risk specialistsPolicy specialistsCompliance project managers Compliance PMORemediation managersQuality assurance reviewers Fractional compliance leadershipBusiness analystsRegulatory reporting specialists

Commercials

How engagements are structured.

Three shapes, chosen by what the problem needs rather than what is easiest to sell.

Project

Fixed objective

Defined scope, deliverables and end date. Priced against the outcome. Best where the finish line is knowable at the start.

  • Assessments and gap analysis
  • Framework and policy design
  • Implementation programmes
  • Bounded remediation
Embedded

Integrated capacity

Named specialists working as part of your team, in your tools, on your cadence. Monthly, with agreed notice on both sides.

  • Capacity gaps and peak load
  • Specialist skills you won't hire full time
  • Programme continuity
  • Interim cover
Managed

Operated capability

We run a defined compliance function to an agreed service standard, with reporting built for your board and your regulator.

  • Ongoing monitoring and testing
  • KYC and financial crime operations
  • Fractional compliance leadership
  • Regulatory change management

Next step

Tell us the objective. We will shape the team.

Most conversations start with a deadline and a gap. That is enough to work with.

Regulatory expertise

Two we lead with.
Seven more we deliver in.

Depth beats coverage. We would rather be the firm you call for GDPR and the AI Act than the firm that lists forty regimes and specialises in none.

Flagship — 01

GDPR & data protection

Eight years in, most privacy programmes are still built on documents rather than records. The distinction matters the first time a supervisory authority asks you to produce something.

Where programmes break

  • A RoPA assembled from interviews, accurate on the day it was signed
  • Lawful basis chosen once, never revisited when the product changed
  • DPIAs treated as a form rather than an assessment
  • Transfer positions undocumented since the last framework change
  • Processor governance that stops at signing the DPA
  • Data subject requests handled heroically by one person

What we build

  • Processing records derived from systems and data flows
  • Lawful basis and legitimate interest assessments that hold
  • A DPIA methodology your product teams can run themselves
  • Transfer impact assessments and a defensible transfer position
  • DSR and breach response runbooks, tested
  • Retention, minimisation and processor controls with evidence

Flagship — 02

The EU AI Act

The Act asks a question most organisations cannot yet answer: which AI systems do you operate, who provides them, and what risk class is each one in? Everything else follows from getting that inventory right.

The sequence that works

  • Discover the estate — including models embedded in purchased software
  • Establish role per system: provider, deployer, importer, distributor
  • Screen for prohibited practices first, and stop those
  • Classify by risk against the Act's own criteria, with reasoning recorded
  • Map obligations only for what is actually in scope
  • Build governance that keeps the inventory true as teams ship

What we deliver

  • AI system inventory and discovery methodology
  • Risk classification framework product teams can apply
  • Gap assessment against high-risk and GPAI obligations
  • AI governance model, policy and human oversight design
  • Technical documentation and conformity readiness
  • Post-market monitoring and the GDPR interlock

AI governance and data protection are the same programme viewed from two angles. Treating them separately is how organisations end up with two inventories, two owners and two sets of contradictory documentation.

Also delivered

The rest of the practice.

Financial crime

AML programme design, KYC and KYB operations, transaction monitoring tuning, sanctions screening, remediation at volume with a QA layer.

DORA & NIS2

Critical function mapping, ICT risk frameworks, register of information, third-party contract remediation, resilience testing.

Enterprise & operational risk

ERM frameworks, risk appetite and taxonomy, RCSA design, KRIs, control rationalisation across regimes.

MDR, IVDR & ISO 13485

Medical device and IVD compliance, quality management systems, software as a medical device, post-market surveillance.

Ethics & conduct

Code of conduct, anti-bribery and corruption, whistleblowing under the EU Directive, conflicts of interest, integrity diligence.

CSRD & ESG governance

Double materiality, sustainability data controls, ESG governance design and assurance preparation.

Industries

The regulation is the same.
The operating reality is not.

A control that works in a bank fails in a forty-person SaaS company, and the reverse. We design for how the organisation actually runs.

Financial services

Evidence under continuous supervision

Established frameworks, fragmented control ownership and a supervisor who asks for proof. Most of the value is in rationalising what already exists.

DORAAMLOperational resilienceERM
FinTech

Licence-grade compliance at start-up speed

Growing faster than the control environment. The work is building something a regulator will accept without stopping the product.

AML / KYCSafeguardingGDPROutsourcing
Technology & SaaS

Compliance as a sales dependency

Enterprise buyers audit you before they buy. Privacy and security posture is a revenue function long before it is a legal one.

GDPRThird-party riskNIS2ISO alignment
AI companies

Governance that keeps up with shipping

The estate changes weekly. Governance has to be something engineering can execute, not a quarterly review board.

EU AI ActGDPRModel documentationHuman oversight
HealthTech & MedTech

Where product regulation meets privacy

Device regulation, quality management and health data in one system. A release can be a regulatory event without anyone noticing.

EU MDRIVDRISO 13485Health data
Digital platforms

Obligations that scale with users

Content, payments, identity and data obligations that arrive together once you cross a threshold you did not plan for.

GDPRPlatform regulationAMLThird-party risk
Multinational enterprise

One framework, many jurisdictions

The problem is rarely a missing control. It is the same control implemented six different ways across six entities.

ERMEthics & ABCCSRDGroup governance
Regulated scale-ups

Building the function for the first time

No legacy to unpick, no framework either. The advantage is you can build it correctly once.

Operating modelPolicy architectureFractional leadership
Market entrants

Entering a regulated market

Establishing what applies before committing to a market, and building only what the market actually requires.

ApplicabilityLicensing readinessLocal requirements

Work

How engagements are structured.

Representative engagement shapes, described the way we would scope them. Situation, work, outcome — no logos, no invented numbers.

EU AI Act — Technology

AI governance for a distributed model estate

Situation

Multiple AI systems built by different product teams across several European entities. No central register, no agreed classification, no single owner. Leadership could not answer a customer questionnaire about AI use.

Work

Discovery across engineering and procurement to find purchased models as well as built ones. Classification methodology written so product teams apply it at design time. Gap assessment against high-risk obligations. Governance model, control framework and a sequenced roadmap tied to the Act's timelines.

Clear regulatory ownership and an AI programme the engineering organisation can run without a consultant in the room.

GDPR — SaaS scale-up

Privacy that stops blocking enterprise deals

Situation

Enterprise security reviews stalling repeatedly at the privacy questionnaire. RoPA eighteen months out of date, lawful basis inconsistent across products, transfer position undocumented.

Work

Processing inventory rebuilt from systems and data flows rather than interviews. Lawful basis and legitimate interest assessments. Transfer impact assessments. DPIA methodology handed to product. DSR and breach runbooks tested against a live scenario.

A defensible privacy position and an evidence pack that answers procurement in days rather than weeks.

DORA — Financial services

Consolidating fragmented ICT risk controls

Situation

ICT risk controls split across technology, information security and vendor management, each with its own register. The same control evidenced three ways, with gaps between them.

Work

Obligations mapped to the existing control estate before designing anything new. Critical function mapping, register of information, incident classification, third-party contract gap analysis and a coordinated remediation plan with owners.

A single consolidated control framework and materially stronger evidence for regulatory review.

Function build — HealthTech

A compliance function built to scale, not to staff

Situation

Rapid European expansion with compliance handled informally between a founder and a part-time adviser. Product handling health data across multiple jurisdictions.

Work

Compliance operating model and policy architecture, risk framework, responsibility model, monitoring plan, and fractional compliance leadership until the internal hire made commercial sense.

A functioning compliance capability without permanently expanding headcount ahead of revenue.

AML — Payments

Remediation at volume with a defensible QA standard

Situation

A significant KYC file backlog following a supervisory finding, with a fixed deadline and no internal capacity to clear it.

Work

A remediation pod scaled to the file volume, working to a documented QA standard with independent second-line review, daily throughput reporting and issue validation to closure.

Backlog cleared to deadline with evidence of quality, not just evidence of completion.

Control testing — Enterprise

Testing the controls, not the paperwork

Situation

An annual attestation cycle that consistently reported healthy controls, followed by internal audit findings that said otherwise.

Work

Independent design and operating effectiveness testing against decomposed requirements, with sampling designed to withstand challenge. Root cause analysis on failures and a redesigned monitoring cycle.

Control failures surfaced by the business before audit found them, and fewer repeat findings from the same cause.

These describe how we structure work, not a claim about specific past clients. Named references are provided under NDA on request.

Insights

Notes from inside the programmes.

Briefings, playbooks and checklists written by the people running this work. No thought leadership, no trend pieces.

About

Compliance should work
in the real world.

Regulation does not fail because organisations cannot read legislation. It fails when requirements never become ownership, controls, processes and evidence. That is where we work.

The founders

Two people who kept hitting the same wall from opposite sides.

One spent a decade proving whether controls actually work. The other spent it getting the work funded, staffed and finished. Provable is what happens when those two problems are finally solved in the same room.

António Pedro Vieira, Chief Executive Officer and Founder Founder

Chief Executive Officer

António Pedro Vieira

António has spent his career on the commercial and operational side of compliance — running regulated operations at scale, governing risk inside global banks, and building compliance practices as businesses rather than as cost centres.

At Accenture he led AML and KYC operations, managing teams of thirty-plus specialists across EMEA and US portfolios and owning enhanced due diligence for complex, high-risk structures. At UBS he moved into governance as Business Risk Manager in the GCRG COO function, designing control and policy frameworks and aligning risk frameworks through a bank acquisition. At Revolut he ran regulatory compliance frameworks and embedded compliance-by-design with product and engineering before launch. Most recently he built a compliance services practice from an empty page — service catalogue, delivery methodology, pricing and go-to-market across the EU AI Act, DORA, PCI DSS and MDR.

He holds a Master’s in Environmental Economics and Management from the University of Porto and the University of Maribor, and is a published author. He works in Portuguese, English, Spanish and French, and is based in Kraków.

Works in
EU AI ActDORAPCI DSS MDRAML & KYCRisk governance Practice building1st, 2nd & 3rd line
João Monteiro, Chief Compliance Officer and Vice President of Delivery Co-founder

Chief Compliance Officer & VP, Delivery

João Monteiro

João works at the point where compliance stops being a document. His discipline is control testing — the evidence-level question of whether a control was designed correctly and whether it actually operated on the date it claims to.

He began as a Compliance Analyst at Vesuvius before joining Zurich Insurance, where he spent more than three years inside internal controls: first as an Internal Controls Testing Specialist across compliance, ICFR and the group control environment, then as an IT Internal Controls Specialist, carrying the same testing rigour into technology and ICT risk. He is now a Product Compliance Consultant at Formalize, where regulatory requirements have to become working product rather than policy.

His territory is governance, risk and compliance, DORA, NIS2 and ISO/IEC 27001 — the regimes where operational resilience and information security stop being separate conversations. In 2024 he stepped out of the profession for five months, deliberately, to go deeper on the technical side rather than wider. It is the single decision that most explains how he works.

He and António first worked together on an Accenture operation in Poland, and again inside the GCRG COO function at UBS — the engagement that turned a long-running argument between friends into this firm.

Works in
GRCDORANIS2 ISO/IEC 27001Control testingICFR IT & ICT riskProduct compliance

How this started

Poland, an Accenture floor, and an argument that never really ended.

MetTwo Portuguese on the same Accenture operation in Poland, a long way from home.
ApartOne went down into the machinery. One went out into the market.
AgainReunited at UBS, leading the GCRG COO function together.
NowThe same firm, built around the gap they had each been falling into for years.

We met in Poland — two Portuguese a long way from home, on the same Accenture operation, neither of us yet doing the job we would end up doing.

What we had in common was a habit of arguing. About the work, about how it ought to be done, about why the process everyone had quietly agreed to tolerate was obviously broken. We were young enough to think that was a personality trait rather than a career.

Then we went in opposite directions.

João went down. Into the machinery. Internal controls, ICFR testing, IT control environments, ISO 27001 — the unglamorous discipline of proving that a control actually operated on the date it claimed to. He spent years in the part of this profession where you cannot bluff, because the evidence either exists or it does not.

António went out. Into operations at scale — thirty, forty people running AML and KYC — and then into the commercial side of the work, where you have to convince a board, price the programme and own the number.

Then we ended up in the same room again.

At UBS, leading the GCRG COO function together. It was the first time we had ever worked the same problem from our two different halves, and it is where this stopped being an observation between friends and became the argument for a company.

Because we could finally see the whole failure at once. João would find a control framework that was technically correct and commercially orphaned — designed properly, then quietly abandoned because nobody senior enough ever sponsored it. António would find a programme that had been sold, approved and budgeted, and was sitting on a shelf because nobody in the building could actually implement it.

Same failure. Opposite ends of it.

That gap — between the advice and the execution — is where most regulatory findings are born, where most compliance budgets die, and where we spent years watching good work go to waste from either side of a wall.

We started this firm to close it. One of us knows what it costs to build a control that survives testing. The other knows what it costs to get that work funded, staffed and finished. We are not guessing that the pair works — we ran it inside a global bank before we ran it as a company.

That is the whole company. Everything else is method.

Principles

Six things we hold to.

01

Practical over theoretical

A framework that is correct and unusable has failed. We design for the organisation in front of us.

02

Execution over presentation

The deliverable is a working control environment. The document is how we describe it, not what you bought.

03

Specialists over generalists

The person doing your AI Act work has done AI Act work. We would rather decline than staff a gap with enthusiasm.

04

Evidence over assumption

If a control cannot produce proof it ran, it is a policy. We test rather than assert.

05

Technology where it earns its place

Tooling that removes work, not tooling that adds a licence and a new place to file things.

06

Senior accountability throughout

The senior name at the pitch is the senior name in delivery. No pyramid, no handover to people you have not met.

How we are different

The uncomfortable part.

Most compliance consultancies are structured to produce documents, because documents are easy to scope, easy to price and easy to sign off. The problem is that documents are not what the regulation asks for.

Being able to execute changes the incentives. We cannot recommend a control framework nobody can operate, because we may be the ones operating it. We cannot hand over a roadmap that ignores your capacity, because we will be inside the delivery when capacity runs out.

That constraint makes the advice better. It is the whole argument for the model.

Contact

What compliance problem
are you solving?

Tell us what you are dealing with — a deadline, a finding, a gap, a regulation that just landed. We will tell you the fastest defensible path from the requirement to the evidence, and whether you need us for all of it or none of it.

This form is not connected yet — wire it to your inbox or CRM before launch.

Direct

Replace with your email address, phone and LinkedIn before launch.

What happens next

  • A reply within one working day
  • A 30-minute call to understand the situation
  • An honest view on whether we are the right firm
  • If yes, a scoped proposal with named people
Provable — compliance designed, delivered, operated Regulation → Requirements → Risks → Controls → Processes → Evidence → Assurance