PROVABLE Compliance Lean Solutions Talk to an expert
Delivery & Work
Insights
About
Talk to an expert

Compliance consultancy & delivery

Regulation in.
Evidence out.

We tell you where you stand, build what is missing, and — if you want — run it for you. GDPR, the EU AI Act, DORA, NIS 2, whistleblowing and AML. Across the EU, and on the ground in Portugal.

Regulatory obligation Requirements Control Control Control Process Evidence Assurance
AssessBuildTestOperate

What we do

One team, from the first
gap assessment to the last control.

You come to us with a regulation and a deadline. We work out exactly what applies to your business, show you where you fall short, then build and implement the policies, controls and evidence that close it — and stay on to run the parts you would rather not staff. Most of our work is GDPR and the EU AI Act, alongside DORA, NIS 2, whistleblowing and AML.

Step 01Gap assessment

What applies to you, what you already have, and precisely where the gaps are. Two to four weeks, fixed price, no obligation to continue.

Step 02Design

Policies, procedures, risk and control framework, and a named owner for every requirement. Built for your size, not a template.

Step 03Implementation

We put it in place with your team — controls live, people trained, evidence being produced and filed.

Step 04Operate or hand over

We test it, prove it works, and either hand you the keys or keep running it as your outsourced compliance capability.

You can stop after any step. Plenty of clients take the gap assessment, do the work themselves, and come back to us for the testing.

What problems we solve

If any of this sounds like
your week, we can help.

In your words, not ours. Pick the one that stings.

A new regulation applies to us and nobody here owns it.

We take it off your desk. We work out what actually applies to your entities and products, write the position down so it survives a staff change, then build the programme and give every requirement a name against it.

Applicability & gap assessment

We failed a client security review and lost the deal.

Enterprise buyers audit you before they buy. We fix the answers and build the evidence pack — records of processing, transfer position, control documentation — so procurement stops being the reason deals stall.

GDPR & privacy programmes

We use AI everywhere and have no idea what that means legally.

Almost nobody does yet. We find every AI system you run — including the ones inside software you bought — classify each one against the AI Act, and build governance your engineers can actually follow.

Map your AI risk

We got an audit finding and the clock is running.

This is the work we do most. We staff and run the remediation — planned, tracked, evidenced to closure — and validate the fix independently so the same finding does not come back next cycle.

Remediation delivery

My compliance team is two people and they are drowning.

You need hands, not a report. We deploy specialists into your team for as long as the peak lasts — control testers, KYC analysts, privacy specialists, a fractional DPO — and scale back down when it passes.

Delivery pods

We have policies, but no idea whether any of it works.

A policy is not a control. We test against the requirement, not against your documentation, and give you a clear list of what is working, what is not, and what a regulator would find first.

Control testing

We are growing fast and have no compliance function at all.

Good — nothing to unpick. We build the function once, properly: operating model, policies, risk framework, who decides what, and fractional leadership until hiring someone permanent makes commercial sense.

Build a compliance function

Somos uma empresa portuguesa e a lei nacional é outra história.

Sim, e é onde a maioria falha. Trabalhamos no contexto legal português — Lei 58/2019, Lei 93/2021, DL 125/2025, CNPD, CNCS — e não apenas na versão europeia do regulamento.

Compliance em Portugal

Compliance delivery

Need people,
not another report?

The most common compliance problem is not that nobody understands the rules. It is that two or three people are already doing five people's work and a new regulation just landed on top of them. We send teams that do the work.

Most consultancies

Diagnose Recommend Leave

You get a findings report and an implementation plan. The implementation is your problem.

Provable

Diagnose Design Implement Operate Improve

You get working controls, tested, with evidence and named owners. We stay as long as that takes and no longer.

Project

Fixed objective

Defined scope, deliverables and end date, priced against the outcome. For assessments, framework design and bounded remediation.

Embedded

Specialists in your team

Named people working in your tools, on your cadence, reporting into your governance. Monthly, with notice on both sides.

Managed

We run it

A defined compliance capability operated to an agreed standard, with reporting built for your board and your regulator.

Scope it yourself

See the team your problem needs.

Three clicks. You get the shape of the engagement we would actually propose — the roles, how long it takes and what lands on your desk at the end.

Delivery pod configurator

Indicative — not a quote

01 — What are you dealing with?

02 — Where are you now?

03 — How much of it is yours to run?

Indicative engagement

GDPR Readiness Pod

Duration6–10 weeks
ModelProject
Team4 specialists
Suggested team
What you would receive

How we work

Six steps. Always in this order.

Skipping one is how a programme ends up needing a second programme.

01

Discover

The regulation, your business model, your systems and your people. What you do, where, and for whom.

02

Assess

Requirements broken down, current state tested against them, gaps ranked by real exposure rather than by ease of fixing.

03

Design

Framework, controls, ownership. Built around how your organisation actually runs.

04

Implement

Policies live, controls in place, people trained. This is the step most engagements never reach.

05

Assure

Independent testing that it works, and the evidence pack that proves it — dated and retrievable.

06

Operate

Where you want it, we keep running the monitoring, testing or specialist capacity — and hand it back whenever you are ready.

What you actually get

Deliverables are what we hand over.
These are what you keep.

A readiness date you can commit to in front of a board
Every requirement mapped to a named owner
Evidence retrievable in hours, not weeks
Control failures visible before an auditor finds them
Client security reviews that stop killing deals
Compliance that scales without proportional headcount

How we are set up

Small, senior, and accountable to you directly.

6
Regulatory regimes, in depth
4
Stages, one method
3
Ways to engage us
2
Markets: EU & Portugal

You deal with the people doing the work. No pyramid staffing, no junior team learning the regulation on your budget.

Next step

What compliance problem are you solving?

Tell us what you are dealing with. We will tell you the fastest defensible route from the requirement to the evidence — and whether you need us for all of it, some of it, or none of it.

Capabilities

Everything between the legal text and the evidence file.

Four service lines. They run in sequence or stand alone — engage us for one assessment or for the whole chain.

The method

The Proof Chain

Every engagement runs along the same chain. Break any link and the programme is decorative — most regulatory findings trace back to one missing link, usually five or six.

01RegulationThe legal text, its scope and what actually applies to you.
02RequirementsObligations broken down into discrete, testable statements.
03RisksWhat fails if the requirement is not met, and how badly.
04ControlsThe specific mechanism that holds the risk down, with an owner.
05ProcessesThe routine that makes the control happen without heroics.
06EvidenceThe artefact proving the control ran, dated and retrievable.
07AssuranceIndependent testing that the whole chain still holds.

01 — Advise

Establish what applies, and how exposed you are.

The most expensive compliance mistakes are scoping mistakes — made early, discovered late. This work makes the scope defensible before anyone starts building.

Regulatory applicability

Which regimes apply to which entities, products and data flows — with the reasoning written down, so the position survives a change of personnel.

Gap & readiness assessment

Current state tested against decomposed requirements. Findings ranked by regulatory exposure and business impact, not by ease of fixing.

Compliance maturity assessment

Where the function sits today across governance, process, control, evidence and culture — and what the next realistic level costs.

Risk assessment & ERM

Risk taxonomy, appetite, RCSA design and key risk indicators that produce decisions rather than a quarterly colouring exercise.

Governance & operating model

Committees, mandates, three-lines design, decision rights and escalation that match the size you actually are.

Board & executive advisory

Regulatory horizon scanning, change management and the briefing your board needs to discharge its own obligations.

02 — Design & implement

Build the capability, then hand over the keys.

Designed to be run by your people. If a framework only works while we are in the building, we designed it wrong.

Compliance management system

The architecture that holds policies, risks, controls, obligations and evidence together in one traceable structure.

Risk & control frameworks

Control libraries mapped to obligations and deduplicated across regimes, so one control can satisfy several requirements.

Policies, procedures & RACI

Documents people can follow, with named accountability rather than departmental fog.

Process mapping & control implementation

Controls embedded into the process where the risk occurs, not bolted on as a quarterly attestation.

Evidence & monitoring design

Deciding up front what proof each control produces, where it is stored and how long it is kept.

GRC & RegTech implementation

Tooling configured around your framework. Technology where it removes work, not where it adds a licence.

03 — Test & remediate

Find out whether it works before someone else does.

We test against the requirement, not against the policy. A policy can be perfectly followed and still fail the regulation.

Control testing

Design and operating effectiveness testing, with sampling that would stand up to an internal audit challenge.

Compliance monitoring

Risk-based monitoring plans, executed on a cycle, reported in a form a board can act on.

Remediation delivery

The programme that closes findings — planned, staffed, tracked and evidenced to closure rather than to a status update.

Audit & inspection readiness

Evidence packs assembled, narratives rehearsed, gaps closed before the notice period runs out.

Issue validation & root cause

Independent confirmation that a fix actually fixed it, and analysis of why it broke, so it stays fixed.

Independent quality assurance

A second line over remediation and operational work at volume, with a documented QA standard.

Regulatory expertise

Six regimes.
What each one asks, and what we do about it.

Scope, then the service. No legislative summaries you could get from a law firm's newsletter.

Regulation 01

GDPR

Eight years in, most privacy programmes are still built on documents rather than records. That distinction matters the first time a supervisory authority asks you to produce something.

Privacy governance that produces evidence

Regulation (EU) 2016/679 · PT: Lei n.º 58/2019
Scope

Privacy governance, records of processing (RoPA), lawful basis and legitimate interest assessments, DPIAs, international transfers, data subject rights operations, breach response, processor governance, retention and minimisation.

Where programmes usually break

A RoPA assembled from interviews and accurate only on the day it was signed. Lawful basis chosen once and never revisited when the product changed. DPIAs treated as a form rather than an assessment. A transfer position undocumented since the last framework change. Processor governance that stops at signing the DPA.

Need help implementing privacy policies, running an impact assessment, or a fractional DPO?

Regulation 02

EU AI Act

The Act asks a question most organisations cannot yet answer: which AI systems do you operate, who provides them, and what risk class is each one in? Everything else follows from getting that inventory right.

Timeline changed Annex III high-risk obligations moved to 2 December 2027

The Digital Omnibus deferred the high-risk deadline from August 2026. Transparency obligations under Article 50 largely did not move. The deferral buys implementation time — it does not remove the inventory work, which is the part that takes a quarter.

Inventory, classification, governance

Regulation (EU) 2024/1689
Scope

Inventory of AI systems, risk classification in line with the Regulation, and definition of the governance model. Role determination per system — provider, deployer, importer, distributor — prohibited-practice screening, high-risk and GPAI obligation mapping, human oversight design, technical documentation, post-market monitoring, and the interlock with GDPR.

The sequence that works

Discover the estate first, including models embedded in software you purchased. Establish your role for each system. Screen for prohibited practices and stop those immediately. Then classify by risk against the Act's own criteria, with the reasoning recorded. Map obligations only for what is genuinely in scope, and build governance that keeps the inventory true as teams keep shipping.

Want to know whether your AI tools comply with the European regulation?

Regulation 03

DORA

DORA turns resilience into an evidenced discipline with named critical functions and contractual teeth. We map obligations to the controls you already have before proposing new ones.

ICT risk, critical functions, third parties

Regulation (EU) 2022/2554 · directly applicable
Scope

ICT risk management, critical function mapping and third-party contract management. Register of information, incident classification and reporting, resilience testing programmes, and remediation of supplier contracts that do not yet carry the required clauses.

What we usually find

ICT risk controls split across technology, information security and vendor management, each with its own register — the same control evidenced three different ways, with gaps in between. Consolidation is worth more than new controls.

Need help aligning your infrastructure and contracts with what DORA requires?

Regulation 04

NIS 2

A directive, which means the obligation that binds you is the national law that implements it. In Portugal that is Decreto-Lei n.º 125/2025, and it has live deadlines.

Portugal — live deadline MyCiber registration closes 15 September 2026

The CNCS platform opened on 23 June 2026. Entities in scope must register, and appoint a permanent contact point and a security officer within 20 business days of qualifying. Asset inventories follow by 31 January 2027.

Scoping, measures, reporting

Directive (EU) 2022/2555 · PT: DL n.º 125/2025
Scope

Entity scoping, cybersecurity risk management measures and reporting obligations. Determining whether you are an essential or important entity, which of the three compliance levels applies, registration and role appointments, incident reporting inside the 24-hour window, and the measure implementation roadmap.

Need help registering your entity on the MyCiber portal? We can do that.

Regulation 05

Whistleblowing

One of the few compliance obligations judged entirely after something has already gone wrong — and one where the legal deadlines for responding to a report are short and absolute.

Channel, policy, and case management

Directive (EU) 2019/1937 · PT: Lei n.º 93/2021
Scope

Implementation of the internal reporting channel, drafting of the whistleblower protection policy, and the case management process and service. In Portugal the obligation applies to employers with 50 or more workers, and to certain entities regardless of size.

Why it fails in practice

The channel gets bought and the process never gets built. A report arrives, nobody knows who triages it, confidentiality is broken in the first week, and the acknowledgement and feedback deadlines pass. The channel is the easy part.

Need to implement the internal policy and reporting channel, and be sure cases are managed within the legal deadlines?

Regulation 06

AML Directive

The one area where the work is genuinely operational. Framework design matters, but most of the value is in file-level execution at volume, with a quality layer that makes the output defensible.

KYC, monitoring, remediation at volume

AMLD · PT: Lei n.º 83/2017 — entidades obrigadas
What we do

KYC and KYB processes, business-wide risk assessment, transaction monitoring, and the capacity to clear backlogs. Enhanced due diligence for complex structures and PEPs, sanctions screening, and a documented QA standard with independent second-line review.

Need operational capacity to review files and run AML/KYC processes?

Also delivered

Adjacent work we take on.

Enterprise & operational risk

ERM frameworks, risk appetite and taxonomy, RCSA design, key risk indicators, and control rationalisation across regimes.

Third-party & supply chain risk

Vendor tiering and criticality, due diligence operations, contractual control clauses and ongoing monitoring.

Ethics & corporate conduct

Code of conduct, anti-bribery and corruption, conflicts of interest, and third-party integrity due diligence.

Markets — European Union

One framework.
Twenty-seven implementations.

A Regulation applies identically everywhere. A Directive does not — it becomes twenty-seven national laws with different thresholds, different regulators and different deadlines. Companies operating across borders usually discover this after they have already built the programme once.

Multi-jurisdiction programmes

Build once. Map to each country. Evidence in one place.

The alternative — a separate programme per entity — is how a group ends up with six versions of the same control and no consolidated view of anything.

01

Regulation versus directive

We separate what is directly applicable — GDPR, DORA, the AI Act — from what depends on national transposition, like NIS 2 and whistleblowing. Only the second group needs country-by-country work.

02

One control library, many obligations

A single control usually satisfies requirements in several regimes and several countries. We map obligations to controls rather than the reverse, which is what stops the library doubling every time you enter a market.

03

Local thresholds, local regulators

Employee-count thresholds, registration duties and reporting windows differ by member state. We check them per entity rather than assuming the strictest applies everywhere — that assumption is expensive.

04

Group governance

Who owns a control at group level, who owns it locally, and how a local finding reaches the group board. Usually the missing piece rather than the controls themselves.

05

One evidence base

Evidence produced once, retrievable by entity, by regime and by control. This is what turns a regulator request from a three-week scramble into an afternoon.

06

Market entry

Before you commit to a country, what would actually be required there — and whether the answer changes the business case. Cheaper to know first.

Sectors we serve

The regulation is the same. The operating reality is not.

A control that works in a bank fails in a forty-person SaaS company, and the reverse. We design for how the organisation actually runs.

Financial services

Evidence under continuous supervision

Established frameworks, fragmented control ownership, and a supervisor who asks for proof. Most of the value is in rationalising what already exists.

DORAAMLERM
FinTech

Licence-grade compliance at start-up speed

Growing faster than the control environment. The work is building something a regulator will accept without stopping the product.

AML / KYCGDPROutsourcing
Technology & SaaS

Compliance as a sales dependency

Enterprise buyers audit you before they buy. Privacy and security posture is a revenue function long before it is a legal one.

GDPRNIS 2Third-party risk
AI companies

Governance that keeps up with shipping

The estate changes weekly. Governance has to be something engineering can execute, not a quarterly review board.

EU AI ActGDPRHuman oversight
Digital platforms

Obligations that scale with users

Content, payments, identity and data obligations that arrive together once you cross a threshold you did not plan for.

GDPRAMLNIS 2
Industry & manufacturing

Operational technology in scope

NIS 2 pulled critical manufacturing and supply chains into a regime built for IT. The gap is usually between the plant and the policy.

NIS 2Third-party riskEthics & ABC
Professional services

Obliged entities without an AML function

Law firms, accountants, consultancies and real estate are obliged entities under AML law, usually without anyone whose job it is.

AMLGDPRWhistleblowing
Scale-ups

Building the function for the first time

No legacy to unpick, and no framework either. The advantage is that you can build it correctly once.

Operating modelFractional leadership
Multinational groups

One framework, many jurisdictions

The problem is rarely a missing control. It is the same control implemented six different ways across six entities.

ERMGroup governanceCSRD

Mercados — Portugal

O regulamento é europeu.
A fiscalização é portuguesa.

Quem vem falar com a sua empresa sobre RGPD normalmente traz a versão de Bruxelas. Nós trabalhamos na Lei n.º 58/2019, na Lei n.º 93/2021, no Decreto-Lei n.º 125/2025 e com a CNPD e o CNCS — porque é aí que a obrigação se torna concreta.

Prazo em curso Registo no MyCiber até 15 de setembro de 2026

O portal do CNCS abriu a 23 de junho de 2026. As entidades abrangidas pelo novo regime de cibersegurança têm de se registar, designar ponto de contacto permanente e responsável de segurança nos 20 dias úteis seguintes à qualificação, e submeter o inventário de ativos até 31 de janeiro de 2027.

Passo 01

Enquadramento da entidade

Determinar se a sua empresa é entidade essencial, importante ou fora de âmbito — e qual dos três níveis de exigência (básico, substancial ou elevado) se aplica. Com fundamentação escrita.

Passo 02

Registo e designações

Registo no MyCiber, designação e comunicação do ponto de contacto permanente e do responsável de segurança da informação, dentro dos prazos legais.

Passo 03

Medidas e reporte

Inventário de ativos, plano de implementação das medidas de gestão de risco e o processo de reporte de incidentes significativos dentro da janela de 24 horas.

Porque isto importa

Regulamento aplica-se. Diretiva transpõe-se.

É a distinção que decide onde está o seu risco real, e a que quase ninguém dá atenção quando compra um serviço de compliance.

Aplicação direta

RGPD, DORA, Regulamento IA

Aplicam-se igualmente em todos os Estados-Membros. O texto é o mesmo em Lisboa e em Berlim — mas a autoridade que o fiscaliza, a prática sancionatória e a linguagem em que tem de responder não são.

Transposição nacional

NIS 2, Whistleblowing, BC/FT

A obrigação que o vincula é a lei portuguesa, não a diretiva. Limiares, prazos, entidades competentes e coimas são definidos em Portugal — e diferem dos de Espanha ou de França.

Exemplo concreto: em 2019 a CNPD deliberou desaplicar várias normas da própria Lei n.º 58/2019 por incompatibilidade com o RGPD (Deliberação 2019/494). Uma empresa que construiu o programa apenas sobre a letra da lei nacional ficou, nesses pontos, a cumprir uma norma que a autoridade não aplica. É este tipo de detalhe que separa quem trabalha o direito português de quem traduz o regulamento europeu.

Legislação nacional

O que se aplica à sua empresa em Portugal.

As normas em que trabalhamos, e a autoridade com que vai lidar.

Lei n.º 58/2019
de 8 de agosto

CNPD

Execução do RGPD em Portugal

Assegura a execução do Regulamento Geral de Proteção de Dados na ordem jurídica interna. Regula matérias deixadas à margem nacional — tratamento de dados de trabalhadores, prazos de conservação, consentimento de menores, contraordenações. Ler em conjunto com a Deliberação 2019/494 da CNPD.

Lei n.º 93/2021
de 20 de dezembro

Regime geral

Proteção de denunciantes de infrações

Transpõe a Diretiva (UE) 2019/1937. Obriga entidades com 50 ou mais trabalhadores — e determinadas entidades independentemente da dimensão — a disporem de canal de denúncia interno, com prazos legais estritos de acusação de receção e de resposta ao denunciante, e regime próprio de confidencialidade e proibição de retaliação.

Decreto-Lei n.º 125/2025

CNCS
Portal MyCiber

Regime jurídico da segurança do ciberespaço — NIS 2

Transpõe a Diretiva NIS 2, concretizada por regulamento do CNCS em junho de 2026. Classifica entidades essenciais, importantes e públicas relevantes; impõe registo no MyCiber, designação de ponto de contacto permanente e responsável de segurança, medidas de gestão de risco em três níveis, inventário de ativos, relatório anual e reporte de incidentes significativos em 24 horas.

Lei n.º 83/2017
de 18 de agosto

BdP · CMVM · ASF · ASAE

Prevenção do branqueamento de capitais e financiamento do terrorismo

Define as entidades obrigadas — muito além do setor financeiro: contabilistas, advogados, mediadores imobiliários, comércio de bens de elevado valor. Deveres de identificação e diligência, avaliação de risco, conservação, exame, comunicação de operações suspeitas, formação e controlo interno.

Regulamento (UE)
2022/2554 — DORA

Aplicação direta

Resiliência operacional digital do setor financeiro

Diretamente aplicável, sem necessidade de transposição. Em Portugal a supervisão cabe ao Banco de Portugal, à CMVM e à ASF conforme o tipo de entidade. Gestão de risco TIC, mapeamento de funções críticas, registo de informação e cláusulas contratuais obrigatórias com fornecedores.

Regulamento (UE)
2024/1689 — IA

Aplicação direta

Regulamento da Inteligência Artificial

Diretamente aplicável. As obrigações de alto risco do Anexo III foram diferidas para 2 de dezembro de 2027 pelo Digital Omnibus, mas o inventário e a classificação de sistemas continuam a ser o trabalho mais longo — e o que tem de começar primeiro. Fica ainda por definir integralmente o quadro nacional de autoridades competentes.

Referências legislativas apresentadas a título informativo e atualizadas à data de publicação. Não constituem parecer jurídico.

Serviços

O que fazemos para empresas portuguesas.

Trabalhamos sobretudo com PME e empresas em crescimento — onde não há departamento de compliance e a obrigação existe de igual modo.

RGPD

Lei n.º 58/2019 · CNPD
Âmbito

Governação de privacidade, registo de atividades de tratamento (RoPA), avaliações de impacto (DPIA) e gestão dos direitos dos titulares.

Precisa de apoio na implementação das políticas de privacidade, avaliação de impacto ou de um DPO fracionado?

Canal de denúncias

Lei n.º 93/2021
Âmbito

Implementação do canal de denúncias interno, elaboração da política de proteção ao denunciante, e o processo e serviço de gestão de casos.

Precisa de implementar a política interna, o canal de denúncias e garantir a gestão de processos no cumprimento rigoroso dos prazos legais?

NIS 2

DL n.º 125/2025 · CNCS
Âmbito

Enquadramento da entidade, medidas de gestão de risco de cibersegurança e obrigações de reporte.

Precisa de ajuda com o registo da entidade no portal MyCiber? Nós podemos ajudar.

DORA

Reg. (UE) 2022/2554
Âmbito

Gestão de risco de TIC, mapeamento de funções críticas e gestão de contratos com fornecedores (third-party risk).

Precisa de ajuda para alinhar a sua infraestrutura e contratos com as exigências do DORA?

Regulamento IA

Reg. (UE) 2024/1689
Âmbito

Inventário de sistemas de IA, classificação de risco de acordo com o regulamento e definição do modelo de governação.

Quer saber se as suas ferramentas de IA estão em conformidade com o regulamento europeu?

BC/FT — AML

Lei n.º 83/2017
O que fazemos

Processos de KYC/KYB, avaliação de risco, monitorização de transações e capacidade para limpeza de backlogs.

Precisa de reforço de capacidade operacional para revisão de ficheiros e processos de AML/KYC?

Porque nós

Somos portugueses. Trabalhamos como consultores europeus.

Falamos a sua língua — nos dois sentidos

Reuniões, políticas e formação em português. Documentação em inglês quando é o seu cliente internacional ou o auditor do grupo que a vai ler.

Escala de PME, exigência de banco

Trazemos método de instituições financeiras e grandes operações reguladas, dimensionado para uma empresa de 40 ou 200 pessoas. Não vendemos um framework de banco a quem não o consegue operar.

Sem pirâmide

Fala com quem faz o trabalho. Não há sócio na apresentação e júnior na execução — somos uma equipa pequena e sénior, e é deliberado.

Conhecemos as autoridades

CNPD, CNCS, Banco de Portugal, CMVM. Saber em que linguagem cada uma espera a resposta poupa-lhe meses.

Fazemos, não só recomendamos

Se não tem equipa para implementar, implementamos nós. Se precisa de capacidade temporária, colocamos especialistas dentro da sua estrutura.

Preço fechado no diagnóstico

A avaliação de gaps tem âmbito e preço definidos antes de começar. Sem obrigação de continuar connosco depois.

Próximo passo

Que problema de compliance tem em mãos?

Diga-nos a situação — um prazo, uma auditoria, uma norma nova. Dizemos-lhe o caminho mais curto e defensável, e se precisa de nós para tudo, para uma parte, ou para nada.

Delivery & work

People who do the work,
and what that looks like.

Advisory tells you what to do. Delivery is us doing it — inside your organisation, on your systems, under your governance, for exactly as long as the problem lasts.

The model

A pod is a team, not a pile of CVs.

Staff augmentation sends you people. A pod sends you a team with a lead who owns the outcome, a plan, a quality standard and a defined end state. The difference shows up in month two.

Composition

Built around the objective

A typical pod carries a compliance lead, a regulatory specialist, a risk and controls consultant, a business analyst and a project manager. Data or technology specialists join where the work demands it.

Scaling

Up for the peak, down for the plateau

Remediation needs volume for twelve weeks and two people afterwards. The pod flexes on agreed notice, so you are not paying for a peak that has passed.

Accountability

One senior name on the outcome

Every pod has a senior lead accountable for delivery, present throughout. Not a partner at kick-off and a graduate thereafter.

GDPR Programme Pod

10–16 wks
Privacy Lead / fractional DPO Data Protection Specialist Data & Technology Specialist Business Analyst
Typical outputs
RoPALawful basis mappingDPIA methodology Transfer assessmentsDSR processBreach playbook

EU AI Act Readiness Pod

8–12 wks
Regulatory Lead AI Governance Specialist Risk & Controls Consultant Business Analyst
Typical outputs
AI system inventoryRisk classificationGap assessment Governance modelControl frameworkRoadmap

DORA & NIS 2 Resilience Pod

12–20 wks
Operational Resilience Lead ICT Risk Specialist Third-Party Risk Specialist Project Manager
Typical outputs
Critical function mappingICT risk frameworkRegister of information Incident classificationTesting programmeContract remediation

AML Remediation Pod

Scales to volume
Financial Crime Lead Remediation Manager KYC / KYB Analysts Quality Assurance Reviewer
Typical outputs
File remediation at volumeQA frameworkBacklog clearance Issue validationRegulator-ready reporting

Roles we deploy

Specialists, not generalists with a template.

Compliance analystsRegulatory specialistsRisk & controls specialists Control testersKYC / KYB analystsAML investigators Privacy specialistsFractional DPOAI governance specialists Third-party risk specialistsPolicy specialistsCompliance project managers Compliance PMORemediation managersQuality assurance reviewers Fractional compliance leadershipBusiness analystsCase managers — whistleblowing

Commercials

Three ways to engage us.

Chosen by what the problem needs rather than what is easiest to sell.

Project

Defined scope, deliverables and end date, priced against the outcome.

Best for

Gap assessments, framework and policy design, implementation programmes, bounded remediation.

Embedded

Named specialists working as part of your team, in your tools, on your cadence.

Best for

Capacity gaps, specialist skills you will not hire full time, programme continuity, interim cover.

Managed

We operate a defined compliance capability to an agreed service standard.

Best for

Ongoing monitoring and testing, KYC operations, whistleblowing case management, fractional compliance leadership.

The work

How engagements actually run.

Representative engagement shapes, described the way we would scope them. Situation, work, outcome — no logos, no invented numbers.

DORA & NIS 2 — Financial services and technology

Consolidating fragmented ICT control frameworks

Situation

ICT risk controls split across technology, information security and vendor management, each with its own register. The same control evidenced three ways, with gaps between them, and no consolidated supplier risk view.

Work

Obligations mapped to the existing control estate before designing anything new. Critical function mapping, register of information, incident classification, third-party contract gap analysis and a coordinated remediation plan with named owners.

A single consolidated control framework and materially stronger evidence for regulatory review.

Whistleblowing — Lei 93/2021

End-to-end reporting process with legal-deadline workflows

Situation

A reporting channel had been purchased but no process existed behind it. No triage owner, no confidentiality protocol, and no mechanism to track the statutory acknowledgement and feedback deadlines.

Work

End-to-end process design and case management with workflows parameterised to the legal deadlines. Whistleblower protection policy, conflict-of-interest handling, investigator roles, retaliation safeguards and an audit trail built to be produced on request.

A channel that functions as a control rather than as a form, with deadlines that cannot quietly pass.

EU AI Act — Technology

AI governance for a distributed model estate

Situation

Multiple AI systems built by different product teams across several European entities. No central register, no agreed classification, no single owner. Leadership could not answer a customer questionnaire about AI use.

Work

Discovery across engineering and procurement to find purchased models as well as built ones. A classification methodology product teams apply at design time. Gap assessment against high-risk and GPAI obligations, governance model, control framework and a roadmap tied to the revised timelines.

Clear regulatory ownership and an AI programme the engineering organisation can run without a consultant in the room.

GDPR — SaaS scale-up

Privacy that stops blocking enterprise deals

Situation

Enterprise security reviews stalling repeatedly at the privacy questionnaire. RoPA eighteen months out of date, lawful basis inconsistent across products, transfer position undocumented.

Work

Processing inventory rebuilt from systems and data flows rather than interviews. Lawful basis and legitimate interest assessments, transfer impact assessments, a DPIA methodology handed to product, and DSR and breach runbooks tested against a live scenario.

A defensible privacy position and an evidence pack that answers procurement in days rather than weeks.

AML — Payments

Remediation at volume with a defensible QA standard

Situation

A significant KYC file backlog following a supervisory finding, with a fixed deadline and no internal capacity to clear it.

Work

A remediation pod scaled to file volume, working to a documented QA standard with independent second-line review, daily throughput reporting and issue validation to closure.

Backlog cleared to deadline with evidence of quality, not just evidence of completion.

Function build — Scale-up

A compliance function built to scale, not to staff

Situation

Rapid European expansion with compliance handled informally between a founder and a part-time adviser, across multiple jurisdictions.

Work

Compliance operating model and policy architecture, risk framework, responsibility model, monitoring plan, and fractional compliance leadership until an internal hire made commercial sense.

A functioning compliance capability without permanently expanding headcount ahead of revenue.

These describe how we structure work, not claims about specific past clients. Named references are provided under NDA on request.

Next step

Tell us the objective. We will shape the team.

Most conversations start with a deadline and a gap. That is enough to work with.

Insights

What changed, and what it
means for your deadline.

Regulatory updates, practical analysis and implementation guides — written by the people running this work. No trend pieces.

Regulatory updates

Currently on our desk.

The Digital Omnibus deferred the high-risk deadline — here is what did not move

EU institutions reached provisional agreement on 6 May 2026, confirmed by member states on 13 May. High-risk obligations for Annex III systems moved from 2 August 2026 to 2 December 2027; Annex I systems, meaning AI embedded in regulated products, moved to 2 August 2028.

What did not move matters more. Article 50 transparency obligations remain largely on the original schedule, with a four-month grace period to 2 December 2026 for watermarking of existing systems. A new Article 5 prohibition covering non-consensual intimate imagery and CSAM arrives with a transitional period to the same date. Bias detection authority now extends to all AI systems rather than only high-risk ones, and the AI Office gains investigation and enforcement powers.

Practical read: the deferral buys implementation time, not discovery time. Inventory and classification is the long pole in every AI Act programme we run — typically a quarter for a company that has been shipping models for a few years. Starting that in 2027 is not a plan.

Registo no MyCiber: o prazo é 15 de setembro de 2026

O Decreto-Lei n.º 125/2025 estabelece o regime jurídico da segurança do ciberespaço, transpondo a Diretiva NIS 2, e foi concretizado por regulamento do CNCS em junho de 2026. O portal MyCiber abriu a 23 de junho.

As entidades abrangidas têm de se registar até 15 de setembro de 2026, designar ponto de contacto permanente e responsável de segurança da informação nos 20 dias úteis seguintes à qualificação, submeter a lista de ativos até 31 de janeiro de 2027, e implementar integralmente as medidas até 22 de junho de 2028. Incidentes significativos reportam-se em 24 horas.

Leitura prática: muitas empresas assumem que NIS 2 é assunto de bancos e operadores críticos. O âmbito é consideravelmente mais largo — inclui setores industriais, logística, gestão de resíduos e fornecedores digitais. O primeiro trabalho é determinar o enquadramento, não comprar tecnologia.

Article 50 transparency: the obligation that arrived on schedule

While the high-risk deadlines slipped, the transparency duties did not. If you deploy a chatbot, generate synthetic content, or run emotion recognition or biometric categorisation, users have to be told — and machine-readable marking of AI-generated content applies, with existing systems given until 2 December 2026.

Practical read: this is the AI Act obligation most likely to catch a company that decided it was out of scope because it does not build high-risk systems. Transparency applies regardless of risk class.

GDPR, NIS 2 and DORA are converging on your suppliers

Three regimes, three vocabularies, one underlying demand: know who your critical suppliers are, know what they can reach, hold them to contractual security obligations, and be able to prove all of it. GDPR frames it as processor governance, NIS 2 as supply chain security, DORA as ICT third-party risk with a register of information.

Practical read: organisations running these as three separate projects build three vendor registers that disagree. One tiering exercise, one diligence process, one contractual clause set mapped to three regimes is materially cheaper and produces better evidence.

Playbooks & guides

Implementation, not theory.

Regulatory updates reflect the position at the date shown and are provided for information. They are not legal advice. Playbook and guide titles are the editorial pipeline — replace with published pieces as they go live.

About

Compliance should work
in the real world.

Regulation does not fail because organisations cannot read legislation. It fails when requirements never become ownership, controls, processes and evidence. That is where we work.

The team

Two people who kept hitting the same wall from opposite sides.

One spent a decade proving whether controls actually work. The other spent it getting the work funded, staffed and finished. Provable is what happens when those two problems are finally solved in the same room.

António Pedro Vieira, Chief Executive Officer and Founder Founder

Chief Executive Officer

António Pedro Vieira

António has spent his career on the commercial and operational side of compliance — running regulated operations at scale, governing risk inside global banks, and building compliance practices as businesses rather than as cost centres.

He led AML and KYC operations at Accenture, managing teams of thirty-plus specialists across EMEA and US portfolios and owning enhanced due diligence for complex, high-risk structures. At UBS he moved into governance as Business Risk Manager in the GCRG COO function, designing control and policy frameworks and aligning risk frameworks through a bank acquisition. At Revolut he ran regulatory compliance frameworks and embedded compliance-by-design with product and engineering before launch. Most recently he built a compliance services practice from an empty page — service catalogue, delivery methodology, pricing and go-to-market across the EU AI Act, DORA and PCI DSS.

He holds a Master’s in Environmental Economics and Management from the University of Porto and the University of Maribor, and is a published author. He works in Portuguese, English, Spanish and French, and is based in Kraków.

Works in
EU AI ActGDPRDORA AML & KYCPCI DSSRisk governance Practice building1st, 2nd & 3rd line
João Monteiro, Associate Consultant Co-founder

Associate Consultant

João Monteiro

João is the technical half of the practice. He works at the point where compliance stops being a document — control testing, and the evidence-level question of whether a control was designed correctly and whether it actually operated on the date it claims to.

He holds a law degree and an MBA, an unusual pairing in this field and the thing that most explains how he works: he reads an obligation the way a lawyer does, then implements it the way an operator has to. His experience spans risk management, control testing, cybersecurity, DORA, NIS 2 and third-party risk management.

He advises and provides hands-on technical support to small and medium-sized companies — organisations where the obligation is identical to a bank’s but there is no department to absorb it. That is deliberate. It is also the work he is best at.

Works in
Control testingGRCCybersecurity DORANIS 2ISO/IEC 27001 Third-party riskRisk management

How this started

Poland, a shared desk, and an argument that never really ended.

MetTwo Portuguese on the same large operation in Poland, a long way from home.
ApartOne went down into the machinery. One went out into the market.
AgainWorking the same problem inside a global bank’s risk governance function.
NowThe same firm, built around the gap they had each been falling into for years.

We met in Poland — two Portuguese a long way from home, on the same operation, neither of us yet doing the job we would end up doing.

What we had in common was a habit of arguing. About the work, about how it ought to be done, about why the process everyone had quietly agreed to tolerate was obviously broken. We were young enough to think that was a personality trait rather than a career.

Then we went in opposite directions.

João went down. Into the machinery. Control testing, control environments, cybersecurity, ICT and third-party risk — the unglamorous discipline of proving that a control actually operated on the date it claimed to. He spent years in the part of this profession where you cannot bluff, because the evidence either exists or it does not.

António went out. Into operations at scale — thirty, forty people running AML and KYC — and then into the commercial side of the work, where you have to convince a board, price the programme and own the number.

Then we ended up on the same problem again.

Inside the risk governance function of a global bank, working the same control estate from our two different halves. It is where this stopped being an observation between friends and became the argument for a company.

Because we could finally see the whole failure at once. João would find a control framework that was technically correct and commercially orphaned — designed properly, then quietly abandoned because nobody senior enough ever sponsored it. António would find a programme that had been sold, approved and budgeted, and was sitting on a shelf because nobody in the building could actually implement it.

Same failure. Opposite ends of it.

That gap — between the advice and the execution — is where most regulatory findings are born, where most compliance budgets die, and where we spent years watching good work go to waste from either side of a wall.

We started this firm to close it. One of us knows what it costs to build a control that survives testing. The other knows what it costs to get that work funded, staffed and finished. We are not guessing that the pair works — we ran it inside a global bank before we ran it as a company.

That is the whole company. Everything else is method.

Principles

Six things we hold to.

01

Practical over theoretical

A framework that is correct and unusable has failed. We design for the organisation in front of us.

02

Execution over presentation

The deliverable is a working control environment. The document is how we describe it, not what you bought.

03

Specialists over generalists

The person doing your AI Act work has done AI Act work. We would rather decline than staff a gap with enthusiasm.

04

Evidence over assumption

If a control cannot produce proof it ran, it is a policy. We test rather than assert.

05

Technology where it earns its place

Tooling that removes work, not tooling that adds a licence and a new place to file things.

06

Senior accountability throughout

The senior name at the pitch is the senior name in delivery. No pyramid, no handover to people you have not met.

How we are different

The uncomfortable part.

Most compliance consultancies are structured to produce documents, because documents are easy to scope, easy to price and easy to sign off. The problem is that documents are not what the regulation asks for.

Being able to execute changes the incentives. We cannot recommend a control framework nobody can operate, because we may be the ones operating it. We cannot hand over a roadmap that ignores your capacity, because we will be inside the delivery when capacity runs out.

That constraint makes the advice better. It is the whole argument for the model.

Contact

What compliance problem
are you solving?

Tell us what you are dealing with — a deadline, a finding, a gap, a regulation that just landed. We will tell you the fastest defensible route from the requirement to the evidence, and whether you need us for all of it or none of it.

This form is not connected yet — wire it to your inbox or CRM before launch.

Direct

Replace with your email address, phone and LinkedIn before launch.

Languages

Portuguese, English, Spanish and French. Meetings, policies and training in whichever your team actually uses.

What happens next

  • A reply within one working day
  • A 30-minute call to understand the situation
  • An honest view on whether we are the right firm
  • If yes, a scoped proposal with named people
Provable — compliance designed, delivered, operated Regulation → Requirements → Risks → Controls → Processes → Evidence → Assurance