Cases on the record.
Each entry below is one engagement: what we did, how long it took, what it produced. Anonymised by default. Named on client approval.
- 15DORA across 11 ICT functionsBanking & FS
- 14GDPR programme, special-category dataFEATUREDPharmaceutical
- 13AI Act classification, 7 modelsEnterprise SaaS
- 11Post-Schrems II transfer assessmentsRetail group
- 10NIS2 essential-entity programmeEnergy operator
- 06AML/CFT remediation, thematic reviewLicensed PSP
Audit-ready GDPR programme stood up in four months.
Eleven priority gaps. Six-month clock. We took the DPO function on day one, rebuilt the programme around special-category data, and delivered a clean response pack in four months.
GDPR programme · DPIAs · Vendor risk · Cross-border transfers · DPO-as-a-Service · Authority liaison
Other engagements.
FIVE ON FILEAI Act classification of 7 production models, kept the Q2 release.
Post-Schrems II transfer assessments across the vendor estate.
NIS2 essential-entity programme passed authority review.
AML/CFT remediation closed all twelve actions from a thematic review.
What we publish, what we keep confidential.
Every engagement starts under mutual NDA. Cases publish only with written client approval.
Sector, scale, jurisdiction, outcome. Names appear only when the client wants the credit.
Named references after engagement letter is signed and the reference client consents to the introduction.
Same shape, your problem.
Senior partner on the call. Scoped engagement letter inside two weeks of the first conversation.