KPN Advisory — Audit, Risk & AI-Powered Business Automation
Audit.Risk.Regulation.AI.
A specialist consultancy for regulated businesses — combining audit and assurance, regulatory compliance, risk management, operational resilience, information security and AI governance with controlled business process automation.

Financial Services · Fintech · Payments · E-money · Regulated Technology · SMEs
What We Do
Six capability areas. One accountable partner.
Our practice covers the full spectrum of governance and operational excellence — from independent audits and risk frameworks to regulatory programmes and AI-enabled automation.
- 01
Audit & Assurance
Operational, IT and regulatory audits that provide genuine assurance — not just compliance sign-off.
- 02
Risk & Governance
Risk management frameworks, internal controls and Board-level governance aligned to ISO 31000.
- 03
Regulatory & Resilience
FCA, DORA, PSD2 / SCA, MiCA and Consumer Duty — from gap analysis to implementation.
- 04
Information Security & Standards
ISO 27001, ISO 27701, ISO 22301, PCI DSS and SOC readiness for regulated technology businesses.
- 05
AI Governance
Responsible AI governance, Microsoft Responsible AI Standard alignment and ISO/IEC 42001 AIMS readiness.
- 06
Business & Controls Automation
Process optimisation and automation with embedded controls and human-in-the-loop oversight.
Why KPN Advisory
Advisory expertise that goes beyond the report.
We work with organisations that need more than a generic consulting engagement. Our work is precise, practical and built to last.
Senior-led engagements
Each engagement receives focused attention from senior specialists — not junior resource and generic frameworks.
Deep audit & risk expertise
Internal audit, enterprise risk management and controls experience at the core of every engagement.
Regulated-industry experience
Working knowledge of FCA, EU DORA, ISO standards and ESG requirements across financial services and fintech.
Implementation, not only recommendations
We work alongside your team to build frameworks, controls and processes that hold.
Evidence-led assurance
Controls designed, operated and evidenced so they stand up to audit and supervisory scrutiny.
AI-enabled, human-controlled
Automation designed with human-in-the-loop controls at every critical decision point.
Commercially practical
Recommendations calibrated to be proportionate, achievable and defensible.
Board- and regulator-ready outputs
Clear written deliverables your Board, auditors and supervisors can rely on.
How We Work
The principles that shape every engagement we take on.
- 01
Precision Over Volume
We take on work we can do exceptionally well. Each engagement receives focused attention and specialist expertise — not junior resource and generic frameworks.
- 02
Implementation, Not Just Advice
Our measure of success is not a report — it is a framework, control, or process that your organisation can operate effectively in the long term.
- 03
AI with Human Oversight
Every automation solution we design includes human-in-the-loop controls at critical decision points. We believe intelligent automation and strong governance are complementary.
- 04
Commercially Practical
We understand the commercial realities of regulated industries. Our recommendations are calibrated to be proportionate, achievable, and defensible to regulators and boards.
Regulatory & Standards Expertise
The frameworks regulated businesses are held to.
Specialist advisory across the regulations and standards that matter most to financial services, fintech, payments and regulated technology firms.
- FCA Consumer DutyPRIN 2A
- UK Operational ResiliencePS21/3
- EU DORADigital operational resilience
- EU MiCACASP assurance
- PSD2 / SCAPayments compliance
- FCA s166Skilled Person Review support
- Third-Party RiskOutsourcing & suppliers
- ESGAssessments
- ISO 27001:2022Information security
- ISO 27701Privacy information management
- ISO 22301Business continuity
- ISO 31000Risk management
- ISO/IEC 42001AI management systems
- Microsoft Responsible AIStandard alignment
- SOC 1 / SOC 2Readiness
- PCI DSSPayment security
Core Competencies
- ISO 27001:2022 ISMS Implementation & Advisory
- ISO 22301 Business Continuity Management Systems
- ISO 27701 Privacy Information Management
- ISO 31000 Risk Management Framework
- EU DORA Compliance & Operational Resilience
- EU MiCA / CASP Regulatory Assurance
- FCA Consumer Duty Assessments
- ESG Compliance & Reporting
- AI Governance & ISO/IEC 42001
- AI-enabled Process Automation Design
- Financial Controls & Governance
- Audit, Assurance & Risk Management
- Information Security & Privacy Governance
Advisory expertise areas. KPN Advisory is an independent consultancy, not an accreditation or certification body, and references to regulators, standards and frameworks do not imply endorsement, partnership or certification.
Featured Services
Where clients most often start.

Audit, Risk & Assurance
Audit & Assurance
Independent, expert-led audit engagements that provide genuine assurance — not just compliance sign-off. We cover operational, IT, and regulatory audit across complex regulated environments.

Regulatory & Resilience
DORA & Operational Resilience
Comprehensive support for EU Digital Operational Resilience Act compliance and UK Operational Resilience framework implementation — built for organisations with complex ICT dependency.

Information Security & Standards
ISO 27001 & ISO 31000
Specialist advisory for organisations pursuing or maintaining ISO 27001:2022 certification and ISO 31000 risk management framework implementation.

AI Governance & Automation
AI Governance, Responsible AI & ISO/IEC 42001
Practical governance frameworks helping organisations deploy and use AI responsibly, manage AI risk, demonstrate accountability and prepare for emerging regulatory and assurance expectations. We bring together three connected offerings: an enterprise AI Governance Framework, alignment with Microsoft's Responsible AI Standard, and ISO/IEC 42001 Artificial Intelligence Management System (AIMS) readiness and implementation. We deliver the assessment and the implementation.
Featured Solutions
Productised solutions with governance built in.
Services provide expertise, advisory and assurance. Solutions are productised: defined implementation programmes, platforms and automation with governance built in.
Consumer Duty Control & Intelligence Platform
- Problem
- Complaints and findings managed in silos with no PRIN 2A outcome mapping
- Solution
- End-to-end FCA PRIN 2A compliance. Evidenced. Automated. Board-ready.
- Outcome
- Zero missed escalations through automated overdue detection
Continuous Controls Monitoring
- Problem
- Controls tested only periodically and by sample
- Solution
- Key controls tested on full populations, not only samples.
- Outcome
- Earlier detection of control failures
FinOps Control Centre
- Problem
- Month-end close taking too long and prone to error
- Solution
- A command hub for finance operations and control.
- Outcome
- Accelerated month-end close
Agentic Workflow Governance
- Problem
- AI agents deployed without a clear owner
- Solution
- AI agents inventoried, bounded, supervised and accountable.
- Outcome
- Clear accountability for every AI agent
Assessments & Diagnostics
Start with a defined-scope assessment.
Not sure where to begin? A structured, expert-led assessment gives you an authoritative view of where you stand — with written outputs and a prioritised roadmap for what to do next.
Explore all assessments- Governance-FocusedFintech Governance & Readiness ReviewStructured findings report + prioritised action plan
- FCA & DORAFCA & DORA Operational ResilienceFCA and DORA Operational Resilience Assessment report + remediation roadmap
- RegulatoryISO 27001 / ISO 27701 ReadinessISO 27001 / ISO 27701 Readiness Assessment report + certification roadmap
- AI GovernanceAI Governance ReadinessAI Governance Readiness Report + prioritised roadmap
- Process AutomationFinance Controls & Automation DiagnosticWritten diagnostic report + automation opportunity map + implementation roadmap
Our Team
The people behind the practice.
A senior-led team combining deep regulatory knowledge with practical operational experience.
“Great business ideas deserve more than ambition alone — they deserve the right foundations to succeed.”

Khissain Pirov
Founder & CEO
Khissain brings 20+ years of experience spanning internal audit, enterprise risk management, regulatory compliance, and AI-enabled process transformation.
Read full profile
He founded KPN Advisory on the conviction that regulated businesses deserve trusted advice that is both technically rigorous and commercially grounded. He advises organisations on governance, risk, audit, compliance, business continuity, information security, privacy management, and AI governance — with expertise across ISO 27001, ISO 22301 Business Continuity Management Systems, ISO 27701 Privacy Information Management, DORA, ISO 31000, FCA Consumer Duty, and responsible AI governance frameworks.
- ISO 27001
- ISO 22301
- ISO 27701
- DORA
- AI Governance
- Audit & Risk

Farhad Foroughi
Lead Information Security Adviser
Farhad is a senior information security, cyber risk, and AI governance adviser with deep experience across fintech, payments, and regulated technology environments.
Read full profile
He advises organisations on governance, risk, audit, compliance, business continuity, information security, privacy management, and AI governance. His expertise includes ISO 27001, ISO 22301 Business Continuity Management Systems, ISO 27701 Privacy Information Management, DORA, PCI-DSS, SOC 2, GDPR, and responsible AI governance frameworks. At KPN Advisory, he helps clients design and implement practical security, compliance, resilience, and AI governance frameworks that support sustainable growth, responsible innovation, and regulatory confidence.
- ISO 27001
- ISO 22301
- ISO 27701
- AI Governance
- DORA
- Cyber Risk
Interested in joining the KPN Advisory team? We are always keen to speak with senior specialists in audit, risk and regulatory advisory. Get in touch
Have a regulatory, audit, risk or automation challenge?
Speak with KPN Advisory about the controls, assurance or implementation support your organisation needs.


