Our Services

Specialist Expertise Across Every Dimension of Governance

Thirteen interconnected practice areas — each delivered with the depth and rigour that regulated industries demand.

Strategic Advisory

Audit & Assurance

Independent, expert-led audit engagements that provide genuine assurance — not just compliance sign-off. We cover operational, IT, and regulatory audit across complex regulated environments.

Who This Is For

CFOs & Finance DirectorsCOOs & Operations LeadersAudit & Risk CommitteesBoard DirectorsFCA-authorised firms

Capabilities

  • Operational Audits
  • IT / ISMS Audits
  • Regulatory Compliance Audits
  • Business Process Reviews & Control Assessments
  • Internal Controls Evaluation
  • Audit Readiness Preparation
  • MiCA / Crypto-Asset Regulatory Audits
  • Continuous Controls Monitoring ControlOps
  • SOC 1 / SOC 2 Readiness ControlOps

What You Get

  • ✓Audit findings report with risk ratings
  • ✓Control gap assessment matrix
  • ✓Prioritised remediation roadmap
  • ✓Board-ready executive summary

Risk of Inaction

Operating without independent audit increases the risk of undetected control failures, regulatory sanctions, financial misstatement, and loss of stakeholder confidence.

Strategic Advisory

Risk Management & Internal Controls

Enterprise risk frameworks designed to be practical, proportionate, and embedded into day-to-day operations — not filed and forgotten.

Who This Is For

CFOs & Finance DirectorsCOOs & Business OwnersRisk & Compliance OfficersBoards requiring risk governance

Capabilities

  • ISO 31000 Risk Management Assessments
  • ISO 31000 Risk Management Framework Implementation
  • Internal Controls Design & Assessment
  • Risk Register Development
  • Control Testing & Effectiveness Review
  • Risk Governance Frameworks
  • Integrated Assurance Mapping ControlOps

What You Get

  • ✓Enterprise risk framework design
  • ✓Risk register with ratings and owners
  • ✓Internal controls assessment report
  • ✓Control testing protocol
  • ✓Governance documentation

Risk of Inaction

Poorly embedded risk management leads to uncontrolled exposures, regulatory findings, and inability to demonstrate governance to investors and regulators.

Regulatory & Resilience

Regulatory Compliance & Implementation

End-to-end regulatory compliance support — from gap assessment through to implementation, policy development, and evidencing compliance to regulators.

Who This Is For

CCOs & Heads of ComplianceCEOs of FCA-authorised firmsFounders preparing for regulatory authorisationLegal & regulatory teams

Capabilities

  • Regulatory Gap Assessments
  • Compliance Framework Implementation
  • Policy & Procedure Development
  • Regulatory Change Management
  • Training & Awareness Programmes
  • Regulatory Reporting Support
  • EU MiCA / CASP Compliance Mapping & Implementation
  • Regulatory Change Intelligence ControlOps

What You Get

  • ✓Regulatory gap assessment report
  • ✓Compliance framework documentation
  • ✓Policy & procedure suite
  • ✓Regulatory change log
  • ✓Training materials

Risk of Inaction

Non-compliance with regulatory requirements can result in FCA enforcement, fines, suspension of permissions, and reputational damage that is difficult to recover from.

Regulatory & Resilience

PSD2 / SCA Compliance Assessment & Implementation

End-to-end PSD2 / Payment Services Regulations and Strong Customer Authentication support — assessing regulatory scope, SCA design, exemption eligibility, Transaction Risk Analysis, transaction-level evidence and governance, and helping firms implement sustainable compliance controls.

Who This Is For

Payment Institutions & Electronic Money InstitutionsFintechs & Payment Service ProvidersCard Issuers & Programme ManagersCCOs & Heads of ComplianceHeads of Payments, Product & Financial CrimeFirms preparing for FCA, Internal Audit or assurance review

Capabilities

  • PSD2 / PSRs Scope & Applicability Assessments
  • SCA & 3-D Secure Control Reviews
  • SCA Exemption & Transaction-Treatment Assessments
  • TRA, Fraud-Rate & Threshold Monitoring
  • Exemption MI & Transaction Data Analytics
  • Product / Programme / BIN Regulatory Mapping
  • PSD2 Governance, Escalation & Assurance Frameworks
  • Compliance Remediation & Implementation Support

What You Get

  • ✓PSD2 / SCA compliance assessment report
  • ✓Product / programme / BIN applicability & exemption matrix
  • ✓TRA and regulatory MI control assessment
  • ✓PSD2 / SCA exemption register
  • ✓Prioritised remediation & implementation roadmap
  • ✓Board-ready executive summary

Assessment & Implementation Scope

Our PSD2 and SCA support is shaped around the firm's legal entity, payment services, payer and customer types, products, programmes, BINs, payment journeys and channels. We provide modular support across assessment and implementation:

PSD2 / PSRs Perimeter & Scope Exclusion Review (incl. Limited Network)
SCA Applicability & Authentication Journey Assessment
SCA Exemption Eligibility Assessment
Transactions Outside Normal SCA Application — MIT, MOTO & Territorial Scope
3-D Secure / ACS Configuration & Control Assessment
Transaction Risk Analysis Control Reviews (UK SCA-RTS Article 18)
Fraud-Rate Methodology & Exemption Threshold Monitoring (Article 19)
Exemption Escalation & Cessation Control Design (Article 20)
Exemption Monitoring, Regulatory MI & Data Analytics (Article 21)
Security Measures Assurance Readiness (Article 3(2))
Control Framework, Exemption Register & Regulatory Rules Library
Governance, RACI, Remediation & Audit-Readiness Implementation

Where relevant we also consider supporting controls that sit alongside — and are distinct from — SCA exemptions, including Consumer Duty and vulnerable-customer outcomes, PCI DSS, information-security controls and fraud monitoring. Our approach is business-model specific, evidence-led and implementation focused: we assess, design, implement and validate the controls, analytics, monitoring and evidence that support compliance — we do not perform live issuer transaction decisioning or certify regulatory compliance.

Risk of Inaction

Weak PSD2 and SCA governance can leave firms unable to demonstrate why transactions were processed without SCA, whether exemptions remain eligible, or whether Transaction Risk Analysis and fraud thresholds are being monitored correctly — increasing regulatory, audit, fraud and customer-friction risk.

Regulatory & Resilience

MiCA / CASP Assurance & Crypto-Asset Compliance

Independent, evidence-led assurance for firms within the scope of the EU Markets in Crypto-Assets Regulation (MiCA), including Crypto-Asset Service Providers (CASPs). We assess regulatory perimeter, governance, prudential safeguards, client-asset protection, custody, conduct and operational resilience, test whether controls work in practice, and support remediation and implementation.

Who This Is For

EU Crypto-Asset Service Providers (CASPs)Crypto exchanges, custodians & wallet providersPayment, e-money & fintech firms entering crypto-assetsCEOs, CCOs, CROs & MLROsCISOs, CTOs & Heads of Internal AuditBoards & Audit / Risk CommitteesFirms preparing for MiCA authorisation or supervisory review

Capabilities

  • MiCA Perimeter & CASP Service Classification
  • CASP Authorisation Readiness Assessments
  • MiCA Compliance Gap Assessments
  • Governance, Internal Control & Prudential Safeguards Reviews
  • Client-Asset Safeguarding, Segregation & Reconciliation Reviews
  • Crypto Custody, Wallet & Key-Governance Control Assessments
  • Conduct, Disclosure, Complaints & Conflicts-of-Interest Reviews
  • Market-Abuse Prevention & Detection Control Assessments
  • DORA / ICT Resilience, Outsourcing & Third-Party Risk Alignment
  • Remediation, Implementation & Independent Assurance

What You Get

  • ✓MiCA / CASP compliance assessment report
  • ✓MiCA obligations & CASP service applicability matrix
  • ✓Risk & control matrix with control-effectiveness ratings
  • ✓Client-asset, custody & reconciliation control assessment
  • ✓Prioritised gap & remediation register
  • ✓Evidence & audit-readiness pack
  • ✓Board-ready executive summary & implementation roadmap

Assessment & Assurance Scope

Our MiCA work is shaped around the firm's legal entities, the crypto-asset services it provides, the crypto-assets it deals in, its clients and its custody and operating model. We provide modular support across assessment, assurance and implementation:

MiCA Perimeter & CASP Service Classification (Art. 3(1)(16))
Governance, Internal Controls & Three Lines of Defence (Art. 68)
Prudential Safeguards: Capital, Monitoring & Escalation (Art. 67)
Safekeeping of Client Crypto-Assets & Funds, Segregation & Reconciliation (Art. 70)
Crypto Custody, Wallet Architecture & Private-Key / MPC / Multisignature Governance (Art. 75)
Conduct, Client Information, Complaints & Conflicts of Interest (Arts. 66, 71, 72)
Trading, Order Execution & Market-Abuse Prevention and Detection (Arts. 76–78, 92)
AML / CTF, Sanctions & Travel Rule Control Interface
DORA: ICT Risk, Incident Management, Testing & ICT Third-Party Risk
Outsourcing & Critical Third-Party Oversight (Art. 73)
Regulatory Reporting, Record-Keeping & Data Traceability
Orderly Wind-Down & Client-Asset Transfer Arrangements (Art. 74)

This is evidence-based testing, not only a policy review. Where relevant we trace positions from on-chain balances → wallet and custody records → the crypto subledger → customer entitlements → the general ledger, and test wallet completeness, ownership, segregation, transaction authorisation, privileged access, key governance and custodian oversight. AML / CTF and Travel Rule duties arise from EU anti-money-laundering law and the Transfer of Funds Regulation (EU) 2023/1113, not from MiCA itself. MiCA is an EU regime; UK activity is assessed separately against the UK FCA framework. We provide advisory and assurance support: we do not grant or guarantee authorisation, give legal opinions, certify compliance or cryptographic security, or hold client assets.

Risk of Inaction

Weak or poorly evidenced MiCA governance and controls can lead to delays or conditions in authorisation, supervisory findings, and difficulty demonstrating that clients' crypto-assets and funds are properly safeguarded. Custody, reconciliation or conduct failures can also cause client detriment, operational disruption, costly remediation and reputational damage.

Regulatory & Resilience

KPN Assurance360 - Skilled Person Review Support

Independent advisory support for FCA-regulated firms before, during and after Skilled Person Reviews under section 166 FSMA — helping firms strengthen governance, controls, evidence, remediation credibility and senior management accountability.

Who This Is For

CCOs & Heads of ComplianceCEOs & Senior Managers of FCA-regulated firmsBoards, Audit Committees & Risk CommitteesPayment institutions & e-money institutionsConsumer credit, lending & investment firmsFintech and digital finance firms

Capabilities

  • s166 Readiness Assessments
  • Skilled Person Review Response Support
  • Regulatory Scope & Evidence Mapping
  • Governance, SMCR & Board Reporting Support
  • Control, Conduct & Customer Outcome Reviews
  • Remediation Planning & Validation

What You Get

  • ✓s166 Readiness Assessment report
  • ✓Regulatory concern and scope mapping
  • ✓Evidence pack and governance documentation
  • ✓Remediation action plan
  • ✓Remediation validation and closure evidence

Scope Modules

Our FCA s166 support can be tailored around the firm's regulatory concern, business model and review stage. We provide modular support across:

s166 Readiness Assessments
Regulatory Concern and Scope Mapping
Evidence Pack Preparation
Skilled Person Review Response Support
Governance, SMCR and Board Accountability Reviews
Systems and Controls Effectiveness Reviews
Financial Crime Reviews
Safeguarding, CASS and Client Money Reviews
Consumer Duty, Customer Outcomes and Redress Reviews
Operational Resilience, ICT and Third-Party Risk Reviews
Regulatory Reporting, Data and MI Reviews
Remediation Planning and Validation

These modules can be delivered individually or combined into a full readiness, response and remediation programme.

Risk of Inaction

Firms unprepared for a Skilled Person Review risk extended scope, increased cost, regulatory escalation, and loss of FCA confidence — all of which are harder to recover from than effective early preparation.

Regulatory & Resilience

ISO 27001 & ISO 31000 Advisory

Specialist advisory for organisations pursuing or maintaining ISO 27001:2022 certification and ISO 31000 risk management framework implementation.

Who This Is For

CTOs & CISOsCEOs of growth-stage fintechsInformation Security teamsFirms pursuing ISO certification

Capabilities

  • ISO 27001:2022 ISMS Compliance Assessments
  • ISO 27001:2022 ISMS Implementation Support
  • Information Security Policy Frameworks
  • Risk Treatment Planning
  • Certification Readiness Reviews
  • ISO 31000 Framework Design

What You Get

  • ✓ISMS gap assessment report
  • ✓ISMS documentation suite
  • ✓Risk treatment plan
  • ✓Statement of Applicability
  • ✓Certification readiness review

Risk of Inaction

Without a formal ISMS, organisations face data breach exposure, loss of enterprise contracts, and inability to demonstrate information security governance to regulators.

Regulatory & Resilience

DORA & Operational Resilience

Comprehensive support for EU Digital Operational Resilience Act compliance and UK Operational Resilience framework implementation — built for organisations with complex ICT dependency.

Who This Is For

CEOs, COOs & CTOs of EU-regulated financial entitiesHeads of Operational Risk & IT RiskCompliance teams at payment firms & fintechsBoards subject to DORA

Capabilities

  • EU DORA Compliance Assessments
  • EU DORA Implementation Support
  • ICT Risk Management Framework
  • Third-Party Risk Assessments
  • UK Operational Resilience Assessments
  • Important Business Services Mapping
  • Impact Tolerance Setting

What You Get

  • ✓DORA gap assessment report
  • ✓ICT risk management framework
  • ✓Third-party risk register
  • ✓Operational resilience testing programme
  • ✓DORA implementation roadmap

Risk of Inaction

Non-compliance with DORA exposes financial entities to regulatory sanctions, operational disruptions, and ICT incidents without governance structures to respond and evidence resilience.

Regulatory & Resilience

FCA Consumer Duty & ESG

Practical support for FCA Consumer Duty implementation and ESG compliance — combining regulatory precision with commercial context.

Who This Is For

CCOs & Heads of ComplianceProduct & Marketing teamsCEOs of FCA-authorised consumer-facing firmsESG & Sustainability leads

Capabilities

  • FCA Consumer Duty Gap Assessments
  • Consumer Duty Implementation Programmes
  • Consumer Outcome Monitoring
  • ESG Compliance Assessments
  • ESG Reporting Framework Implementation
  • Sustainability Risk Integration

What You Get

  • ✓Consumer Duty gap assessment
  • ✓Consumer outcome monitoring framework
  • ✓Vulnerable customer policy
  • ✓ESG compliance framework
  • ✓Board reporting pack

Risk of Inaction

Failure to demonstrate Consumer Duty compliance creates regulatory risk, potential FCA intervention, and reputational exposure in an increasingly scrutinised area.

Operational Solutions

Process Optimisation & Business Automation

AI-enabled process improvement, workflow automation, and embedded control solutions — with human-in-the-loop oversight at every critical decision point.

Who This Is For

CFOs & Finance DirectorsCOOs & Operations LeadersHeads of Finance OperationsCTOs & Technology teams

Capabilities

  • AI-enabled Finance Operations Automation
  • Trade Receivables Management Solutions
  • FinOps Control Centre Design & Implementation
  • Financial Controls Platform Design
  • Payroll Operations Automation
  • Expenses & Purchase Order Management
  • Contract & Supplier Management Automation
  • Safeguarding & Reconciliation Automation
  • HR & Payroll Process Automation
  • Bespoke AI-enabled Process Solutions
  • Treasury & Cash Visibility ControlOps
  • Revenue Assurance ControlOps
  • Business Approval & Delegated Authority ControlOps
  • HR Joiner / Mover / Leaver ControlOps

What You Get

  • ✓Process assessment & optimisation report
  • ✓Automation solution design
  • ✓Implementation roadmap
  • ✓Governance framework for automated processes
  • ✓Post-implementation testing

Risk of Inaction

Persisting with manual, unautomated processes creates cost inefficiency, operational risk, audit exposure, and competitive disadvantage as the business scales.

Regulatory & Resilience

Business Continuity Management — ISO 22301

We help organisations design, implement, and improve Business Continuity Management Systems aligned with ISO 22301. Our approach supports clients in planning for disruptive incidents, protecting critical operations, strengthening resilience, and improving recovery capabilities.

Who This Is For

COOs & Operations LeadersRisk & Resilience OfficersBoard Directors & Senior ManagementOrganisations with critical operational dependenciesFirms subject to regulatory resilience expectations

Capabilities

  • ISO 22301 BCMS Gap Assessment
  • Business Impact Analysis (BIA)
  • Business Continuity Plan Design & Implementation
  • Recovery Strategy Development
  • Incident Response Framework Design
  • BCMS Testing & Exercising
  • ISO 22301 Certification Readiness Reviews
  • ISO 22301 BCMS ControlOps

What You Get

  • ✓BCMS gap assessment report
  • ✓Business impact analysis
  • ✓Business continuity plans and procedures
  • ✓ISO 22301 implementation roadmap
  • ✓Certification readiness review

Risk of Inaction

Without a structured Business Continuity Management System, organisations risk uncontrolled disruption to critical operations, reputational damage, regulatory concern, and slow or ineffective recovery from disruptive incidents.

Regulatory & Resilience

Privacy Information Management — ISO 27701

We support organisations in implementing ISO 27701-aligned Privacy Information Management Systems that complement existing information security frameworks. Our services help strengthen privacy governance, data protection controls, accountability, and compliance readiness.

Who This Is For

Data Protection OfficersCTOs & CISOsCCOs & Compliance teamsOrganisations handling personal data at scaleFirms seeking to demonstrate privacy accountability

Capabilities

  • ISO 27701 PIMS Gap Assessment
  • Privacy Information Management System (PIMS) Implementation
  • Privacy Governance Framework Design
  • Data Protection Controls Assessment
  • UK GDPR Alignment Review
  • Privacy Policy & Procedure Development
  • ISO 27001 / ISO 27701 Integration Advisory
  • ISO/IEC 27701 Privacy ControlOps

What You Get

  • ✓PIMS gap assessment report
  • ✓Privacy information management framework
  • ✓Privacy policy and procedure suite
  • ✓ISO 27701 implementation roadmap
  • ✓Certification readiness support

Risk of Inaction

Without structured privacy information management, organisations face data protection risks, regulatory exposure under UK GDPR and related legislation, and inability to demonstrate accountability and compliance to regulators, customers, and partners.

Strategic Advisory

AI Governance

We help organisations establish responsible AI governance frameworks covering AI risk management, regulatory alignment, ethical controls, accountability, transparency, monitoring, and assurance. Our services support safe, compliant, and trusted use of AI-enabled systems.

Who This Is For

CTOs & CISOsCEOs & Board DirectorsRisk & Compliance OfficersOrganisations deploying AI in regulated environmentsFirms subject to emerging AI regulation

Capabilities

  • AI Governance Framework Design
  • AI Risk Assessment & Risk Register
  • Regulatory Alignment (EU AI Act, FCA, ICO)
  • Ethical AI Controls & Accountability Frameworks
  • Model Governance & Documentation
  • AI Transparency & Explainability Review
  • Human-in-the-Loop Control Design
  • AI Assurance & Monitoring Frameworks
  • Agentic Workflow Governance

What You Get

  • ✓AI governance framework design
  • ✓AI risk assessment and register
  • ✓Responsible AI policy suite
  • ✓Model governance documentation
  • ✓AI compliance readiness report

Risk of Inaction

Deploying AI without adequate governance exposes organisations to regulatory risk, reputational harm, ethical failures, and the inability to demonstrate accountability and transparency to regulators, customers, and boards.

Ready to Build a Control Environment That Scales With Your Business?

Start with a structured Fintech Readiness Review — or speak with an adviser about the specific challenge you are facing.

Specialist consultancy for Financial Services, Fintech, Advisory Firms & Entrepreneurs