f
Practices · 05 / 06

Risk & Compliance

ERM · Regulatory · Third-party assurance

The test of a control environment is not the audit it passes but the incident it survives. We build risk and compliance programs that are operationally real — controls owned by the people who run the process, evidence produced as a by-product of the work, and escalation paths that get used.

Much of our practice is remediation under regulatory attention: consent orders, undertakings, and findings programs where the deadline is not negotiable and the second submission has to be the last.

How we engage

Enterprise risk management

Risk appetite, taxonomy, and reporting the board actually reads.

Regulatory remediation

Findings-to-closure programs run against the regulator's calendar, not the client's.

Third-party assurance

Vendor and outsourcing risk frameworks sized to the estate's real concentration.

Financial-crime programs

KYC/AML operating models that scale with volume instead of headcount.

Where this practice is led

Practice home
Washington L Street NW
Regulated industries & the public interest
Also carried at
  • Sydney Retirement systems & conduct
  • Rome Energy & infrastructure under public oversight

Every engagement is senior-led. Talk to the partner who would run yours →