Skip to content

Risk & Compliance · UAE

Controls and governance proportionate to the risk you carry.

Risk assessed, controls designed and obligations mapped to named owners — proportionate to the risk actually carried, not to a template.

6 capabilities in this practice

Discuss risk & compliance

The problem

A framework on paper, not in practice

Compliance programmes rarely fail on policy. They fail on ownership: an obligation exists, a document describes it, and no individual is accountable for the specific act that satisfies it. Under review the gap is immediate and difficult to explain.

Business impact

What it costs to leave alone.

Regulatory exposure
Obligations that nobody owns are obligations that get missed, and the record shows it.
Controls that do not operate
A designed control that is not performed, or not evidenced, is indistinguishable from no control.
Board blind spots
Directors carry responsibility for risks they are not being told about in a form they can act on.

Our approach

How we work on it.

Proportionate by design
The framework is sized to the business. Over-engineering a programme guarantees it is not followed.
Obligation, owner, evidence
Every requirement is mapped to a person and to the artefact that proves it happened.
Test before someone else does
Controls are tested on a schedule, so weaknesses surface internally rather than in an inspection.

Capabilities

Everything in Risk & Compliance.

Each of these is a discrete piece of work. Most engagements combine several.

  • Risk Advisory

  • Internal Controls

  • AML

  • Corporate Governance

  • Compliance

  • Fraud Risk

One capability has a detailed page — the linked one above.

Process

How an engagement runs.

Four stages. You know which one you are in and what closes it.

  1. Risk assessment

    Identify and rate the risks the business actually carries, including fraud and financial crime exposure.

  2. Design

    Build the control framework and governance structure proportionate to those ratings.

  3. Embed

    Assign owners, train the people performing the controls, and agree how each is evidenced.

  4. Monitor

    Independent testing on a cycle, with findings reported to the board in a form they can use.

Deliverables

What you receive.

  • Risk register with ratings and owners
  • Control framework and policy set
  • AML programme documentation
  • Independent control testing reports
  • Board and governance reporting pack

Next step

Talk to someone who does risk & compliance.

A short conversation establishes whether there is a real question here, who should answer it, and what it will take.

Not ready for a meeting? Ask one specific question instead.

What follows

  • A person in the relevant practice reads it, not a routing queue.
  • One reply that already contains a view, not a request to book a call.
  • A written scope and fee basis, or a straight answer that there is no work to do.
  • Sunday – Thursday, 9:00 – 18:00 GST