Risk & Resilience foundation
A practical foundation for organisations that need a clear view of risk, resilience, and the governance work that should happen next.
Defined deliverables, clear price ranges, and the option to bring in senior support by the hour when the work does not fit a fixed-scope engagement.
Start with a defined obligation, then add the level of continuing governance your organisation actually needs. Programme scope and availability are confirmed before work begins.
A practical foundation for organisations that need a clear view of risk, resilience, and the governance work that should happen next.
Ongoing AI governance support layered onto the foundation, keeping use cases, controls, evidence, and decisions aligned as the organisation moves.
A senior governance programme for organisations that need continuing ownership across risk, security, privacy, and AI obligations.
Each engagement is designed around a specific regulatory, contractual, or insurance requirement. The work is bounded, the buying decision is simpler, and the output gives leadership and outside reviewers something concrete to rely on.
A practical readiness review for organisations developing or deploying AI. We identify relevant AI systems, assess current governance, close priority gaps, and produce documented alignment to the NIST AI Risk Management Framework. For Texas operations, the work also addresses TRAIGA.
Authority: Texas Responsible Artificial Intelligence Governance Act (HB 149), effective 1 January 2026. Substantial alignment with a recognised AI risk framework can support the Act’s affirmative defence.
A focused assessment of customer-information safeguards, incident response, service-provider oversight, disposal practices, notification procedures, and required records. You receive a prioritised gap report and a practical readiness package.
Required by: The amended SEC Regulation S-P Safeguards Rule, 17 CFR Part 248, including written incident-response, service-provider oversight, customer-notification, and recordkeeping requirements.
An accurate, thorough analysis of risks and vulnerabilities affecting electronic protected health information, with documented findings and prioritised corrective actions suitable for covered entities and business associates.
Required by: HIPAA Security Rule, 45 CFR § 164.308(a)(1)(ii)(A). The analysis must be kept current as systems, operations, and risks change; many organisations review it annually.
A focused assessment of the written information security programme and the controls protecting non-public personal information, with an evidence package ready for the requesting underwriter or lender.
Required by: The applicable underwriter or lender agreement, assessed against ALTA Best Practices Pillar 3. Certification timing is set by the requesting underwriter or lender.
A tailored incident response plan followed by a facilitated tabletop exercise. Your team leaves with defined roles, escalation paths, notification decisions, an after-action report, and a prioritised improvement list.
Required or expected under: SEC Regulation S-P, HIPAA Security Rule incident procedures, NCUA incident-reporting obligations, and many cyber-insurance policies.
A focused review of public AI claims, adviser marketing, supporting evidence, and internal reality. We identify statements that overreach and give the firm a defensible path to accurate, substantiated language.
Required by: SEC Marketing Rule 206(4)-1 and Investment Advisers Act anti-fraud obligations, which require adviser advertising claims to be fair, balanced, and supportable.
For discrete advisory work, engagement overages, urgent response, and matters that do not require a fixed-scope project or recurring programme.