Service 01 · Managed service

Contract Management as-a-Service

Relieve your contractual workload. A full 10-step lifecycle, run by our experts — from regulatory classification to annual register submission, with a free Home Clause licence included.

View this service
Service 02 · Audit

Provider (Pooled) Audit

Structured pooled audit campaigns — from trigger and call for interest, through plan validation and on-site performance, to a final report shared with all mandating entities.

View this service
Service 03 · Consulting

ICT / TPRM Consulting

Gap analyses, ICT inventories, policies & procedures, contract files, Business Impact Analysis and action-plan testing — aligned to DORA, GDPR, NIS 2, the AI Act and the CRA.

View this service
Service 04 · Project delivery

Project Management

Remediation projects that strengthen governance and regulatory compliance — from scoping and planning to execution and delivery, with particular focus on ICT frameworks like DORA, GDPR, NIS 2, the AI Act and the Data Act.

View this service
Service 05 · On-demand support

Virtual Compliance Assistant

On-demand, expert-level support for every regulatory and contractual challenge — unlimited questions, plus real-time assistance during your meetings and negotiations.

View this service
Service 06 · Training

Vocational Training

Tailored programmes on contract management in the financial sector, the European regulatory landscape, and practical DORA compliance — for management and all three lines of defence.

View this service
1 / 6
DORA compliant
GDPR aligned
NIS 2 ready
AI Act aware
Hands-on expert support
01
Managed service · includes Home Clause

Contract Management as-a-Service

Relieve your contractual workload. Our experts run the full lifecycle of your regulated contracts — a structured, ten-step methodology that keeps every classification, assessment and clause aligned with current regulation.

1

Regulatory classification

We evaluate whether your contract falls under outsourcing, entails ICT-related services, or involves the processing of personal data.

2

Criticality assessment

We assess whether the service contributes to, supports, or enables any of your critical or important business functions.

3

Conflict of interest assessment

A detailed evaluation to identify any actual, potential, or perceived conflicts between your organisation and the provider.

4

Provider due diligence

We examine the provider's governance, operational capabilities, financial stability, and regulatory compliance posture.

5

Service risk assessment

A comprehensive assessment to identify, categorise, and evaluate all risks associated with the service.

6

Contractual compliance

We review the contractual clauses in detail to ensure full alignment with applicable regulatory and sector-specific requirements.

7

Service monitoring

A structured monitoring framework — defining KPIs and KCIs, reviewing service reports, and assessing performance levels.

8

Service exit strategy

For critical or important arrangements, a structured exit strategy ensuring business continuity and regulatory compliance.

9

Regulatory notification (services)

We handle the full notification process to the regulator for any contract supporting your important or critical functions.

10

Regulatory notification (registers)

We maintain and yearly-submit your regulatory registers — outsourcing and DORA — to the competent authority.

Included

Lifecycle Management

From document creation onward, including a structured annual review of every file to keep classifications, assessments and clauses current.

Included

Service Reporting

One comprehensive report per quarter (four per year) tracking the evolution of your providers and the services they deliver.

Included

CLM Software Access

One free Home Clause licence with every subscription — real-time access to your documentation, dashboards, workflows and compliance tools.

Back to all services
02
Audit campaign

Provider (Pooled) Audit

A structured, six-stage pooled-audit campaign that lets multiple financial entities share a single audit of a common provider — efficient, confidential, and fully reported.

1

Audit trigger

Triggered by specific events such as incidents or material changes (ad hoc), or periodically when a predefined date is reached. Each trigger concerns a specific provider.

2

Call for interest

A market-wide campaign assesses whether other financial entities wish to join the pooled audit. Participant names stay confidential until the campaign closes.

3

Audit plan preparation

Plan prepared per the provider's regulatory exposure (DORA, NIS2, GDPR, AI Act) — checks of standards (ISO, ISAE), regulator approvals, litigation/compliance history.

4

Audit plan validation

The draft plan is adapted and validated with the mandating entities, ensuring alignment with their specific requirements and priorities.

5

Audit performance

The audit is performed directly at the provider's premises or systems, per the validated plan and agreed methodology.

6

Audit report

The final report is drafted and communicated to all mandating entities — results, findings, and recommendations for follow-up actions.

Back to all services
03
Consulting · DORA · GDPR · NIS 2

ICT / TPRM Consulting

Hands-on third-party-risk and ICT consulting that turns regulatory frameworks into operational resilience — from gap analysis through to tested action plans.

Gap Analysis

Targeted analyses of governance, processes and ICT services against GDPR, DORA, outsourcing rules, NIS 2, the AI Act and the CRA — with actionable recommendations to close critical gaps.

Policies & Procedures

We create, review and enhance corporate policies — third-party, contract and procurement management — keeping a robust internal control framework aligned with evolving rules.

ICT Inventories

Detailed inventories mapping business functions, roles, supporting ICT and information assets, and third-party interconnections — a foundation for operational resilience.

Contract Files

We manage regulated contract files (DORA and beyond) from classification to regulatory notification, with structured methodologies and a client-approved calculation tool.

Business Impact Analysis

Quantitative and qualitative BIA evaluating disruption consequences across critical functions, assets, third-party dependencies and processes — to prioritise continuity planning.

Action Plan Testing

Design, execute and improve tests of exit strategies, BCPs, DR plans and crisis-communication plans — realistic scenarios that validate your response mechanisms.

Back to all services
04
Project delivery · DORA · GDPR · NIS 2 · AI Act · Data Act

Project Management

Management of projects designed to remediate regulatory compliance practices and strengthen governance — from scoping and planning through to execution and delivery, with particular focus on ICT regulatory frameworks including DORA, GDPR, NIS 2, the EBA Guidelines, the AI Act and the Data Act.

1

Scoping

We define the objectives, boundaries and success criteria of the remediation project — clarifying which regulatory practices and governance gaps it must address.

2

Planning

A structured plan setting out workstreams, milestones, resources and dependencies, aligned to the relevant ICT regulatory frameworks and your internal governance.

3

Stakeholder alignment

We engage management and the three lines of defence, agreeing roles, responsibilities and reporting so every stakeholder is aligned before execution begins.

4

Execution

Hands-on delivery of the remediation workstreams — implementing controls, policies and processes that bring practices back into regulatory alignment.

5

Monitoring & control

Continuous tracking of progress, risks and issues against the plan — keeping the project on schedule and evidencing compliance throughout.

6

Delivery & handover

Formal closure with documented outcomes, a strengthened governance framework and a handover that embeds the changes into business-as-usual.

Focus

ICT Regulatory Frameworks

Deep focus on DORA, GDPR, NIS 2, the EBA Guidelines, the AI Act and the Data Act — translating obligations into concrete remediation actions.

Focus

Governance Strengthening

Every project is designed to leave your governance measurably stronger — clearer accountability, better controls and durable compliance.

Focus

End-to-End Delivery

A single accountable partner from scoping and planning through execution to delivery — keeping momentum and ownership across the lifecycle.

Back to all services
05
On-demand expert support

Virtual Compliance Assistant

Our Virtual Compliance Assistant provides on-demand, expert-level support for all your regulatory and contractual challenges. Through a simple, transparent standard tariff, you gain unlimited access to our expertise — submit as many questions as you need, whenever you need them, to guide and secure your compliance decisions.

Whether it's clarifying complex regulatory requirements, interpreting contractual obligations, or validating the compliance implications of strategic choices, we act as your trusted partner — always available, always precise. With the Virtual Compliance Assistant, you are never alone in facing compliance challenges: we transform complexity into clarity and help you move forward with confidence.

Unlimited information hub

Submit as many questions as you need under one transparent standard package — regulatory interpretation and contractual decision support on demand.

Real-time meeting support

Operational support during meetings and negotiations with partners, providers, regulators or internal stakeholders — preparing positions and anticipating counterarguments.

Back to all services
06
Vocational training

Vocational Training

Tailored programmes that build real capability across management and all three lines of defence.

Management of service contracts in the financial sector

The legal, operational and compliance foundations to manage service contracts in highly regulated environments — across the full lifecycle, from pre-award planning and tendering to performance monitoring and termination or renewal.

Regulatory compliance stakeholders in the financial sector

A comprehensive overview of the European and Luxembourg financial regulatory landscape — financial entities, internal governance, and the role of European and national regulators and their supervisory powers.

Digital Operational Resilience Act (DORA)

For the management body and the three lines of defence — practical strategies that translate DORA requirements into concrete, actionable measures, with real-world examples, tested tools and best practices.

Back to all services
Let's talk

Expert oversight, real outcomes

Tell us where your contractual workload hurts most — we'll tailor the right mix of platform and service.