Assess, improve, embed, maintain: four phases, stop after any of them. Everything scoped, everything in writing, nothing open-ended.
Fast, sharply priced pieces of paid work with a short written output. The easiest first step a firm can take.
Pick one high-risk area, AML, complaints, wherever the worry is, and get a quick, honest read: strengths, blind spots and what is coming.
The six things the regulator cares about right now, and a straight read on how your firm stacks up against each of them.
What is coming over the hill, mapped against your firm's exposure and priorities, with a simple, ordered action plan.
Bigger pieces of defined work, each with a written report, priorities and timelines, and each a natural route into whatever comes next.
A review ahead of PII renewal, split into quick wins and the year's strategic focus, so you walk into the broker conversation ready rather than hopeful.
An honest look at whether your file reviews are finding what they should: the process, the quality, and what a year of your data is telling you.
The behaviours, attitudes and governance signals that shape your risk culture, read through conversations with your people, the things an audit never sees.
The client lifecycle end to end: who does what, where the tech helps and hinders, and where the friction and vulnerabilities hide.
Is the technology doing what you think it is? Screening and electronic ID checked against Legal Sector Affinity Group guidance.
Each one produces data, priorities and a conversation about where your firm is trying to get to. What happens next is up to you, and it never has to be everything at once.
Independent Regulation 21 audits, required every one to two years depending on the size and nature of your firm, priced bronze, silver and gold so you choose the depth, every tier a fully compliant audit. And unlike most, the audit doesn't have to be the end of it.
A compliant audit with clear recommendations your team implements.
Your team does the remedial work; I review it so you know it has landed.
I rewrite the documents, build the process or run the training myself. One rule: I never audit work I have written.
Fixing things is the easy half. The improvement only counts when it lives in your people and their habits, not in a policy nobody opens on the intranet.
A bespoke programme across six or twelve months: sessions, written updates and resources, built from your data and delivered by the same senior person all year. Nobody else offers it this way.
Single sessions on the topics your data says you need, delivered to fee earners in language they don't resent.
The behaviours, attitudes and governance signals that decide whether any of it sticks, read honestly and worked on deliberately.
Retainers built on two rules: remediation before maintenance, and explicitly scoped reviews. Never open-ended, and never designed to make you dependent.
A bank of days or hours over a period, drawn down flexibly as you need them. A short commitment that shows your board value fast. Also available as senior interim cover for an absence.
Policy reviews, file reviews, escalations and breach support on a defined scope, for a small, vetted number of firms.
You keep doing the doing. Each quarter I review your risk data, file reviews, claims, complaints, cross-reference it with what is moving in the sector, and report to the board on exposure, opportunity and priority. External scrutiny, not meddling.
No pitch, no jargon, nothing open-ended. Email eloise@itsallthingsrisk.com, find All Things Risk on LinkedIn, or start with a fifteen-minute call.
Let's talk