Home/What we do/Regulatory, Risk & Forensic

Service

Regulatory, Risk & Forensic

A compliance obligation is an operating decision wearing a deadline.

Regulatory response, risk frameworks and investigative work, sequenced so the obligation leaves the business better run rather than only better documented.

The practice

We handle regulatory change, risk frameworks and investigative work — the three things that arrive without being asked for and have to be dealt with while the business keeps running.

A regulatory obligation is an operating decision wearing a deadline. Treated as a filing exercise it produces documents; treated as an operating decision it produces a business that is genuinely easier to run and happens to be compliant. The second costs slightly more once and considerably less every year after.

Start here

An obligation is an operating decision wearing a deadline.

Treated as a filing exercise, a regulatory obligation produces documents. Treated as an operating decision, it produces a business that is easier to run and happens also to be compliant.

The second costs slightly more once and considerably less every year afterwards. The choice between them is usually made implicitly, in the first two weeks, by whoever is asked to own the response.

Regulatory responseCore
Reading a new obligation for what it requires operationally, then sequencing the change around it.
Risk frameworksCore
Risk management that informs decisions rather than documenting them afterwards.
Forensic & investigationsCore
Establishing what happened, in a form that holds up to external examination.
MonitoringCore
Designed so the next examination is a retrieval exercise.
Legal adviceNot us
We are not lawyers and do not advise on legal questions or represent you.
Certifying complianceNot us
We do not certify compliance to a regulator on your behalf.

Regulatory reach

Four levels of regulator, and they do not coordinate.

An obligation almost never arrives from one direction. A single operating change can be governed by a city ordinance, a state statute, a federal rule and an international standard at once — written by bodies that do not read each other, on clocks that do not align. Mapping which of them actually binds you, and in what order, is most of the work.

01 · Local

City, county and municipal

Permits, licensing, zoning, local tax and the inspection regimes attached to them. Usually the least documented and the most likely to stop an opening date.

Where this bites
  • Business licensing
  • Permitting & zoning
  • Local tax registration
  • Health & safety inspection
  • Municipal procurement

What we do: build the obligation register nobody has, jurisdiction by jurisdiction, and put a named owner and a renewal date against each line.

02 · State

Statutes, agencies and boards

Fifty regimes, rarely aligned, frequently amended. The state layer is where multi-state operators quietly accumulate exposure they cannot see from the centre.

Where this bites
  • State privacy statutes
  • Insurance & DOI filings
  • Professional licensing
  • Wage & hour
  • Data breach notification
  • State procurement

What we do: a multi-state matrix showing where requirements diverge, so you change the operating model once rather than fifty times.

03 · Federal

Agencies and rulemaking

Where the largest single obligations sit and where the response is most often mistaken for a documentation exercise.

Where this bites
  • SEC & SOX
  • CMS & HHS
  • FTC
  • OCC, FDIC & CFPB
  • FAR & DFARS
  • OSHA
  • FERC

What we do: read the rule for what it requires operationally, then sequence the change around it — including the parts of the business the rule does not mention but will affect.

04 · International

Standards and cross-border regimes

Standards bodies and foreign regulators reach you through contracts and customers as often as through law. A counterparty requirement binds as hard as a statute.

Where this bites
  • ISO 27001 / 9001 / 42001
  • NIST CSF & 800-53
  • SOC 2 (AICPA TSC)
  • GDPR & UK GDPR
  • EU AI Act
  • PCI DSS
  • Basel & IFRS

What we do: map the frameworks onto one another so a single control set answers several of them, instead of running parallel programmes that test the same thing four ways.

Risk & Forensic

What we are actually engaged to do.

Six named pieces of work. Each is bought on its own, each has a defined output, and none of them requires a law firm — though three of them are frequently run alongside one, at your counsel’s direction.

Risk

Risk framework build

The taxonomy, the appetite statement and the assessment method — designed so the output changes a decision rather than filling a register nobody reads between audits.

  • Risk taxonomy
  • Appetite & tolerance
  • Assessment method
  • Board reporting
Risk

Operational risk & resilience

Where the business actually breaks: concentration, single points of failure, third parties, and the recovery assumptions nobody has tested since they were written.

  • Critical process mapping
  • Third-party risk
  • Scenario & stress testing
  • Continuity testing
Risk

Controls & monitoring design

Monitoring built so evidence is a by-product of operating rather than a project run twice a year at considerable cost.

  • Control design
  • Automated monitoring
  • Testing programme
  • Exception handling
Forensic

Investigations

Establishing what happened, in a form that holds up when examined by people who did not commission it. Scope agreed in writing before anyone starts.

  • Scoping & protocol
  • Interviews
  • Evidence handling
  • Findings report
Forensic

Fraud & financial misconduct

Transaction and ledger analysis where something does not reconcile — unsupported entries, duplicate vendors, round-sum patterns, approvals that route around the control.

  • Transaction analysis
  • Vendor & payment review
  • Scheme reconstruction
  • Quantification
Forensic

Disputes & regulatory response

Reconstructing the record for a regulator, an examiner or a counterparty, and preparing the people who will have to explain it.

  • Record reconstruction
  • Response preparation
  • Data & e-discovery support
  • Remediation follow-through

We are not a law firm and we do not give legal advice or certify compliance to a regulator. Where an investigation requires privilege, we work at the direction of your counsel — a conversation to have before the engagement starts, not during it.

What we do

Four ways this practice is bought.

Most engagements start as one of these and grow into a second. None of them are productised — the shape is set in the first two weeks.

01Regulatory Change

Translating an obligation into the operating change it actually requires.

Impact assessmentOperational designImplementationEvidence

02Risk Frameworks

Risk management built to inform decisions rather than to survive an internal audit of itself.

TaxonomyAppetiteAssessmentReporting

03Forensic & Investigations

Fact-finding that holds up when examined by people who did not commission it.

ScopingEvidence handlingAnalysisFindings

04Controls & Monitoring

Monitoring designed so evidence is a by-product of operating rather than a project.

Control designAutomationTestingReporting

Our thinking

What we pride ourselves on.

Three of these are true of every Taidou engagement regardless of practice. They are also the three things we are most often told are unusual — which says more about the industry than about us.

The person who scopes it runs it.

There is no handoff between the team that wins the work and the team that does it. If you met someone in the first conversation, you will still be dealing with them in the last one. This is the single thing clients tell us they notice first.

We write down what we are not doing.

Every engagement starts with a scope that names the things we have deliberately excluded and why. It makes the first conversation harder and every conversation after it easier.

We stay past the point it is comfortable.

Most firms hand over when the design is agreed and the change has been announced — the moment of maximum fragility. We hand over to named owners after it is running, and we come back to check.

Taidou Answer

Not sure this is the practice you need?

Describe the problem in your own words. Taidou Answer indexes it across every industry and service line we practice in, and routes you to the senior consultant who has handled it before.

Ask Us a Question