01Regulatory Change
Translating an obligation into the operating change it actually requires.

Home/What we do/Regulatory, Risk & Forensic
Service
A compliance obligation is an operating decision wearing a deadline.
Regulatory response, risk frameworks and investigative work, sequenced so the obligation leaves the business better run rather than only better documented.
The practice
We handle regulatory change, risk frameworks and investigative work — the three things that arrive without being asked for and have to be dealt with while the business keeps running.
A regulatory obligation is an operating decision wearing a deadline. Treated as a filing exercise it produces documents; treated as an operating decision it produces a business that is genuinely easier to run and happens to be compliant. The second costs slightly more once and considerably less every year after.
Start here
Treated as a filing exercise, a regulatory obligation produces documents. Treated as an operating decision, it produces a business that is easier to run and happens also to be compliant.
The second costs slightly more once and considerably less every year afterwards. The choice between them is usually made implicitly, in the first two weeks, by whoever is asked to own the response.
Regulatory reach
An obligation almost never arrives from one direction. A single operating change can be governed by a city ordinance, a state statute, a federal rule and an international standard at once — written by bodies that do not read each other, on clocks that do not align. Mapping which of them actually binds you, and in what order, is most of the work.
Permits, licensing, zoning, local tax and the inspection regimes attached to them. Usually the least documented and the most likely to stop an opening date.
Where this bitesWhat we do: build the obligation register nobody has, jurisdiction by jurisdiction, and put a named owner and a renewal date against each line.
Fifty regimes, rarely aligned, frequently amended. The state layer is where multi-state operators quietly accumulate exposure they cannot see from the centre.
Where this bitesWhat we do: a multi-state matrix showing where requirements diverge, so you change the operating model once rather than fifty times.
Where the largest single obligations sit and where the response is most often mistaken for a documentation exercise.
Where this bitesWhat we do: read the rule for what it requires operationally, then sequence the change around it — including the parts of the business the rule does not mention but will affect.
Standards bodies and foreign regulators reach you through contracts and customers as often as through law. A counterparty requirement binds as hard as a statute.
Where this bitesWhat we do: map the frameworks onto one another so a single control set answers several of them, instead of running parallel programmes that test the same thing four ways.
Risk & Forensic
Six named pieces of work. Each is bought on its own, each has a defined output, and none of them requires a law firm — though three of them are frequently run alongside one, at your counsel’s direction.
The taxonomy, the appetite statement and the assessment method — designed so the output changes a decision rather than filling a register nobody reads between audits.
Where the business actually breaks: concentration, single points of failure, third parties, and the recovery assumptions nobody has tested since they were written.
Monitoring built so evidence is a by-product of operating rather than a project run twice a year at considerable cost.
Establishing what happened, in a form that holds up when examined by people who did not commission it. Scope agreed in writing before anyone starts.
Transaction and ledger analysis where something does not reconcile — unsupported entries, duplicate vendors, round-sum patterns, approvals that route around the control.
Reconstructing the record for a regulator, an examiner or a counterparty, and preparing the people who will have to explain it.
We are not a law firm and we do not give legal advice or certify compliance to a regulator. Where an investigation requires privilege, we work at the direction of your counsel — a conversation to have before the engagement starts, not during it.
What we do
Most engagements start as one of these and grow into a second. None of them are productised — the shape is set in the first two weeks.
Translating an obligation into the operating change it actually requires.
Risk management built to inform decisions rather than to survive an internal audit of itself.
Fact-finding that holds up when examined by people who did not commission it.
Monitoring designed so evidence is a by-product of operating rather than a project.
Our thinking
Three of these are true of every Taidou engagement regardless of practice. They are also the three things we are most often told are unusual — which says more about the industry than about us.
There is no handoff between the team that wins the work and the team that does it. If you met someone in the first conversation, you will still be dealing with them in the last one. This is the single thing clients tell us they notice first.
Every engagement starts with a scope that names the things we have deliberately excluded and why. It makes the first conversation harder and every conversation after it easier.
Most firms hand over when the design is agreed and the change has been announced — the moment of maximum fragility. We hand over to named owners after it is running, and we come back to check.
Where this lands
Related thinking
CMS-0057-F is being treated as a date to survive. The organizations treating it as an operating decision are the ones still compounding on it in three years.
ResearchTaidou Answer
Describe the problem in your own words. Taidou Answer indexes it across every industry and service line we practice in, and routes you to the senior consultant who has handled it before.
Explore more