
A programme built from how funds really move
Licensing, monitoring and governance designed by people who spend the rest of their time tracing what happens when those controls are missing.
- Jurisdictions worked with local counsel
- 31
- Typical programme design to evidenced
- 12 wks
- Readiness and registration support
- MiCA
- Custody standard implementation
- CCSS
Where regulation meets what your systems actually do
The gap between the written policy and the running process is where supervisory findings come from. Closing it is most of the work.
Licensing & registration
VASP registrations, MiCA readiness and money transmitter applications prepared with the operational evidence regulators ask for second.
- Application drafting
- Policy and control packs
- Regulator correspondence
AML & transaction monitoring
Rule sets tuned against real typologies rather than vendor defaults, so your analysts stop drowning in alerts that never mattered.
- Typology-driven rules
- Threshold calibration
- False-positive reduction
Travel rule & data sharing
Counterparty due diligence, protocol selection and the operational reality of exchanging originator data without breaking settlement.
- Protocol selection
- Counterparty due diligence
- Sunrise-period handling
Risk assessment & framework
Enterprise-wide risk assessments that hold up in a supervisory visit because the ratings trace to evidence rather than to a workshop.
- EWRA build and refresh
- Control mapping
- Board-level reporting
Policy & governance
Written policies your staff can actually follow, with the escalation paths and decision rights named rather than implied.
- Policy suite drafting
- Escalation design
- Committee charters
Strategic advisory
Chain selection, custody model, counterparty exposure and treasury policy. Decisions that are expensive to reverse once they are live.
- Custody model selection
- Counterparty risk policy
- Treasury exposure limits
Evidence first, policy second
Most programmes fail because the document came before anyone looked at the flows. We run it the other way round.
- 01
Understand the actual exposure
Before any policy gets written we screen your live flows. Nine times in ten the risk sits somewhere the existing framework never contemplated, and the framework gets designed around that instead of around a template.
Weeks 1–2
- 02
Design controls that survive volume
A control that works at fifty transactions a day and collapses at five thousand is not a control. We build for the volume you expect next year, not the one on today's dashboard.
Weeks 2–5
- 03
Implement with the people doing the work
Analysts, engineers and the MLRO in the same room. Policies written without them get followed for about a month.
Weeks 5–10
- 04
Evidence the operation
Supervisors do not grade intentions. We stand up the evidence pipeline of decision logs, alert dispositions and testing records, so the programme can prove itself on demand.
Weeks 8–12
- 05
Test it like an examiner would
A mock examination against your own records, run by people who have sat on both sides of that table. Findings come to you before they come from a regulator.
Quarterly thereafter
Different obligations, the same underlying question
Everyone we advise is trying to answer one thing to a supervisor's satisfaction: do you know where your value came from and where it went?
Exchanges & custodians
Licensing, custody policy, monitoring
Funds & asset managers
Counterparty screening, treasury policy
Banks entering digital assets
Risk framework, third-party diligence
Protocols & issuers
Governance, disclosure, sanctions posture
Our advice is calibrated by our casework
When an investigation shows a typology slipping past a common rule set, that finding goes straight into the monitoring designs we build. Advisory firms that do not investigate are working from published typologies, which is to say from what was true two years ago.
- Rules tuned against typologies we have traced this quarter
- Counterparty risk scored on observed behaviour, not just registry status
- Mock examinations run by people who have prepared responses for real ones
- Escalation paths tested against live incident timelines

What comes up in scoping calls
No, and we will not pretend otherwise. We handle the technical and operational side, meaning risk assessment, controls, monitoring and evidence, and work alongside your counsel on the legal position. Where you do not have counsel yet, we can point you to firms we have worked with in the relevant jurisdiction.
In part. We can carry programme design, monitoring tuning, quality assurance and examination readiness. Named regulatory roles have to sit with someone accountable inside your business, and we will say so rather than take the fee.
We work matters in thirty-one jurisdictions with local counsel, which surfaces changes in supervisory expectation long before it shows up in guidance. Where a question is genuinely unsettled, we tell you it is unsettled.
Usually calibration and evidence. Vendor platforms generate alerts; whether those alerts map to how funds actually move through your business is a separate question, and it is the one we answer.

Get ahead of the question you will be asked
Whether it is a licence application, a supervisory visit or a board that has started asking about exposure, the answer is easier to build now than to assemble under a deadline.