What we do
We automate the manual work that surrounds investment compliance, and we design the human checkpoints and evidence trail that make it defensible.
Every engagement starts from the same question: which parts of this function require judgment, and which parts are people doing by hand because nobody has built anything better? The first category stays with your team. The second is where we work.
Guideline documentation
A guideline register that is structured, versioned, traceable to source, and current — without three weeks of manual reading every time a document changes.
The source of truth for what a portfolio may and may not do is spread across an IMA, a prospectus, a fund supplement, a set of side letters, a board resolution and whatever was agreed in an email in 2019. Turning that into a clean, testable guideline set is slow work, and keeping it aligned as documents are amended is slower.
We build workflows that read the source documents, extract each restriction as a structured entry, and hold it against a defined schema: what the restriction is, which document and clause it comes from, which portfolios it applies to, how it is monitored, and who confirmed it.
The system proposes. A person confirms. Nothing enters the register without a named reviewer, and every entry links back to the paragraph it came from, so the review is a check rather than a re-read.
When a document is amended, the workflow compares versions, flags what has changed, and routes only the affected entries for review. An annual guideline review stops being a project.
What you get
- A structured guideline register, exportable and version-controlled
- Clause-level traceability from every entry back to its source document
- Change detection across document versions, with a reviewer queue
- A documented mapping between guidelines and how each one is monitored — coded rule, manual check, or accepted as not monitored, with the reason recorded
- Review history: who confirmed what, when, and on which version
Illustrative example, not a client engagement.
A UCITS manager with 40 sub-funds, four IMAs and a set of segregated mandates. Two people spend most of each January re-reading documents to confirm the guideline register is still accurate. After the workflow is in place, the same review runs as a queue of 60 flagged changes, each with the old and new clause side by side. It takes four days, and the sign-off record is produced as a by-product.
Records and evidence
Breach files, attestations, approvals and committee packs assembled as the work happens, in a form that stands up eighteen months later.
Most compliance evidence is created twice. Once when the work is done, informally, in email and spreadsheets. Then again when someone needs to produce it for an audit, a due diligence questionnaire or a regulator, at which point somebody spends a week reconstructing what happened from fragments.
We build the record at the point of work. A breach is raised, and the file assembles itself: the trigger, the affected portfolios, the guideline it relates to, the source document, the analysis, the correspondence, the decision, the rationale, the sign-off, and the timestamp on each. The compliance officer writes the analysis and makes the decision. Everything around it is collected automatically.
The same applies to attestations, approvals, conflicts logs and committee reporting. The pack is generated from the underlying records rather than typed up from them.
What you get
- Breach files that assemble themselves, with a fixed structure and complete chronology
- Draft narrative prepared from the record, for the compliance officer to edit and approve — never issued unreviewed
- Attestation and approval workflows with automatic chasing and a completion record
- Committee and board packs generated from source, with figures traceable to where they came from
- A single searchable evidence store, retention-aware, with export for audit and DDQ responses
Illustrative example, not a client engagement.
A firm receives an operational due diligence questionnaire asking for evidence of guideline breach handling over the past two years. Previously: a fortnight of retrieval across email, a shared drive and the monitoring system. With the evidence store in place: a filtered export, reviewed and redacted by the compliance officer, produced the same day.
Manual monitoring
The checks that were never coded, run consistently, on schedule, with the result recorded whether or not anything was found.
Every compliance function has a set of checks that live outside the monitoring system. Some are qualitative. Some depend on data the system does not hold. Some exist because a side letter says so and nobody wanted to build a rule for one client. They are done monthly, or quarterly, or when someone remembers.
These are the checks that fail an audit — not because they were done badly, but because there is no evidence they were done at all.
We build them into scheduled workflows. Data is gathered, thresholds are applied, exceptions are surfaced with the relevant context attached, and a person reviews and signs. Where nothing is found, that is recorded too, because a clean result is evidence.
The workflow never closes an exception on its own. It prepares the case; the reviewer decides.
Typical checks we automate
- Liquidity classification and bucket monitoring against policy
- Counterparty and issuer concentration outside coded limits
- ESG and sustainability commitments, including exclusion list maintenance
- Side letter and soft restriction monitoring
- Personal account dealing, gifts, entertainment and outside business interests
- Best execution and dealing commission review support
- Regulatory change tracking and impact assessment against the guideline register
Illustrative example, not a client engagement.
Eleven quarterly manual checks maintained across four spreadsheets by one person, with no record of the quarters where nothing was found. After automation: a scheduled run, an exception queue averaging three items, and a complete four-quarter history with reviewer sign-off on every cycle including the clean ones.
Oversight and governance
The control documentation, checkpoints and accountability map a senior manager needs before putting their name to an automated process.
The hardest part of automating compliance work is not building it. It is being able to explain it — to internal audit, to a board committee, to an ODD team, and eventually to a regulator.
Accountability cannot be outsourced to an algorithm, and a review of the Senior Managers Regime is currently examining how individual accountability operates where AI performs functions that were previously subject to direct human oversight. Nobody has published the answer. In the meantime, the defensible position is documentary: show where the automation stops, who decides, and how you would know if it went wrong.
We produce that documentation as part of every build. Where a firm already has automation in place, we can do this as a standalone review.
What you get
- A control map for each automated workflow: inputs, processing steps, control points, human checkpoints, outputs, and failure modes
- Accountability mapping to the relevant senior management function, in language suitable for a statement of responsibilities
- Model and tool inventory, with intended use, limitations and validation approach recorded for each
- Escalation and override design — how a person intervenes, and how the intervention is recorded
- Monitoring of the monitoring: sampling, exception review and periodic assurance over the automated processes themselves
- Board and committee reporting on AI use, written for a non-technical audience