Advisory evidence, control analysis and international financial context
Representative experience

Senior expertise. Hands-on delivery. Evidence-ready outcomes.

How experience is presented

By problem type, not by client logo.

Regulatory, supervisory and remediation assignments frequently contain confidential information. The examples below therefore describe the work, jurisdiction and outcome without identifying clients.

Every engagement shown was led or delivered with direct senior adviser involvement.

01

Licensing & market entry

From regulatory perimeter and feasibility to application, institution readiness and regulator dialogue.

SAUDI ARABIA

Multi-licence market entry portfolio

Multi-sector financial applicantsApplication & readiness leadFour sandbox acceptances + submissions

Prepared four accepted SAMA sandbox applications and supported a bank branch establishment, payment institution, insurance aggregator and SME credit applications, together with a CMA Advisory & Arranging application.

BAHRAIN

AISP establishment and operating readiness

Digital financial service providerEstablishment & control designLicence and operating readiness

Supported an Account Information Service Provider through licensing readiness, IT policy and standards, system establishment advisory and AML process design.

TÜRKİYE

Payment and e-money authorisations

Payment and e-money applicantsApplication preparationAuthorisation readiness

Prepared payment and electronic money institution applications, aligning governance, operating documentation and IT readiness with the intended activity model.

02

Technology governance & regulated operations

Structures that connect architecture, data, technology risk and accountable operations.

INTERNATIONAL FINANCIAL SERVICES

Multi-jurisdiction IT compliance

Wealth management groupMulti-market compliance & remediationResolved without financial penalty

Supported a wealth management group with technology and outsourcing compliance across its markets, including Malta regulator engagement and remediation that concluded without a financial penalty.

BAHRAIN

Risk, IT governance and lending controls

Financial and lending businessesGovernance & policy designOperating control structures

Established risk management and IT governance structures; separately developed a credit policy and supported the design of a lending decision tree.

TÜRKİYE

Architecture and digital transformation

Technology-enabled businessArchitecture & transformation designTarget structure and roadmap

Supported technology and information architecture design and prepared a target operating structure with an executable digital transformation roadmap.

TÜRKİYE

Crypto-asset governance and tokenisation

Crypto-asset businessGovernance & solution designIT/AML model and tokenisation structure

Designed IT and AML governance for a crypto-asset business and delivered a separate tokenisation initiative from operating concept to implementation structure.

03

Assurance, resilience & remediation

Independent testing, regulator-ready reporting and closure evidence.

LAOS

Data centre continuity assurance

Data centre operatorContinuity assuranceISAE 3000 report

Performed a business continuity assessment for a data centre and produced an ISAE 3000 assurance report.

GERMANY

ISO/IEC 27001 audit

Technology-enabled organisationsAudit & certification readinessAudit and readiness outcomes

Performed an ISO/IEC 27001 audit for a German organisation and supported another organisation through its certification readiness process.

TÜRKİYE

Crypto-asset IT audits

Two crypto-asset companiesIndependent IT auditTwo formal reports

Completed IT audits for two crypto-asset companies and issued independent reports covering governance, control and technology risk.

MALTA

Software and SDLC agreed-upon procedures

Software providerAgreed-upon proceduresFormal AUP report

Conducted an AUP engagement covering source code, functionality and the software development lifecycle, with a formal report.

TÜRKİYE

Regulatory finding response

Regulated service providerFinding response & regulator engagementDefence and BDDK process

Prepared a regulated service provider's response to an independent audit finding and managed the related BDDK engagement.

04

Strategy, feasibility & institutional readiness

Decision support before capital, operating model and transformation commitments are made.

LIBYA

Payment business feasibility and stress testing

Prospective payment businessFeasibility & stress testingScenario-tested investment view

Assessed the commercial viability of establishing a payment institution and tested the business model under alternative operating and downside scenarios.

TÜRKİYE

E-TURQUALITY® application readiness

Game companyInstitutional and application readinessProgramme application preparation

Prepared a game company for the programme through corporate readiness, process documentation, technology controls and application support.