Compliance, With Quality

Compliance management · Quality assurance · Advisory

I help organisations get compliance and quality right, and make both hold up under scrutiny.

I run my own advisory practice. It does two things, compliance management and quality assurance, and I lead every engagement. I set it up for two situations. In the first, a regulator, an auditor or a large customer has asked a question the organisation could not answer. In the second, the policies are written and nobody can say whether they are followed. The standards I work to are ISO 37301, ISO 31000 and ISO 9001. I do not hand a ten-person firm the system a bank would need.

Connected nodes representing an organisation run as a system

What the practice does

Two connected specialisms, one approach: build the system that fits how you actually operate, tie it to the standard and the law, and make it stick as behaviour rather than a binder nobody reads.

A set of scales beside a classical institution

Compliance management

My specialism. I help owners and managers build compliance and risk frameworks that hold up, aligned to ISO 37301 and ISO 31000, get the regulatory duties right, and turn policy into what people actually do.

How I work →
Connected nodes representing a quality system

Quality assurance

Quality management systems that keep the work consistent and provable, aligned to ISO 9001, plus the course, curriculum and accreditation quality assurance that keeps a training programme credible as it grows.

See how I work →

How an engagement runs

I run each engagement in the same order, and you are free to stop after any stage. If the Diagnostic shows that you need nothing more, I will tell you so.

  1. DiagnosticThis part takes two or three days. I go through your paperwork and sit down with two or three of your staff. Then I mark what I have seen against whichever standard or regulator applies to you. At the end you have a few pages of findings and a plan for the next 90 days. We talk both through on a call.
  2. BuildThis is a project with a fixed scope, and it fills the gap the Diagnostic found. That might be a compliance framework or a risk framework. It might be a quality management system. For a training provider it can be the evidence pack an accreditor asks for.
  3. SustainOnce a system is built, somebody has to look after it. Keep, Assure and Assure Plus are three ways of having the practice do that for 12 months, with me accountable for the work. Under all three I update your documents once a year for changes in the law or the standard. Under Assure and Assure Plus I also check every quarter whether people still follow them.
  4. Add where neededSome work is a one-off: a mock inspection, a day of internal audit, an update after a rule change, a report for your board, or a block of advisory hours.

Start with the Diagnostic if you are not sure. Half the point of it is to find out whether you need a project in the first place. If you sign a Build project within 60 days of the findings call, I credit the Diagnostic fee in full against the project fee. For the detail, go to the compliance management page or the quality assurance page.

Compliance management

Compliance and risk, put to work in your business.

This is advice for owners and managers on compliance and risk. I build the framework to ISO 37301 and the risk side to ISO 31000. I check you have the regulatory duties right. Then I work on the hard part, which is getting people to do what the policy says. I keep it practical, and I keep it to the size of your business. And I start from the law of the place you trade in.

Compliance management
  • Compliance frameworks aligned to ISO 37301, sized to your organisation.
  • Risk assessment aligned to ISO 31000: a register that works, not a list nobody reads.
  • Training and competence frameworks for regulated firms, records included.
  • Regulatory readiness across GDPR, AML, health and safety and newer duties.
  • Audits and gap analysis with a prioritised plan you can act on.

Quality assurance

Quality that is consistent, and that you can prove.

I help organisations build quality management systems that keep the work consistent, documented and audit-ready, aligned to ISO 9001. And for those who train, I set up the course, curriculum and accreditation quality assurance that keeps a programme credible as more people teach it. Same principle in both: make the right way the standard way, and be able to show it.

Quality assurance
  • Quality management systems aligned to ISO 9001, built to run day to day.
  • Process and document control so the work is repeatable and provable.
  • Internal audit and continual improvement that catch problems before clients do.
  • Course and curriculum design that fits the recognition you are after.
  • Accreditation readiness and the internal quality assurance an awarding body expects.

Who the practice is for

What these organisations share is simple. Somebody outside wants proof that the staff know their jobs and the systems work, and there is no compliance department to produce that proof. These are the six kinds of organisation the practice is set up to serve.

Gambling

Licensed operators

Operators with a remote or land-based licence. That includes Malta-based groups that also hold a Great Britain licence. For a remote operator, the Gambling Commission's social responsibility code requires all reasonable steps to evaluate how well its customer interaction approach is working, and the operator must be able to show the Commission the results. You cannot do that without trained staff and good records.

Financial services

Regulated firms

If the FCA's Training and Competence rules apply to your firm, you have to assess your people as competent, supervise them appropriately at all times, check regularly that they stay competent, and keep a record of it all. I set up the framework and the paper trail that sits behind it.

Health and social care

Care providers in England

CQC Regulation 18 says a provider must have enough suitably qualified, competent, skilled and experienced staff, and must give them the training and supervision they need. My job is to help you show an inspector how you do that.

Training

Training and apprenticeship providers

You have a course, and you want a CPD body, an awarding organisation or a sector body to recognise it. They will look hard at the curriculum, the assessment and your internal quality assurance. I get those three ready before they do.

Construction and manufacturing

Firms that must show competence

A manufacturer wants ISO 9001, and wants the shop floor to follow it too. In Great Britain, the construction regulations say that anyone who appoints a designer or contractor must take reasonable steps to check that they have the skills, knowledge and experience for the work. In both sectors the question is whether people are competent for the work they do.

Any sector

Owner-managed businesses

Plenty of smaller firms have no compliance officer at all. The owner does it, or the operations manager, or whoever looks after HR, on top of the day job. I build the system so that person can run it without me.

The standards I work to

I design and run compliance, risk and quality systems to internationally recognised ISO standards. Alignment is a design principle, not a badge: the structure and intent of the standard shapes the system, sized to how your organisation actually works, and built so it holds up when someone checks.

Compliance

ISO 37301
Compliance management systems

The backbone of how I build a compliance framework: governance, obligations, controls and evidence that stand up under scrutiny.

Risk

ISO 31000
Risk management

Risk assessed and managed as a discipline, so the register drives real decisions instead of sitting in a drawer.

Quality

ISO 9001
Quality management systems

Quality systems that keep the work consistent, documented and audit-ready, day to day.

Anti-bribery

ISO 37001
Anti-bribery management systems

Controls proportionate to your exposure, from third-party due diligence to gifts and hospitality.

Education

ISO 21001
Educational organisations

For training providers: a management system that keeps a learning organisation credible as it grows.

Learning services

ISO 29993
Learning services outside formal education

Course and curriculum quality assurance, so a programme stays sound as more people teach it.

What alignment means

  • The standard shapes the design, the controls and the evidence, sized to your organisation.
  • Obligations mapped to the regulation and the risk, with proof you can put in front of an auditor.
  • A gap analysis against the standard, and a prioritised plan you can act on.
  • Policy turned into behaviour, so the right way is the way people actually work.

What it does not mean

  • This is an advisory practice, not a certification body.
  • Certification against a standard is issued by an accredited certifier, not by me.
  • Alignment gets you ready for certification if you want it; it is not the same as holding the certificate.

The practice

Who does the work.

I lead every engagement and do most of the work myself. You deal with me from the first call until the work is signed off. Some engagements need a second specialist, such as an assessor to sample assessment decisions or a second auditor for a mock inspection. When that happens I bring in a specialist I have vetted myself. I check the degree certificate and the relevant experience before anyone works on a client engagement. Before they start, I tell you who they are and what they will do.

The practice is run from Malta, and I am in the United Kingdom regularly. It takes work in the United Kingdom, the European Union and Malta. I own other businesses. Before I accept an engagement I check it for a conflict of interest with any of them. You can read how an engagement is run, and what happens to your information, on the Trust page. My own record is on the About page and the CV.

Business Insights

All insights →

These are short pieces taken from two of my books. Each picks one compliance or quality model and tells it through a real company. Each ends on a question you could ask at your own management meeting this week.

The Three Lines Model: business, compliance and audit as three separate lines

Key Compliance Models

The Three Lines Model

Three teams were watching the risk. All three had gone slack at the same time. That is the HSBC story in one line.

1 min read
PDCA: Plan, Do, Check, Act, the Deming Cycle

Key Quality Models

PDCA, the Deming Cycle

Most people change how they work and never check if it helped. They just move on. Next month, the same problem is back.

1 min read
ISO 31000: a living loop of identify, analyse, evaluate and treat

Key Compliance Models

ISO 31000, Risk Management

UBS did not lack a process on paper. A process that is not lived is not a control. It is a document.

1 min read
Practice

Compliance, risk and quality across finance, iGaming, manufacturing, hospitality, retail and property.

Standards

Work aligned to ISO 37301, ISO 31000 and ISO 9001, with ISO 37001 for anti-bribery.

Doctorate

Completing a DBA, with research on how organisations put learning into practice.

Where I work

Across the UK, the EU and Malta, tying guidance to the jurisdiction that governs you.

Common questions

What does the advisory practice do?

It does two things. On the compliance side I build frameworks to ISO 37301 and risk management to ISO 31000. For firms in regulated sectors I also build training and competence frameworks, and I get an organisation ready for whichever duties apply to it. On the quality side it is ISO 9001 systems, plus the quality assurance that sits behind a training course. That means the curriculum, the assessment and the accreditation paperwork. All of it is advice given to one organisation at a time, and the documents are written for that organisation.

Who will I be working with?

Stefan Gauci Scicluna. I lead every engagement and you deal with me from start to finish. Some engagements need a second specialist. When one does I bring in a specialist I have vetted myself, and I tell you who they are before they start.

Do you issue ISO certificates or accreditations?

No, and nobody in my position can. An ISO certificate comes from an accredited certification body. An accreditation comes from the accreditor or the awarding body. My part is to build the system with you and prepare you for the day. The decision is theirs, and I will not promise you an outcome.

Where do I start?

I recommend starting with the Diagnostic. It takes two or three days of my time and leaves you with scored findings and a 90-day plan. If you already know what you need, skip the Diagnostic and use the contact page. I will want to know who you are, what is putting you under pressure and when it has to be done. You will usually hear back within a couple of working days.

Which countries do you cover?

The UK, the EU and Malta. The practice is run from Malta. I work from the law of the place you trade in, and Scotland does some things differently from England. My own ground is the United Kingdom, Malta and European Union rules. For the national law of another member state I work alongside a local adviser.

Start a conversation

Need help getting compliance or quality assurance right?

Tell me what you want done and by when. You will get a plain yes or no on whether this practice is the right one for it, and if it is, how I would go about it.

Make an enquiry