Compliance management
My specialism. I help owners and managers build compliance and risk frameworks that hold up, aligned to ISO 37301 and ISO 31000, get the regulatory duties right, and turn policy into what people actually do.
How I work →Compliance, With Quality
Compliance management · Quality assurance · Advisory
I run my own advisory practice. It does two things, compliance management and quality assurance, and I lead every engagement. I set it up for two situations. In the first, a regulator, an auditor or a large customer has asked a question the organisation could not answer. In the second, the policies are written and nobody can say whether they are followed. The standards I work to are ISO 37301, ISO 31000 and ISO 9001. I do not hand a ten-person firm the system a bank would need.
Two connected specialisms, one approach: build the system that fits how you actually operate, tie it to the standard and the law, and make it stick as behaviour rather than a binder nobody reads.
My specialism. I help owners and managers build compliance and risk frameworks that hold up, aligned to ISO 37301 and ISO 31000, get the regulatory duties right, and turn policy into what people actually do.
How I work →Quality management systems that keep the work consistent and provable, aligned to ISO 9001, plus the course, curriculum and accreditation quality assurance that keeps a training programme credible as it grows.
See how I work →I run each engagement in the same order, and you are free to stop after any stage. If the Diagnostic shows that you need nothing more, I will tell you so.
Start with the Diagnostic if you are not sure. Half the point of it is to find out whether you need a project in the first place. If you sign a Build project within 60 days of the findings call, I credit the Diagnostic fee in full against the project fee. For the detail, go to the compliance management page or the quality assurance page.
Compliance management
This is advice for owners and managers on compliance and risk. I build the framework to ISO 37301 and the risk side to ISO 31000. I check you have the regulatory duties right. Then I work on the hard part, which is getting people to do what the policy says. I keep it practical, and I keep it to the size of your business. And I start from the law of the place you trade in.
Compliance managementQuality assurance
I help organisations build quality management systems that keep the work consistent, documented and audit-ready, aligned to ISO 9001. And for those who train, I set up the course, curriculum and accreditation quality assurance that keeps a programme credible as more people teach it. Same principle in both: make the right way the standard way, and be able to show it.
Quality assuranceWhat these organisations share is simple. Somebody outside wants proof that the staff know their jobs and the systems work, and there is no compliance department to produce that proof. These are the six kinds of organisation the practice is set up to serve.
Operators with a remote or land-based licence. That includes Malta-based groups that also hold a Great Britain licence. For a remote operator, the Gambling Commission's social responsibility code requires all reasonable steps to evaluate how well its customer interaction approach is working, and the operator must be able to show the Commission the results. You cannot do that without trained staff and good records.
If the FCA's Training and Competence rules apply to your firm, you have to assess your people as competent, supervise them appropriately at all times, check regularly that they stay competent, and keep a record of it all. I set up the framework and the paper trail that sits behind it.
CQC Regulation 18 says a provider must have enough suitably qualified, competent, skilled and experienced staff, and must give them the training and supervision they need. My job is to help you show an inspector how you do that.
You have a course, and you want a CPD body, an awarding organisation or a sector body to recognise it. They will look hard at the curriculum, the assessment and your internal quality assurance. I get those three ready before they do.
A manufacturer wants ISO 9001, and wants the shop floor to follow it too. In Great Britain, the construction regulations say that anyone who appoints a designer or contractor must take reasonable steps to check that they have the skills, knowledge and experience for the work. In both sectors the question is whether people are competent for the work they do.
Plenty of smaller firms have no compliance officer at all. The owner does it, or the operations manager, or whoever looks after HR, on top of the day job. I build the system so that person can run it without me.
I design and run compliance, risk and quality systems to internationally recognised ISO standards. Alignment is a design principle, not a badge: the structure and intent of the standard shapes the system, sized to how your organisation actually works, and built so it holds up when someone checks.
Compliance
ISO 37301
Compliance management systems
The backbone of how I build a compliance framework: governance, obligations, controls and evidence that stand up under scrutiny.
Risk
ISO 31000
Risk management
Risk assessed and managed as a discipline, so the register drives real decisions instead of sitting in a drawer.
Quality
ISO 9001
Quality management systems
Quality systems that keep the work consistent, documented and audit-ready, day to day.
Anti-bribery
ISO 37001
Anti-bribery management systems
Controls proportionate to your exposure, from third-party due diligence to gifts and hospitality.
Education
ISO 21001
Educational organisations
For training providers: a management system that keeps a learning organisation credible as it grows.
Learning services
ISO 29993
Learning services outside formal education
Course and curriculum quality assurance, so a programme stays sound as more people teach it.
The practice
I lead every engagement and do most of the work myself. You deal with me from the first call until the work is signed off. Some engagements need a second specialist, such as an assessor to sample assessment decisions or a second auditor for a mock inspection. When that happens I bring in a specialist I have vetted myself. I check the degree certificate and the relevant experience before anyone works on a client engagement. Before they start, I tell you who they are and what they will do.
The practice is run from Malta, and I am in the United Kingdom regularly. It takes work in the United Kingdom, the European Union and Malta. I own other businesses. Before I accept an engagement I check it for a conflict of interest with any of them. You can read how an engagement is run, and what happens to your information, on the Trust page. My own record is on the About page and the CV.
These are short pieces taken from two of my books. Each picks one compliance or quality model and tells it through a real company. Each ends on a question you could ask at your own management meeting this week.
Key Compliance Models
Three teams were watching the risk. All three had gone slack at the same time. That is the HSBC story in one line.
Key Quality Models
Most people change how they work and never check if it helped. They just move on. Next month, the same problem is back.
Key Compliance Models
UBS did not lack a process on paper. A process that is not lived is not a control. It is a document.
Compliance, risk and quality across finance, iGaming, manufacturing, hospitality, retail and property.
Work aligned to ISO 37301, ISO 31000 and ISO 9001, with ISO 37001 for anti-bribery.
Completing a DBA, with research on how organisations put learning into practice.
Across the UK, the EU and Malta, tying guidance to the jurisdiction that governs you.
It does two things. On the compliance side I build frameworks to ISO 37301 and risk management to ISO 31000. For firms in regulated sectors I also build training and competence frameworks, and I get an organisation ready for whichever duties apply to it. On the quality side it is ISO 9001 systems, plus the quality assurance that sits behind a training course. That means the curriculum, the assessment and the accreditation paperwork. All of it is advice given to one organisation at a time, and the documents are written for that organisation.
Stefan Gauci Scicluna. I lead every engagement and you deal with me from start to finish. Some engagements need a second specialist. When one does I bring in a specialist I have vetted myself, and I tell you who they are before they start.
No, and nobody in my position can. An ISO certificate comes from an accredited certification body. An accreditation comes from the accreditor or the awarding body. My part is to build the system with you and prepare you for the day. The decision is theirs, and I will not promise you an outcome.
I recommend starting with the Diagnostic. It takes two or three days of my time and leaves you with scored findings and a 90-day plan. If you already know what you need, skip the Diagnostic and use the contact page. I will want to know who you are, what is putting you under pressure and when it has to be done. You will usually hear back within a couple of working days.
The UK, the EU and Malta. The practice is run from Malta. I work from the law of the place you trade in, and Scotland does some things differently from England. My own ground is the United Kingdom, Malta and European Union rules. For the national law of another member state I work alongside a local adviser.
Start a conversation
Tell me what you want done and by when. You will get a plain yes or no on whether this practice is the right one for it, and if it is, how I would go about it.