Compliance & risk management consultancy

Compliance and risk management that protects the business and earns its place.

I help owners and managers build compliance and risk management that actually protects the business, not a binder that passes the audit and changes nothing. Practical, practitioner-led advisory for organisations in the United Kingdom and Malta, aligned to ISO 37301 and ISO 31000, and tuned to the jurisdiction that governs you.

What I do

Compliance and risk management is my specialism. The work spans the whole picture, from the framework on paper to the behaviour on the floor, and it is built to be run by the people already in the business.

01

Compliance framework design

A compliance management system that fits how you actually operate, aligned to ISO 37301: scope, roles, controls and the evidence trail, sized to your organisation rather than a large corporate template.

02

Risk assessment and management

Risk identified, rated and owned, aligned to ISO 31000: a working risk register, a clear risk appetite, and controls tied to the risks that actually threaten the business, not a list nobody reads.

03

Regulatory readiness

The duties that apply to you, made practical: data protection and GDPR, anti-money laundering, health and safety, anti-bribery, whistleblowing, and newer duties such as the EU AI Act, tied to your jurisdiction.

04

Compliance audits and gap analysis

An honest read of where you stand against the standard and the law, what is missing, and what to fix first, with a prioritised plan you can act on rather than a report that sits in a drawer.

05

Turning policy into behaviour

The step most compliance skips: making the compliant way the easy way, so policies become what people actually do. Where formal training is the answer, I design it and can point you to delivery.

06

Board and leadership advisory

Compliance and risk framed for the people who carry the accountability: what to worry about, what to measure, and how to show a clean, provable posture to clients, regulators and partners.

How I work

One clear method, worked at three levels at once, so the strategy, the system and the day-to-day decision all point the same way.

Strategic

Where compliance protects value

The board-level view: the risks that could actually harm the business, the posture that wins trust and work, and where compliance stops being a cost and starts being an asset.

Operational

The system that runs it

The live framework, not a dead binder: controls, owners, evidence and review, built so the organisation can run and prove it without a large function behind it.

Tactical

The decision on the floor

Where compliance is won or lost: the everyday choice made the compliant way because that is the easy way, with managers as the control rather than a policy nobody reads.

I work in plain language, from practice rather than theory, and I keep a clear line between what the standard requires and what is my judgment. Guidance is always tied to the jurisdiction that governs you, because the United Kingdom and Malta diverge on points that matter.

Who I work with

Owners, managers and department heads at small and mid-sized organisations that carry real compliance and risk without a large function behind them, across the United Kingdom and Malta. I have worked across regulated and demanding sectors, from finance and iGaming to manufacturing, hospitality, retail and property, and I teach compliance management at university and professional level, so the advice is grounded in both the standard and the room.

The method, in a book

Cover of Compliance Beyond Ticking the Box by Stefan Gauci Scicluna

Compliance · Auren Institute

Compliance Beyond Ticking the Box

The same method I use with clients, set out as a workbook you can run yourself. How managers turn compliance from a cost you endure into a system that protects the business and drives its growth, with a fill-in tool in every chapter and real, documented cases from major UK, European and US companies. A good place to see how I think before we ever speak.

Why me

A practitioner and a teacher, not a box of templates.

I am a doctoral candidate in business administration, hold a master's from the College of Europe and a Malta teaching warrant, and I have lectured in compliance management, governance, GDPR, AML and internal audit since 2013 alongside running businesses in education, property and supply chain. I write on the subject as well: Compliance Beyond Ticking the Box sets out the method in full. The full record of education, publications and lecturing is on my CV page.

A note on scope: this is advisory work tailored to your organisation and its jurisdiction. It is not legal advice, and it does not replace your regulator's own guidance or, where you need it, a qualified lawyer. For compliance and governance training as a product, see Auren Institute.

Common questions

What is compliance and risk management consultancy?

It is practical advisory work that helps an organisation build compliance and risk management that protects the business and holds up under scrutiny, rather than a binder of policies that passes the audit and changes nothing. It covers the framework, the risk assessment, the regulatory duties that apply, and the way all of it turns into behaviour on the floor.

Do you work with small businesses that have no compliance team?

Yes. Most of the work is with owners, managers and department heads who carry compliance and risk without a large function behind them. The method is built to be run by the people already in the business, not to depend on a department they do not have.

Which standards and regulations do you work to?

Compliance management systems are aligned to ISO 37301 and risk management to ISO 31000, with anti-bribery work referencing ISO 37001. Regulatory areas commonly include data protection and GDPR, anti-money laundering, health and safety, whistleblowing, and newer duties such as the EU AI Act, applied to the jurisdiction that governs you.

Do you work across the UK and Malta?

Yes. The practice covers the United Kingdom and Malta, and the wider European Union where the law reaches. Guidance is always tied to the jurisdiction that applies to you, because the UK and Malta diverge on important points.

How do we start?

Use the contact page to outline your organisation, the pressure you are under and roughly what you need. You will get a straight answer on fit, scope and how the work would run, usually within a couple of working days.

Make an enquiry