Structure that survives scrutiny
A governance framework is tested at the worst possible moment: during a regulatory review, a dispute, or a transaction. What matters is whether decisions were made by people authorised to make them and whether that is evidenced.
Risk that is owned
A risk register with no named owner and no review date is documentation, not risk management. We build registers where each risk has an owner, a current assessment, a treatment and a review cadence the board actually follows.
AML and CFT
Where the business is within scope, a proportionate anti-money-laundering and counter-terrorist-financing programme: customer due diligence, screening, monitoring, record keeping and reporting lines.
How the engagement runs
Assess
Review current governance, authority levels and risk practice against expectation.
Design
Build the committee structure, delegation of authority and risk register.
Embed
Train the people who have to operate it, not just issue the document.
Review
Periodic assessment that the framework is being followed in practice.
Frequently asked questions
What does GRC mean for a company in Qatar?
Do we need an AML programme?
What is a delegation of authority matrix?
How often should a risk register be reviewed?
Need this done?
Tell us your deadline and we will tell you what is required, what it involves and what it costs.


