Compliance & regulatory affairs
Someone is asking you
to prove you are compliant.
A customer, an auditor, a regulator or a tender. Usually that is the moment people call me, and usually the first question is the same: what actually applies to us, and what do we need to do about it? I answer that question for you, in plain language, and then help you build the policies, controls and evidence that make the answer hold up.
Scoping
Not every rule is your rule
European regulation is stacking up, at entity level and increasingly at product level. Only part of that field ever lands on your organisation. So the first job is deciding which obligations apply, how they connect, and which one to start with. Everything after that is easier once that decision is made.
Every obligation that exists, the ones that actually apply to you, and the one to open with.
Frameworks
How I support you per regulation
European regulation is stacking up, at entity level and increasingly at product level. I help your organisation understand exactly what applies, what is missing and what needs to happen, framework by framework.
01
GDPR
I guide your organisation from baseline assessment to demonstrable compliance, covering gap analysis, records of processing, privacy by design and employee awareness.
- GDPR gap analysis and risk assessment
- Record of processing activities (RoPA)
- Privacy policy, DPAs and cookie compliance
- Privacy by Design in processes and systems
02
NIS2
NIS2 places direct responsibility on management for cybersecurity measures. I help determine scope, set up incident response procedures and build the governance structures required.
- Scope determination and registration
- Risk analysis and security measures
- Incident response and reporting procedures
- Supply chain security and vendor management
03
EU AI Act
I help classify the risk level of your AI applications and translate that into the right obligations, from documentation and transparency to governance and oversight structures.
- AI inventory and risk classification
- Conformity assessments for high-risk AI systems
- Technical documentation and transparency obligations
- AI governance policy and internal oversight
04
CSRD & EU Taxonomy
I help structure your sustainability reporting, from double materiality analysis and EU taxonomy screening to data collection and preparation for external verification.
- CSRD scope and reporting obligations
- Double materiality analysis (ESRS)
- EU taxonomy screening and alignment
- Data collection, gap analysis and reporting structure
05
DORA
For financial institutions and ICT service providers, I set up a DORA-compliant programme covering ICT risk management, incident reporting, resilience testing and third-party oversight.
- ICT risk management framework
- Incident classification and reporting processes
- Digital resilience testing programme
- Third-party risk and contract management
06
CBAM & EUDR
I help organisations map their CBAM and EUDR obligations, set up due diligence systems and build the supply chain transparency required for reporting and market access.
- CBAM scope analysis and declaration obligations
- EUDR due diligence system
- Supplier data collection and chain transparency
- Process and system adaptation for reporting
07
ESPR & Digital Product Passport
The Ecodesign for Sustainable Products Regulation pushes product requirements well beyond safety, into durability, recycled content and mandatory data disclosure. I determine when your product categories enter scope, what the Digital Product Passport has to contain and who in your chain must deliver that data.
- ESPR scope and product category timelines
- DPP data model, data carriers and access rights
- Substances of concern and SCIP notification
- Supplier data clauses and chain responsibility
08
GRS & recycled content
The Global Recycled Standard certifies recycled content in any product category, not only textiles. I prepare the scope, supplier chain of custody, input verification and documentation that make a recycled content claim hold up with customers, auditors and regulators. Where only content verification is needed, the lighter RCS route can be enough.
- GRS scope, thresholds and certification readiness
- Chain of custody and transaction certificates
- Recycled input verification and content calculation
- Social, environmental and chemical requirements
09
LCA & Environmental Product Declarations
A life cycle assessment is increasingly the evidence base behind a regulatory claim rather than a marketing document. I set up LCAs to ISO 14040 and 14044, arrange EPDs under EN 15804 where relevant, and make sure the results survive verification.
- Goal, scope and system boundary definition
- Data collection, data quality and modelling
- EPD development and third-party verification
- Substantiation of environmental claims
10
GHG accounting & carbon reporting
Emissions figures are no longer a voluntary disclosure, but assured data feeding CSRD, CBAM and customer requirements. I build the accounting structure underneath: boundaries, methodology, controls and audit trail.
- Scope 1, 2 and 3 inventory per GHG Protocol and ISO 14064-1
- Organisational and operational boundaries, base year setting
- Scope 3 screening, supplier data and emission factors
- Assurance-ready documentation and internal controls
The method in figures
10
Frameworks I work through on this page, from GDPR and NIS2 to ESPR and GHG accounting.
4
Steps in the route I follow, from inventory and assessment to implementation and embedding.
30
Minutes in the opening compliance scan, enough to place your question and name the next step.
How I work
No generic checklists and no jargon you have to translate for your own team.
Roy Zopfi, Royaal Project
My approach
From inventory to embedding
I work pragmatically and with an organisational focus. No generic checklists, but an approach that fits your sector, scale and risk appetite.
1
Inventory
Map which laws apply to your organisation and prioritise based on risk and impact.
2
Assessment
A thorough gap analysis to understand where you stand today and what the distance to full compliance is.
3
Implementation
Policies, processes and controls are set up or adjusted. Responsibilities are clearly assigned.
4
Monitoring and embedding
Ongoing monitoring, periodic audits and timely adjustment when legislation changes.
Proven in practice
Four standards, one system, three months.
Technical manufacturer, approx. 100 FTE
Two parties asking for certification at the same time
A key customer and the regulator were both demanding certification. Nothing was in place: no management system, no documented processes, no audit history.
Rather than running four parallel projects, I built one integrated system covering ISO 9001, 14001 and 27001 alongside GRS, and ran the internal audit and management review in house.
Certified against all four standards within three months, from a standing start.
I do not publish client names. Happy to walk you through how this was done in a call, or read the full case.
Let’s talk
Take control of your compliance.
I am here to help.
Whether you need a compliance scan, framework implementation or structural support, I think alongside you pragmatically and strategically.