Compliance

Compliance & regulatory affairs

Someone is asking you
to prove you are compliant.

A customer, an auditor, a regulator or a tender. Usually that is the moment people call me, and usually the first question is the same: what actually applies to us, and what do we need to do about it? I answer that question for you, in plain language, and then help you build the policies, controls and evidence that make the answer hold up.

Scoping

Not every rule is your rule

European regulation is stacking up, at entity level and increasingly at product level. Only part of that field ever lands on your organisation. So the first job is deciding which obligations apply, how they connect, and which one to start with. Everything after that is easier once that decision is made.

IN SCOPESTART HERENOT YOURS

Every obligation that exists, the ones that actually apply to you, and the one to open with.

Frameworks

How I support you per regulation

European regulation is stacking up, at entity level and increasingly at product level. I help your organisation understand exactly what applies, what is missing and what needs to happen, framework by framework.

01

GDPR

I guide your organisation from baseline assessment to demonstrable compliance, covering gap analysis, records of processing, privacy by design and employee awareness.

  • GDPR gap analysis and risk assessment
  • Record of processing activities (RoPA)
  • Privacy policy, DPAs and cookie compliance
  • Privacy by Design in processes and systems

02

NIS2

NIS2 places direct responsibility on management for cybersecurity measures. I help determine scope, set up incident response procedures and build the governance structures required.

  • Scope determination and registration
  • Risk analysis and security measures
  • Incident response and reporting procedures
  • Supply chain security and vendor management

03

EU AI Act

I help classify the risk level of your AI applications and translate that into the right obligations, from documentation and transparency to governance and oversight structures.

  • AI inventory and risk classification
  • Conformity assessments for high-risk AI systems
  • Technical documentation and transparency obligations
  • AI governance policy and internal oversight

04

CSRD & EU Taxonomy

I help structure your sustainability reporting, from double materiality analysis and EU taxonomy screening to data collection and preparation for external verification.

  • CSRD scope and reporting obligations
  • Double materiality analysis (ESRS)
  • EU taxonomy screening and alignment
  • Data collection, gap analysis and reporting structure

05

DORA

For financial institutions and ICT service providers, I set up a DORA-compliant programme covering ICT risk management, incident reporting, resilience testing and third-party oversight.

  • ICT risk management framework
  • Incident classification and reporting processes
  • Digital resilience testing programme
  • Third-party risk and contract management

06

CBAM & EUDR

I help organisations map their CBAM and EUDR obligations, set up due diligence systems and build the supply chain transparency required for reporting and market access.

  • CBAM scope analysis and declaration obligations
  • EUDR due diligence system
  • Supplier data collection and chain transparency
  • Process and system adaptation for reporting

07

ESPR & Digital Product Passport

The Ecodesign for Sustainable Products Regulation pushes product requirements well beyond safety, into durability, recycled content and mandatory data disclosure. I determine when your product categories enter scope, what the Digital Product Passport has to contain and who in your chain must deliver that data.

  • ESPR scope and product category timelines
  • DPP data model, data carriers and access rights
  • Substances of concern and SCIP notification
  • Supplier data clauses and chain responsibility

08

GRS & recycled content

The Global Recycled Standard certifies recycled content in any product category, not only textiles. I prepare the scope, supplier chain of custody, input verification and documentation that make a recycled content claim hold up with customers, auditors and regulators. Where only content verification is needed, the lighter RCS route can be enough.

  • GRS scope, thresholds and certification readiness
  • Chain of custody and transaction certificates
  • Recycled input verification and content calculation
  • Social, environmental and chemical requirements

09

LCA & Environmental Product Declarations

A life cycle assessment is increasingly the evidence base behind a regulatory claim rather than a marketing document. I set up LCAs to ISO 14040 and 14044, arrange EPDs under EN 15804 where relevant, and make sure the results survive verification.

  • Goal, scope and system boundary definition
  • Data collection, data quality and modelling
  • EPD development and third-party verification
  • Substantiation of environmental claims

10

GHG accounting & carbon reporting

Emissions figures are no longer a voluntary disclosure, but assured data feeding CSRD, CBAM and customer requirements. I build the accounting structure underneath: boundaries, methodology, controls and audit trail.

  • Scope 1, 2 and 3 inventory per GHG Protocol and ISO 14064-1
  • Organisational and operational boundaries, base year setting
  • Scope 3 screening, supplier data and emission factors
  • Assurance-ready documentation and internal controls

The method in figures

10

Frameworks I work through on this page, from GDPR and NIS2 to ESPR and GHG accounting.

4

Steps in the route I follow, from inventory and assessment to implementation and embedding.

30

Minutes in the opening compliance scan, enough to place your question and name the next step.

How I work

No generic checklists and no jargon you have to translate for your own team.

Roy Zopfi, Royaal Project

My approach

From inventory to embedding

I work pragmatically and with an organisational focus. No generic checklists, but an approach that fits your sector, scale and risk appetite.

1

Inventory

Map which laws apply to your organisation and prioritise based on risk and impact.

2

Assessment

A thorough gap analysis to understand where you stand today and what the distance to full compliance is.

3

Implementation

Policies, processes and controls are set up or adjusted. Responsibilities are clearly assigned.

4

Monitoring and embedding

Ongoing monitoring, periodic audits and timely adjustment when legislation changes.

Proven in practice

Four standards, one system, three months.

Technical manufacturer, approx. 100 FTE

Two parties asking for certification at the same time

A key customer and the regulator were both demanding certification. Nothing was in place: no management system, no documented processes, no audit history.

Rather than running four parallel projects, I built one integrated system covering ISO 9001, 14001 and 27001 alongside GRS, and ran the internal audit and management review in house.

Certified against all four standards within three months, from a standing start.

I do not publish client names. Happy to walk you through how this was done in a call, or read the full case.

Let’s talk

Take control of your compliance.
I am here to help.

Whether you need a compliance scan, framework implementation or structural support, I think alongside you pragmatically and strategically.