Experience

We build AI. We govern AI. And we spent twenty years on the other side of the table first.

Read in order, these make one argument. The AI work is the product. The assurance work is why you’d trust the judgement behind it.

Group A

Building AI

Recent delivery. Anonymised at each client’s level of comfort.

AI Enablement Programme

Commodity trading & structured finance firm

Context A lean trading firm — crude marketing and structured finance — carrying the reporting and reconciliation load of a company five times its size, in spreadsheets, by hand, at month-end. An initial workshop conversation ended with the firm appointing us implementation partner for an AI optimisation programme.

Approach A function-specific in-person enablement programme rather than a platform rollout. Crude marketing, accounts and administration, structured finance, and the executive team each worked one-to-one on their own live files — a daily market report drafter, a queryable set of finance records, a monthly reporting tool. Delivered alongside scope: a branded document engine reproducing the firm’s report templates, and a daily market-report pipeline running end to end from their own source workbook.

Outcome Every participant left with a working tool built on their real work and the ability to run it unaided. Now scoping a multi-module build programme against the firm’s own optimisation brief.

Enablement as the honest front end of discovery. An afternoon on someone’s real files tells you more than a two-week requirements exercise.

Data-Boundary-First Build

Luxury concierge

Context An entire business running out of WhatsApp and one person’s memory. High-net-worth clients acquired by referral, bookings and preferences held in chat history — and regulated client identity and payment details sitting in plain text on a single phone with no backup and no access controls. A previous overseas engagement had taken her money and shipped nothing.

Approach We started at the data boundary, not the feature list. The first thing designed was the gate that keeps regulated data away from every clever component downstream. That design was put through adversarial review, failed it, and was rebuilt before any workflow was built on top. Then sequenced to put working software in her hands in weeks, because her history demanded it.

Outcome Sensitive client data moved off an unmanaged phone and behind access controls. A command centre that feeds itself, so she does no data entry.

Most “AI automation” advice is about wiring. Wiring is how you build a compliance breach with a nice interface.

The Build We Talked The Client Out Of

Streaming media founder

Context A talk-show brand publishing long-form interviews and slicing them into clips across four platforms. Social media was eating the team’s time and paying nothing back. The brief was the obvious one: an end-to-end AI posting pipeline with captions, approvals and scheduling.

Approach Three weeks into discovery the ground shifted and the obvious plan became the wrong plan. So we killed it before writing a line of pipeline code and hand-ran a concierge pilot instead — a weekly growth brief reading her own platform analytics and answering one question: what’s working, and what should you make more of. No tooling cost, no live API into her accounts, and her data never left her control in a form we didn’t govern.

Outcome The recommendations kept landing and the channel’s target audience segment grew across the first three briefs. The pipeline was never built, because it turned out not to be the thing worth building.

The highest-impact AI automation is sometimes the one you don’t build. Prove the output is worth having before you build the machine that produces it.

Decision Support, Not Replacement

Independent logistics operator

Context A two-person trucking business under real financial pressure, run by a technically capable owner who had already built her own tools with AI. Her stated bottleneck was finding loads worth bidding on — the core revenue activity she had no bandwidth for.

Approach Not a replacement for her work. We packaged her own bid-decision arithmetic as a deterministic component she owns, can open, can edit and can run standalone — the maths exact every time, no model doing the multiplication — then wrapped it in a morning report that pulls the day’s available loads, runs each through her parameters, checks the destination market for a return load, and ranks them with a one-line reason each.

Outcome A morning decision that used to be guesswork, made fast and well-informed. Read-only by design: it takes neither the decision nor the action away from her.

Control placement. Arithmetic in code where it must be exact, judgement in the model where it adds something, the decision with the person accountable for it.

Foundation Before Feature

Interior design studio, 53 staff

Context The stated pain was invoicing. The actual problem was that nothing was written down and the whole business — client history, project status, supplier relationships, pricing — lived in the CEO’s head. She was candid about her own comfort with technology, and about a history of adopting tools and then not using them.

Approach So invoicing came second. First was a morning briefing, a lightweight client list, and an automated onboarding questionnaire — the data foundation everything else depends on. Automating invoices on top of nothing is automating nothing. The honest risk went in the recommendation in her own words, and a weekly human check-in was built into the engagement to counter it.

Outcome Daily visibility over her own business for the first time, at a total interaction cost of reading one message a day.

Adoption is the risk, not the technology. Naming it in the proposal — and designing against it — is the difference between a system that sticks and another unused tool.

Group B

Governing AI

The assurance side, applied to AI.

AI Governance Foundation

Multi-sector research programme

Context A multi-organisation programme needed a defensible, board-ready position on AI governance, shadow AI, agentic systems, data residency and use-case risk — the questions arriving at audit committees without a credible answer in the room.

Approach Delivered an AI Governance Matrix, a Shadow AI report, an agentic protocol audit, a data residency flow map, a use-case risk taxonomy, and a board and C-suite briefing pack, supported by a 12–18 month executive action roadmap.

Outcome A complete, sequenced AI governance foundation deployable both as policy and as a programme.

The governance work is not a paper exercise bolted onto the build practice. It came first, and it’s why the builds are designed the way they are.

Group C

Two decades on the other side of the table

Before building AI systems, the work was assessing, auditing and challenging systems like them. Second line of defence at Tier-1 banks. Deputy CISO at a regulated trading technology firm. Advising a Critical Information Infrastructure operator. That isn’t previous career history filed for completeness — it’s the reason a client lets us near their data.

Regional super-app

Cybersecurity Strategy & Governance Uplift

A South-East Asian digital platform operating across multiple jurisdictions needed to mature its cybersecurity posture against rapid product expansion and regulatory scrutiny. Authored a multi-year Cybersecurity Strategic Plan and Maturity Model spanning data governance, EDR, vulnerability management and cloud security posture management. The framework became the cornerstone of the organisation’s cyber practice.

Global trading technology firm

SOC 2 / Control Readiness

A regulated trading and risk-management technology provider serving financial institutions and central banks needed to sustain SOC 2 attestation while embedding secure SDLC practices across global engineering teams. Led the global security strategy, embedded risk-based vulnerability management, and operationalised RCSA cycles through a GRC platform — issues, remediation actions and KRIs tracked through to closure.

Energy sector operator

Critical Infrastructure Cybersecurity Advisory

A Critical Information Infrastructure operator in energy required risk-based cybersecurity strategy aligned to Singapore’s Cybersecurity Act 2018 and broader OT-security expectations. Advised on strategy execution, embedded Zero Trust principles and incident response into daily operations, and developed ISMS-aligned governance frameworks and security policies.

Multi-sector

Executive Cyber Tabletop Exercises

Executive teams across financial services and critical infrastructure needed structured pressure-testing of incident response, ransomware decision-making and crisis communications. Designed and facilitated resilience simulations and ransomware tabletops tailored to each organisation’s threat profile, regulatory exposure and board composition.

Capability development

Cybersecurity Academy Advisory

A capability-development institution needed advisory support on the strategy, governance and curriculum architecture of a cyber academy. Strategic advisory across academy positioning, partnership architecture, curriculum design and cyber range requirements specification.

Start here

Happy to talk specifics under NDA.

Everything above is anonymised at the client’s level of comfort. On a call we can go considerably further into any of it.