Why clients call us
Compliance management now accounts for roughly 28% of data governance activity, and financial services remains the leading vertical. The reason is structural: DORA, NIS2, the EU Data Act, the AI Act and the Cyber Resilience Act each impose dated documentary obligations that recur every year rather than closing after a project.
We approach governance from the flow upwards. Cartography, lineage and reference data are engineering artefacts before they are policy documents, which is why our governance work holds up with both the CIO and the second line of defence. We are data engineers rather than legal advisers, and we work alongside your counsel rather than in place of them.
What we do
- Flow cartography and lineageA maintained map of what moves where, through which platform, under whose ownership. The artefact every subsequent obligation depends on.
- Register of Information and third-party mappingStructuring and populating the ICT third-party register expected annually under DORA, sourced from real contracts and real flows.
- DORA and NIS2 readinessGap analysis against operational resilience and registration requirements, translated into a prioritised technical backlog.
- Reference data and master data managementGolden record definition, party and address referentials, survivorship rules and stewardship workflows. The fastest-growing segment in this pillar, and the one AI use cases break on first.
- Policy as code and stewardshipGovernance rules expressed as executable controls inside the pipeline, with named stewards and a review cadence, rather than a document nobody opens.
The AI Act treats data governance as a condition of deploying AI systems, not a parallel workstream. Lineage is becoming a prerequisite for using a model at all.
Buying triggers
- A DORA register submission deadline
- NIS2 transposition and registration in a member state
- EU Data Act access, portability and interoperability clauses
- AI Act transparency and data governance obligations
- An internal audit finding on data lineage or ownership
Technical foundation
- Flow cartography and lineage tooling
- Microsoft Purview
- Reference data and MDM design
- ICT third-party register structuring
- Control implementation in ACE, MQ, Sterling
Start here
A 5 to 15 day assessment gives you a map of this scope, a gap analysis and a costed plan.
Market vocabulary
How this offer is named in tenders and job specifications
- data governance
- data stewardship
- Register of Information
- DORA readiness
- NIS2
- MDM
- golden record
- policy-as-code
- AI governance
Proof
Where this has already been delivered
Public institutions and infrastructure
Critical flows under compliance constraint
Integration of critical flows for public-sector and infrastructure organisations, where sovereignty, archiving requirements and full traceability shape the architecture from the first design review.
Integration hub · Traceability · Archiving · Compliance
How we work on this
Assessment — 5 to 15 days, fixed price. Flow cartography, gap analysis, costed plan. A short document written to be signed by a decision-maker.
Build — A bounded project. Design, development, testing and cut-over on a defined perimeter.
Run — Recurring. Operations, monitoring, evolution and on-call cover on your critical flows.
Let's start with what actually flows today.
A 5 to 15 day assessment gives you a flow map, a gap analysis and a costed plan. Short, fixed price, written to be signed by a decision-maker.