Consulting for Compliance and Risk Management
Compliance Consulting and Risk Management: From the Rule to Evidence That Holds
Compliance is the sum of the arrangements a company uses to make sure that laws, contracts and its own policies are actually observed in day-to-day work; risk management is the other side of the same task, asking which events could endanger the business and who steers them. Neither usually becomes urgent on its own initiative. It becomes urgent when a client asks for evidence, when a body of rules applies to the company for the first time, when an incident raises uncomfortable questions, or when a financing round assumes an orderly control landscape. What that calls for is less a new set of policy documents than a realistic picture of your own risks, a handful of effective controls in the right places, and people who own those controls in everyday work. Compliance consulting starts at exactly that point.
Leading companies trust our network
What Compliance Consulting Delivers — and What It Does Not

Compliance consulting — bundled with risk management under the heading governance risk compliance in most organisations — works on one question: do the rules that apply to a company actually take effect in day-to-day work? A rule passes through four states. It is decided, it is known, it is built into a work step, and it is verifiable. Projects almost never fail at the first state, because policies are plentiful. They fail at the move from the second state to the third, and that is where the work sits.
It separates the rulebook from the control. A policy document is not a control. A control has a named owner, a cycle, a threshold at which someone steps in, and a trail showing that it took place. Twenty maintained controls at the points where something can genuinely go wrong carry further than two hundred pages of policy.
It sorts risks by how far they can be steered, not by how alarming they sound. A register ordered by loss amount creates attention for rare catastrophes and blindness towards the transaction that goes wrong every week. The list becomes usable only once every entry says who can influence it, with which measure — and how you would recognise that the measure is working.
It builds the rule into the work step rather than beside it. A check that lives in a separate file gets skipped under deadline pressure; one that sits in the approval step of the system does not. That includes the willingness to delete rules that block a process without lowering a risk.
What it does not do. It is not legal advice: whether a norm applies in a particular case, and which duties follow from it, belongs in the hands of a lawyer. It is not an audit and not a certification either, and it cannot guarantee compliant behaviour — anyone promising legal certainty is selling a feeling. And without the business functions, IT and procurement on board, every control stays a document.
Adjacent topics deliberately sit elsewhere: the reporting side of environmental and social duties in sustainability consulting, the governance of machine learning applications in AI consulting, permissions and service provider steering in IT consulting, supplier diligence along the chain in supply chain consulting, and the plain mapping of workflows in operations and process improvement.
When External Support on Compliance and Risk Topics Pays Off
Not every situation calls for help from outside. Where the question of what applies is already settled, where a named owner with a time budget exists in-house, and where a comparable body of rules has been introduced before, the internal route is the faster one. In the situations below the calculation comes out differently — not because knowledge of the business is missing, but because routine with this kind of evidence work is.
1. A Client Asks You for Evidence
- The supplier questionnaire asks about policies, controls and reporting channels — and the answers would have to be worked out first.
- The evidence is a condition of the contract, and improvised answers get noticed at the next review.
2. A Body of Rules Reaches You for the First Time
- A threshold has been crossed, a new market was added, or a product category newly falls under a requirement.
- The real question is rarely the legal text, but what it means for the way the work is organised.
3. An Incident Has Made a Gap Visible
- A mishap, a complaint or an audit finding has shown that a control was missing or did not bite.
- Whoever owned the transaction is badly placed to review it, so an outside view is also a relief.
4. The Risk Register Is a Spreadsheet Nobody Uses
- The list exists, gets updated once a year and changes no decision.
- What is missing is usually not the entry but the assignment: who steers it, with what, and how the effect is measured.
5. Compliance Is a Side Role Without a Time Budget
- The task hangs on one person who carries it next to a main job, and it grows faster than that person's capacity.
- Until a permanent appointment is decided, temporary reinforcement keeps the operation upright.
6. A Growth or Investment Step Is Coming Up
- An investor, a bank or a buyer looks at governance — and finds gaps that never got in the way of day-to-day business.
- What is put in order before a review costs a fraction of what has to be supplied afterwards.
Does one of these points describe the place you are standing in right now? A short conversation is usually enough to sort it out: which bodies of rules could reach you at all, which control is missing first — and whether an outside pair of hands is needed for it.
The Control Areas Compliance Consulting Works On
The areas are staffed one at a time or together, depending on where a company stands. It usually begins with the risk register and the controls; data protection, reporting channels and supplier screening follow wherever exposure calls for them. This is a selection — the category pages add a large number of further specialisations.
Compliance Management System
The frame that holds the single rules together: principles, responsibilities, training, monitoring and improvement. We build it along the actual risk picture instead of along a model handbook, and keep it small enough to stay maintainable. Frameworks such as ISO 37301 serve as an ordering grid, not as a target state.
Risk Register and Risk Steering
Collecting, scoring and updating the risks that can endanger the business, its assets or its reputation — with impact, frequency and, above all, a named owner for steering. Part of it are a reporting line that reaches the management in time and an escalation threshold. What decides the value of the register is whether it changes decisions.
Internal Control System (ICS)
Controls where value moves and mistakes get expensive: approval limits, segregation of duties, four-eyes checks, reconciliations in accounting, permissions in the leading systems. We first record what is already being controlled in practice, remove the duplication and close what is left open — until a control plan stands that the line organisation carries on without accompaniment.
Data Protection Organisation
The organisational side of data protection: records of processing, deletion concept, processor management, data subject rights, the notification route for incidents, and the question of who in the house decides what. We bring the paperwork together with lived practice and make it fit for review. The legal assessment of a single processing activity stays untouched by this.
Whistleblowing and Internal Investigation
A reporting office is quick to set up and hard to run. It needs confidentiality, deadlines, a traceable way of handling a case, protection against retaliation, and somebody who assesses a report independently. We set the route up and define when an internal investigation begins. Judging a concrete case belongs into a lawyer's hands.
Supplier and Third-Party Screening
Whoever works for you works in your name. This covers risk classification of the supplier base, self-disclosures, contract clauses, audits on site and a way of handling findings that goes beyond filing them. The area connects compliance with procurement and logistics — from sanctions screening through to diligence duties along the chain.
Which of these areas has to carry first in your case can be sorted out in a short conversation. Describe the situation to us; what comes back is an assessment, not a deck of offer slides.
In Which Forms Compliance Experience Is Brought In
The outcome is often decided less by technical depth than by the way experience is brought in: how much external capacity, with what mandate, over what period. The same frame holds for every form — a named internal owner, goals agreed in writing before the start, and a handover point that is fixed from day one.
An Outside Review
An experienced professional goes through the applicable rules, the exposure, the existing controls and the state of evidence, and names the gaps that count first. Deliberately short and open-ended — it often ends with the finding that the organisation manages the rest on its own.
Building in a Mixed Team
External specialists work on the control framework together with your own people, under internal professional leadership. This is the most common model for a first build: the knowledge stays in the house, and later maintenance does not hang on a contract.
Responsibility for a Period
An external person takes over a compliance or risk responsibility with decision-making authority — for an unfilled position, in a special situation, or when an authority is needed that does not sit inside the internal interests.
Support in Regular Operation
Recurring support on a fixed cycle: following up controls, preparing reports, refreshing training, accompanying audits. Sensible once the framework stands and the routine exists in the house but the capacity does not.
Compliance by Sector: Which Rulebook Sets the Pace
The pressure to regulate is felt everywhere; its source is not the same everywhere. In banking and insurance the supervisor sets the pace and the audit rhythm, in industry it is product safety, export control and the standards demanded by customers, in pharma and healthcare it is market authorisation together with its documentation duties, in retail the supply chain requirements of the sales markets, in logistics and foreign trade the customs and sanctions rules, in administration and utilities procurement law.
That is why we staff by sector experience and not by availability: with professionals who know the relevant bodies of rules, the usual system landscapes and the points at which comparable projects have run aground before. This is what separates regulatory compliance consulting from a generic policy exercise — the requirement is read in the language of the sector that has to meet it. The basis is a network spanning 25 specialist areas with more than 300 role profiles. The six sectors below ask for compliance and risk work most often; none is excluded by that.
Banking & Financial Services
Hardly any sector is regulated this densely, and hardly any has as much practice at it. The supervisor sets the pace: reporting duties, anti-money-laundering, oversight of outsourcing, plus an audit rhythm that asks for evidence permanently instead of occasionally. The effort rarely arises in the technical question but in the chain of evidence: every control needs a trail, every exception a justification, and both have to be findable years later.
Industry & Mechanical Engineering
The pressure comes from two sides. From outside through product safety, export control and sanctions lists, which can bite in any business touching critical goods. From inside through customer requirements: anyone supplying large buyers fills in questionnaires on policies, reporting channels and supplier diligence long before a law asks for them. Typical is a grown landscape of work instructions and inspection plans, sound in substance but not readable as a control system — we put it in order and make the export control check a step inside the order process.
Pharma & Healthcare
Where market authorisation and patient safety are at stake, documentation is not an accessory but part of the product. Validation, change control, deviation management and training records already form a control system — it is simply rarely connected to the rest. The work here usually consists of using that quality system as the base structure instead of raising a second structure beside it.
Logistics & Foreign Trade
Cross-border goods flows touch customs law, rules of origin, sanctions lists and dangerous goods regulations — and the picture changes faster than in any other field. A list version from the day before yesterday is, in case of doubt, not evidence. The check therefore has to sit automated inside the shipping process and leave a trail behind it. Exceptions need a defined route instead of an email.
Retail & Consumer Goods
Retail sits at the end of a long chain and is measured at its beginning. Product conformity, labelling, proof of origin and diligence duties towards upstream suppliers meet a supplier base that is large, changing and often far away. The effective lever is rarely one more questionnaire but a risk classification that steers the checking effort to where it changes something — tied to procurement, because otherwise it ends where the orders are placed.
Public Administration & Utilities
Here conformity is not a competitive advantage but a condition of existence — and it is negotiated in public. Procurement law, documentation duties and sector-specific requirements shape the working day, while the capacity for steering tasks is tied to budget years. The lever sits with the management of service providers: whoever awards a contract has to be able to evidence that it was delivered.
Banking & Financial Services
Hardly any sector is regulated this densely, and hardly any has as much practice at it. The supervisor sets the pace: reporting duties, anti-money-laundering, oversight of outsourcing, plus an audit rhythm that asks for evidence permanently instead of occasionally. The effort rarely arises in the technical question but in the chain of evidence: every control needs a trail, every exception a justification, and both have to be findable years later.
Industry & Mechanical Engineering
The pressure comes from two sides. From outside through product safety, export control and sanctions lists, which can bite in any business touching critical goods. From inside through customer requirements: anyone supplying large buyers fills in questionnaires on policies, reporting channels and supplier diligence long before a law asks for them. Typical is a grown landscape of work instructions and inspection plans, sound in substance but not readable as a control system — we put it in order and make the export control check a step inside the order process.
Pharma & Healthcare
Where market authorisation and patient safety are at stake, documentation is not an accessory but part of the product. Validation, change control, deviation management and training records already form a control system — it is simply rarely connected to the rest. The work here usually consists of using that quality system as the base structure instead of raising a second structure beside it.
Logistics & Foreign Trade
Cross-border goods flows touch customs law, rules of origin, sanctions lists and dangerous goods regulations — and the picture changes faster than in any other field. A list version from the day before yesterday is, in case of doubt, not evidence. The check therefore has to sit automated inside the shipping process and leave a trail behind it. Exceptions need a defined route instead of an email.
Retail & Consumer Goods
Retail sits at the end of a long chain and is measured at its beginning. Product conformity, labelling, proof of origin and diligence duties towards upstream suppliers meet a supplier base that is large, changing and often far away. The effective lever is rarely one more questionnaire but a risk classification that steers the checking effort to where it changes something — tied to procurement, because otherwise it ends where the orders are placed.
Public Administration & Utilities
Here conformity is not a competitive advantage but a condition of existence — and it is negotiated in public. Procurement law, documentation duties and sector-specific requirements shape the working day, while the capacity for steering tasks is tied to budget years. The lever sits with the management of service providers: whoever awards a contract has to be able to evidence that it was delivered.
Projects From Compliance Practice and Their Evidence Goals
What actually gets commissioned falls for the most part into four types. Each has a typical starting point, an order of work that has proven itself, and an evidence goal that is agreed before the start and demonstrated at the end rather than estimated. The examples are a selection, not a boundary.
Building a Compliance Management System
Starting point: scattered policies, committed individuals, but no frame that shows what belongs together. The order that holds: first clarify exposure and risks, then collect the controls that already exist, then close the gaps, and write last. The evidence goal is a control plan with owners and cycles that is still being maintained in the second year.
Setting Up a Risk Register and Reporting Line
Starting point: a risk list exists, changes no decision and reaches the management once a year. The work consists of interviews in the business functions, one consistent scoring logic and the nerve to produce a shorter list. The evidence goal is a report on a fixed cadence that triggers at least one decision per cycle.
Putting a Whistleblowing System Into Operation
Starting point: a reporting channel has been bought or is about to be, and the operation behind it is missing. To be settled are ownership, confidentiality, deadlines, documentation and the question of when legal support is brought in. The evidence goal is a documented handling route that also holds on the first serious case.
Anchoring Diligence Duties in the Supply Chain
Starting point: questionnaires went out, the answers came back, and nobody knows what should follow from them. The order: classify the supplier base by risk, align the depth of checking to it, add contract clauses and escalation routes, use audits selectively. The evidence goal is a demonstrable chain from the classification through the check to the consequence.
Which Profiles Staff Compliance and Risk Projects
The cut of the assignment decides the staffing: a risk register calls for a different profile than an export control check inside the order process. The profiles below are the ones most often asked for in compliance and risk work; they are a selection, and the category pages add many more. The task profile, the typical assignments and the daily rate range sit on each role's own page.
How a Compliance Project Takes Shape Step by Step
The scope and the duration of the steps depend on size and regulatory density; the sequence does not: first clarify what applies, then score, then build, then embed, then evidence. The scoring is never skipped — otherwise everything ends up controlled to the same depth.
1. Review the Rulebooks and Your Exposure
2. Score the Risks and Put Them in Order
3. Design the Controls
4. Embed Them Into Workflows and Systems
5. Produce the Evidence
6. Test the Effect and Keep It Current
What Compliance Consulting Costs: Daily Rates and Budgeting
Two figures determine the budget: the daily rate and the number of days. The second one is the larger and the one planned less often. Work through our network is billed by daily rate, with no project lump sum and no success-based components.
What moves the rate. In first place the seniority and the decision proximity of the role: whoever represents a control framework towards management, a supervisor or auditors sits above a role that supplies input. Next the regulatory density of the sector — in supervised or authorisation-bound environments the additional experience required is scarce, and scarcity works more strongly than any other factor. The share of on-site presence pushes in both directions: site and supplier audits need attendance, while work on policies and control plans runs largely remote and opens the pool of eligible profiles beyond your own region. Last the duration: an assignment over twelve months sits below a four-week engagement per day at the same onboarding effort.
The ranges from our own network — as published on each role page. For governance, control and framework work €750 to €1,300 per day (Freelance GRC Consultant, Freelance IT Governance Consultant). For regulatory specialist roles in foreign trade €800 to €1,300 (Freelance Trade Compliance Specialist, Freelance Export Control Specialist, Freelance Customs Expert). For controls in accounting €700 to €1,300 (Freelance Financial Controller, Freelance Group Controller). For supplier, contract and evidence work €800 to €1,400 (Freelance Supplier Auditor, Freelance Contract Manager (Procurement), Freelance ESG Reporting Consultant). Leadership responsibility sits above that: a finance responsibility for a period moves between €1,300 and €2,500 (Interim CFO). These are ranges and not a price tag — what applies to a specific assignment is set down in writing before the engagement.
Release in stages rather than as one sum. A project can be cut into four sections, each ending with a decision that is allowed to read „not further“: the assessment, the concept with risk register and control plan, the implementation with the embedding into workflows and systems, and the operation with its cycle and effect testing. Whoever releases everything in one amount loses the points at which the cut could still be corrected cheaply.
The difference from a law firm or an audit mandate lies less in the price than in what you are buying. A law firm assesses the legal position and represents you; an audit firm audits and certifies and, for independence reasons alone, must not build what it later audits. Here you staff a role inside your own line organisation that builds the framework and runs it — the experience stays where the transaction is handled. Costs for certification, external audits, legal review or software licences are not part of the daily rate.
Staffing follows the cut of the assignment: a control framework calls for a different profile than an export control check. The full overview sits under Compliance & Legal — among them GRC consultants and trade compliance specialists. Adjacent profiles are listed by Finance & Controlling for controls in accounting, Purchasing & Procurement for supplier and contract screening, Supply Chain Management for customs and export control, IT Service Management for IT governance and AI & Machine Learning for the governance of AI applications. The complete overview sits under Experts by Area.
The Number of Rulebooks Grows Faster Than the Capacity to Serve Them
1,000
Four States
Two Registers
Frequently Asked Questions About Compliance Consulting
Excellent. We are not the only ones who think so.
consultingheads has received several awards from leading trade magazines and independent third parties.