Compliance, Risk & Corporate Governance
Practical, board-level compliance and risk advisory for companies, funds and international groups operating in Romania and Central & Eastern Europe.
For general counsels, compliance officers, internal audit, local subsidiaries and investors who need a clear, defensible governance setup.
Policies & controls
Codes of conduct, anti-bribery, AML, whistleblowing, data & records — aligned with group requirements.
Why work with our Compliance, Risk & Governance team
We combine regulatory understanding (EU, Romanian, sector-specific) with how companies are actually managed — board, shareholders, audit, internal control, reporting — so that compliance is adopted, not ignored.
Board-level language
We translate legal and compliance requirements into concise notes for boards, audit committees and shareholders.
Risk-based approach
We map risks and controls by materiality and likelihood, not by theory — so you know what to implement first.
Regulatory fit
We align with ANAF, ASF, NIS2, ANSPDCP (GDPR) and sector regulators, including banking and energy operators.
Group & local alignment
We make sure the Romanian entity complies with the group compliance program and local law at the same time.
What we do
A structured, investor-facing set of compliance, risk and governance services that can be shown to the Board, auditors, regulators or potential buyers.
Compliance Programs
Design and implementation of full compliance frameworks that local teams can actually run.
- Compliance gap assessment vs. EU / Romanian law and group policies.
- Code of Conduct, Conflict of Interest, Gifts & Hospitality, Third-party onboarding.
- Whistleblowing setup and investigations procedure.
- Training programs and management reporting.
- Annual compliance plan and KPIs.
Risk & Internal Control
Risk mapping and control design that stands in front of external audit, internal audit and regulators.
- Enterprise risk assessment (strategic, financial, operational, compliance).
- Control matrices for P2P, O2C, inventory, assets, HR & payroll.
- Segregation of duties (SoD) and approval hierarchies.
- Monitoring and reporting to Audit/Risk Committee.
- Integration with internal audit and remediation plans.
Corporate Governance
Set up or refresh the governance framework so that shareholders, boards and management work on the same rules.
- Articles, internal regulations, Board/Audit Committee charters.
- Decision-making workflows and authority matrices.
- Fit & proper requirements, independence, related-party transactions.
- Policies on ESG, sustainability reporting, ethics.
- Alignment with Romanian corporate law and sector rules.
Anti-Bribery, AML & Sanctions
Compliance structures to protect you in public-sector, energy, defense, banking or high-risk jurisdictions.
- ABAC/ABC policies and dealing with public officials.
- AML/KYC procedures for clients, suppliers and partners.
- Sanctions screening and export controls.
- Third-party due diligence templates.
- Incident response and investigation reports.
Data Protection, GDPR & NIS2
Data, privacy and cybersecurity compliance tailored for businesses with EU customers and Romanian operations.
- GDPR gap assessments and RoPA documentation.
- DPIA, data retention and cross-border transfer rules.
- NIS2 readiness for essential / important entities.
- Data breach and incident playbooks.
- Training for HR, sales, procurement and IT.
Investor / M&A Readiness
Prepare your compliance and governance files so that buyers, lenders or DFIs can close faster.
- Compliance DD packs for buyers / lenders.
- Regulatory licenses, filings, authorizations.
- Remediation plans for findings raised in DD.
- Integration plans for post-merger compliance.
- Board and shareholder approvals.
Start a compliance / risk mandate
Tell us what you need: a compliance program for Romania, a risk/control matrix, GDPR/NIS2 alignment, governance refresh or an investor-ready compliance pack.
