Compliance & Risk Advisory · Gorey, Co. Wexford

Regulatory rigour
for firms that cannot
afford ambiguity.

Compliave Advisory designs and operates compliance programmes for regulated institutions and growth-stage technology firms. We work as an extension of your second line — measured, evidence-led, audit-ready.

Frameworks covered

5 in practice

  • GDPREU General Data Protection Regulation
  • ISO/IEC 27001:2022Information Security Management
  • SOC 2Type I & Type II readiness
  • DORADigital Operational Resilience Act
  • NIS2Network & Information Security Directive

Cross-framework mapping minimises duplicate evidence and keeps the control library coherent as obligations evolve.

Compliave Client Portal

Continuous visibility
across your compliance programme.

A supporting capability of the advisory practice — not a product we sell. Clients receive a private workspace where their programme score, framework progress, open actions and evidence repository are reviewed alongside their engagement partner.

  • Programme score updated as controls are evidenced
  • Framework-level progress against GDPR, ISO 27001, DORA
  • Open actions tracked to owner and due date
  • Inherent and residual risk roll-up
  • Evidence repository with audit-grade retention
portal.compliave.com / programme
Live

Programme score

72+4 this quarter

Target

85 by Q4

Risk summary

  • 2

    High

  • 7

    Medium

  • 14

    Low

Framework progress

Q2 · 2026

  • GDPR92%·Maintaining
  • ISO 27001:202278%·Stage 2 prep
  • DORA54%·Implementing
  • SOC 241%·Readiness
  • NIS233%·Scoping

1,284

Evidence · artefacts

186

Controls · of 213

47

Next audit · days

Open actions

4 of 11 shown

  • Refresh DPIA — payments processor v2K. Doyle23 Jun
  • Internal audit A.5 Organisational controlsM. Ryan01 Jul
  • Vendor TIA — US sub-processorC. O'Neill08 Jul
  • Quarterly access review — productionPlatform15 Jul

Background & philosophy

Founded by practitioners who built and audited the controls others write about.

Compliave Advisory was established in 2026 in Gorey, Co. Wexford. The firm is led by practitioners who have served as in-house Data Protection Officers, Information Security Managers and Big Four assurance leads — work delivered for regulated payments institutions, MiFID firms and EU technology operators.

We do not chase scale. Engagements are partner-led, fixed-fee and limited in concurrency so that every programme receives the same depth of review.

  • Regulatory philosophy

    Compliance is a control discipline, not a documentation exercise. Every artefact must hold up to the question: 'show me how this operates today'.

  • Operating approach

    Programmes are designed against the auditor's evidence requirements first, then reverse-engineered into procedures your team will actually run.

  • Independence

    No software resale, no audit-firm contracts, no referral fees. Our recommendation is the one the client needs — nothing more.

  • Concurrency cap

    The firm operates a deliberate engagement ceiling. We turn down work rather than dilute partner attention.

Frameworks supported

Five regulatory regimes,
one mapped control library.

Controls are authored once and mapped across frameworks. Evidence is collected against the control, not duplicated against each regime.

01 / 05

GDPR

General Data Protection Regulation

EU · DPC Ireland

99 articles · 173 recitals

02 / 05

ISO 27001

Information Security Management

ISO/IEC · 2022 revision

Annex A · 93 controls

03 / 05

NIS2

Network & Information Security Directive

EU · Member-state transposition

10 essential measures

04 / 05

DORA

Digital Operational Resilience Act

EU · Financial entities

5 pillars · 64 articles

05 / 05

SOC 2

Trust Services Criteria

AICPA · Type I & II

5 TSCs · point-in-time / period

Cross-framework control mapping

  • Access control
  • Vendor assurance
  • Incident response
  • Data retention
  • GDPR Art. 32
  • ISO A.5 / A.8
  • NIS2 Art. 21
  • DORA Ch. III
  • SOC 2 CC6/CC7

Methodology

A four-stage
operating cadence.

Every engagement follows the same disciplined lifecycle. The depth of each stage flexes to the size and regulatory exposure of the firm.

01

Diagnose

Structured assessment of current controls, regulatory exposure and operational gaps against the target framework.

02

Design

A prioritised roadmap with control narratives, owners, evidence requirements and a defensible risk-treatment plan.

03

Implement

Hands-on remediation alongside your engineering, legal and operations teams. We write the procedures we hold you to.

04

Sustain

Continuous testing, board-grade reporting and audit liaison. The programme matures rather than decays.

Evidence workflow

Every artefact, traceable
from system to auditor.

Stage 01

Captured

Artefacts ingested from systems of record — IdP, ticketing, change pipelines.

Stage 02

Linked

Mapped to control IDs across GDPR, ISO 27001, DORA and SOC 2 simultaneously.

Stage 03

Tested

Sampled by the engagement partner each quarter; exceptions logged with owner.

Stage 04

Attested

Frozen, retained and packaged into the audit-ready evidence file.

Ireland · European Union

Based in Gorey, Co. Wexford.
Serving organisations across Ireland and the EU.

The practice operates from Co. Wexford and engages with clients across Dublin, Cork, Limerick and the wider EU. Engagements are delivered on-site where the programme requires it and remotely where it does not.

  • Office

    Gorey, Wexford

  • Primary regulator

    DPC · CBI

  • Languages

    English · Gaeilge

  • Coverage

    IE · EU/EEA

Engagement enquiries

Bring us a regulatory deadline, a board concern, or a control you cannot evidence.