Compliance & Risk Advisory · Gorey, Co. Wexford
Regulatory rigour
for firms that cannot
afford ambiguity.
Compliave Advisory designs and operates compliance programmes for regulated institutions and growth-stage technology firms. We work as an extension of your second line — measured, evidence-led, audit-ready.
Frameworks covered
5 in practice
- GDPREU General Data Protection Regulation
- ISO/IEC 27001:2022Information Security Management
- SOC 2Type I & Type II readiness
- DORADigital Operational Resilience Act
- NIS2Network & Information Security Directive
Cross-framework mapping minimises duplicate evidence and keeps the control library coherent as obligations evolve.
Compliave Client Portal
Continuous visibility
across your compliance programme.
A supporting capability of the advisory practice — not a product we sell. Clients receive a private workspace where their programme score, framework progress, open actions and evidence repository are reviewed alongside their engagement partner.
- Programme score updated as controls are evidenced
- Framework-level progress against GDPR, ISO 27001, DORA
- Open actions tracked to owner and due date
- Inherent and residual risk roll-up
- Evidence repository with audit-grade retention
Programme score
Target
85 by Q4
Risk summary
2
High
7
Medium
14
Low
Framework progress
Q2 · 2026
- GDPR92%·Maintaining
- ISO 27001:202278%·Stage 2 prep
- DORA54%·Implementing
- SOC 241%·Readiness
- NIS233%·Scoping
1,284
Evidence · artefacts
186
Controls · of 213
47
Next audit · days
Open actions
4 of 11 shown
- Refresh DPIA — payments processor v2K. Doyle23 Jun
- Internal audit A.5 Organisational controlsM. Ryan01 Jul
- Vendor TIA — US sub-processorC. O'Neill08 Jul
- Quarterly access review — productionPlatform15 Jul
Background & philosophy
Founded by practitioners who built and audited the controls others write about.
Compliave Advisory was established in 2026 in Gorey, Co. Wexford. The firm is led by practitioners who have served as in-house Data Protection Officers, Information Security Managers and Big Four assurance leads — work delivered for regulated payments institutions, MiFID firms and EU technology operators.
We do not chase scale. Engagements are partner-led, fixed-fee and limited in concurrency so that every programme receives the same depth of review.
Regulatory philosophy
Compliance is a control discipline, not a documentation exercise. Every artefact must hold up to the question: 'show me how this operates today'.
Operating approach
Programmes are designed against the auditor's evidence requirements first, then reverse-engineered into procedures your team will actually run.
Independence
No software resale, no audit-firm contracts, no referral fees. Our recommendation is the one the client needs — nothing more.
Concurrency cap
The firm operates a deliberate engagement ceiling. We turn down work rather than dilute partner attention.
What we do
Three disciplined engagements,
one operating standard.
— 01
GDPR & data protection
What you receive
An Article 30 register your DPC inspector can read in fifteen minutes, DPIAs aligned to live processing, a vendor due-diligence file with signed DPAs, and a breach runbook tested against real incident scenarios.
Read scope
— 02
ISO 27001 readiness
What you receive
A scoped ISMS, the Statement of Applicability your certification body expects, a risk treatment plan tied to live owners, and Stage 1 / Stage 2 audit liaison through to a recommended-for-certification report.
Read scope
— 03
Ongoing compliance monitoring
What you receive
Quarterly control tests with sampled evidence, a regulatory horizon-scan briefing, an exception log triaged to owner, and a board-grade quarterly pack your audit committee can sign off without rework.
Read scope
Frameworks supported
Five regulatory regimes,
one mapped control library.
Controls are authored once and mapped across frameworks. Evidence is collected against the control, not duplicated against each regime.
01 / 05
GDPR
General Data Protection Regulation
EU · DPC Ireland
99 articles · 173 recitals
02 / 05
ISO 27001
Information Security Management
ISO/IEC · 2022 revision
Annex A · 93 controls
03 / 05
NIS2
Network & Information Security Directive
EU · Member-state transposition
10 essential measures
04 / 05
DORA
Digital Operational Resilience Act
EU · Financial entities
5 pillars · 64 articles
05 / 05
SOC 2
Trust Services Criteria
AICPA · Type I & II
5 TSCs · point-in-time / period
Cross-framework control mapping
- Access control
- Vendor assurance
- Incident response
- Data retention
- GDPR Art. 32
- ISO A.5 / A.8
- NIS2 Art. 21
- DORA Ch. III
- SOC 2 CC6/CC7
Methodology
A four-stage
operating cadence.
Every engagement follows the same disciplined lifecycle. The depth of each stage flexes to the size and regulatory exposure of the firm.
01
02
03
04
01
Diagnose
Structured assessment of current controls, regulatory exposure and operational gaps against the target framework.
02
Design
A prioritised roadmap with control narratives, owners, evidence requirements and a defensible risk-treatment plan.
03
Implement
Hands-on remediation alongside your engineering, legal and operations teams. We write the procedures we hold you to.
04
Sustain
Continuous testing, board-grade reporting and audit liaison. The programme matures rather than decays.
Evidence workflow
Every artefact, traceable
from system to auditor.
Captured
Artefacts ingested from systems of record — IdP, ticketing, change pipelines.
Linked
Mapped to control IDs across GDPR, ISO 27001, DORA and SOC 2 simultaneously.
Tested
Sampled by the engagement partner each quarter; exceptions logged with owner.
Attested
Frozen, retained and packaged into the audit-ready evidence file.
Ireland · European Union
Based in Gorey, Co. Wexford.
Serving organisations across Ireland and the EU.
The practice operates from Co. Wexford and engages with clients across Dublin, Cork, Limerick and the wider EU. Engagements are delivered on-site where the programme requires it and remotely where it does not.
Office
Gorey, Wexford
Primary regulator
DPC · CBI
Languages
English · Gaeilge
Coverage
IE · EU/EEA
Engagement enquiries
