HOW WE WORK

Three pieces of work that only hold up together.

Technology is the right foundation for everything your firm does. Compliance is the regulatory and ethical framework your firm is required to have. Automation means less repetition, and more time for the work that matters. We do all three, and we govern AI across every one of them.

What each part does.

Technology

The right foundation for everything your firm does.

We configure and manage your Microsoft 365 tenant: licensing, identity and access, device registration and policy, data protection, retention and backup. Every device that touches firm data, firm-owned or personal, is registered and covered by policy before it gets access. Tenant-level changes are scoped and change-controlled, so the controls your compliance depends on don't quietly drift.

Cybersecurity baseline  →
Compliance

The regulatory and ethical framework your firm is required to have.

AML/CTF, privacy and data breaches, cybersecurity and staff AI use. We map the obligations that typically apply to a firm like yours, put the program and controls in place, and set up how each one is evidenced, so when an insurer, auditor or regulator asks, the record is there.

Compliance  →
Automation

Less repetition. More time for the work that matters.

Customer due diligence, risk assessments, registers and reminders run as part of the matter, not as a separate job. Once that foundation is in place, the same automation goes to work on fee-earning matters.

AI and automation  →

Take one away and the other two stop working.

A policy without configured systems is a document. Configured systems without evidence capture can't prove anything. Automation without compliance underneath it just moves risk faster. That's why we hold all three, and why the gaps between three separate providers are where most firms' risk sits.

Technology, compliance and automation depend on each other, with AI governance running across all three. Technology Compliance Automation AI governance Technology, compliance and automation depend on each other, with AI governance running across all three. Technology Compliance Automation AI governance

AI governance isn't a fourth pillar.

It's how we check every engagement: which AI tools are in use, what data they can reach, what your policy says, and whether supervision is recorded. In the technology, that means setting what AI tools can reach inside your tenant. In compliance, it means a staff AI use policy and the records that show it's followed. In automation, AI-assisted steps run inside defined limits, with a person reviewing the result.

Staff AI use  →Take the free AI Audit  →

We hold the tenant. Your IT provider keeps the hands-on work.

We provision your Microsoft licences and manage your tenant: configuration, security policy and every tenant-level change. Your local IT provider keeps doing day-to-day support, on-site help and the equipment we don't supply, working to a scope we agree with them. Ongoing security monitoring is a condition of our engagement, and it can sit with the same provider. If you don't have an IT provider, we'll introduce you to one we work with.

We supply the devices your team works on, so they arrive registered, configured and covered by policy. Your firm owns them.

Most firms already pay for Microsoft 365 features they haven't switched on. Depending on what we find, some firms need a higher Microsoft 365 plan to turn on the security and compliance features their obligations require. We tell you before any work starts.

One obligation at a time, fixed scope, fixed fee.

  1. Start with what's pressing. Most firms come in through one obligation: the AML Health Check, the free AI Audit or a cybersecurity baseline review.
  2. Scope and fee, before anything starts. You get a written scope and a fixed fee. Nothing proceeds until you've confirmed it.
  3. We build in your systems. The work is done in your own Microsoft 365 and connected to the practice management system you already use.
  4. Handover to your process owner. Each piece of work is handed to the person in your firm who owns it, with documentation. You also get an exit pack on day one, with what you need to keep running if we're not there.
  5. Changes are change-controlled. After go-live, adds, moves and changes are scoped, agreed and recorded, so the configuration your evidence depends on doesn't drift.

For firms that want the whole picture.

Practice Resilience® is our structured program for firms that want to work through technology, compliance and AI governance in order, rather than one problem at a time. It runs in four stages: Diagnostic, Foundation, Transformation and AI Implementation. Most firms don't start at stage one, and you don't have to complete all four.

About Practice Resilience®  →

Frequently asked questions

  • No. Most firms start with one obligation. Technology and automation come into it only as far as that obligation needs them, and we tell you where that is before any work starts.

  • No. We manage your Microsoft 365 tenant and its security configuration. Your IT provider keeps the hands-on, day-to-day support. If you don't have one, we'll introduce you to one we work with.

  • In your own Microsoft 365 tenant, with your core Microsoft 365 data stored in Australia. The workflows and records we build sit there too.

  • Yes. We work with every practice management system, so your team keeps working where it works now.

  • As part of every engagement. We find out which AI tools are in use, set what they can reach, put a staff AI use policy in place and keep the record that shows AI-assisted work is reviewed.

Start with the obligation that's pressing.

Fixed scope, fixed fee, and a clear view of where you stand.