Risk approach

Turning uncertainty into certainty.

Whether something complies depends on how the regulator reads the norm. That is why we work with legal risk: the probability that a threat exploits a legal vulnerability. And that can be measured, prioritised and anticipated.

What Gauss taught us

In 1801, Giuseppe Piazzi discovered Ceres and followed it for some forty days, until it was lost in the glare of the Sun. Many tried to calculate where it would reappear.

Carl Friedrich Gauss succeeded with his method of least squares. Months later, astronomers found Ceres exactly where he had said.

The lesson has stayed with us ever since: mathematics lets us get ahead of a future event with a high degree of certainty. The same holds for a legal event.

40 days of observationlost near the Sunorbit calculated by GaussCeres, in sight again

01

Two paradigms that change everything

01

Technological innovation

Kurzweil’s law of accelerating returns describes exponential technological progress. Organisations that bring it into their DNA evolve with their environment.

02

Scientific method

Every task that can be systematised will end up in the hands of an algorithm. At the same time, we need regulatory frameworks and ethical models built on mathematics.

02

Regulation lives in every layer

Every innovation brings its own order

StatesLaws that protect rights within a territory.
PlatformsTerms and conditions that order the use of each service.
StandardsTechnical protocols that make the internet work.
OrganisationsProcesses, people, services, products and data.
Software and artificial intelligenceCode and models that will be regulated too.

03

How it is calculated

Legal risk = threat × vulnerability × impactComplying, on its own, is a statement of intent. The advanced method uses mathematics, as a fourth dimension, to anticipate.

ThreatThe probability of being inspected or audited for a possible breach. It comes from outside.
VulnerabilityThe organisation’s maturity to mitigate that risk. It lies inside, and it can be worked on.
ImpactWhat the sanction or the contractual penalty would mean for the organisation.
Probability →Impact →
  • Monitor
  • Manage
  • Prioritise

Each obligation finds its place on the map. That way, management starts with what matters most.

04

Two new ways of looking

Risk by design

Regulatory risk is known from the design of every process and activity. Each layer identifies which norm applies to it and what impact a breach would have.

Law by algorithm

Regulation will reach all things, with the code to comply programmed inside. Every device will record evidence, and traceability will be permanent.

05

Compliance by design, step by step

01

Identify

Analyse the applicable regulatory frameworks: laws, regulations, technical norms, standards and contractual relations.

02

Value

Measure threat, vulnerability and impact to know the real state of compliance.

03

Make it objective

Apply methods based on mathematics, machine learning and artificial intelligence.

04

Sustain

Run a compliance programme with periodic cycles of continuous management.

The risk approach is an effective system rooted in compliance obligations, valuing their probability and impact to prioritise their management effectively.

Regulatory risk approach

We stand on the shoulders of giants such as Kelsen, Einstein and Gauss: a law that looks beyond territory, a relativistic view of the norm and a method that predicts and quantifies. The mathematical model is in Legal algorithms.