Licensing & registration support
Preparation of VASP registration and MiCA/CASP authorisation files — governance arrangements, internal control framework, ICT and security policies, and responses to regulator questions during the review.
COMPANY & SERVICES OVERVIEW
An independent Luxembourg advisory boutique — Fractional CISO, DPO and regulatory compliance for the financial sector.

Formally designated DPO and outsourced CISO roles — senior regulatory presence at a fraction of a full-time hire, reporting directly to your Executive Committee and Board.
GDPR, CSSF circulars and DORA read as one continuous framework. Gap assessments, remediation roadmaps and regulatory correspondence prepared to institutional standard.
Deep familiarity with regulated financial entities — banks and branches, payment and electronic money institutions, and virtual asset service providers (VASPs) navigating Luxembourg's compliance, risk and IT expectations.
PRACTICE AREAS
"Compliance is not a certificate on the wall. It is a posture — sustained, documented, and worthy of examination."
25+ years across IT Governance, Security and Compliance. Lecturer, University of Luxembourg — Master's in IT Security.
MANAGING PARTNER
Twenty-five years across IT Governance, Data Privacy, Information Security and Regulatory Compliance — advising banks, branches and their Head Offices through ISO 27001 and PCI-DSS certification. Lecturer at the University of Luxembourg on the Master's in IT Security, and PECB Certified Trainer. Holds CISM, CRISC, and ISO 27001 Lead Implementer, Lead Auditor and Master credentials.
DIGITAL ASSETS
We advise virtual asset service providers, crypto-asset firms and their banking counterparties on the full regulatory perimeter — VASP registration and MiCA authorisation, AML/CFT for on-chain activity, custody and key management, GDPR on blockchain data, and DORA-grade ICT resilience. The same Fractional CISO and DPO model applies, adapted to the operating reality of a digital-asset business.
Preparation of VASP registration and MiCA/CASP authorisation files — governance arrangements, internal control framework, ICT and security policies, and responses to regulator questions during the review.
Travel Rule implementation, blockchain analytics and wallet screening controls, transaction monitoring calibration for on-chain flows, and source-of-funds/source-of-wealth evidencing for crypto-derived assets.
Review of hot, warm and cold wallet architecture, HSM and MPC key ceremonies, segregation of client assets, signing policies, and recovery and business continuity testing for key material.
GDPR analysis of blockchain and wallet data, DPIAs for analytics and screening tooling, retention and erasure positions on immutable ledgers, and transfer assessments for offshore exchange and custody partners.
DORA readiness for crypto-asset firms — ICT third-party registers for exchanges, custodians and node providers, incident classification and reporting, penetration testing and smart-contract review coordination.
Advising banks and PSPs onboarding VASP clients or launching digital-asset offerings: risk appetite, counterparty due diligence on exchanges, and control expectations aligned with CSSF and EBA guidance.
Engagements range from a targeted licensing or Travel Rule review to an ongoing Fractional CISO or DPO mandate for a regulated digital-asset entity.
WHY THE ADVISORY GROUP
Years of practice
Regulated disciplines
Certifications
CISM · CRISC · ISO 27001 Lead Implementer, Lead Auditor & Master · PECB Certified Trainer
Track record
Guided financial institutions through ISO 27001 and PCI-DSS certification. Hands-on experience advising crypto-asset service providers (VASPs) on GDPR, AML/CFT-adjacent controls and information security. Academic grounding at the University of Luxembourg.
ENGAGEMENT MODEL
REQUEST A CONSULTATION
Share a topic and two preferred windows. The Managing Partner will confirm a slot within one business day.