Started on the trading floor. Moved into compliance — not because I had to, but because I saw where it goes wrong when you follow rules without understanding the market.
Compliance simply means that your business demonstrably follows the rules that apply to you. No more, no less. The problem is that nobody tells you which rules those are. A staffing agency faces different laws than an IT company or a mortgage adviser. Some rules apply to everyone, others only above a certain turnover or with certain clients.
That is why you suddenly hear about it everywhere: on LinkedIn, from your bank, from your accountant. The rules are getting stricter and regulators are inspecting more often, including smaller businesses. Those who have not sorted it out find out at the worst possible moment: during an inspection, an incident, or when a major client demands guarantees.
The good news: for most SMEs, compliance is perfectly manageable, as long as you know where to start. Further down this page you will find our free scans, which show you in five minutes which obligations apply to your business and where you are exposed today.
Go to the free scans ↓No intake, no strings attached. Our online scans give you an immediate, professional picture of your obligations and risks — using the same analytical framework we apply in client engagements.
Not every law applies to every business. Find out which obligations apply to your company — from AML and GDPR to NIS2 — and where you are exposed today.
Start the QuickscanEleven focused questions on incident response, NIS2 readiness and security basics. See how your organisation scores per domain and what the first logical step is.
Start the Cyber Risk ScanYour answers are only used for your results. Prefer an on-site deep dive including a report? See the NIS2 Quickscan under Services.
Does the Dutch Cybersecurity Act apply to you? Half a day of analysis gives you a direct answer and a concrete list of priorities.
From a dedicated compliance partner for SMEs to senior interim assignments at major financial institutions — and everything in between.
Your dedicated compliance partner on a retainer basis. Just as you have an accountant or lawyer — always available, always up to date, without the cost of a full-time hire.
Temporary but fully embedded. We step into the role, work alongside your team and keep things running — without months of searching for a permanent candidate.
Compliance only works when people understand and feel it. We deliver tailored training — from AML awareness and integrity to NIS2 and the AI Act.
For organisations that simply want compliance taken care of.
Your compliance fully managed — without you having to think about it every day.
For organisations with a licence, supervisory contact or more complex regulatory obligations.
As a business owner, you should not have to submit the same UBO information every time a bank, notary or other institution requests it. UBOSafe solves that.
You enter your UBO data once and store it securely in your personal compliance vault. You then give — and only you give — permission to a bank, notary or other trusted institution to access that data. You always see who has viewed it and when. And the data is kept up to date so you never fall behind again.
Less hassle. More control. Always compliant.
📧 info@ubosafe.nl — find out more or request early accessNo standard intake forms or weeks of onboarding. We get up to speed quickly and start with what matters.
Where do you stand? Which regulations apply, what is already in place and where are the gaps. No assumptions — just an honest look at what is there.
Not everything at once. Based on the assessment we determine together what carries the most risk. That becomes the roadmap.
Getting the basics right — procedures, registers, policy documents. No more than necessary, but complete and verifiable.
Policy only works when people know it. Training staff on what it means for their day-to-day work.
Compliance is not a one-off project. Periodic checks, tracking regulatory changes and reporting to management.
Always prepared when the supervisor comes calling — no panic, but a file that demonstrates you are in control.
Some sectors know they need compliance. Others have not yet realised it. We know both.
Wtp transition, MiFID II, fiduciary management, SFTR. Deep knowledge of the regulatory pressure on asset managers and pension funds.
Thousands of small AFM-licensed firms. Tightened supervisory guidelines raise the bar directly. No budget for an in-house CO.
High regulatory pressure, limited internal compliance capacity. DNB/AFM supervision from day one. DORA and MiCA hit them directly.
Classified directly under NIS2 as essential entities. Smaller IT firms are impacted through supply chain responsibility.
From 1 January 2027, you may only supply temporary staff with an authorisation under the Wtta. It is that simple. The registration window for the transitional scheme runs from 1 November to 31 December 2026, and it requires an SNA certificate. Obtaining that certification takes months, so anyone who has not started yet is already behind. On top of that, staffing agencies are required to screen their clients for money-laundering risks — something many agencies only discover when the first questions arrive.
Notary offices are subject to Wwft and in daily contact with SME clients. Client due diligence, integrity policy and GDPR are structural obligations.
One wrong client and you are in the middle of a sanctions investigation. International buyers, opaque ownership structures and payments routed through multiple countries: exactly the profile that banks and regulators flag. Dutch shipyards and yacht builders are global players, but that makes the question "who is my client, really?" anything but a formality. We make sure you can prove the answer before anyone asks.
Started on the trading floor. Then moved into compliance — not because I had to, but because I saw where it goes wrong when you follow rules without understanding how markets actually work.
"Compliance only works when the business understands it too. Our role is to make that translation."
Current developments in compliance, regulation and supervision.
The Dutch implementation of NIS2 — the Cybersecurity Act — is expected to come into force this year. Organisations in critical sectors are well advised to start preparing now.
From 2 August 2026, general obligations apply to organisations that purchase and use AI systems. This affects virtually every SME using tools such as ChatGPT or AI-driven software.
Staffing and recruitment agencies can register for the Wtta transitional scheme from 1 November to 31 December 2026; this requires an SNA certificate, and certification takes months. The act enters into force on 1 January 2027, with enforcement by the Labour Inspectorate from 1 January 2028.
CompliAdvice is structured like a good law firm: senior professionals carry out the work, and the partner personally reviews every file. New team members are trained in-house and work under direct supervision. That keeps turnaround times short and quality consistent, and you always know who bears final responsibility.
Three anonymised examples of recent engagements.
The global market conduct and sanctions programme was redesigned from the ground up. Screening and monitoring models for sanctions lists, embargoes and export controls were designed and integrated into trading platforms. MiFID II, EMIR, SFTR and sanctions legislation were translated into workable procedures for trading and control teams across EU, UK, US and other jurisdictions.
EMIR, SFTR and MiFID II reporting frameworks implemented. End-to-end controls and validation logic designed for complex financial transactions, resulting in improved documentation quality and regulatory traceability.
The onboarding process was redesigned including data models and workflows. Lead times were reduced and data quality structurally improved through process analysis and translation of compliance requirements into IT specifications.
Fill in the form and we will be in touch within one working day.
We will be in touch within one working day.