Governance
When responsibilities and follow-up are unclear, decisions can stall between committees and teams.
Clarify responsibilities, decision information and follow-up so oversight leads to action.
I connect finance, operations, governance, risk and compliance to help leaders see where they want to go, what stands in the way and how to make change work in practice.
For boards and management, and heads of risk, compliance and internal audit seeking practical change with business teams.
Discuss your challengeTeams may be busy producing evidence while processes, emerging risks, financial consequences and ownership remain unclear. I start with the business model and objectives, compare actual ways of working with regulatory expectations and relevant practice, and help decide what to improve, what to monitor and where controls add value.
Choose a focused assignment in one area, or connect the functions around a decision, transformation or regulatory change.
For financial services and fintech, insurers and captives, and industrial groups.
When responsibilities and follow-up are unclear, decisions can stall between committees and teams.
Clarify responsibilities, decision information and follow-up so oversight leads to action.
When reporting, costs and insurance flows are disconnected, management may lack a clear financial picture.
Connect controlling, consolidation and insurance operations to management decisions.
As risk maps and control libraries grow, priorities can become harder to see.
Identify and challenge risk scenarios; assess likelihood and financial, reputational, regulatory and operational impacts; prioritise risk exposures and agree responses. Separately, strengthen internal control design, implementation and effectiveness.
Risk management — four practical stages
Internal control — four delivery stages
These are practical delivery stages, not COSO’s component count. The internal control review draws on COSO’s five components: control environment, risk assessment, control activities, information and communication, and monitoring activities. Management owns risks and controls; risk and compliance provide oversight and challenge, while internal audit provides independent assurance.
When obligations are treated as checklists, their connection to business processes can be lost.
Map obligations to risks, controls, owners and evidence, then test whether they work.
When findings recur, the underlying process may need a closer look.
Perform risk-based operational and finance reviews and turn findings into feasible action.
Risk, compliance and audit need timely evidence as processes and requirements change.
Use approved AI to support mapping, testing and documentation, with professional validation and each line’s independence preserved.
A focused pilot can map applicable regulatory requirements to the internal governance framework—policies, procedures and processes—then review controls, assess evidence and draft completed testing templates and findings. A pilot can connect these steps through AI agents, with reviewer checkpoints. Professionals assess which tasks can be automated and validate every conclusion against evidence.
| Use case | Input | AI assistance | Human validation | Output |
|---|---|---|---|---|
| Regulatory mapping to the internal governance framework | Applicable regulation and supervisory guidance; domain-specific policies, procedures and process documentation; relevant market practices and standards | Map requirements to policies and flag gaps; then assess whether procedures and documented processes reflect the required policy provisions and relevant practices and standards | Confirm applicability and source versions; validate policy coverage and gaps, and the alignment of procedures and processes. Distinguish mandatory requirements from recommended practices | Traceable requirements-to-policy-to-process mapping and a gap register with owners |
| Control review and testing readiness | Risk to be mitigated, control objective and description, testing criteria and expected evidence | Assess whether the objective addresses the risk and whether the description provides clear, testable steps; flag missing owners, frequency or evidence requirements | Validate risk–objective alignment, control wording and testing readiness before proceeding | Reviewed control descriptions and agreed testing requirements |
| AI-assisted control testing | Reviewed control objective and description; evidence collected for design and operating-effectiveness testing; testing templates and criteria | Assess which test steps can be automated; use AI agents to compare evidence with the control requirements and draft completed design and operating-effectiveness templates, citing evidence and flagging gaps | Check evidence relevance and sufficiency, review every template requirement and validate exceptions and conclusions before sign-off | Draft completed testing templates with traceable evidence, exceptions and conclusions for reviewer approval |
| Finding drafting | Test notes | Structure condition, criteria, cause, risk and action | Check accuracy and wording | Findings for discussion with owners |
The pilot uses only an environment authorised by your organisation, such as your enterprise AI tools. Sources remain traceable; professional judgment and the distinct roles of risk, compliance and internal audit guide the conclusions.
A first assignment could examine one important process: map how it actually runs, identify its obligations and material risks, test the relevant controls and agree a short action plan with owners. An assignment may also focus on financial reporting, insurance operations or board and committee effectiveness.
Reference frameworks include AML/CFT and the EU AML package, DORA, CSSF and Commissariat aux Assurances expectations, and the EU AI Act. Applicable requirements and scope are agreed for each assignment.
Review objectives, processes, exposures, existing controls and their cost. Identify gaps, duplication and the decisions that need evidence.
You receive: A process map, obligations and risk register, and prioritised gaps.
Work with owners to redesign the controls that matter, support remediation and make reporting useful to management and committees.
You receive: Revised control descriptions, an action plan with owners and dates, and a management reporting template.
Assess design and operating evidence, track change and pilot AI-assisted monitoring where it reduces manual work responsibly.
You receive: Test results, a findings and follow-up log and, where piloted, a documented AI-assisted method.
These assignments and roles were undertaken in employment; they are presented as Nadine’s experience, not as UMN client work.
For a market-entry or partnership project, I can coordinate an initial feasibility and risk review: map stakeholders, test financial and operational assumptions, identify local constraints and plan execution with relevant contacts.
My network spans Senegal, The Gambia, Benin, Burkina Faso, Côte d’Ivoire, Cameroon, Republic of the Congo, DR Congo, Rwanda, Ethiopia, Uganda, Kenya, Zambia and South Africa. Local partners and scope are agreed for each mandate.
Executive MBA (Vlerick Business School) · Master’s in Finance (IUP Finance) · Master’s in Management & Business Development (INSEEC) · Associate in Risk Management – ARM (The Institutes) · AML/KYC/Compliance certificate (EBU)
An independent advisor with more than 17 years across finance, insurance, regulated services and industry. My work in controlling, operations, second-line risk and compliance, and audit helps me connect strategic objectives to processes, financial impact and workable change. Board and insurance leadership experience informs the decisions I help clients make.
Available for non-executive director and risk, audit or compliance committee mandates, subject to independence and conflict-of-interest considerations.
Languages: English, French and Kinyarwanda (fluent) · Spanish (conversational) · Dutch (elementary)
Tell me the decision, change or control challenge you are facing. We can define a focused first step.