Technology Solutions
We drive the governance, technology and compliance of your organization
Our leaders
Governance, Risk, Technology and Compliance services to transform organizations. We help strengthen your governance, manage risk, accelerate your technological transformation and meet regulatory and business requirements. We combine expertise in risk, audit, cybersecurity, technology and compliance to design solutions that protect, optimize and enhance our clients' operations.
Our solutions, organized into 4 pillars
21 specialized services across Risk, Technology, Cybersecurity and Compliance
Technology Risk & IT Governance
Description
We provide specialized services to strengthen the management of Operational Risk and Technology and Information Security, joining our clients as a team that contributes experience and specialized knowledge.
What it includes
- Implementation of processes, governance and indicators for Operational Risk and TISI.
- Regulatory compliance and continuous monitoring.
- Integration as a working team that contributes experience and specialized knowledge.
Description
We comprehensively manage the life cycle of critical vendors and third parties, from the initial assessment to the ongoing monitoring of associated risks.
What it includes
- Initial assessment and ongoing monitoring of critical vendors and third parties.
- Implementation of methodologies and controls for vendor management.
- Assurance of regulatory compliance and reduction of risk exposure.
Description
We assess the maturity level of technology, security and risk management processes against regulatory frameworks and international standards.
What it includes
- Assessment of the maturity level of technology, security and risk processes.
- Identification of gaps against regulatory frameworks and international standards.
- Development of prioritized roadmaps for remediation.
Description
We identify and assess technology and information security risks over the organization's critical assets.
What it includes
- Survey and inventory of critical IT and IS assets.
- Identification of threats and vulnerabilities affecting critical assets.
- Analysis of the likelihood and impact of events on the infrastructure.
- Assessment of the maturity level of technology controls.
- Development of an IT and IS risk matrix, including third-party risk.
Frameworks and regulations:ISO 27005NIST SP 800-30
Description
We define and implement IT governance models that align the technology strategy with business objectives.
What it includes
- Definition of governance models and strategic IT and IS KPIs.
- Design of functional structures and responsibility matrices.
- Design of dashboards with performance metrics and indicators.
- Management of regulatory findings.
Frameworks and regulations:COBITITILISO 38500
Description
We run comprehensive Business Impact Analysis (BIA) projects, generating strategic information that makes it possible to set recovery priorities and strengthen continuity programs.
What it includes
- Definition of methodology and tool parameterization.
- Information gathering and analysis of results.
- Identification and assessment of critical IT processes and assets.
- Definition of RTO and RPO.
- Design and implementation of DRP / BCP and incident response plans.
Audit, Compliance & Regulatory
Description
We support organizations throughout the entire process of adapting to regulatory requirements, turning findings into concrete action plans.
What it includes
- Transformation of regulatory findings into concrete action plans.
- Design and implementation of policies, procedures and controls.
- Practical, sustainable documentation aligned with regulators' expectations.
- Alignment with local and international regulatory frameworks.
Frameworks and regulations:BCRA A-7724CNVSOXISO 27001
Description
We assist organizations in the comprehensive management of findings issued by internal and external audits and regulatory bodies.
What it includes
- Comprehensive management of findings from internal audits, external audits and regulators.
- Definition of action plans and support during their implementation.
- Preparation of the evidence supporting the remediation and closure of findings.
Description
We assess the effectiveness of the technology control environment, risk management and compliance with applicable policies, procedures and regulatory requirements.
What it includes
- Review of IT General Controls (ITGC): access, changes, operations, incidents, backup and recovery, continuity, vendors and infrastructure security.
- Assessment of the main IT management and security processes.
- Specific security and control reviews in SAP environments: users, profiles, privileged access and configuration.
- Issuance of reports with findings, risks and recommendations.
Description
We assess the applicable regulations and assist in preparing and reviewing the supporting documentation required for filings before CNV and IGJ.
What it includes
- Assessment of applicable regulations and gap analysis.
- Recommendations on digital recording and retention processes, controls and technology.
- Preparation and review of supporting documentation for filings before CNV and IGJ.
- Validation of the integrity, availability, traceability and retention of documentary evidence.
Description
We perform the annual audit required by the CNV to verify compliance with the conditions and requirements applicable to the different contact channels.
What it includes
- Independent audit and review of IT processes and controls.
- Verification of contact methods for the subscription and redemption of mutual funds (FCI).
- Verification of the methods used to take and receive client orders for ALyC.
Description
We help organizations strengthen their fraud prevention, detection and response capabilities through a comprehensive approach that combines risk management, specialized controls and the review of analytical models.
Our services include
Fraud Risk Strategy & Management
- Identification, assessment and mitigation of fraud risk.
- Design of anti-fraud policies, procedures and controls.
Model Audit & Validation
- Independent assessment of detection and prevention models.
- Review of continuous monitoring mechanisms and early warnings.
Training & Awareness
- Training programs to strengthen a culture of prevention.
- Support in incident investigation and executive reporting.
Regulatory & Legal Support
- Case documentation and preparation of evidence.
- Support during regulatory requirements or legal proceedings.
Cybersecurity & Resilience
Description
We support the implementation and certification process of your Information Security Management System.
What it includes
- Design of ISMS policies, controls and documentation.
- Pre-assessments for ISO 27001:2022 certification.
- Preparation of the organization for certification audits.
Description
We design and implement information security standards, rules and best practices, building security in from the design stage of every project.
What it includes
- Definition of information security standards and best practices.
- Secure development guidelines (SSDLC) built in from the design stage of every project.
Description
We define and strengthen the organization's cybersecurity strategy, with a Virtual CISO service available.
What it includes
- Definition and strengthening of the cybersecurity strategy.
- Virtual CISO service (vCISO).
- Preparation for security audits.
- Cybersecurity assessments and specialized strategy consulting.
Description
We work on the cybersecurity culture and behavioral change within the organization.
What it includes
- Implementation of awareness platforms.
- Management and administration of awareness programs.
- Security training talks and workshops.
- Design of cultural change programs.
Description
We help anticipate, respond to and recover from cybersecurity incidents.
What it includes
- Design of cyber resilience capabilities.
- Incident response planning.
- Crisis simulations and exercises (Tabletop).
- Red Team and controlled attack exercises.
Description
We translate cyber risk into business risk, quantifying the potential financial impact.
What it includes
- Actuarial services for risk estimation.
- Analysis of likelihood and financial impact.
- Definition of continuity and recovery objectives.
- Identification of critical third parties (vendors).
Digital Transformation, Data & AI
Description
We lead IT and IS projects to implement new systems, migrate platforms and develop new technology products.
What it includes
- Leadership and control of IT and IS projects.
- Custom development and integrations.
- Support across the full project life cycle.
- Definition of methodologies and standards.
- Project portfolio management, governance and control.
- Support with our own team.
Description
We support the development of AI strategy and adoption, assessing maturity, risk and governance.
What it includes
- Development of AI strategy and adoption.
- Assessment of maturity in the use of AI.
- Diagnosis and classification of AI risks.
- Development of AI governance frameworks.
- Training in AI governance.
- AI Impact Assessment (EFIA).
Frameworks and regulations:ISO 42001
Description
We design and implement data and analytics solutions to strengthen business decision-making.
What it includes
- Specialized functional analysts.
- Design and implementation of Data Lake and Business Intelligence (BI).




