Bylaw | Evidence — my weekly field notes on the risks companies face and how to prove they’re handled
What I do

Understand your risk. Then prove it’s handled.

There are two jobs most companies hire separately: insuring the business against what could go wrong, and governing the whole company so its rules become provable controls, checked live across your systems and on-site. Insurance transfers the risk you can’t prevent; governance mitigates the rest. Mitigate, retain, transfer, prove — one discipline, worked as one job. I write about how the two fit together — and where a company your size is usually exposed.

Insured and protected — for far less than it costs to staff it.

Big companies hire separate teams for risk, insurance, and compliance. I do all three with the Bylaw method: audit the whole business, place the right coverage against the real risk, and protect it by governing every department — checked live across your systems and on-site. One expert, one continuous record, a lower total cost of risk.

Choose your depth. Keep your data. Start where you stand.

Whichever level you choose, three things never change: I work from your rules — every governing document your company has, from compliance policies to brand guidelines to CRM sales flows to HR handbooks — across the systems you already run; I collect evidence, never your underlying data; and I never change your workflows. Every level includes insurance placement where risk is identified. I meet you where you operate today and make it insured and provable for tomorrow.

01Audit it

See where you’re exposed.

I examine the whole business — your risk, your coverage, and how provable your rules are across compliance, brand, sales, HR, and ops — reconcile every governing document, and give you one clear picture of where you’re exposed. The foundation everything else is built on.

Explore depth 01 →

02Insure & protect it

Transfer the risk. Prevent the rest.

The right commercial coverage is placed for your real exposure; governance handles where you operate — your rules become live, checkable controls, and I collect continuous evidence across your systems and on-site. This is where most engagements live.

Explore depth 02 →

Each level contains the one before it.

01 / audit it

Clarity you can act on.

Risk identified, coverage reviewed, every governing document read and reconciled. You leave with one clear picture of your exposure — and a foundation your team can actually build on, whether or not I ever connect a system.

02 / insure & protect it

Everything in 01, insured and kept proven.

The right coverage is placed and the identified controls become live, checkable ones — the record runs continuously across your systems and on-site. Audit requests become a pull of the record, not a project.

03 / run it with me

Everything in 02, run day to day.

I run the function: coverage management, risk reviews, framework tracking, auditor coordination, vendor reviews, questionnaire responses. Your team gets its quarters back.

Built for companies carrying real risk — and real rules.

My clients are growing companies that carry risk across every department and face real compliance obligations — and refuse to either stay underinsured or hand a vendor their data to fix it. Too lean to staff a risk office; too serious to leave it to chance.

  • Coverage gaps, unproven controls, or a compliance framework — SOC 2, ISO 27001, HIPAA, GDPR, or the EU AI Act — is in scope. Or a merger, an expansion, or a new enterprise deal is.
  • Enterprise customers are sending longer questionnaires every quarter — and expecting proof, not promises.
  • The team is small, senior, and tired of assembling proof by hand — or finding out coverage was wrong after a claim.