A rapidly growing electronic money and wealth management firm recognised the need to strengthen its enterprise risk function in response to evolving regulatory and market expectations.
To support this evolution, the firm partnered with Thistle Initiatives to enhance its risk management capability through a Risk Management as a Service (RMaaS) model. Our expert team stepped in as an outsourced Chief Risk Officer (CRO), guiding the firm through a comprehensive transformation of its risk governance framework.
Several key challenges were identified and addressed:
Thistle Initiatives delivered a multi-faceted RMaaS solution tailored to the firm’s structure, scale, and ambitions:
The engagement delivered measurable improvements across the risk function:
Lorraine leads a team delivering complex projects for a diverse range of payment service providers (PSPs) and electronic money institutions (EMIs).
She is a seasoned regulatory compliance professional with a strong background across both industry and consultancy. Her expertise spans compliance frameworks, systems and controls, monitoring programmes, conduct risk, and organisational culture. Lorraine has successfully supported many firms through the FCA authorisation process, offering practical, hands-on guidance throughout.
A certified GDPR Practitioner, she also brings deep experience in data protection and privacy compliance. Lorraine’s consulting work covers start-ups to listed entities, with a proven ability to turn complex regulatory challenges into practical, commercial solutions. Her portfolio includes governance and culture initiatives, risk management frameworks, safeguarding assessments, due diligence reviews, and Skilled Person (s166) engagements.
Part of our wider Risk and Resilience offering, RMaaS is a dynamic, scalable solution designed to empower firms with outsourced expert risk management resource, avoiding the costs associated with in-house teams. RMaaS offers a flexible approach to identifying, assessing, mitigating, and monitoring risks, ensuring businesses stay compliant, resilient, and well-prepared to navigate the ever-changing regulatory landscape.