The six platforms in this portfolio are presented here as case studies in regulatory judgement, not as products. Each one follows the same arc: a compliance failure mode a regulated business actually faces → the control I designed for it → the legal and regulatory reasoning behind that control → the working software that proves the reasoning holds. The law leads; the build is the evidence.
These are specialisms of one person, not separate profiles — the CV sets out the career in outline, and what follows is the detail underneath it.
Honesty first. All six systems are my own builds and run live in the portfolio, entirely client-side. Private-party data is synthetic throughout, or a dated, frozen dataset in Meridian’s case; Frontier and Sentinel are decision-support, not legal advice; the applied methods papers are preprints — submitted and pending peer review. Nothing on these pages is a client result, and no real subject data appears anywhere.
Case study 01 · Financial-crime forensics
FRIS Forensic & Regulatory Intelligence Suite
Sanctions and AML regimes attach to named parties — value hides in third parties. A 23-engine forensic workbench for beneficial-ownership tracing, sanctions & adverse-media screening and deterministic peel-chain analysis, exact to the last unit.
Horizon-scanning tells you a rule changed; the board asks whether it hits us and how hard. A provenance-first intelligence platform where every figure carries its source, timestamp and confidence class — and gaps are shown, never invented.
A forecast you cannot defend is a risk, not a plan. A dependency-free forecasting engine that shows its error before its forecast — models chosen by back-tested performance on rolling origins, never by fashion.
Regulatory programmes miss statutory dates on sequencing and capacity, not intent. A scheduling engine that turns a written brief into a live programme — log a delay and every view re-plans, keeping the record of why.
Is this cross-border transfer lawful — and can you prove it? Three regimes in one rules engine (EU GDPR Chapter V, Swiss FADP, UK GDPR), a Schrems II-style transfer impact assessment, and an audit-ready exportable record.
GDPR Ch. V · FADP · UKSchrems II TIAAdequacy · SCCs · derogations
Two bodies of law, almost never assessed together: lawful to build and use (EU AI Act) and lawful to move (dual-use export controls). Sentinel answers both in one deterministic pass, with an audit-ready control record.
EU AI Act · Annex IIIDual-use 2021/821Wassenaar Cat 3/4/5Human control · logging