Why Taft

Real regulatory experience, business thinking and technology, applied to find the smarter way through a compliance problem.

Business standards

Applying internal governance, audit logic, and procedural discipline to every engagement.

Each engagement is governed by defined protocols for scope, ownership, documentation, and approval. Work product is not issued without structured validation and audit support.

Operating principles

Principles guiding our compliance approach.

Compliance must be practical, durable, and proportional to managed risks.

  1. Practical

    Programs are built to be run by the people who will run them, at the size of the business that has to run them.

  2. Durable

    Documentation, controls and evidence assembled so they still hold when the person who built them has moved on.

  3. Proportional

    Regulatory expectations met with clarity, consistency and minimal operational disruption; never a bank’s program imposed on a firm that is not one.

A note from our founder

I wanted to bring together the people I would want around me if I had a difficult problem to solve.

I have spent most of my working life in compliance. I have worked in different countries, with different regulators and with very different financial businesses. I have built programs, run compliance functions, sat through examinations, worked through hard regulatory problems, and watched the financial world change enormously along the way.

I started Taft because I wanted the people I would want around me if I had a difficult problem to solve: former regulators, chief compliance officers, lawyers, financial crime specialists, technology experts, and people who have worked inside the businesses we advise. Collectively, that is more years of experience than I like to say out loud.

Our international experience matters to me. Business is global now, regulation overlaps more every year, and what happens in one market shapes decisions in another. We help our clients understand all of that without making compliance more complicated than it needs to be.

I also believe that good compliance should support a good business. Sometimes that means building something substantial. Sometimes there is a simpler and smarter answer. Our job is to know the difference.

Most of all, I want Taft to stay personal. I do not care whether a client is a founder with a first regulatory question or an established company facing a serious problem. If you trust us with it, we treat it as our own. We bring the best people we can find, we tell you what we really think, and we care about getting it right.

That is the firm I wanted to build, and it is the firm I want Taft to remain.

Natalia Taft
Founder

Our experts

Senior people, the right expertise, wherever the problem takes us.

Taft brings together senior professionals who have spent their careers inside regulators, financial institutions, Big Four firms and leading technology and advisory organizations: former regulators, chief compliance officers, legal and financial crime leaders, technology specialists and industry practitioners across the United States and the major international markets. Where an engagement needs local regulatory knowledge, legal expertise, technology or a narrow specialism, we bring in trusted specialist partners and professional networks, so the team fits the assignment without layers of people the client does not need.

Natalia Taft

Founder

Natalia has spent 25 years inside the problems Taft is hired to solve. She helped build the first generation of US BSA/AML programs at Deloitte, EY and FIS Global, advising global investment banks, universal banks and critical market infrastructure providers.

She has held the chair herself: Chief Compliance Officer at Bank Hapoalim New York and at Agricultural Bank of China New York, and US Head of AML at Scotiabank, where she led more than 200 compliance professionals. She has taken Written Agreement remediations at two international banks through to completion.

Most recently she was Global Chief Compliance Officer of an international prime brokerage group, leading a team of 43 across entities supervised by the FCA, MFSA, CySEC and SFC, including digital-asset businesses in Switzerland, Mauritius and El Salvador.

Since founding Taft in 2016 she has led more than 50 engagements, for clients from one of the world’s largest asset managers to leading US and European banks. She is a founding member of ACAMS and holds the Chainalysis CCFC certification.

Representative experience

Ten kinds of problem we have been hired to solve.

Described by the problem rather than the client. Each is an engagement Taft’s people have led, before and since the firm was founded.

  • Regulatory remediation

    From enforcement action to a program that runs itself.

    A major financial institution was operating under formal regulatory action after significant weaknesses in its financial crime and compliance framework. We led remediation across governance, risk assessment, customer due diligence, transaction monitoring, investigations, testing, data and management reporting, working across compliance, operations and technology on root causes rather than individual findings. The remediation requirements were completed, and the institution moved from answering findings to running a framework it could sustain.

  • Global expansion

    Compliance built while the business kept growing.

    A financial services business was expanding quickly across the United Kingdom, the European Union, Asia and the Middle East, adding regulated entities, products and licenses as it went. We built the global compliance operating model and supported market entry, licensing, regulatory engagement, governance and the local frameworks, connecting the entities through common standards while keeping each local requirement intact. The business entered several regulated markets with a framework that scaled with it instead of being rebuilt for every new country.

  • Licensing and regulatory approval

    A business plan into a regulated business.

    Financial services businesses needed new permissions and licenses to launch products or enter markets. We defined the regulatory perimeter, weighed the licensing options, built the frameworks, policies, governance and operating models, prepared the submissions and stood beside management through the regulator’s questions. Licenses and approvals were granted across several jurisdictions and business models, with the infrastructure in place to operate once they were.

  • Examinations and inspections

    The program, and the people behind it.

    Institutions faced examinations and inspections with complex requests, management interviews and detailed testing of their programs. We ran the readiness work: the likely areas of focus, documentation and controls challenged in advance, management and compliance teams prepared for interviews, responses coordinated and communication with the regulator supported throughout. Examinations were completed with management prepared, responses controlled, and issues found and addressed before they grew into larger problems.

  • Compliance technology and automation

    Compliance out of spreadsheets.

    Manual compliance processes were expensive, inconsistent and could not scale with the business. We designed and implemented automated capabilities across onboarding, customer due diligence, sanctions screening, transaction monitoring, surveillance, investigations, regulatory reporting and management information, translating requirements into practical system design between the compliance and technology teams. Operations became more automated and scalable, with stronger control evidence, better data and less reliance on manual work.

  • AML and financial crime transformation

    The program, not just the finding.

    A financial institution had significant weaknesses across its financial crime framework, in people, processes, technology, data and governance. We redesigned the program across risk assessment, customer and enhanced due diligence, transaction monitoring, investigations, suspicious activity reporting, sanctions, testing and governance. The result was an integrated, risk-based framework with clear ownership, stronger controls and a closer fit between the rules and the daily work.

  • Compliance program build

    From a blank page to a function that operates.

    A regulated business needed more than policies. It needed a compliance function that could run. We designed the regulatory framework, governance, risk assessments, policies, procedures, monitoring, testing, reporting, training and escalation, defined roles and responsibilities and embedded the program in the business. The firm got a working program built around its own products, risks and obligations rather than a library of generic policies.

  • Regulatory response

    When the regulator has already found the problem.

    A financial institution faced significant regulatory concerns that needed an immediate response, investigation and remediation. We interpreted the findings, identified the underlying causes, wrote the corrective action plans, set the governance and evidence requirements and managed remediation through implementation and testing. The concerns became concrete actions, the remediation was completed, and the controls were redesigned to reduce the risk of recurrence.

  • Regtech and data

    When the system works but the control does not.

    Financial crime technology was generating ineffective alerts and control failures caused by problems in data, mapping, scenarios and business requirements. We ran root cause analysis from the regulatory requirement through data lineage, mappings, system configuration, scenarios and downstream processes, working between compliance, business and technology. Control performance improved, data integrity strengthened, and every compliance decision could be traced back to the requirement behind it.

  • Fractional compliance leadership

    Senior leadership without building the whole function.

    Growing and transitioning businesses needed experienced compliance leadership but were not ready for a permanent senior hire, or needed specialist expertise beyond the existing team. We provided senior compliance leadership, regulatory judgment, governance, board support, program oversight, examination preparation and specialists as the work required. Clients gained experienced leadership and a broader bench while keeping their flexibility as the business and its obligations changed.

Regulatory coverage

The regimes, standards and frameworks we work in.

Twenty-two areas, from the Securities Act of 1933 to post-quantum cryptography. Type a rule or a regulator to find it.

22 areas

  • US securities and investment management

    Securities Act of 1933, Securities Exchange Act of 1934, Investment Advisers Act of 1940, Investment Company Act of 1940, Rule 206(4)-7, the Marketing Rule, Regulation Best Interest, Regulation SHO, Rules 15c3-1 and 15c3-3, books and records requirements including Rule 17a-4, CAT reporting, SEC and FINRA supervision, communications and conduct requirements.

  • Banking and prudential regulation

    Federal Reserve, OCC and FDIC regulations and guidance, FFIEC frameworks, NYDFS requirements, prudential regulation, safety and soundness, governance and regulatory expectations.

  • US AML and financial crime

    Bank Secrecy Act, Anti-Money Laundering Act, USA PATRIOT Act, FinCEN requirements, FINRA AML requirements, customer due diligence, beneficial ownership, suspicious activity reporting, FATF Standards and the Wolfsberg Principles.

  • European and UK AML

    EU Anti-Money Laundering Regulation, Sixth Anti-Money Laundering Directive, the AMLA framework and supervisory standards, UK Money Laundering Regulations, Proceeds of Crime Act and related financial crime requirements.

  • Fraud and scams

    UK failure to prevent fraud requirements, authorized push payment fraud reimbursement, EU Verification of Payee, US fraud and scam prevention expectations, elder financial exploitation, first-party and third-party fraud frameworks.

  • Sanctions and export controls

    OFAC regulations, US export controls, UK sanctions requirements, European Union sanctions regimes, United Nations sanctions frameworks, global sanctions governance and sanctions evasion risk.

  • Markets, trading and market conduct

    Dodd-Frank, CFTC and NFA requirements, MiFID II, MiFIR, the Market Abuse Regulation, EMIR, market surveillance, market manipulation, insider trading, conflicts of interest and trading conduct.

  • Investment firms and funds

    SEC and FINRA requirements, AIFMD, UCITS, FCA COBS, SYSC and CASS, governance, custody, valuation, investor protection and fund compliance.

  • Payments and fintech

    US money services business and money transmitter requirements, Regulation E, Nacha requirements, UK Payment Services Regulations, Electronic Money Regulations, safeguarding, EU payments frameworks, partner bank compliance and embedded finance.

  • Digital assets

    US digital asset requirements, the GENIUS Act stablecoin framework, the NYDFS BitLicense, the Markets in Crypto-Assets Regulation, the UK cryptoasset regime, FATF Virtual Asset and Travel Rule standards, UAE digital asset and virtual asset frameworks.

  • Consumer protection and fair lending

    CFPB requirements, UDAAP, ECOA and Regulation B, TILA and Regulation Z, FCRA, Regulation E, the FCA Consumer Duty, fair treatment, disclosures, complaints and consumer protection.

  • Governance and individual accountability

    UK Senior Managers and Certification Regime, board and senior management governance, individual accountability, compliance governance, risk ownership, escalation and regulatory reporting.

  • Anti-bribery and corruption

    Foreign Corrupt Practices Act, UK Bribery Act, OECD anti-bribery standards and global anti-corruption frameworks.

  • Privacy and data protection

    GDPR, GLBA, SEC Regulation S-P, US privacy requirements, data governance, confidentiality and information protection.

  • Cybersecurity and operational resilience

    Digital Operational Resilience Act, NYDFS Part 500, US interagency third-party risk management guidance, EBA outsourcing guidelines, cybersecurity governance, operational resilience, business continuity and technology risk.

  • Artificial intelligence and model governance

    EU AI Act, NIST AI Risk Management Framework and its Generative AI Profile, model risk management guidance, AI governance, validation and oversight, responsible AI and regulatory expectations for AI use.

  • Post-quantum readiness

    NIST post-quantum cryptography standards and migration guidance, cryptographic governance, readiness assessment, third-party readiness and migration governance.

  • Examinations, inspections and remediation

    SEC and FINRA examinations, US banking examinations, FCA and international inspections and supervisory reviews, regulatory investigations, enforcement remediation, Written Agreements, corrective action programs and regulatory responses.

  • Licensing and market entry

    SEC and FINRA registrations, investment adviser registration, broker-dealer registration, money services business and money transmitter licensing, banking, payments and digital asset licensing, international market entry and regulatory perimeter analysis.

  • Whistleblowing and investigations

    SEC whistleblower framework, EU Whistleblowing Directive, internal investigations, escalation, retaliation controls, reporting and governance.

  • Tax transparency

    FATCA, the Common Reporting Standard, DAC8, the OECD Crypto-Asset Reporting Framework and international tax transparency requirements.

  • Global regulatory frameworks

    US, UK and EU frameworks, plus experience with SFC Hong Kong, DFSA, ADGM/FSRA, VARA, MFSA, CySEC and other international regulatory regimes.

See our difference in one conversation.