Why Taft
Real regulatory experience, business thinking and technology, applied to find the smarter way through a compliance problem.

Business standards
Applying internal governance, audit logic, and procedural discipline to every engagement.
Each engagement is governed by defined protocols for scope, ownership, documentation, and approval. Work product is not issued without structured validation and audit support.
Operating principles
Principles guiding our compliance approach.
Compliance must be practical, durable, and proportional to managed risks.
Practical
Programs are built to be run by the people who will run them, at the size of the business that has to run them.
Durable
Documentation, controls and evidence assembled so they still hold when the person who built them has moved on.
Proportional
Regulatory expectations met with clarity, consistency and minimal operational disruption; never a bank’s program imposed on a firm that is not one.
A note from our founder
I wanted to bring together the people I would want around me if I had a difficult problem to solve.
I have spent most of my working life in compliance. I have worked in different countries, with different regulators and with very different financial businesses. I have built programs, run compliance functions, sat through examinations, worked through hard regulatory problems, and watched the financial world change enormously along the way.
I started Taft because I wanted the people I would want around me if I had a difficult problem to solve: former regulators, chief compliance officers, lawyers, financial crime specialists, technology experts, and people who have worked inside the businesses we advise. Collectively, that is more years of experience than I like to say out loud.
Our international experience matters to me. Business is global now, regulation overlaps more every year, and what happens in one market shapes decisions in another. We help our clients understand all of that without making compliance more complicated than it needs to be.
I also believe that good compliance should support a good business. Sometimes that means building something substantial. Sometimes there is a simpler and smarter answer. Our job is to know the difference.
Most of all, I want Taft to stay personal. I do not care whether a client is a founder with a first regulatory question or an established company facing a serious problem. If you trust us with it, we treat it as our own. We bring the best people we can find, we tell you what we really think, and we care about getting it right.
That is the firm I wanted to build, and it is the firm I want Taft to remain.
Natalia Taft
Founder
Our experts
Senior people, the right expertise, wherever the problem takes us.
Taft brings together senior professionals who have spent their careers inside regulators, financial institutions, Big Four firms and leading technology and advisory organizations: former regulators, chief compliance officers, legal and financial crime leaders, technology specialists and industry practitioners across the United States and the major international markets. Where an engagement needs local regulatory knowledge, legal expertise, technology or a narrow specialism, we bring in trusted specialist partners and professional networks, so the team fits the assignment without layers of people the client does not need.
Natalia Taft
Founder
Natalia has spent 25 years inside the problems Taft is hired to solve. She helped build the first generation of US BSA/AML programs at Deloitte, EY and FIS Global, advising global investment banks, universal banks and critical market infrastructure providers.
She has held the chair herself: Chief Compliance Officer at Bank Hapoalim New York and at Agricultural Bank of China New York, and US Head of AML at Scotiabank, where she led more than 200 compliance professionals. She has taken Written Agreement remediations at two international banks through to completion.
Most recently she was Global Chief Compliance Officer of an international prime brokerage group, leading a team of 43 across entities supervised by the FCA, MFSA, CySEC and SFC, including digital-asset businesses in Switzerland, Mauritius and El Salvador.
Since founding Taft in 2016 she has led more than 50 engagements, for clients from one of the world’s largest asset managers to leading US and European banks. She is a founding member of ACAMS and holds the Chainalysis CCFC certification.
Representative experience
Ten kinds of problem we have been hired to solve.
Described by the problem rather than the client. Each is an engagement Taft’s people have led, before and since the firm was founded.
Regulatory remediation
From enforcement action to a program that runs itself.
A major financial institution was operating under formal regulatory action after significant weaknesses in its financial crime and compliance framework. We led remediation across governance, risk assessment, customer due diligence, transaction monitoring, investigations, testing, data and management reporting, working across compliance, operations and technology on root causes rather than individual findings. The remediation requirements were completed, and the institution moved from answering findings to running a framework it could sustain.
Global expansion
Compliance built while the business kept growing.
A financial services business was expanding quickly across the United Kingdom, the European Union, Asia and the Middle East, adding regulated entities, products and licenses as it went. We built the global compliance operating model and supported market entry, licensing, regulatory engagement, governance and the local frameworks, connecting the entities through common standards while keeping each local requirement intact. The business entered several regulated markets with a framework that scaled with it instead of being rebuilt for every new country.
Licensing and regulatory approval
A business plan into a regulated business.
Financial services businesses needed new permissions and licenses to launch products or enter markets. We defined the regulatory perimeter, weighed the licensing options, built the frameworks, policies, governance and operating models, prepared the submissions and stood beside management through the regulator’s questions. Licenses and approvals were granted across several jurisdictions and business models, with the infrastructure in place to operate once they were.
Examinations and inspections
The program, and the people behind it.
Institutions faced examinations and inspections with complex requests, management interviews and detailed testing of their programs. We ran the readiness work: the likely areas of focus, documentation and controls challenged in advance, management and compliance teams prepared for interviews, responses coordinated and communication with the regulator supported throughout. Examinations were completed with management prepared, responses controlled, and issues found and addressed before they grew into larger problems.
Compliance technology and automation
Compliance out of spreadsheets.
Manual compliance processes were expensive, inconsistent and could not scale with the business. We designed and implemented automated capabilities across onboarding, customer due diligence, sanctions screening, transaction monitoring, surveillance, investigations, regulatory reporting and management information, translating requirements into practical system design between the compliance and technology teams. Operations became more automated and scalable, with stronger control evidence, better data and less reliance on manual work.
AML and financial crime transformation
The program, not just the finding.
A financial institution had significant weaknesses across its financial crime framework, in people, processes, technology, data and governance. We redesigned the program across risk assessment, customer and enhanced due diligence, transaction monitoring, investigations, suspicious activity reporting, sanctions, testing and governance. The result was an integrated, risk-based framework with clear ownership, stronger controls and a closer fit between the rules and the daily work.
Compliance program build
From a blank page to a function that operates.
A regulated business needed more than policies. It needed a compliance function that could run. We designed the regulatory framework, governance, risk assessments, policies, procedures, monitoring, testing, reporting, training and escalation, defined roles and responsibilities and embedded the program in the business. The firm got a working program built around its own products, risks and obligations rather than a library of generic policies.
Regulatory response
When the regulator has already found the problem.
A financial institution faced significant regulatory concerns that needed an immediate response, investigation and remediation. We interpreted the findings, identified the underlying causes, wrote the corrective action plans, set the governance and evidence requirements and managed remediation through implementation and testing. The concerns became concrete actions, the remediation was completed, and the controls were redesigned to reduce the risk of recurrence.
Regtech and data
When the system works but the control does not.
Financial crime technology was generating ineffective alerts and control failures caused by problems in data, mapping, scenarios and business requirements. We ran root cause analysis from the regulatory requirement through data lineage, mappings, system configuration, scenarios and downstream processes, working between compliance, business and technology. Control performance improved, data integrity strengthened, and every compliance decision could be traced back to the requirement behind it.
Fractional compliance leadership
Senior leadership without building the whole function.
Growing and transitioning businesses needed experienced compliance leadership but were not ready for a permanent senior hire, or needed specialist expertise beyond the existing team. We provided senior compliance leadership, regulatory judgment, governance, board support, program oversight, examination preparation and specialists as the work required. Clients gained experienced leadership and a broader bench while keeping their flexibility as the business and its obligations changed.
Regulatory coverage
The regimes, standards and frameworks we work in.
Twenty-two areas, from the Securities Act of 1933 to post-quantum cryptography. Type a rule or a regulator to find it.
22 areas
US securities and investment management
Securities Act of 1933, Securities Exchange Act of 1934, Investment Advisers Act of 1940, Investment Company Act of 1940, Rule 206(4)-7, the Marketing Rule, Regulation Best Interest, Regulation SHO, Rules 15c3-1 and 15c3-3, books and records requirements including Rule 17a-4, CAT reporting, SEC and FINRA supervision, communications and conduct requirements.
Banking and prudential regulation
Federal Reserve, OCC and FDIC regulations and guidance, FFIEC frameworks, NYDFS requirements, prudential regulation, safety and soundness, governance and regulatory expectations.
US AML and financial crime
Bank Secrecy Act, Anti-Money Laundering Act, USA PATRIOT Act, FinCEN requirements, FINRA AML requirements, customer due diligence, beneficial ownership, suspicious activity reporting, FATF Standards and the Wolfsberg Principles.
European and UK AML
EU Anti-Money Laundering Regulation, Sixth Anti-Money Laundering Directive, the AMLA framework and supervisory standards, UK Money Laundering Regulations, Proceeds of Crime Act and related financial crime requirements.
Fraud and scams
UK failure to prevent fraud requirements, authorized push payment fraud reimbursement, EU Verification of Payee, US fraud and scam prevention expectations, elder financial exploitation, first-party and third-party fraud frameworks.
Sanctions and export controls
OFAC regulations, US export controls, UK sanctions requirements, European Union sanctions regimes, United Nations sanctions frameworks, global sanctions governance and sanctions evasion risk.
Markets, trading and market conduct
Dodd-Frank, CFTC and NFA requirements, MiFID II, MiFIR, the Market Abuse Regulation, EMIR, market surveillance, market manipulation, insider trading, conflicts of interest and trading conduct.
Investment firms and funds
SEC and FINRA requirements, AIFMD, UCITS, FCA COBS, SYSC and CASS, governance, custody, valuation, investor protection and fund compliance.
Payments and fintech
US money services business and money transmitter requirements, Regulation E, Nacha requirements, UK Payment Services Regulations, Electronic Money Regulations, safeguarding, EU payments frameworks, partner bank compliance and embedded finance.
Digital assets
US digital asset requirements, the GENIUS Act stablecoin framework, the NYDFS BitLicense, the Markets in Crypto-Assets Regulation, the UK cryptoasset regime, FATF Virtual Asset and Travel Rule standards, UAE digital asset and virtual asset frameworks.
Consumer protection and fair lending
CFPB requirements, UDAAP, ECOA and Regulation B, TILA and Regulation Z, FCRA, Regulation E, the FCA Consumer Duty, fair treatment, disclosures, complaints and consumer protection.
Governance and individual accountability
UK Senior Managers and Certification Regime, board and senior management governance, individual accountability, compliance governance, risk ownership, escalation and regulatory reporting.
Anti-bribery and corruption
Foreign Corrupt Practices Act, UK Bribery Act, OECD anti-bribery standards and global anti-corruption frameworks.
Privacy and data protection
GDPR, GLBA, SEC Regulation S-P, US privacy requirements, data governance, confidentiality and information protection.
Cybersecurity and operational resilience
Digital Operational Resilience Act, NYDFS Part 500, US interagency third-party risk management guidance, EBA outsourcing guidelines, cybersecurity governance, operational resilience, business continuity and technology risk.
Artificial intelligence and model governance
EU AI Act, NIST AI Risk Management Framework and its Generative AI Profile, model risk management guidance, AI governance, validation and oversight, responsible AI and regulatory expectations for AI use.
Post-quantum readiness
NIST post-quantum cryptography standards and migration guidance, cryptographic governance, readiness assessment, third-party readiness and migration governance.
Examinations, inspections and remediation
SEC and FINRA examinations, US banking examinations, FCA and international inspections and supervisory reviews, regulatory investigations, enforcement remediation, Written Agreements, corrective action programs and regulatory responses.
Licensing and market entry
SEC and FINRA registrations, investment adviser registration, broker-dealer registration, money services business and money transmitter licensing, banking, payments and digital asset licensing, international market entry and regulatory perimeter analysis.
Whistleblowing and investigations
SEC whistleblower framework, EU Whistleblowing Directive, internal investigations, escalation, retaliation controls, reporting and governance.
Tax transparency
FATCA, the Common Reporting Standard, DAC8, the OECD Crypto-Asset Reporting Framework and international tax transparency requirements.
Global regulatory frameworks
US, UK and EU frameworks, plus experience with SFC Hong Kong, DFSA, ADGM/FSRA, VARA, MFSA, CySEC and other international regulatory regimes.
Nothing by that name in the list. Ask us; the list is what we have written down, not everything we have done.