THE 4URIGHT PRACTICE
The practice behind ONE FILE.
4URIGHT is a juridical, governance, risk and compliance practice that creates and maintains ONE FILE for the company. ONE FILE is the governed architecture connecting who the organisation is, where it is going, how it operates, who decides, why it acts, when it reviews itself and what evidence proves it.
It is not one document and it does not give everyone access to everything. Regulators, banks, insurers, auditors, clients, employees and investors require different information and different permissions. Each authorised view must nevertheless come from the same coherent company truth. Our practice brings that truth into contracts, decisions, risk assessments, fiscal records, digital systems, controls, behaviour and evidence. We help make it right, keep it right and prove it.
How the practice works
Use this page to understand:
- what juridical GRC means inside an operating company;
- how the six 4URIGHT practice areas contribute to ONE FILE;
- whether your matter concerns one discipline or several connected parts of the company;
- how we assess, structure, implement and maintain the work;
- what information helps us read your situation responsibly;
- whether you need an integrated ONE FILE assessment, a focused project or a retained GRC mandate.
WHAT JURIDICAL GRC MEANS
The rule, the decision and the evidence must agree.
Juridical GRC examines the complete relationship between rights, duties, authority, risk, conduct and proof. It asks more than whether the company has a contract, policy or register. It asks whether the document reflects reality, whether the responsible person can act, whether the control works, whether the risk has been consciously accepted, and whether the company can demonstrate what happened. The work may begin before difficulty, during change or after something has failed. The underlying discipline remains the same: every relevant part must reconcile within ONE FILE.
THE SERVICE PERIMETER
Six connected practice areas. One coherent company file.
You do not need to diagnose the company before contacting us. A matter that appears contractual may also concern authority, privacy, fiscal evidence or risk. A digital incident may reveal weaknesses in governance, supplier control, employment practice and reporting. The six practice areas help identify where the work begins. During intake, we read the connections and determine what must be brought together within ONE FILE.
01
Juridical and contractual architecture
For organisations that need contracts and formal duties connected to ownership, operational responsibility, risk and evidence.
Typical matters: terms and conditions, commercial and employment contracts, authority and signing rules, intellectual property, contractual registers, renewals, liability, audit rights, evidence duties and controlled exit.
02
Governance and decision authority
For organisations that need clarity about who may decide, who must be consulted, who controls execution and who remains accountable.
Typical matters: board and shareholder responsibilities, delegations, approval thresholds, policy structures, conflicts of interest, decision records, management reporting and governance calendars.
03
Risk management and resilience
For organisations that need risk management to influence real decisions rather than remain an administrative register.
Typical matters: risk appetite and tolerance, enterprise and project assessments, third-party exposure, key risk indicators, treatment plans, scenarios, escalation, continuity, incidents and recovery priorities.
04
Compliance and fiscal control
For organisations that need legal, regulatory and fiscal obligations translated into owners, calendars, controls, monitoring and reliable evidence.
Typical matters: obligation registers, regulatory change, VAT and corporate tax-control processes, payroll controls, transaction evidence, retention, monitoring, corrective actions and audit readiness.
05
Digital, data and privacy
For organisations that need digital systems, personal data, access and automated processes governed as part of the company rather than left to technology alone.
Typical matters: GDPR, AI governance, DORA and NIS2 readiness where applicable, access, logging, ICT suppliers, data mapping, privacy records, e-signatures, retention, digital evidence and operational resilience.
06
Certification and assurance readiness
For organisations that need credible preparation for certification, customer assurance, institutional due diligence or external review.
Typical matters: scope definition, gap analysis, policy and control implementation, evidence architecture, internal checks, management review, corrective action, mock assessment and coordination with an independent certification body.
HOW A 4URIGHT ENGAGEMENT WORKS
The practice does not begin with a generic opinion or a predetermined package. It begins with the company, the question, the available evidence and the consequence of getting the answer wrong.
We examine what is formally required, what leadership believes is happening, what people actually do, what the systems record and what another authorised reader would be able to verify.
The objective is not to describe complexity. It is to establish one coherent reading, identify the right sequence of work and ensure that the resulting structure becomes part of ONE FILE.
THE BASIC PROCESS
1. Confidential intake
You explain the organisation, the question, what triggered it, which stakeholders are involved, what decision is approaching and which documents or evidence already exist.
2. Integrated reading
We examine the relevant contracts, obligations, decisions, processes, data, systems, people, third parties and risks. We identify where the parts agree, where they contradict and what cannot yet be proven.
3. ONE FILE architecture
We define the authoritative sources, responsible owners, access permissions, review moments, control requirements and evidence needed to create a coherent company file. The resulting plan sets priorities, deadlines and dependencies.
4. Implementation and maintenance
Where the mandate continues, we help turn the architecture into contracts, policies, registers, workflows, controls, training and reports. We test whether the parts reconcile, correct what does not work and maintain the file as the company changes.
PREPARE YOUR INTAKE
What helps us read the matter properly.
You do not need to assemble a perfect dossier before contacting us. Tell us what you know, what you do not know and why the question matters now. Concrete information helps us understand the likely perimeter, urgency and professional responsibility. Missing or contradictory information is itself relevant and does not prevent an initial intake.
The company
Name, legal form, ownership, sector, size, locations, principal activities and whether the company is growing, changing, under pressure, involved in a transaction or preparing for closure.
The question
What triggered the contact, who is asking, which decision must be made, what management needs to understand and what may happen if the issue remains unresolved.
The available evidence
Contracts, terms, policies, registers, decisions, reports, financial records, privacy documentation, system information, correspondence, transaction materials or earlier remediation work.
Time and consequence
Regulatory, contractual, payment or transaction deadlines, operational pressure, stakeholder expectations, dependencies and the risk of financial, legal, human or reputational escalation.
WHY THIS MATTERS
When the company tells different stories, people carry the consequence.
Disconnection is never only administrative. A contract that does not match the service can delay payment. Unclear authority can expose an employee or director. Weak records can undermine a tax position. Uncontrolled access can harm a person whose data was entrusted to the company.
Behind every control, transaction and report are people, salaries, savings, suppliers, families, reputations and future decisions. A company may remain commercially active while becoming progressively harder to explain and defend. ONE FILE gives leadership a disciplined way to recognise contradictions early, repair what has weakened and answer stakeholders without inventing coherence under pressure.
Read the deeper reason
4URIGHT exists because structure protects more than compliance. It protects decisions, relationships, money, responsibility and the people who depend on the company behaving as it says it does.
BOUNDARIES
What the 4URIGHT mandate does and does not claim.
- We do not treat a template, policy or report as complete until it is connected to ownership, operation and evidence.
- We do not separate a problem from the wider company where the facts show that several disciplines are involved.
- We do not give material fiscal, juridical or structural direction without sufficient context and documentation.
- We do not promise that governance eliminates risk or that certification guarantees ethical behaviour.
- We do not certify our own work. Independent certification and protected assurance remain with the appropriate accredited or authorised body.
- We do not replace an advocate, civil-law notary, statutory auditor, forensic specialist or other protected professional where that authority is required.
- We do not give every stakeholder access to the complete file. Information is disclosed lawfully, proportionately and according to role and purpose.
- We do not alter the reading to provide comfort where the evidence points elsewhere.
The practice is for leaders who want the company to become coherent and readable, including when the first reading reveals work that must be done.
CONFIDENTIAL INTAKE
Tell us what must reconcile.
Use the confidential intake when a stakeholder is asking questions, when an important decision is approaching, or when different parts of the organisation no longer tell the same story. You do not need to decide which practice area applies. Describe the company, the question, who is asking, what evidence exists and what deadline or consequence is approaching. A confirmation is issued immediately. Relevant enquiries are normally reviewed within 24 to 48 hours.