Risk and suitability process support
Consistency across client journey, documentation, and oversight routines.
We strengthen frameworks, templates, and monitoring discipline, collaborating with relevant licensed parties where required.
What is this?
Risk and suitability is where good intentions either become a disciplined decision, or turn into an expensive lesson. In financial services it is also where firms most commonly get exposed, not because the strategy was “wrong”, but because the client journey, evidence trail, and ongoing oversight were not built to withstand scrutiny.
Across corporates, SMEs and private clients, the same principle holds: if you cannot clearly explain why a decision was appropriate at the time, with supporting facts and a repeatable process, then you are relying on memory, personalities, and optimism rather than governance.
The market context is simple. Clients have more choice, more information, and less patience for ambiguity. Regulators and counterparties expect clearer documentation, better outcomes monitoring, and stronger control frameworks.
ESMA explicitly frames suitability as one of the most important investor protection requirements within MiFID.
The FCA’s own material is direct: firms must gather the information needed to make a suitable recommendation, including financial situation, investment objectives, and multiple dimensions of risk (attitude to risk, capacity for loss, and knowledge/experience). At the same time, the Consumer Duty has increased expectations around evidencing outcomes and board-level oversight in retail contexts.

Where firms and individuals typically come unstuck
Most “suitability failures” aren’t dramatic. They are small gaps that accumulate:
A risk profile that is treated as a tick-box exercise rather than a structured assessment. Capacity for loss is captured vaguely, or not tied back to the proposed solution.
Costs, liquidity, concentration and counterparty exposure are described, but not translated into a clear trade-off the decision maker actually understands.
Suitability reports (or decision memos) explain features, but do not clearly link the recommendation to objectives, constraints, time horizon, and downside scenarios.
Ongoing oversight is assumed rather than designed. Reviews become calendar-based admin, rather than trigger-based governance.
When these gaps exist, the business becomes reliant on individual judgement and goodwill. That is fine until a complaint, market stress, staff turnover, or a regulator asks you to evidence why the decision made sense at the time.

A practical “risk and suitability operating system”
CGI’s role is to tighten the system end-to-end so it becomes repeatable, auditable, and commercially usable. The goal is not paperwork for its own sake. The goal is faster, cleaner decisioning with fewer surprises.
We typically focus on four building blocks.
1. The front end: capturing the right inputs, once
We design the fact find / discovery inputs so the client (or internal decision maker) tells their story once, properly, in plain English. For FS this includes risk appetite, capacity for loss, objectives, time horizon, liquidity needs, knowledge/experience and constraints. For corporates and SMEs this might be risk appetite statements, treasury/investment policy constraints, cash-flow sensitivities, and “must not fail” outcomes. For private clients it may include cross-border realities, dependants, liabilities, and practical lifestyle constraints.
2. The decision logic: linking inputs to an appropriate solution
We translate objectives into decision rules that can be evidenced. This is where many firms rely on generic risk questionnaires or legacy templates. We help you connect the dots: why this solution, why now, what you are optimising for (cost, liquidity, capital preservation, growth, diversification), and what you are explicitly not doing (avoiding concentration, avoiding leverage, avoiding illiquidity, limiting counterparty exposure, and so on).
3. The documentation layer: evidence that stands up to scrutiny
In FS, this is where suitability reports, file notes, disclosures, and approvals must read as a coherent narrative rather than a compliance bundle. Under Consumer Duty expectations, firms also need to evidence outcomes monitoring and board governance around customer outcomes. In non-FS contexts, the same discipline becomes a decision memo and governance pack: concise, defensible, and usable by committees, boards, lenders, or counterparties.
4. The oversight layer: monitoring discipline that protects value
Good oversight is not “more meetings”. It is clearer triggers, cleaner MI, and an escalation path that people actually use. We help define what gets monitored (performance and drawdown measures, concentration, liquidity, cost leakage, breaches, exceptions, complaints, vulnerability indicators where relevant), the cadence, and who owns actions. In regulated environments we also align this to broader expectations around governance and control frameworks, including operational resilience considerations where the business model relies on key third parties or platforms.

Why CGI, rather than a large consultancy or a generic compliance provider
Large firms can be excellent, but they often operate as a production line. You repeat the story, the work is split across teams, and the output can feel templated. CGI is intentionally smaller and senior-led.
That means one accountable lead, fewer handovers, faster iteration, and a practical bias toward what will actually work inside your business.
We also sit in the middle ground that many organisations struggle to find: commercial enough to protect revenue and client experience, and disciplined enough to stand up to regulator, auditor, investor, or counterparty scrutiny.
Where licensed advice is required, we collaborate and complement the relevant regulated parties, but we keep ownership of the operating framework, the delivery plan, and the evidence trail.

Call to action
If you want your risk and suitability process to be a competitive advantage rather than a constraint, CGI can run a short diagnostic and give you a prioritised remediation plan within an agreed scope.
The immediate deliverable is clarity: what to fix, in what order, who owns it, and how you evidence it.




