I work where someone can make you prove it.
Not every industry is a fit for the way I work, and I’d rather say so than pretend otherwise. The method — regulation defines what you must prove, so build the evidence, so fix the model, so the tool becomes a detail — needs one ingredient to function: an outside party with the standing to say “show me.” A regulator. An auditor. An acquirer running diligence. An insurer pricing your risk. A board that has finally understood it carries personal accountability.
Where that party exists, “prove it” has a referent and everything I do has something to stand on. Where it doesn’t — where the pressure is purely commercial or purely political — the framework has nothing to attest against, and you’d be better served by someone else. So the sectors below aren’t a marketing list of everywhere I’ll take money. They’re the places where the method actually bites.
The common shape
Read across these verticals and the same structure keeps appearing, which is why depth in one transfers to the next. Each has a supervisor or a standard that has moved from reviewing documents to demanding evidence. Each has critical operations that must survive disruption. Each has third-party dependencies that are now the firm’s own risk. And each has a data model quietly deciding whether any of it can be demonstrated. Different acronyms, same skeleton.
The sectors
Financial services. The origin of the modern proof regime and still its sharpest edge — DORA, operational resilience, ICT third-party risk, model risk. If your supervisor can ask you to evidence a control on a clock, this is where you already live.
Insurance and InsurTech. Underwriting is an evidence-and-attestation business wearing an actuarial coat. The regulatory overlay — FCA, PRA, EIOPA, DORA — sits on top of a data model that decides whether any of it holds together. A strong fit that surprisingly few people serve well.
Maritime and shipping. Where operational technology and information technology have quietly converged on the bridge, and where IMO and class-society cyber expectations turned “we run a tight ship” into “show us the resilience evidence for the newbuild.” An unusual vertical, and a genuinely underserved one.
Healthcare and health data. The European Health Data Space is the biggest health-data shift in a generation, with deadlines that look distant until you count backwards from what you’d need to build. Taxonomy is the right lens, the competition is thin, and the obligations are only sharpening.
Manufacturing and industrial. Sixteen posts’ worth of ERP and SAP reality, OT/IT convergence, and NIS2 obligations for entities that never thought of themselves as regulated. The “why ERP implementations fail” story is a data-model story, and this is where it lands hardest.
Professional services. Legal, accounting and advisory firms holding sensitive client data under GDPR, the SRA, the ICAEW and their peers — where matter and document classification is the unglamorous root of both the compliance posture and the AI ambition.
Digital assets. Crypto-asset service provision meeting MiCA, custody obligations, and the travel rule. Ambition on one side, a supervisor demanding evidence on the other, and a technology estate that has to satisfy the second without strangling the first.
What sector depth actually changes
The claim that a consultant “understands your industry” is cheap, so let me be specific about what it buys you when it’s real, because it’s not domain trivia.
It changes the first question. A generalist starts by asking what you want to achieve. Someone who knows the sector starts by knowing what your supervisor will ask you to prove, which competitors have already been through the version of this that went badly, and where — specifically — firms like yours tend to have built a control that’s real but unattestable. That shortens the diagnosis from months to days, because I’m not learning your regulatory context on your budget.
It changes the model. Every one of these sectors has a characteristic way its data model breaks: the insurer whose “policy” means five things, the manufacturer whose part supersessions were never modelled, the digital-asset firm whose custody records can’t survive the travel rule, the maritime operator whose OT and IT registers were never reconciled. Knowing the failure pattern in advance means designing around it rather than discovering it in an audit.
And it changes what “done” looks like. In a regulated sector, the deliverable isn’t a strategy deck — it’s an estate that can answer the supervisor’s question on the supervisor’s clock, with evidence your board can rely on. Sector depth is what makes that outcome specific enough to actually build toward.
Why sector depth matters here
A generalist can give you generic advice about any of these. The value is in the person who knows what the specific supervisor actually asks, how the specific data model tends to break, and which of your competitors already learned the expensive version of the lesson. That’s what turns “technology governance” from a phrase into a control your board can rely on and your regulator can’t fault.
- You’re in one of these. → Start a conversation
- You want the method first. → How I work
- You have a specific deadline. → Regulations