PracticesCompliance, ESG & Internal Controls
Practice area

Compliance, ESG & Internal Controls

Compliance programmes, ESG implementation, internal investigations and representation before regulators — built to fit the business, not to sit in a drawer.

Contact us

Strict and complex regulation increasingly shapes how companies operate, and compliance has become a condition of reputation, sustainable growth and investment.

Companies face constant legislative change, growing demands from regulators and rising expectations from investors and consumers. Compliance is no longer only about avoiding penalties.

It lets companies limit regulatory risk, build investor confidence, secure long-term stability and gain a competitive position. Firms with clear internal policies and ESG standards become preferred partners for international investors and clients.

Our aim is that compliance is experienced as an opportunity to improve the business rather than an imposition, which is why we write policies that fit the client’s real operating model.

Key practice areas

What we handle

Eight areas of work, from preventive controls to defence before regulators.

01

Policies and risk control measures

  • Comprehensive compliance policies covering data protection, anti-corruption rules and environmental obligations.
  • Rulebooks, codes of conduct and whistleblowing procedures.
  • Internal control and reporting systems that let management react in time.
02

Internal investigations

  • Investigations where there is suspicion of irregularity or breach of rules or ethical standards.
  • Procedures run lawfully and with respect for the rights of employees and others involved.
  • Review of documentation, contracts, electronic communication and other relevant data.
  • Reports with clear recommendations, and support for management in deciding what follows.
03

Implementing corrective measures

  • Determination of the corrective steps that bring the company back into compliance.
  • Remediation plans covering procedural change, additional training and communication with regulators.
  • Support in negotiations with the authorities to reduce or avoid penalties.
  • Systems that prevent the same irregularity recurring.
04

ESG implementation

  • Advice on embedding ESG principles in strategy and day-to-day operations.
  • Environmental questions (emissions and waste), social responsibility (equal opportunity, employee rights) and governance (transparency, ethical conduct).
  • Preparation of ESG reports and communication with investors who increasingly require them.
  • Particular support for companies developing AI and technology solutions, which face high standards of accountability.
05

ESG due diligence in M&A transactions

  • Analysis of the ESG risks carried by a target company.
  • Review of compliance with environmental rules, labour standards and governance practice.
  • Identification of liabilities that could affect deal value and the buyer’s negotiating position.
  • Warranties and contractual mechanisms proposed on the basis of the findings.
06

Employee compliance training

  • Tailored training on anti-corruption, data protection, antitrust rules, ESG standards and codes of ethics.
  • Interactive workshops, e-learning modules or specialised sessions for management.
  • Content designed so employees understand the rules, the internal procedures and the consequences of breach.
  • Practical material based on real business situations.
07

Monitoring and regular compliance reviews

  • Continuous monitoring through periodic reviews and reports.
  • Revision of existing policies, testing of procedures and checks on how internal rules are applied.
  • Particular focus on high-risk areas: data protection, financial flows and employment.
  • Early detection of risk before it becomes a regulatory penalty.
08

Representation in proceedings

  • Representation before courts, arbitral tribunals and regulators in compliance-related proceedings.
  • A defence strategy that combines disputes and compliance expertise.
  • Active negotiation with regulators to limit the consequences for the company.
  • Protection of business interests and reputation at the lowest cost and disruption.
How we work

What working with us looks like

Five stages, from the first assessment to continuing support.

01

Initial analysis

We assess regulatory risk and business processes to find potential breaches.

02

Strategy

We set a compliance plan of policies, procedures and controls fitted to the industry.

03

Documentation

We draft internal acts, compliance programmes, ESG policies and reporting procedures.

04

Implementation and training

We put the policies into practice, train staff and set up monitoring.

05

Ongoing support

We update policies as the rules change and advise in regulatory proceedings.

Track record

Selected matters

A sample of recent work in the sector.

Programme

Compliance programme for an IT company

Developed internal policies and procedures on data protection and conflicts of interest.

ESG

ESG due diligence in an M&A transaction

Reviewed the target against ESG standards and prepared a detailed report for the investor.

Investigation

Internal investigation in manufacturing

Investigated a breach of internal procedures and proposed corrective measures.

Training

Training in the financial sector

Ran workshops on anti-corruption measures and competition rules.

What Clients Ask Us Most

Are ESG standards mandatory for every company?

ESG standards are not yet legally binding for all companies in Serbia, but they have become a decisive business factor. The EU is introducing ESG reporting obligations for a large number of companies, which affects Serbian firms working with European partners.

Many multinationals already require their suppliers and partners to apply ESG policies, so ESG operates as a market standard as much as a legal framework.

What is the first step towards compliance?

An internal review of the current position — a compliance check covering contracts, policies, internal acts and actual practice with employees and partners.

A compliance plan follows, with clear steps, deadlines and priorities. What matters most is that the plan fits the real needs of the business rather than formally ticking statutory boxes.

Does compliance only concern large companies?

No. Large companies attract more regulatory attention, but compliance matters just as much for small and medium businesses, where penalties and reputational damage are harder to absorb.

Companies planning to work with foreign partners or attract investors also have to demonstrate that they operate to the expected standards.

How does compliance affect reputation?

Reputation now carries as much weight as financial results. Companies that neglect compliance risk the trust of customers, investors and employees.

Those that apply compliance and ESG standards proactively build a reputation as a reliable partner, which often opens new markets and opportunities.

Is compliance worth the cost?

It is an investment rather than a cost. It requires resources for policies, training and internal reviews, but reduces the risk of penalties, litigation and lost business.

A single regulatory fine or the termination of an important contract can cost several times more than implementing the programme.

What happens if a regulator finds non-compliance?

Depending on the breach, a regulator can impose a fine, prohibit an activity, require corrective measures or start proceedings.

Having an adviser who knows the procedure and can negotiate with the regulator is decisive. We provide representation and prepare the plan for returning the business to compliance.

Next step

Let’s talk about your compliance programme

Tell us where the exposure sits and we will map the policies, controls and steps that follow.

Contact us
Newsletter

Learn legal updates, and what to do about them

Legal developments in Serbia and the EU, each with the step it asks of your business.

Sign up

Two emails a month. Unsubscribe any time.