Honest trade-offs · Including the ones that compete with us

Options: in-house, consultancy, law firm or specialist

In-house delivery, a permanent hire, a consulting firm, a law firm, a GRC platform, or a specialist managed service. What each one is good at, and where each one fails.

There are six realistic ways a mid-sized regulated firm can meet an obligation under DORA, the EU AI Act, NIS2, GDPR or ISO 27001. Morclear Europe is one of them. This page describes all six honestly, including the ones that compete with us, because the wrong choice here is expensive in a way that is only visible eighteen months later, when a supervisor asks for evidence and the file does not hold up.

Read it as a decision aid rather than a pitch. If one of the other five fits your situation better, take it.

Option one

Do it in-house with the team you have

The cheapest option on paper, and the one most firms default to. Someone in risk or operations picks up the framework alongside their existing role, works through the text, and builds what they can.

It works when the obligation is narrow and the person has genuine capacity. It fails quietly when it does not, because nobody wants to report upward that the programme is three months behind. The failure mode is a set of documents that exists but was never operationalised: risk ratings that were never revisited, review dates that passed, a register that reflects the vendor list as it stood on the day it was written.

Choose this if you have a named person with real time allocated, and a second person who reviews their work.

Option two

Hire a compliance professional

A permanent hire gives you ownership, availability and institutional memory, which nothing external replicates. It is the right end state for most firms that grow past a certain size.

The difficulties are timing and recruitment. Filling a compliance role in the Irish market takes months, and the deadline is usually not willing to wait. There is also a scope mismatch below a certain size: one person cannot credibly hold DORA, the AI Act, NIS2 and GDPR simultaneously at depth, so you either hire a generalist and accept the depth limit or hire a specialist and outsource the rest anyway.

Choose this if compliance is a permanent, growing part of your operating model and you can absorb a search of several months.

Option three

Engage a consulting firm

General-practice consulting, from the Big Four through the mid-tier advisory firms, brings scale, multi-jurisdiction reach and a name your board recognises. For statutory audit, independent assurance opinions, or group-wide programmes running across several entities at once, this is the correct answer and we will tell you so.

The structural constraint is shape rather than quality. A consulting engagement is scoped as a project with a start, a deliverable and a close. Regulatory obligations do not close. What happens between engagements is the part that is usually unfunded.

Choose this if the work is genuinely a programme rather than an obligation, or if the deliverable needs to carry an assurance signature.

Option four

Instruct a law firm

Where the question is legal interpretation, a law firm is the right instrument and no managed service substitutes for it. Whether a particular AI system falls inside Annex III, whether an Article 2(3) carve-out applies, how a contractual allocation of obligations survives a dispute: these are legal questions and they attract legal privilege, which matters if the position is ever contested.

What a legal opinion does not do is build the register, run the assessment or file the report. It tells you where you stand. The delivery is a separate problem, and usually a larger one.

Choose this if classification is genuinely contested, or if you need privilege over the analysis.

Option five

Buy a GRC platform

Governance, risk and compliance software gives you workflow, a control library, evidence collection and a dashboard. For firms with an existing compliance function, good tooling is a genuine multiplier and worth the licence.

The gap is that a platform gives you structure and no signature. It will tell you a control is unmapped; it will not decide whether the mapping is defensible for your business, and it will not answer the regulator. Firms that buy a platform without the person to run it typically end up with a well-organised record of work that was never done.

Choose this if you already have the expertise in-house and what you lack is process and evidence discipline.

Option six

A specialist managed compliance service

This is what Morclear Europe does. CORA™, our Compliance Operations and Risk Automation platform, runs eight modules across DORA incident response, gap assessment, third-party ICT risk, regulatory monitoring, board reporting, training, regulator communication and AI governance. The AI drafts. A named compliance professional reviews, corrects and signs every output before it reaches you, and keeps the programme current between deadlines rather than handing it over and leaving.

The honest limits: we cover five frameworks and nothing else, we do not provide assurance opinions or legal advice, and we are a new firm without a published client list. If any of those is a blocker, one of the five options above serves you better.

Choose this if you have a live obligation, a team already at capacity, and you need the work owned continuously rather than delivered once.

The question that actually decides it

Most of the choice collapses into one question: when this obligation changes, and it will, who picks it up? If the answer is a named person with the time and the standing to act, build around that person. If the answer is nobody, then a project-shaped solution will leave you exactly where you started, and the only options that survive contact with reality are a permanent hire or a managed service.

Our entry points are a free ten-minute EU AI Act assessment, a fixed-price gap assessment at €999 delivered in two weeks, Programme Build from €15,000*, Managed Compliance from €2,000 per month*, Regulatory Radar at €199 per month and Virtual DPO from €1,200 per month.

*Fees confirmed after a free scoping call.

Take the assessment first. It costs nothing and it tells you which of the six options your situation actually calls for.

Free AI Act Assessment Book a scoping call

See also: Specialist compliance firm or consulting firm · Why work with Morclear · CORA™ Managed Compliance