On-call advice
Questions answered by email, phone or meeting within agreed response times.
Most compliance questions do not need a project. They need a quick, reliable answer from someone who already knows your business. A retainer gives you a named adviser and a monthly block of hours for exactly that.
An ongoing advisory arrangement with a fixed monthly fee and hours. You get a named adviser for questions, document reviews, regulatory updates and short pieces of work, without scoping a new project each time.
Regulation in Malaysia is moving fast: the PDPA amendments and new JPDP guidelines, the Cyber Security Act, BNM and SC policy changes, and anti-corruption expectations under Section 17A. Organisations without an in-house compliance team either guess or pay project rates for small questions. A retainer is cheaper and faster, and the adviser builds context over time.
Questions answered by email, phone or meeting within agreed response times.
Policies, contracts, notices and board papers reviewed.
A monthly note on changes that affect you.
Attending or briefing meetings when needed.
Short pieces of work drawn from the monthly hours.
Access to specialists across the Orbix practice.
One monthly fee.
No scoping cycle for small questions.
The adviser learns your business.
One relationship across compliance areas.
Larger work quoted separately.
Understanding your business, obligations and priorities.
Agreeing focus areas each month.
Advice, reviews and updates.
Monthly summary of hours and work.
Adjusting hours and focus.
A consistent point of contact.
Changes that matter to you.
Record of questions and answers.
What was used and on what.
Priorities and recommendations.
We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.
Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.
Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.
Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.
Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.
CoaaS gives you an outsourced compliance officer who performs the role. The retainer gives you expert advice and support while your own people perform it.
Additional hours are billed at the agreed rate, or the retainer can be resized at the quarterly review.
Terms are agreed at the start. We keep it simple and transparent.
PDPA, AML/CFT, anti-corruption, governance, Cyber Security Act and BNM and SC matters, with specialists where needed.
Typically six or twelve months, so the adviser can build context.
Tell us your industry and the kinds of questions you face. We will propose monthly hours and a fixed fee.