Jackstien International — Risk Management
Jackstien International is an award-winning firm of risk management consultants operating under two distinct verticals of risk management: Financial and Regulatory Risk Management, and Hybrid Work Risk Management.
We are an advisory practice. We build the policy, process and practice that let an organisation manage risk deliberately rather than discover it late — integrating technical, financial, technological, and behavioural expertise across both verticals.

The Right Way.
Financial and Regulatory Risk Management
Risk management for banks, NBFCs and other financial regulated institutions. We design the frameworks that govern regulatory obligation, financial exposure and operational control.
Manage Risk
Hybrid Work Risk Management
Risk management for organisations whose people, premises and processes no longer sit in one place. A distributed working model changes what has to be controlled, what it costs, and what a regulator expects to see. We design for all three.
Manage Risk
Synchronised Areas of Expertise
Both verticals draw on the same four disciplines. It is the combination that makes cross-management of risk feasible — no single field can resolve a problem alone without shifting the underlying risk elsewhere.
| Technical
- Legal & Regulatory
- Statutory & Licensing
- Cross-Border Law
- Direct/ Indirect Tax
- Macro-Economics
- Actuarial
| Financial
- Credit & Market Risk
- Value Enhancement
- Opportunity Cost
- Fin. Recording
- Disclosures
- Capital Structure
| Technological
- Process Re-engineering
- Cyber-Security
- Automation/ ML
- Cost Balance/ ROI
- Privacy Obligations
- Redundancy
| Behavioural
- Adaptation
- Communication
- Succession
- Performance
- Training
- Org. Psychology
Advisory Services
The Right Way.
Jackstien International is led by Nishant Shah, Managing Partner.
How does a risk management consultant differ from an audit function?
Internal, external or concurrent audits provide assurance. Each tests whether existing controls work, and reports what it finds.
Jackstien International works upstream of that. We are an advisory practice: we build the policy, process and practice that an audit function would later test. We are engaged where an institution needs a framework designed or redesigned, not where it needs one assessed.
While we often perform detailed walk-throughs as a preparatory exercise for our deliverables to clients, we do not perform independent reviews.
How do you turn regulatory requirements into policies, SOPs and practices that people actually follow?
Most institutions have the sensitivity to regulatory needs. However, conversion to practice is difficult.
The translation runs through three stages, and it fails at a different point in each:
- Policy states what the institution has decided. It fails when it restates the regulation instead of deciding anything — a policy that could belong to any institution has made no choices, and gives the business nothing to act on.
- Process turns that decision into a sequence with owners, evidence and timing. It fails when it is written by the function that owns the risk rather than with the people who will run it, and so describes work nobody actually does.
- Practice is what happens when nobody is watching. It fails when the process was never embedded into the systems, approvals and reporting that shape day-to-day behaviour — leaving a documented framework and an undocumented reality.
The distance between the three is where regulatory findings come from. Closing it is design work, not documentation work.
What should a regulated financial institution look for when appointing an external risk adviser?
An external risk adviser should be assessed on four things.
- Current regulatory fluency, not historical. A framework written against superseded directions ages badly, and both the RBI and SEBI perimeters have moved materially in recent years.
- Practitioner experience of the function being advised on. There is a difference between having read the guidance and having held the role, and it shows in whether a framework survives contact with the business.
- Standing with the regulators and industry bodies that set the rules. Advice carries more weight when the adviser has sat on the committees and working groups where the requirements were shaped.
- Independence from the assurance chain. An adviser who also audits carries a conflict.
What does a risk management advisory engagement typically involve, and how long does it take?
Engagements vary in scope, but most follow the same arc.
- Understand. Detailed walk-throughs of how the work is actually done, rather than how it is documented. This is typically where the gap that triggered the engagement surfaces.
- Design. Policy, process and practice built together rather than in sequence, so each is written knowing what the others require.
- Integrate. The stage at which the design meets the systems, approvals and reporting that will carry it. Engagements that stop before this point produce documents rather than change.
- Handover. The framework owned by named people or positions inside the organisation, with the reasoning behind each decision recorded so it survives their successors.
Duration depends on scope and on how much of the institution the framework touches — a single focused process may take days, a set of interrelated processes may take weeks, a firm-wide framework months. We agree the scope accurately at the outset so there is predictability for both parties.
What does hybrid work risk management actually cover, beyond information security?
Information security is the part everyone sees. It is rarely the part that causes the seepages that accumulate the losses.
When work is distributed, controls that a shared physical location provided silently stop operating — and most were never written down, because nobody had to design them. Re-establishing them is an operating risk discipline. It covers:
- Cost. Flexibility offered without cost discipline is expensive. An organisation that leaves the option open to employees, without designing its estate, technology and support footprint around that choice, ends up carrying the cost of both models — where the same flexibility, designed deliberately, can be optimised.
- Process integrity. Steps that depended on physical adjacency, such as a signature, a second pair of eyes or a physical handover, either get formalised or get skipped.
- Regulatory complexity and cross-border exposure. Where work is performed becomes a regulatory question. Staff operating from other states or other countries can draw an organisation into obligations, permissions and tax positions it never chose.
- Supervision and control. Oversight that relied on proximity — the overheard call, the visible desk, the manager who noticed — has to be rebuilt as something designed rather than assumed.
- Information handling at the edges. Not systems access, but what surrounds it: screens, printing, personal devices used for convenience, and premises the organisation neither owns nor inspects.
- Team interaction, behaviour and trust. Hybrid working changes how teams interact, and the behaviours that made the previous model work do not transfer unaltered. Trust in particular has to be maintained by design, having previously been a by-product of sharing a room — and escalation depends on it, since reporting a concern requires both knowing who to tell and feeling able to.
Underlying all of it is a single requirement: that the organisation’s best interests stay front and centre while the working model changes. That is an operating risk exercise and it needs operating risk expertise. This is hard science that goes considerably beyond information security or soft-skill discussions.
What are the risk implications of a distributed workforce for a regulated institution?
For an unregulated business, a weakened control is an operational and financial problem. For a regulated business, it is an existential problem. A regulated entity’s licence is what allows it to continue operations.
Distribution changes three things specifically:
- Where regulated activity is deemed to take place. Licences, permissions and record-keeping obligations attach to locations. When staff performing regulated functions work from places the institution has not declared, the perimeter shown to the regulator stops matching the one that exists.
- Cost. Managing your real estate to optimise for hybrid work must protect the mandatory controls and safeguards required under regulations. One cannot come at the cost of the other. Avoiding optimisation, on the other hand, is not an option either.
- What must be evidenced, rather than merely done, and who the organisation remains answerable for. Supervisory frameworks assume controls that can be demonstrated to a third party after the fact — proximity-based oversight leaves no record, designed oversight does. And premises the organisation does not control, devices it does not own and third parties supporting distributed work all sit inside its accountability while sitting outside its direct control.
A hybrid model designed only for productivity will satisfy the business and still leave the licence exposed. Managing both is where real value is delivered.