Legal

Compliance & Risk Policy

Last updated: 22 May 2026

EPMLogic is committed to conducting its business with integrity, transparency, and in full compliance with applicable laws and professional standards. This policy sets out how we identify, assess, and manage compliance and risk across our practice.

1. Purpose and Scope

This Compliance and Risk Policy applies to EPMLogic and all individuals acting on its behalf, including principals, associates, subcontractors, and any third parties engaged in the delivery of EPMLogic services.

The purpose of this policy is to:

  • Define EPMLogic's approach to legal and regulatory compliance
  • Set out how we identify and manage risks in our consulting engagements
  • Establish standards of professional conduct for all who represent EPMLogic
  • Provide transparency to clients and stakeholders about our risk management approach

EPMLogic - Finstarte Consulting operates primarily under Indian law, with offices in Bengaluru, Karnataka and Varanasi, Uttar Pradesh and engages with clients across APAC, EMEA, and North America. We are committed to complying with applicable laws and regulations in all jurisdictions in which we operate.

2. Legal and Regulatory Compliance

EPMLogic is committed to full compliance with applicable laws and regulations, including but not limited to:

  • The Information Technology Act 2000 and its amendments (India)
  • The Digital Personal Data Protection Act 2023 (India)
  • The General Data Protection Regulation (EU) 2016/679 (GDPR), where applicable to EU/UK clients
  • The Income Tax Act 1961 and applicable GST legislation (India)
  • The Companies Act 2013 (India), where applicable
  • Anti-corruption and anti-bribery laws, including the Prevention of Corruption Act 1988 (India) and the UK Bribery Act 2010 (where applicable to UK-connected engagements)
  • Export control and sanctions regulations applicable to international engagements

EPMLogic reviews its compliance obligations regularly and takes appropriate steps to remain current with regulatory developments in its key operating jurisdictions.

3. Anti-Bribery and Anti-Corruption

EPMLogic has a zero-tolerance policy for bribery and corruption in any form. We do not offer, give, receive, or solicit any financial or other advantage intended to improperly influence a business decision, government action, or any other outcome.

All individuals acting on behalf of EPMLogic are prohibited from:

  • Offering or accepting bribes, kickbacks, or facilitation payments in any form
  • Making improper payments to government officials or private-sector counterparts
  • Using third-party intermediaries to channel improper payments
  • Concealing any transaction related to bribery or corruption

Gifts and hospitality may only be offered or accepted where they are: (a) of modest value; (b) consistent with reasonable and customary business practice; (c) not intended to influence a business decision; and (d) properly recorded.

Any individual who becomes aware of potential bribery or corruption must report it immediately to EPMLogic's principal contact. EPMLogic will not retaliate against anyone who raises a good-faith concern.

4. Conflicts of Interest

EPMLogic is committed to identifying and managing conflicts of interest that could compromise the integrity of our advice or our obligations to clients.

A conflict of interest arises when EPMLogic's interests, or those of an individual acting on its behalf, conflict, or could reasonably appear to conflict, with the interests of a client.

EPMLogic will:

  • Disclose to prospective clients any material conflict of interest before commencing an engagement
  • Decline engagements where a conflict cannot be adequately managed or disclosed
  • Maintain confidentiality between clients to prevent the cross-contamination of sensitive information
  • Not accept engagements with direct competitors of an existing client without appropriate disclosure and consent

Individuals acting on behalf of EPMLogic are required to disclose any personal interest in a client, supplier, or third party that could create a conflict, and to recuse themselves from affected decisions.

5. Data Protection and Information Security

EPMLogic takes data protection and information security seriously. Our approach is set out in full in our Privacy Policy. Key commitments under this compliance framework include:

  • Processing personal data only as permitted by applicable law and our Privacy Policy
  • Implementing appropriate technical and organisational measures to protect client and personal data
  • Not retaining client data beyond what is necessary for the delivery of services and legal obligations
  • Ensuring that subcontractors and associates who handle client data are bound by appropriate confidentiality and data protection obligations
  • Notifying clients promptly in the event of any actual or suspected data security incident affecting their data

EPMLogic does not store Workday tenant credentials or access client Workday environments beyond what is necessary and authorised for the delivery of agreed services. Access is managed under the principle of least privilege.

6. Professional Standards and Quality

EPMLogic is committed to delivering services to a high professional standard. Our quality commitments include:

  • Deploying appropriately experienced architects to each engagement
  • Producing written architecture documentation before commencing build work
  • Conducting internal review of deliverables before client submission
  • Seeking client feedback at key engagement milestones
  • Maintaining and improving our technical knowledge of Workday Adaptive Planning, AI forecasting, and enterprise FP&A through ongoing professional development

We do not represent ourselves as having expertise we do not possess. If a client requirement falls outside our areas of expertise, we will communicate this clearly and, where possible, recommend appropriate alternative resources.

7. Engagement Risk Assessment

Prior to accepting a new client engagement, EPMLogic conducts a proportionate risk assessment covering:

Scope and delivery risk: Whether the engagement scope is clearly defined, achievable within the proposed timeline, and within EPMLogic's area of expertise.

Client risk: The client's ability and willingness to engage constructively, provide necessary access and information, and meet its payment obligations.

Reputational risk: Whether the engagement could expose EPMLogic to reputational harm, including association with entities subject to sanctions, regulatory investigations, or unethical business practices.

Conflict of interest risk: Whether the engagement conflicts with existing client obligations or EPMLogic's own interests.

Data and information security risk: Whether the engagement requires access to sensitive data and whether appropriate safeguards are in place.

EPMLogic reserves the right to decline any engagement that presents unacceptable risk, without being required to provide detailed justification.

8. Subcontractors and Third Parties

Where EPMLogic engages subcontractors or associates in the delivery of services, we take responsibility for ensuring:

  • They possess the relevant expertise and experience for the work assigned
  • They are bound by confidentiality obligations equivalent to those EPMLogic owes to its clients
  • They comply with applicable data protection requirements
  • They are made aware of and agree to comply with this Compliance and Risk Policy

EPMLogic does not use subcontractors to circumvent the standards set out in this policy. Clients will be informed if a subcontractor is engaged in a material capacity in their engagement, subject to any confidentiality constraints.

9. Intellectual Property Compliance

EPMLogic respects the intellectual property rights of third parties and requires that all individuals acting on its behalf do the same. We do not knowingly incorporate third-party intellectual property into our deliverables without appropriate licence or permission.

EPMLogic is an independent consulting practice and is not affiliated with, endorsed by, or a partner of Workday, Inc., Oracle, or any other software vendor unless expressly stated. References to Workday Adaptive Planning, Oracle EPM, OneStream, or other platforms are for descriptive purposes only and do not imply an official partnership or certification unless separately verified.

All clients retain ownership of their own data. EPMLogic does not claim any ownership over client data processed in the course of an engagement.

10. Whistleblowing and Reporting Concerns

EPMLogic encourages anyone (including clients, associates, and subcontractors) who has a concern about potential non-compliance, unethical conduct, or policy breach to raise it promptly.

Concerns can be raised directly with EPMLogic's principal contact or by emailing info@epmlogic.com. All concerns will be treated seriously, investigated promptly, and handled with discretion.

EPMLogic will not retaliate against any individual who raises a concern in good faith, even if the concern turns out to be unfounded after investigation.

11. Policy Review

This Compliance and Risk Policy is reviewed at least annually and updated as required to reflect changes in applicable law, regulatory guidance, or EPMLogic's business operations.

Questions about this policy or requests to report a concern should be directed to: info@epmlogic.com

Report a concern or ask a question

If you have a compliance concern or a question about this policy, contact us directly. All concerns are treated seriously and handled with discretion.

Email info@epmlogic.com