Last updated: 22 May 2026
EPMLogic is committed to conducting its business with integrity, transparency, and in full compliance with applicable laws and professional standards. This policy sets out how we identify, assess, and manage compliance and risk across our practice.
This Compliance and Risk Policy applies to EPMLogic and all individuals acting on its behalf, including principals, associates, subcontractors, and any third parties engaged in the delivery of EPMLogic services.
The purpose of this policy is to:
EPMLogic - Finstarte Consulting operates primarily under Indian law, with offices in Bengaluru, Karnataka and Varanasi, Uttar Pradesh and engages with clients across APAC, EMEA, and North America. We are committed to complying with applicable laws and regulations in all jurisdictions in which we operate.
EPMLogic is committed to full compliance with applicable laws and regulations, including but not limited to:
EPMLogic reviews its compliance obligations regularly and takes appropriate steps to remain current with regulatory developments in its key operating jurisdictions.
EPMLogic has a zero-tolerance policy for bribery and corruption in any form. We do not offer, give, receive, or solicit any financial or other advantage intended to improperly influence a business decision, government action, or any other outcome.
All individuals acting on behalf of EPMLogic are prohibited from:
Gifts and hospitality may only be offered or accepted where they are: (a) of modest value; (b) consistent with reasonable and customary business practice; (c) not intended to influence a business decision; and (d) properly recorded.
Any individual who becomes aware of potential bribery or corruption must report it immediately to EPMLogic's principal contact. EPMLogic will not retaliate against anyone who raises a good-faith concern.
EPMLogic is committed to identifying and managing conflicts of interest that could compromise the integrity of our advice or our obligations to clients.
A conflict of interest arises when EPMLogic's interests, or those of an individual acting on its behalf, conflict, or could reasonably appear to conflict, with the interests of a client.
EPMLogic will:
Individuals acting on behalf of EPMLogic are required to disclose any personal interest in a client, supplier, or third party that could create a conflict, and to recuse themselves from affected decisions.
EPMLogic takes data protection and information security seriously. Our approach is set out in full in our Privacy Policy. Key commitments under this compliance framework include:
EPMLogic does not store Workday tenant credentials or access client Workday environments beyond what is necessary and authorised for the delivery of agreed services. Access is managed under the principle of least privilege.
EPMLogic is committed to delivering services to a high professional standard. Our quality commitments include:
We do not represent ourselves as having expertise we do not possess. If a client requirement falls outside our areas of expertise, we will communicate this clearly and, where possible, recommend appropriate alternative resources.
Prior to accepting a new client engagement, EPMLogic conducts a proportionate risk assessment covering:
Scope and delivery risk: Whether the engagement scope is clearly defined, achievable within the proposed timeline, and within EPMLogic's area of expertise.
Client risk: The client's ability and willingness to engage constructively, provide necessary access and information, and meet its payment obligations.
Reputational risk: Whether the engagement could expose EPMLogic to reputational harm, including association with entities subject to sanctions, regulatory investigations, or unethical business practices.
Conflict of interest risk: Whether the engagement conflicts with existing client obligations or EPMLogic's own interests.
Data and information security risk: Whether the engagement requires access to sensitive data and whether appropriate safeguards are in place.
EPMLogic reserves the right to decline any engagement that presents unacceptable risk, without being required to provide detailed justification.
Where EPMLogic engages subcontractors or associates in the delivery of services, we take responsibility for ensuring:
EPMLogic does not use subcontractors to circumvent the standards set out in this policy. Clients will be informed if a subcontractor is engaged in a material capacity in their engagement, subject to any confidentiality constraints.
EPMLogic respects the intellectual property rights of third parties and requires that all individuals acting on its behalf do the same. We do not knowingly incorporate third-party intellectual property into our deliverables without appropriate licence or permission.
EPMLogic is an independent consulting practice and is not affiliated with, endorsed by, or a partner of Workday, Inc., Oracle, or any other software vendor unless expressly stated. References to Workday Adaptive Planning, Oracle EPM, OneStream, or other platforms are for descriptive purposes only and do not imply an official partnership or certification unless separately verified.
All clients retain ownership of their own data. EPMLogic does not claim any ownership over client data processed in the course of an engagement.
EPMLogic encourages anyone (including clients, associates, and subcontractors) who has a concern about potential non-compliance, unethical conduct, or policy breach to raise it promptly.
Concerns can be raised directly with EPMLogic's principal contact or by emailing info@epmlogic.com. All concerns will be treated seriously, investigated promptly, and handled with discretion.
EPMLogic will not retaliate against any individual who raises a concern in good faith, even if the concern turns out to be unfounded after investigation.
This Compliance and Risk Policy is reviewed at least annually and updated as required to reflect changes in applicable law, regulatory guidance, or EPMLogic's business operations.
Questions about this policy or requests to report a concern should be directed to: info@epmlogic.com
If you have a compliance concern or a question about this policy, contact us directly. All concerns are treated seriously and handled with discretion.
Email info@epmlogic.com