About

How We Engage

Operational trust before you commit.

Fixed-Scope SOW Model

Every engagement begins with a written Statement of Work (SOW) that defines scope boundaries, deliverables, assumptions, exit criteria, and dependencies. We do not default to open-ended retainers. If a client asks for one, we discuss why and structure the retainer with 90-day exit clauses and defined scope boundaries. Our preference is fixed-scope work with clear milestones, even when engagement duration extends beyond 12 weeks.

What this means for you: You know what you are paying for and when the engagement ends. No billing surprises. No scope creep that erodes your budget without your knowledge.

Sample Deliverables

1

Statement of Work (SOW)

Written scope document defining objectives, deliverables, assumptions, timelines, and pricing. Reviewed by legal counsel on both sides before execution.

2

Deliverable Specification

Technical and operational specification for implementation work. Includes data flow diagrams, system integration points, testing requirements, and go-live criteria. Used as the acceptance baseline for UAT.

3

UAT Test Plan

Structured test script covering functional validation, error handling, data migration accuracy, and performance thresholds. Designed to be executed by client operations staff; no external tooling required.

4

Go-Live Readiness Checklist

Pre-deployment checklist covering access provisioning, fallback procedures, training completion, and post-go-live support setup. Includes a 30-day hypercare support window at no additional charge.

5

Implementation Close-Out Report

Written summary of what was delivered, what was tested, what remains open, and recommendations for next-phase work. Includes actual vs. planned scope delta with documented rationale.

6

Compliance Mapping Document

For regulatory-driven projects: detailed mapping of current state vs. target state against a specific regulatory framework (e.g., UCITS, AIFMD, MiFID II). Includes control owner assignments and remediation priority.

Data Confidentiality Posture

No data retention post-engagement. Client data — including portfolio data, system configurations, operational procedures, and communications — is not retained after engagement completion. Any working copies held during the engagement are destroyed within 30 days of engagement close, confirmed in writing.

NDA standard. All engagements are covered by a mutual NDA executed before work begins. The NDA is not a one-time consent form — it is an active agreement with defined confidentiality periods (minimum 3 years from execution) and explicit carve-outs for legally required disclosures.

Working data isolation. During the engagement, client data is stored in dedicated, access-controlled environments. We do not use shared development environments for client data. System access is restricted to personnel directly assigned to the engagement.

No secondary use. Client data is not used for benchmarking, marketing, product development, or any purpose other than the defined engagement deliverables. This is contractually prohibited, not just policy.

Data residency. For institutional clients with specific data residency requirements, we can accommodate controlled access models where data remains in your environment. Discuss this before engagement start; retrofitting is not always possible.

Security Practices

We are prepared to complete standard enterprise security questionnaires (SIGLite, CAIQ, custom vendor risk assessments) on request. Response time is 10 business days for initial submission. We do not provide custom security questionnaires to clients who have not signed an NDA.

Current Security Posture

  • Infrastructure: Cloud-based delivery using isolated, access-controlled environments. No on-premise infrastructure required.
  • Access management: Role-based access control (RBAC) with least-privilege principles. Multi-factor authentication enforced. Access logs retained for minimum 90 days.
  • Encryption: Data in transit via TLS 1.2+. Sensitive data at rest encrypted using AES-256 or equivalent. Encryption keys managed via cloud-native key management services.
  • Vulnerability management: Regular patching cadence aligned with vendor release cycles. Annual third-party penetration test (most recent: 2025). Results available under NDA to prospective clients with legitimate security review requirements.
  • Incident response: Documented incident response procedures with defined escalation paths. Client notification within 72 hours of confirmed breach affecting their data.
  • Business continuity: Documented backup and recovery procedures. Recovery time objective (RTO) for critical systems: 4 hours. Recovery point objective (RPO): 1 hour.

Certifications and Compliance

We are in the process of obtaining SOC 2 Type II certification (target completion: Q4 2026). We maintain GDPR compliance for EU-based client engagements.

No Referral Conflicts

PBW Professional Services L.L.C. does not accept referral fees from software vendors, implementation partners, or service providers. We have no reseller agreements with any technology vendor. We do not recommend specific technology stacks in exchange for referral payments, revenue sharing, or kickbacks. We do not accept finder fees for introducing clients to other service providers.

When we recommend a technology platform — e.g., Bloomberg AIM, Charles River Development, or any other OMS/EMS — the recommendation is based solely on fit for the client's operational requirements. We have no financial incentive tied to which platform you select.

We do not receive volume rebates, referral fees, or training commissions from technology vendors. Our revenue comes entirely from client fees for consulting services.

Disclosure practice: If any third-party compensation arrangement, referral offer, or vendor incentive could affect a shortlist or recommendation, it is disclosed before advice is given.

Competitive neutrality: We work with all major buy-side technology platforms and are not exclusive to any vendor. Our recommendations are driven by your operational requirements, not by vendor relationships.

Contract and Legal Readiness

Contract Structure

  • Master Services Agreement (MSA): Governs the overall relationship, including confidentiality, intellectual property, liability caps, and dispute resolution. One-time execution; applies to all subsequent SOWs.
  • Statement of Work (SOW): Project-specific scope document referencing the MSA. Each SOW is a standalone contract with its own pricing and timeline.

IP Ownership and Liability

Client retains all rights to work product created specifically for their engagement. Our methodology frameworks and templates remain our intellectual property. Total liability under any engagement is capped at fees paid for the applicable SOW. This is negotiable for multi-phase engagements above $100K.

Legal Review Timelines

  • MSA review by client legal: Typically 2–4 weeks, depending on internal review process.
  • SOW review: Typically 3–7 business days.
  • Bespoke contract terms: We accommodate reasonable client contract modifications. Complex redlines or non-standard terms may require additional review time (1–2 weeks).

Every engagement is governed by a signed contract and project-specific SOW. Engagements do not begin work until contracts are fully executed.

Client Responsibilities

Engagement success depends on timely inputs from the client side. Here is what we require and when.

Access Provisioning

  • System access for any platform in scope (test environments sufficient for early phases)
  • VPN or remote access credentials if applicable
  • Access provisioning within 5 business days of SOW execution

Stakeholder Availability

  • Named engagement owner — single point of contact with authority to make decisions
  • Access to subject matter experts for technical and operational questions (response within 2 business days)
  • Decision-maker availability for milestone reviews (monthly minimum)

Data Handover

  • Historical data exports in standard formats (CSV, Excel, XML) — we will not handle manual data entry
  • Documented data dictionary or schema for any custom database exports
  • Data handover within 10 business days of SOW execution

Testing Resources

  • For implementation engagements: minimum 2 designated UAT testers available in the 2 weeks prior to go-live
  • UAT tester access to production or staging environment

What Happens If Inputs Are Delayed

  • Engagement timeline extends with no additional cost to you (for delays caused by client-side factors)
  • We document all delays in a shared issue log
  • If delays exceed 30 days from projected date, we re-scope the SOW in writing — no surprise billing

What We Do Not Require

  • We do not require access to your production trading systems during discovery phases
  • We do not require executive sign-off on every detail — we work with operational staff and escalate strategically
  • We do not require you to have a completed RFP before engaging us — we can work from a brief

Typical Timelines

Engagement Duration by Type

Engagement Type Typical Duration Scope
Assessment 4–8 weeks Current-state review, gap analysis, recommendations. Fixed price.
Sprint 6–12 weeks Defined problem, specific deliverable. Fixed price.
Full Implementation 12–24 weeks End-to-end delivery including UAT, go-live, and hypercare. Fixed price with defined milestones.
Advisory Retainer 12 months (rolling) Ongoing access to senior advisory resources. 90-day exit clause. Monthly billing.

Assessment Engagements

  • Weeks 1–2: Stakeholder interviews, document review, environment access
  • Weeks 3–4: Technical analysis, data review, operational assessment
  • Weeks 5–6: Findings documentation, recommendation development
  • Weeks 7–8: Draft delivery, review cycle, final report

Output: Written assessment with prioritized findings and recommendation roadmap. No implementation is included in a standard assessment.

Implementation Engagements

  • Phase 1 — Setup (4–6 weeks): Environment provisioning, configuration, data migration setup
  • Phase 2 — Build (6–12 weeks): Core configuration, integration development, testing environment setup
  • Phase 3 — UAT (3–4 weeks): Client testing, issue resolution, sign-off
  • Phase 4 — Go-Live (2–4 weeks): Deployment, cutover, hypercare

Timelines assume client-side inputs are provided on schedule. Delays on client side extend timelines proportionally.

Change-Order Governance

We do not begin work outside of defined scope without a written change order. This is not a technicality — it is the mechanism that protects you from billing surprises.

Change-Order Process

  1. Identification: Either party can identify a scope change. We document it in writing within 2 business days.
  2. Impact assessment: We provide a written impact statement covering timeline, cost, and resource implications. No verbal estimates.
  3. Approval: Client written approval (email acceptable) required before work begins on scope changes.
  4. Execution: Work proceeds under a revised or supplemental SOW.
  5. Documentation: All scope changes are logged and reflected in the final engagement close-out report.

What Qualifies as a Scope Change

  • Client requests work that falls outside the original SOW boundaries
  • Client provides materially different data or requirements than assumed in the original SOW
  • External events (regulatory changes, market events) require work not originally anticipated
  • Client requests acceleration that requires additional resources

What Does Not Require a Change Order

  • Clarifications of existing deliverables
  • Reasonable adjustments to deliverable format (e.g., PDF vs. Word)
  • Questions and review comments on draft deliverables
  • Minor adjustments to timeline within the existing scope

Client Protection

If we begin work that we believe is outside scope without a change order, you are not obligated to pay for it. We will document and justify any out-of-scope work at your request before billing.

We will never bill you for work you did not approve. This is non-negotiable and is reflected in our contract language.

Ready to scope an engagement?

Book a 30-Minute Call

Use the call to confirm fit, required evidence, likely engagement model, and the right next step.