When the legal answer is only part of the problem.

ITLawCo works alongside sophisticated in-house teams at large regulated organisations — financial institutions, insurers, manufacturers — on the technology, data and AI decisions where legal analysis has to become something the organisation can actually use.

The problem we solve

Translation burden

Advice on complex technology, data and AI matters typically leaves the client to do the integration.

Legal produces an answer. Technology asks what it means operationally. Risk asks how it becomes a control. Project management asks who owns what. Business asks what it can actually do. Someone internally spends enormous energy translating between all of them.

This is translation burden. It’s invisible in every fee arrangement and expensive in every organisation. It’s why programmes stall between advice and implementation — not because the advice is wrong, but because turning it into decisions, controls, contracts and processes falls to teams already at capacity.

Sophisticated in-house teams recognise translation burden the moment it’s named. They pay it constantly. Most advisers don’t see it because they don’t feel it — their engagement ends at the memo.

ITLawCo is built to absorb it.

How we work

Three disciplines. One team.

Complex technology, data and AI decisions rarely sit inside one discipline. Ours doesn’t either.

Legal judgment answers what is required, permitted, prohibited, or defensible. This is the anchor. Under privilege where appropriate. Correct on what the law says, and grounded enough in technology to know what the law is being asked to govern.

Operational and systems analysis answers where that answer must live — in which processes, systems, roles, and controls. This is the discipline that tests whether the legal answer survives the organisation as it actually exists.

Disciplined delivery answers what has to happen, through whom, by when, for the result to become real. This is the discipline that makes sure engagements move — through stakeholders, workstreams, evidence, and deadlines — and that the artefacts we produce are usable by the people who have to use them.

Every engagement is tested against all three. We don’t sell one and add the others on request. It’s the same three principals in the room.

Who we work with

Sophisticated in-house teams. Consequential decisions.

Financial institutions, insurers and manufacturers are our most consistent clients. Other regulated organisations too, where the problem has the same shape: material technology dependence, meaningful regulatory exposure, and internal teams sophisticated enough to know what they need from us.

Financial services

Banking, capital markets, payments. We work with legal, risk, data, and technology functions on AI in credit and risk decisioning, model governance and data lineage, major technology outsourcing and cloud programmes, third-party technology risk, and regulator-facing programmes.

Insurance

Life, non-life, reinsurance, insurance technology. Our work covers algorithmic underwriting and claims governance, distribution and claims technology, cross-border data governance across African markets with divergent privacy regimes, and the operational discipline required when the regulator, the actuary, and the technology team are all in the room.

Manufacturing

Industrial, consumer, and technology-adjacent manufacturing. Our work covers ERP and industrial-platform programmes across jurisdictions, ICT procurement at enterprise scale, OT/IT convergence and cybersecurity, AI in production and quality, and the contractual architecture that holds complex vendor ecosystems together — including legacy systems, systems integrators, and production-critical SLAs.

We also work with organisations outside these three sectors where the problem clearly fits our shape. If that sounds like you, get in touch.

What this looks like in practice

The pattern we see across engagements

An engagement typically begins with a client bringing us a problem framed as legal. Discovery usually shows the question is structural rather than tactical. We design a decision architecture the client can use — not a document to file. Engagements evolve.

Here’s how that has played out.

Financial services / Insurance

The client asked a legal question. The answer required an operating model.

A multi-market financial services group wanted to use a major messaging platform for customer communications — contractual, servicing, and account-related.

The instruction appeared narrow: determine what consent, notices and customer wording were required.

It wasn’t.

Discovery showed that customer communications crossed multiple systems, consent and preference data was fragmented across sources, logging and retrieval practices varied, and accountability was distributed across Legal, Compliance, Technology, and Operations. No single function held the complete picture. A well-drafted consent clause would have solved almost nothing.

We ran an intensive discovery and architecture phase across four business functions. We mapped customer communication pathways, systems and integration dependencies, consent and preference data, logging and evidentiary requirements, retention, and operational ownership. We designed a Consent Lifecycle Architecture connecting legal requirements to systems, controls, records, and customer journeys.

The narrow legal instruction became a multi-month enterprise transformation programme: current-state architecture, target-state design, control and logging requirements, records and retention, operating procedures, customer migration readiness, and assurance.

What the client got

  • One shared model of how the channel was supposed to work — legally, technically, and operationally
  • Ownership clarified across Legal, Compliance, Technology, and Operations
  • Retention and evidentiary requirements designed into the channel, not bolted on
  • A narrow compliance instruction converted into a structured transformation roadmap

What happened after

The discovery phase materially changed the scope of the client’s programme. What began as a bounded advisory instruction became an ongoing relationship covering broader implementation and governance work. The value of the original engagement compounded: subsequent decisions could be assessed against an architecture that already existed.

Client details anonymised to protect confidentiality. Real engagement, real outcomes.

The team

There are three of us.

ITLawCo was founded by Nathan-Ross Adams, a former General Counsel who had been on the receiving end of outside counsel. He knew what good and bad legal support felt like from inside the business — and built the practice around what he wished he had been able to buy.

The team has grown around that idea.

Nathan-Ross combines legal practice with data science training and deep experience in ICT contracting, data protection, and AI.

Jesica brings operations and systems analysis, interrogating the processes, systems, and control environment our advice has to work in.

Amy-Rae leads project delivery and user experience — keeping complex engagements moving across stakeholders, workstreams, and deadlines, and making sure the artefacts we produce work for the people who have to use them.

The combination is deliberate. Good advice is not enough if it cannot work in the client’s operating environment, cannot be used by the client’s teams, or leaves the client to manage the machinery around it. We take responsibility for the substance, the delivery, and the experience of the work.

When an engagement calls for specialist expertise beyond the core team, we bring in trusted collaborators we have worked with and can vouch for. Accountability stays with us. Senior attention does not dilute, and the people leading your work remain directly involved.

Based in Cape Town. Working across jurisdictions.

Recent insights

Field notes.

Analysis on the questions our clients bring us — regulatory, operational, strategic. Written for the people who have to make the decisions.

04/09/2026 in Data protection and privacy

Information Regulator briefing 2026: POPIA and PAIA update

The Information Regulator media briefing on 31 August 2026 set out where POPIA and PAIA enforcement now stands: more than 8,000 security compromise notifications since commencement, an enforcement notice against…
Read More
18/08/2026 in Policy lifecycle management

How to review corporate policies systematically

Systematic corporate policy review is the structured process of testing whether a policy or related governance instrument is legally sound, appropriately authorised, operationally workable, internally coherent, auditable, and clear enough…
Read More
02/07/2026 in Data protection and privacy

Mauritius DPO Regulations 2026: What businesses must do by 1 January 2027

Mauritius has put its data protection officer regime on a statutory footing. The new regulations take effect on 1 January 2027, and on one key point, they reverse what the…
Read More

Contact

Let's talk about what you're navigating.

Initial conversations are exploratory and confidential. If you’re weighing a technology decision, sitting with a regulatory question, or feeling that your current outside counsel isn’t quite catching what you need — reach out. If we’re not the right fit, we’ll tell you.

Cape Town · Working across jurisdictions · support@itlawco.com