Preparing for Windows 11 26H2: A...
Windows 11 version 26H2 is expected later in 2026, bringing changes to recovery, resilience and the Windows update experience. This...
Read MoreI’m Emmanuel Charlot, a consultant at AJC specialising in risk management, fraud prevention and technical and governance-focused writing.
I have close to 30 years’ experience in the payments industry, and my work is centred around helping organisations understand and manage risk, strengthen their controls and build greater resilience in an increasingly complex payments and digital environment.
I have been working with AJC for six years. I first joined the team following a recommendation from Natasha Cummings, when I took part in a Visa Global Acquirer Risk Standards (GARS) review for a high-profile client facing scrutiny from both the card payment schemes and the German financial supervisory authority.
At AJC, I work with businesses and financial institutions to strengthen their approach to risk management, fraud prevention and wider resilience.
My work can involve conducting detailed risk assessments, evaluating existing controls and helping organisations understand how well their processes align with card-scheme requirements, regulatory expectations and industry good practice.
A key part of my role is identifying vulnerabilities that could expose a client to financial or reputational loss or operational disruption. Just as importantly, I help translate those findings into clear and actionable recommendations, whether that involves developing technical or procedural documentation, policies, remediation plans or longer-term strategies.
No two engagements are exactly the same. The risks, regulatory environment, organisational maturity and commercial priorities of each client can be very different, so my approach needs to reflect the individual circumstances of the organisation rather than applying a standard template.
The range of projects I have worked on with AJC reflects that variety. These include GARS reviews, high brand risk applications and merchant onboarding, card-scheme compliance work, risk remediation roadmaps, risk management policies and procedures, SWIFT CSCF assessments and ESG implementation roadmaps. I have also developed technical specifications for fraud solutions and worked on automating repetitive and resource-intensive assessment tasks.
I aim to give clients a rigorous but proportionate approach to risk management, helping them strengthen their operational resilience while meeting relevant card-scheme and regulatory expectations.
An engagement might begin with a detailed risk assessment or gap analysis. I look at the organisation’s control environment through a card-scheme, regulatory and commercial lens, identifying areas of vulnerability and helping the client understand both the likelihood and potential impact of those risks.
From there, I can help develop remediation strategies and implementation roadmaps that reflect the client’s particular exposure, level of maturity and longer-term objectives.
My consultancy work can also involve helping clients develop ESG roadmaps, embedding greater business resilience through good governance, ethical decision-making and appropriate controls.
This can involve assessing an organisation’s current ESG maturity, governance arrangements and existing policies, before identifying relevant risks, obligations and stakeholder expectations. I can then help establish priorities, responsibilities, measurable objectives and a practical implementation roadmap, embedding ESG into the organisation’s wider governance framework and business processes.
Consistency and transparency are important to me. Clients should understand why a recommendation is being made, the principles behind it and what the proposed control is intended to achieve.
I promote replicability, a fail-fast mindset and a risk-based approach, encouraging organisations to identify weaknesses early rather than allowing them to become larger problems. That means testing assumptions, addressing issues decisively and embedding resilience into processes from the outset rather than adding controls after something has gone wrong.
In practice, a fail-fast mindset means having the authority, processes and tools in place to identify potential failures early and take timely corrective action. In areas such as merchant onboarding, financial risk underwriting or transaction monitoring, this can include setting pre-approved risk thresholds, giving teams clear authority to escalate or stop a process and testing remedial options before a weakness develops into a more significant risk.
My approach is deliberately tailored rather than templated. Effective risk management should be proportionate to the organisation and the risk it faces, rather than introducing complexity for its own sake.
Building trusted relationships is also an important part of the way I work. I want clients to feel that they understand the risks they face and are better equipped to manage them after an engagement with AJC.
Ultimately, the aim is not simply to meet today’s requirements. It is to help organisations anticipate their event horizon, maintain their competitive edge and build resilience that allows them to grow securely in an evolving payments landscape.
For me, anticipating the event horizon means considering the potential impact of change before it is fully implemented. A change to a transaction monitoring rule, for example, might be driven by new fraud patterns, regulatory requirements or changes in customer behaviour. Assessing the likely impact, testing the proposed change and monitoring its early performance allows an organisation to refine its approach before a significant fraud event or control failure occurs.
I bring close to 30 years’ experience in the payments industry, with a career spanning risk management, fraud prevention and the wider controls needed to protect organisations operating in the payments ecosystem.
My experience covers the full lifecycle of fraud control, including fraud detection and prevention, management information, gap analysis, operational requirements and compliance. This has given me a broad understanding of how different elements of a business need to work together to manage risk effectively.
My career has included roles with Visa International and Visa Europe, Mastercard, Payvision and Optal, giving me experience across many different areas of the payments ecosystem. At Visa, my work encompassed card payment processing, authorisation, clearing and settlement, exception management, compliance, business intelligence and fraud and risk management. My subsequent roles broadened that experience into areas including cardholder authentication, high-risk acquiring and merchant onboarding, transaction monitoring, virtual card issuance and the design and implementation of fraud and third-party risk solutions.
Over the course of my career, I have seen both the payments landscape and the nature of fraud change significantly.
When I began my career, many of the major developments were around the rollout of card acceptance, ATMs and technologies such as CVV, PIN and Chip. Since then, we have seen exponential growth in online payments and banking, followed by mobile and contactless payments and increasingly complex third-party payment models. At the same time, the risks have evolved, from the growth of cross-border and online fraud to deceptive merchant models, mule accounts, authorised push payment fraud and, more recently, AI-enabled fraud.
That breadth of experience has taught me the importance of looking beyond an individual control or immediate problem. Effective risk management requires an understanding of the wider business, the environment in which it operates and how decisions in one area can create consequences elsewhere.
What I enjoy about consulting is the opportunity to apply that experience to different organisations and different challenges.
AJC works with clients across a broad range of areas, including cyber security, fraud prevention, risk management, compliance and business resilience. Being part of that team means I can bring my own specialist knowledge while also drawing on the wider experience within the business.
I particularly enjoy the international nature of AJC’s client base and the variety of engagements we undertake. The team also brings together people from a wide range of professional backgrounds, which creates plenty of opportunity for knowledge sharing and for me to continue expanding my own expertise and the areas in which I work.
For me, good consultancy is about more than identifying what is wrong. It is about helping a client understand the issue, determine what matters most and establish a practical route forward.
The greatest satisfaction comes from leaving a client in a better position than when the engagement began, with greater risk awareness and stronger risk management embedded in its processes. That might mean successfully completing a high brand risk application, helping an organisation gain a competitive edge through better risk practices or putting in place the foundations for greater long-term resilience.
When I encounter a problem that appears difficult to resolve, I have a personal method that has served me well throughout my career.
Rather than continuing to push at the problem, I deliberately stop, clear the noise and return to it just before I fall asleep. Giving my mind the opportunity to process the issue without the constraints of active analysis often allows me to see connections or possible solutions that were not obvious earlier in the day.
By the time I wake up, I will often have a different perspective or a clearer route forward. It is a useful reminder to me that sometimes solving a complex problem is not about thinking harder, but giving yourself enough space to think differently.
Outside work, I also enjoy crafting and gardening, which give me an opportunity to switch off from the world of payments, fraud and risk.
If your organisation is looking for specialist support with fraud prevention, risk management, payments or wider business resilience, please get in touch with AJC.
Our team can help you understand the risks facing your organisation, identify practical improvements and develop an approach that reflects both your regulatory obligations and your wider business objectives.
Contact us on 020 7101 4861 or email us at info@ajollyconsulting.co.uk if you think we can help.
Windows 11 version 26H2 is expected later in 2026, bringing changes to recovery, resilience and the Windows update experience. This...
Read MoreA recent cyber security incident affecting London Stansted Airport has highlighted the risks associated with customer data, even when financial...
Read MoreWhen a data breach is attributed to human error, the underlying cause may extend far beyond the actions of one...
Read More