Strategies

Our investment teams have distinct strategies and focus on investing in mid-market companies in a variety of sectors in the US and Europe.

Our investment teams have distinct strategies and focus on investing in mid-market companies in a variety of sectors in the US and Europe.

Flexible capital and strategic assistance for market-leading companies in high-growth sectors in North America and Europe

Equity capital for mid-sized companies in the DACH region and Italy

Growth capital and strategic assistance to software companies throughout Europe

Impact platform investing in climate and nature-based solutions

Equity capital for founder-owned companies in consumer and multi-unit, food and beverage, and business services

Private equity primaries, co-investments, and secondaries across North America and Europe

Based in New York, the group will invest globally in both LP and GP-led transactions, leveraging Bregal’s GP relationships and network of eight offices worldwide

Report Menu
Cyber + Responsible AI 1920X1080

Responsible Investment Report 2025-26

Cybersecurity and AI Readiness

At Bregal, we’ve made it a priority to support our companies in adopting cyber best practices.[[1]]

We focus on assessing the risk landscape during diligence, implementing immediate improvements and defining long-term roadmaps to drive resilience.

94%
OF COMPANIES

have data privacy and security policies[[1]]

82%
OF COMPANIES

have conducted or plan to conduct penetration testing in Next Twelve Months[[1]]

Istock 1408211250

One important pillar of our responsible investing program is integrating tech and cyber due diligence into every prospective investment evaluation.

STEP 1

Due Diligence

We work with third-party providers to assess a company’s data governance, incident response plans, and IT infrastructure where applicable.

STEP 2

Roadmap Creation

The insights enable a tailored security roadmap for each portfolio company, flagging the highest-priority actions to pursue during the holding period. To benchmark progress, independent experts are engaged who assess cybersecurity hygiene against essential controls mapped to industry standards such as CIS v8.

STEP 3

Implementation and Monitoring

Since adopting this approach, we have driven performance  in our portfolio companies cyber resilience via strong governance and risk mitigation processes. We aim to further develop our program by supporting portfolio companies in identifying appropriate cyber insurance, ensuring a consistent level of protection and further mitigating risks associated with cyber incidents.

AI Readiness

AI-driven products are increasingly shaping decision-making in technology and services businesses.

At Bregal, we are optimistic about AI-driven innovation, while also recognizing the potential risk landscape introduced from lack of transparency, data misuse, or unintentional bias. Our goal is to help companies harness AI’s advantages while minimizing any human rights and/or environmental impacts from energy usage introduced in specific product and operational use cases. 

64%
OF COMPANIES HAVE IMPLEMENTED AI ACCEPTABLE USE POLICIES

We are working closely with companies to innovate while establishing product safeguards and maintaining customer trust.

Portfolio Case study[[2]]

Strengthening Responsible AI Governance 

M-Files, a provider of an intelligent, repository-neutral platform, has the mission to transform how companies do business in the digital, work-from-anywhere world.

M-Files’ AI-powered intelligent information management connects siloed systems, applications and repositories and provides a full view of all relevant information across an organization. 

Istock 1746213675

Regulatory compliance:
M-Files has assessed its AI applications against the EU AI Act to understand transparency requirements, assess organizational maturity and determine focus areas for compliance and internal risk management.

Governance:
Accountability for AI governance sits with the Executive Leadership team, and AI-related matters are regularly discussed at the Board. A dedicated team of AI specialists oversees  AI deployment across product and operations, and evaluates how AI can support the company’s long-term strategic direction.

Risk management:
M-Files has embedded human-in-the-loop processes and incident response procedures to help ensure accuracy, safety, and adherence to ethical standards, while enabling timely identification and mitigation of potential risks. AI vendors are evaluated for IT security risks, and end-users are informed when interacting with AI-enabled systems.

Responsible AI KPIs

Icons8 Requirements
AI Acceptable Use Policy
Icons8 Tick (1)
Implementing internal guidelines for responsible AI

Istock 2204416287
Portfolio Case study[[4]]

Scaling Regulatory Intelligence with Responsible AI

Enhesa tracks EHS regulatory changes across 300+ jurisdictions worldwide. To keep pace with this volume, the company built an AI-powered content factory: an LLM-based pipeline that generates regulatory summaries from vetted legal sources, with structured human review at every stage. What previously required extensive manual drafting now runs largely automated, reducing content approvals to seconds, freeing Enhesa’s regulatory experts to focus on the judgment calls AI can’t make: interpreting ambiguity, weighing jurisdictional nuance, and connecting regulatory signals to client impact.

Enhesa’s responsible AI integration  in its product launches has been forward-leaning:

  • Human in the loop: Every piece of customer-facing content passes through human review before publication, with reviewers able to intervene at any stage.
  • Defined success metrics: Output quality is monitored using true and false positive and negative rates, with models tuned to minimize false negatives.
  • Governance: Enhesa is bringing on a dedicated AI governance Lead to strengthen their governance and accountability.
Portfolio Case study[[4]]

Improving Healthcare Compliance Through Responsible AI

Large medical institutions rely on both internal and external audits to manage compliance and revenue integrity, but historically these have sat in separate systems. MDaudit, a healthcare revenue integrity and billing compliance software, built an AI feature that allows end users to upload external audit documents directly into the platform. The system then automatically scans documents, identifies key fields, and surfaces relevant findings to the user, connecting the dots between external and internal audits in one place. The second AI feature empowers end-users to query their own data using plain, conversational language to deliver real-time insights on demand, without relying on ad hoc reports.

Generic Header 28 Abstract tech landscape

MDAudit has developed a mature, responsible AI approach:

  • Governance and controls: Established a dedicated Data Security and AI Committee, adopted an AI Acceptable Use Policy in 2024, and achieved HITRUST’s AI certification of over 400+ controls with zero corrective action plans
  • Human in the loop: Users have a mechanism to validate or flag  AI-extracted findings, which feeds back into ongoing quality improvements
  • Leadership: MDAudit’s CEO is a public advocate for human oversight in AI-driven healthcare revenue cycle management, reinforming leadership accountability

AI at Bregal

Aside from our portfolio company engagement, at Bregal, we’ve designed the following internal policies, which have allowed us to establish guidelines and responsibly support technological innovations:

Icons8 Requirements

AI Acceptable Policy

Informs employees of the risks associated with AL Models and outlines guidelines for the use of AI Models at the firm.
Icons8 Security Shield

AI Risk Framework[[3]]

Identifies and mitigates potential risks related to AI ethics at every stage of the AI lifecycle. This framework aligns with emerging regulations. such as the EU AI Act and the OECD AI Principles.
Icons8 Chain

AI Trustworthy Principles

Aims to ensure that potential AI systems developed by Bregal are used in a responsible, ethical, transparent, and accountable manner. This includes ensuring that AI systems are designed to respect human rights, prevent harm, remain compliant, and operate fairly and non-discriminatorily.

Disclosure: While Bregal Sagemount is part of the Bregal platform, it applies its own responsible investment policies and procedures. None of the Bregal policies and procedures apply to Sagemount unless expressly stated by Sagemount. Sagemont does utilize and share certain resources and benefits from certain synergies and efficiencies from the Bregal platform, including with respect to responsible investing.

Disclosure