Assurance
Compliance audits
Independent gap analyses and readiness reviews against MiCA, FCA, FINMA and FATF standards | findings flagged clearly, not smoothed over.
What it is
What does a compliance audit actually test?
An audit is only useful if it tells you what's actually wrong. We review your policies against current regulatory text, then test whether your real procedures | onboarding files, monitoring alerts, filings | match what the policy says should happen. Contradictions, outdated references and structural errors (like a prohibited-country list that accidentally includes EU member states) get logged explicitly, rated by severity, and handed back as a workbook you can act on.
Packages
Choose the depth of review you need
Desk Review
Policy Audit
A focused review of your written policies and procedures against current regulatory text.
Get started- ✓Policy & procedure review
- ✓Severity-rated findings log
- ✓Sample file testing
- ✓Country risk list validation
- ✓Remediation support
Full Review
Programme Audit
Policy review plus sample testing of onboarding files, monitoring alerts and filings.
Get started- ✓Policy & procedure review
- ✓Severity-rated findings log
- ✓Sample file & alert testing
- ✓Country risk list validation
- ✓Remediation implementation support
Audit + Fix
Audit & Remediate
Full programme audit plus hands-on support implementing the fixes.
Get started- ✓Everything in Programme Audit
- ✓Remediation roadmap with ownership
- ✓Hands-on policy rebuild for flagged items
- ✓Re-test on closure
In detail
What's inside the service
Structured findings log
Every finding rated by severity and delivered as a multi-tab workbook, not a narrative report.
Country risk list validation
Prohibited and high-risk jurisdiction lists checked against current FATF, sanctions and EU/EEA membership.
Policy consistency checks
Internal contradictions | like conflicting PEP provisions | surfaced explicitly rather than glossed over.
Sample file testing
A representative sample of onboarding files and monitoring alerts tested against stated procedure.
Remediation roadmap
Findings translated into a prioritised action list with clear ownership and timelines.
Regulator-ready evidence
Documentation formatted the way an examiner expects to see it, not just internally.
FAQ
Frequently asked questions
What does a compliance audit deliver?+
A structured findings log rating each gap by severity, a validated country risk list where relevant, and a remediation roadmap with clear ownership and timelines.
How long does an audit take?+
A Policy Audit typically takes two to three weeks. A Programme Audit including sample testing of files and transactions usually runs four to six weeks.
Do you deliver findings as a report or a spreadsheet?+
Findings are delivered as a structured, multi-tab workbook rather than a narrative report, so findings can be filtered, prioritised and tracked to closure.