Services About Legal & Compliance Advisory Desk Partners Toolkit
Theme
Request Introduction
Service 03 · Audit · Training · Risk

Operations
& Audit.

Independent compliance audit and assurance, CPD-aligned training programmes, and risk assessment modelling for regulated fintech and digital asset firms. The ongoing compliance infrastructure that keeps authorised businesses ahead of supervisory expectations, not just compliant on paper.

Request Introduction → Free Compliance Toolkit
What We Deliver

The ongoing infrastructure
regulators expect.

01
Compliance Audit & Assurance

Independent periodic audits of compliance controls, designed to provide the board with an objective view of whether the compliance framework is working, not just whether it exists. We audit with the same rigour the FCA applies in supervisory review.

  • Scope-based audit against compliance monitoring programme
  • Controls testing, documented sampling and evidence review
  • AML/KYC specific audit, BWRA, CDD, Travel Rule, SAR
  • Thematic deep dives, Consumer Duty, SMCR, DORA
  • Board-ready report with RAG-rated findings and remediation
02
CPD Training Programmes

Tailored, CPD-aligned regulatory and financial crime training for boards, senior managers, and operational teams. Role-specific content, not generic e-learning modules. Designed to embed a genuine culture of compliance, not tick a box on an annual training record.

  • Board-level regulatory awareness sessions
  • Senior manager SMCR and personal accountability training
  • MLRo and compliance team financial crime training
  • Operational team AML/KYC and fraud awareness
  • Completion certification and CPD credit documentation
03
Risk Assessment Modelling

Enterprise risk frameworks, conduct risk models, and financial crime risk assessments built to provide the board with a structured, evidence-based view of the firm's risk profile. Outputs are designed to satisfy FCA supervisory expectations and support ICAAP / ILAAP where applicable.

  • Enterprise risk framework design and calibration
  • Conduct risk model, retail and wholesale environments
  • Financial crime risk assessment, digital asset specific
  • Risk appetite statement, board-level articulation
  • Residual risk scoring and mitigation action plans
04
Regulatory Gap Analysis

Independent assessment of the firm's compliance framework against current regulatory requirements, useful for newly authorised firms, firms preparing for supervisory review, or businesses that have grown faster than their compliance infrastructure. Prioritised remediation with clear timelines.

  • Full compliance framework review against FCA / MiCA requirements
  • Sourcebook-by-sourcebook mapping of gaps
  • Consumer Duty outcomes assessment, four outcome areas
  • DORA (EU) operational resilience gap review
  • Prioritised remediation roadmap, board-ready output
05
Supervisory Response Support

When the FCA issues a section 166 skilled person review, a Dear CEO letter, or direct supervisory feedback, the response must be precise and credible. We support firms in managing the supervisory dialogue, preparing written responses, and designing and executing remediation programmes.

  • Section 166 skilled person review preparation
  • FCA information request responses
  • Remediation programme design and project management
  • Voluntary requirement (VREQ) compliance monitoring
  • Supervisory correspondence strategy
06
Cross-Border Regulatory Monitoring

For firms operating across UK and EU jurisdictions, keeping pace with regulatory change across both perimeters is operationally demanding. We provide a monitoring and horizon-scanning service, flagging material changes to FCA, MiCA, AMLD6, and DORA requirements as they develop.

  • Fortnightly regulatory change briefings
  • FCA consultation paper and policy statement tracking
  • ESMA regulatory technical standards (RTS) monitoring
  • Impact assessments for material regulatory changes
  • Framework update recommendations
What We Audit Against

The regulatory frameworks
we test compliance with.

FCA SYSC · FCA Handbook
Systems & Controls
The FCA's systems and controls sourcebook, the primary framework for compliance monitoring, governance, and risk management in FCA-authorised firms. All audit work maps findings against SYSC requirements.
MLRs 2017 · JMLSG
AML/KYC Regulatory Standards
AML audit work tests against the Money Laundering Regulations 2017 and JMLSG sector guidance, the two frameworks the FCA uses in its own supervisory AML reviews.
FCA PS22/9
Consumer Duty Outcomes
Consumer Duty audit tests whether the firm can demonstrate good outcomes across all four outcome areas, products, price and value, understanding, and support, with evidence, not assertions.
DORA · Reg 2022/2554
Digital Operational Resilience Act
Applies to all EU-regulated financial entities including MiCA CASPs. Mandatory ICT risk framework, incident reporting, TLPT testing, and third-party monitoring requirements, all auditable obligations.
FCA PS21/3
Operational Resilience
Requires annual testing of important business service impact tolerances. Audit work verifies testing has been conducted, documented, and that the board has received and acted on the results.
ICA · CISI · ACAMS
CPD Accreditation Standards
Training programmes are designed to meet ICA, CISI, and ACAMS CPD standards. Completion documentation is provided in a format that can be submitted for CPD credit by participants.
How We Work

The engagement
model.

01
Scope Agreement

We agree audit scope, methodology, and access requirements with the board or senior management before any work begins. Output: written audit plan.

02
Fieldwork

We review documentation, interview key personnel, and test controls against the agreed scope. We access systems, records, and evidence, not just policy documents.

03
Draft Report

A draft report is shared with management for factual accuracy review. Findings are RAG-rated, root-cause analysed, and supported by specific evidence references.

04
Board Presentation

The final report is presented to the board or audit committee. We remain available to support the remediation programme and validate closure of findings.

Independent Assurance
Audit that gives the board
genuine confidence, not paperwork.
Request Introduction → Free Compliance Toolkit