Obligations and risk assessment
Confirm reporting-institution and supervisory status, then assess enterprise, product, customer, geographic, channel and transaction risk.

An AML/CFT programme must reflect the institution’s customers, products, delivery channels, geographies, merchants, counterparties and transaction behaviour. A policy copied from another business will rarely explain how risk decisions are made in the actual system.
Discuss your routeConfirm reporting-institution and supervisory status, then assess enterprise, product, customer, geographic, channel and transaction risk.
Develop CDD, EDD, PEP, sanctions, beneficial-ownership, monitoring, escalation, reporting, recordkeeping and training arrangements.
Map controls to onboarding screens, data fields, rules, case management, approval authorities, vendors and evidence.
Test files and controls, document findings, train accountable teams and establish periodic review and management reporting.
Using a generic risk assessment that does not drive onboarding, monitoring or approval decisions
Collecting documents without verifying ownership, source, purpose and expected activity
Treating sanctions, PEP and adverse-information screening as a one-time onboarding event
Writing escalation and reporting procedures that are not reflected in systems, cases, roles and evidence
We provide reporting-institution analysis, AML/CFT and customer-risk assessments, policy suites, onboarding and escalation design, vendor and rule review, board and staff training, compliance testing and remediation support.
Send a non-confidential enquiryNo. The business model, regulatory status, products, customers and statutory category determine the applicable obligations and supervisory position.
A vendor can support verification and screening, but the regulated business remains responsible for its risk decisions, oversight, escalation, records and compliance.
Review should be risk-based and triggered by legal, product, customer, geographic, system, vendor or risk changes, as well as periodic assurance requirements.