Compliance

Compliance as a service

An outsourced compliance function and fixed scope projects for payment and crypto companies in the EU and Canada. From frameworks and licence applications to the day-to-day running of compliance.

Contact us

When this is for you

A licence ahead, no compliance team yet

You are applying for a licence or registration and the regulator expects a working compliance framework before you have hired one person for it.

Your officer is drowning in operations

The appointed officer spends days on alert triage and file reviews instead of judgement calls. The routine can be handed over; the responsibility stays clear.

An inspection or audit is coming

A date is set and the documentation has gaps. You need them found and closed before the regulator does.

Two ways to engage

Engage us for a fixed project, ongoing operational support, or both.

Consulting projects

Fixed scope and fixed dates: a gap assessment, an AML or ICT risk framework, a licence application, remediation after an audit. You receive filing-ready drafts for your review and approval, together with the source files.

Outsourced compliance function

Our team runs your compliance operations under your appointed officer: transaction monitoring reviews, periodic client reviews, the reporting calendar and support in correspondence with the regulator.

Reload team runs the routine Your appointed officer mandate and judgement Regulator prepared work oversight and sign-off reports

What we cover

Six areas, one team. Each engagement picks the areas that apply to your licence and stage.

AML and KYC

  • AML and CFT policy set
  • Business-wide risk assessment
  • Client scoring and KYC guideline
  • Enhanced due diligence and adverse media screening
  • Transaction monitoring scenarios
  • Staff training and its records

DORA and ICT risk

  • Gap analysis against DORA
  • ICT risk management framework
  • Register of information
  • Incident procedures and reporting
  • ICT third-party contract reviews against Article 30

MiCA

  • Readiness review for CASP applicants
  • The documentation set for the application
  • Support during the regulator's follow-up questions

Licensing

  • Payment institution and small-scale licences in the EU
  • MSB registration in Canada
  • Application drafting and regulator dialogue

Regulatory reporting

  • A reporting calendar per licence
  • Supervisory returns, prepared or reviewed
  • The records a supervisor asks to see

Audits and inspections

  • Preparation before an inspection
  • Responses to regulator findings
  • Remediation plans with owners and dates

The rhythm of an outsourced function

What running your compliance looks like once it is set up. The cadence is agreed per client; this is the usual shape.

Monthly Quarterly Annually and the cycle repeats

Monthly

  • Transaction monitoring review
  • Sanctions and PEP screening runs
  • Alert triage with case notes
  • A short management summary

Quarterly

  • Periodic client file reviews
  • Control testing and quality assurance
  • Management report
  • Regulatory watch digest

Annually

  • Business-wide risk assessment refresh
  • Policy and procedure review
  • Staff training
  • Audit preparation and support

Typical engagements

The shapes most of this work takes.

A CASP applicant in the EU

Readiness review of the draft application, the missing policy set written, answers to the regulator's follow-up questions.

A payment institution before an inspection

A walkthrough against the inspection agenda, gaps closed in documentation and records, staff prepared for the interviews.

A Canadian MSB building its program

A FINTRAC-aligned compliance program from scratch: policies, risk assessment, reporting procedures and training.

Where we work

Hands-on work with regulated companies in each of these perimeters, not textbook knowledge.

  • European Union

    A CNB-supervised payment company operates inside our group, and our DORA, MiCA and AML work runs across EU jurisdictions. We know the supervisor's forms, language and rhythm first-hand.

  • Canada

    MSB registration and FINTRAC obligations: compliance programs, reporting, and the RPAA regime for payment providers.

Who does the work

People who write and maintain compliance documentation for regulated financial companies as their daily work, in the field since 2017. The team holds European and international compliance certifications, and the CEO is completing CAMS.

Training on live cases

We have worked in compliance since 2017 and train teams on what actually happens, not on slide decks.

  • AML and CFT training for operations, management and the board
  • Anonymised live cases from payment practice: real alerts, real files, real decisions
  • Onboarding sessions for new joiners in regulated roles
  • Attendance and content records, ready for the supervisor

Delivered as in-house training for your team. Where a jurisdiction requires an accredited training provider, we say so up front.

How an engagement starts

From a first email to running work.

  1. Describe your setup

    Licence or licence plans, jurisdictions, products, and what documentation exists today.

  2. Assessment

    We review what you have and come back with a gap list and a fixed scope proposal.

  3. Project or retainer

    Project work ships against fixed dates. An outsourced function runs on a monthly rhythm with agreed deliverables.

Tell us where you stand

Write what you run or plan to run, and in which jurisdiction. We will reply with an initial view of what applies and a proposed scope.

Contact us