Home / About

Built for practical risk decisions

Riskill Consulting Limited is an independent compliance and risk advisory firm focused on financial crime compliance and enterprise risk management for African financial institutions. Registered in Kenya; delivered remotely and on-site across East, West and Southern Africa.

Leadership & capability

Credentials, not personalities

Engagements are led by a senior practitioner and supplemented by a specialist bench scoped to the mandate. Full names, CVs and references are provided directly to clients under engagement or formal tender, subject to confidentiality.

Specialist bench — scoped to the engagement

Financial crime specialists

AML/CFT/CPF, sanctions/TFS, KYC/CDD/EDD, transaction monitoring and STR/SAR governance.

ERM & operational risk specialists

Risk governance, RCSA, KRIs, operational risk, third-party risk and board reporting.

Digital, data & fraud specialists

Digital channels, fraud controls, transaction analytics, sampling and evidence testing.

Riskill supplements the lead with consultants and analysts covering sanctions/TFS, digital channels and fraud, data analytics, cybersecurity and technology risk, policy drafting, training design and evidence testing — engaged according to scope.

How we deliver

A six-phase, decision-framed method

Every engagement is structured around the risk decision — scoped, evidenced, tested, rated, aligned with management, and closed board- and regulator-ready.

See the full methodology →
Regulatory, governance & risk coverage

The frameworks we work against

Engagements are anchored in the Kenyan and regional regulatory framework and the international AML/CFT benchmark.

Framework / areaScopeApplicability
POCAMLA 2009 (as amended)Kenya's primary AML/CFT legislation, including amendments relevant to reporting institutions and financial crime controls.All regulated sectors
CBK AML/CFT/CPF Guidelines & CircularsCentral Bank supervisory expectations on governance, CDD/EDD, record-keeping, reporting, training and control oversight.Banks, MFBs, remittance providers, forex bureaus, PSPs
FRC requirementsFIU obligations, STR/CTR filing, goAML readiness, cooperation, record-keeping and evidentiary expectations.Reporting institutions
Prevention of Terrorism & TFS RegulationsCounter-terrorism financing, targeted financial sanctions, freezing, screening, reporting and escalation obligations.All sectors with sanctions or cross-border exposure
FATF 40 RecommendationsInternational AML/CFT/CPF benchmark and basis for risk-based supervision and mutual evaluations.All regulated sectors
ESAAMLG Mutual Evaluation FrameworkRegional evaluation methodology and supervisory context for East and Southern Africa.National and institutional programme assessments
ERM, Governance & Operational Risk StandardsRisk governance, risk appetite, RCSA, KRIs, internal controls, operational risk, issue management and board reporting.Banks and other regulated financial institutions
Outsourcing, Third-Party & Technology RiskVendor due diligence, outsourcing governance, information security, business continuity, incident management and exit planning.Institutions using material vendors, cloud, systems or outsourcing
Kenya Data Protection Act, 2019Data protection obligations governing evidence handling, confidentiality, security and cross-border data considerations.All engagements
Representative experience — anonymised

Where Riskill has delivered

References and contactable referees are available on request, subject to client consent and confidentiality obligations.

AreaRepresentative experience
Licensed remittance providersIndependent AML/CFT audit covering governance, risk assessment, CDD/EDD, sanctions/TFS, transaction monitoring, STR/SAR, training and regulatory reporting; supported regulator engagements with CAP and board brief.
Commercial bankIndependent AML/CFT compliance audit mandated under CBK supervisory expectations, covering governance, risk assessment, CDD/EDD, sanctions/TFS and transaction monitoring, with a regulator-ready CAP delivered.
Insurance intermediaryAML/CFT effectiveness review aligned to sector regulatory requirements.
SACCOs, MSBs and banksRisk advisory through statutory audit and specialist AML/CFT assignments, strengthening CDD/EDD standards, STR governance, internal controls and training effectiveness.
ERM governance & frameworkDevelopment and review of ERM policy architecture, board risk appetite statements, operational risk governance, committee terms of reference, RCSA tools, KRI dashboards and issue/action trackers.
Third-party & technology riskAssessment of vendor, outsourcing and technology change risks, including control evidence review, regulatory considerations, information security concerns and internal closure matrices.
Board & management reportingPreparation of board-ready risk reports, thematic risk summaries, executive dashboards, risk matrices and decision papers for governance and supervisory use.
Engagement models

How to engage Riskill

Scope, model and pricing are tailored to actual risk exposure. Pick the shape that fits the decision.

Fixed-scope review

Defined assessments — AML audit, RCSA build, policy review, inspection readiness, vendor risk review or board reporting pack.
→ Agreed report, toolkit, matrix, CAP or board pack

Advisory desk

Urgent or recurring support to MLROs, Heads of Risk, Compliance, Operations, IT/InfoSec or senior management.
→ Targeted opinions, document review, risk challenge, drafting, issue closure

Toolkit build

Institutions needing practical workbooks, registers, dashboards, templates or control assessment tools.
→ Editable toolkit with validation logic, scoring and user guidance

Training & capability

Boards, management, risk owners, compliance teams, analysts and frontline staff.
→ Workshop, e-learning, case exercises, job aids, attendance pack

Registered, independent, confidential.

Riskill Consulting Limited, incorporated in Kenya. Tax PIN and Certificate of Incorporation available on request. Engagements are NDA-backed and independence is ring-fenced.

Engage Riskill →