Home / Reviews & Audits

Reviews & audits

Independent, evidence-based reviews, audits and assessments across financial crime and enterprise risk — structured to withstand board, supervisory and external-audit scrutiny. Every engagement ends in a rated report, a corrective action plan, and the tools to close it.

Financial crime

AML/CFT/CPF reviews & audits

Assessed against Kenya's POCAMLA, CBK and FRC framework and the FATF standard.

Full detail →
Independent AML/CFT/CPF audit & effectiveness review
Objective assessment of the design and operating effectiveness of the AML/CFT/CPF framework and controls, with risk-rated findings, regulatory mapping and a board- and regulator-ready corrective action plan.
AML/CFT/CPF inspection-readiness review
A pre-inspection health check: evidence gaps, control self-assessment and a prioritised action plan, so you meet the supervisor prepared.
Sanctions & TFS programme review
Screening perimeter, list governance, alert handling, PEP and adverse-media controls, overrides and hit-disposition quality assurance.
Transaction monitoring & STR/SAR governance review
Scenario coverage and tuning, case quality, suspicion formation, escalation, MLRO decisioning and filing readiness.
Digital channels compliance & fraud-risk review
Mobile, web, wallet, agent and digital-onboarding channels — digital KYC, behavioural risk signals, control governance and escalation.
Enterprise risk

ERM reviews & assessments

Practical, bank-grade governance and control assessment — usable and defensible.

Full detail →
ERM framework & governance review
Framework, taxonomy, committee architecture, reporting cadence and governance maturity — with a clear implementation roadmap.
Risk appetite & board reporting review
Risk appetite statement, thresholds, breach protocols and the quality of what actually reaches the board.
RCSA & control-effectiveness assessment
Process-based risk registers, inherent/residual scoring, control effectiveness and evidence discipline.
Third-party, outsourcing & technology risk assessment
Vendor, outsourcing, system-change, cybersecurity and data-protection risk, with approval packs and closure matrices.
Operational risk review
Incident and loss-event handling, control standards, issue management, root-cause analysis and action tracking.

Bring us the decision. We return the report.

Tell us what you need to be sure of — inspection readiness, framework effectiveness, a defensible screening programme — and we scope it, evidence it, and close it board-ready.

Request a review →