01, Component
Assess: business risk assessment, annual risk assessment report, health check
The business risk assessment is the document every other control is supposed to follow from: customers, products, channels, geographies and delivery, scored for inherent risk, set against the controls in place, with a residual rating the Board has approved. We build it as an editable model with the scoring method visible, refresh it as the annual AML/CFT risk assessment report, and run the health check as an independent read of the whole framework against the current law, the supervisor's guidance and what the institution actually does. The health check is the usual starting point where a framework predates the 2025 law.
02, Component
Build: policies and procedures, compliance department setup, software selection
A policy set written to the 2025 Decree-Law and its Executive Regulations and to the institution's own risk assessment, covering customer due diligence, enhanced and simplified measures, politically exposed persons, targeted financial sanctions, suspicious transaction reporting, record keeping and governance, with procedures a first-line team can follow. For an institution building the function, the department design: roles, reporting lines to the Board, committee terms of reference, the compliance officer's mandate, monitoring plan and management information. For system selection, a requirements specification and a scored evaluation of screening, transaction monitoring and case management vendors. We hold no vendor relationships and take no commission.
03, Component
Test: screening software testing and validation
Sanctions and name screening engines and transaction monitoring systems are models, and they fail in the ways models fail: thresholds set once and never revisited, fuzzy matching that misses transliterated Arabic names, list updates that do not load, scenarios that fire on noise and stay silent on the typology they were built for. We test them the way we validate a credit model. Controlled test data with known true matches and deliberate variations, measured detection and false positive rates, threshold sensitivity, above-the-line and below-the-line sampling, list completeness and timeliness, data lineage from core system to screening input, and a documented validation report. This is the part of the service that draws most directly on the practice's model validation work.
04, Component
Run: training, regulatory reporting, managed KYC and customer due diligence
Training by audience: Board and senior management, the compliance function, and front-line staff, built on the institution's own risk assessment and typologies, with attendance and assessment records a supervisor can inspect. Regulatory reporting support covering the returns and questionnaires the supervisor requires and the preparation and quality review of suspicious transaction and activity reports filed through the goAML platform; the decision to file, and the filing, stay with your compliance officer. Managed KYC and customer due diligence: onboarding files, periodic reviews, remediation backlogs and enhanced due diligence research prepared to your procedures and your risk ratings. This is outsourced work carried out under your procedures and your control, not the regulated third-party reliance the Executive Regulations describe, and responsibility for the accuracy of the due diligence stays with the institution, so every file comes back for your sign-off.