Know how your compliance framework will stand up to scrutiny

Clearhaven provides independent compliance reviews and regulatory readiness assessments for fintechs, payment firms and crypto-asset service providers.

We test your framework against current regulatory requirements, supervisory priorities, the risks in your business model and the evidence produced by your controls.

Compliance Reviews and Regulatory Readiness

Know how your compliance framework will stand up to scrutiny.

Clearhaven provides independent compliance reviews and regulatory readiness assessments for fintechs, payment firms and crypto-asset service providers.

We test your framework against current regulatory requirements, supervisory priorities, the risks in your business model and the evidence produced by your controls.

CTA: Discuss a compliance review

A clear view of where the business stands

Policies form only one part of a regulator’s assessment.

Regulators also look at decisions, customer files, transaction alerts, safeguarding records, management information, governance and the level of challenge provided by senior management.

Our reviews examine the same evidence. We establish which parts of the framework are working, where the business is exposed and what should be addressed first.

Independent compliance framework reviews

A full compliance review provides the board and management with an independent assessment of the firm’s regulatory framework.

The review can cover:

  • Regulatory permissions and business activities

  • Compliance governance

  • Board and committee oversight

  • Management responsibilities

  • Compliance policies and procedures

  • Regulatory risk assessments

  • Compliance monitoring

  • Regulatory reporting and notifications

  • Customer onboarding

  • Consumer outcomes and complaints

  • Financial promotions

  • Outsourcing and third-party risk

  • Operational resilience

  • Staff training

  • Record keeping

  • Management information

  • Issue management and remediation

The scope is agreed around the firm’s products, permissions, customers and target markets.

Regulatory readiness assessments

A regulatory readiness assessment prepares the firm for a specific application, review, meeting or supervisory event.

We consider the questions a regulator is likely to ask and whether the firm can support its answers with evidence.

This can include:

  • Mock regulatory interviews

  • Management and board preparation

  • Document and evidence reviews

  • Customer and transaction file testing

  • Governance record reviews

  • Regulatory reporting checks

  • Control walkthroughs

  • Sample testing

  • Likely regulator questions

  • Readiness scoring

  • Priority actions

  • Remediation planning

The assessment gives management time to address gaps and prepare the people who will represent the business.

Fintech and payments compliance reviews

We review the regulatory frameworks of payment institutions, electronic money institutions, digital wallets, embedded finance providers, remittance businesses and open banking firms.

Our fintech compliance reviews can cover:

  • Payment institution and EMI permissions

  • Regulatory perimeter

  • Safeguarding and reconciliations

  • Capital and liquidity

  • Financial crime risk

  • Fraud and scam controls

  • Customer onboarding and KYC

  • Consumer Duty

  • Complaints and customer outcomes

  • Fees, disclosures and communications

  • Agents and distributors

  • Banking and commercial partners

  • Outsourcing arrangements

  • Operational resilience

  • Regulatory reporting

  • Wind-down planning

We follow the movement of customer funds and information through the business, examining the controls that operate at each stage.

Crypto and CASP compliance reviews

MiCA has introduced a broader supervisory framework for crypto businesses operating in Europe.

Clearhaven reviews crypto exchanges, custodians, brokers, wallet providers, trading platforms, stablecoin businesses and other crypto-asset service providers.

A crypto compliance review can cover:

  • MiCA and CASP requirements

  • UK cryptoasset regulation

  • Regulatory permissions and service scope

  • Governance and local substance

  • AML and sanctions

  • Blockchain analytics

  • Crypto transaction monitoring

  • Travel Rule compliance

  • Source of funds and source of wealth

  • Wallet screening

  • Custody and client asset protection

  • Token and asset onboarding

  • Market abuse surveillance

  • Conflicts of interest

  • Complaints handling

  • Financial promotions

  • Cross-border activity

  • Outsourcing

  • ICT risk and DORA

  • Regulatory reporting and record keeping

We assess whether the compliance function has the authority, capacity and access it needs to operate effectively.

Financial crime compliance reviews

An independent financial crime review tests whether the AML and sanctions framework reflects the risks in the business.

Our reviews can include:

  • Business-wide financial crime risk assessment

  • Customer risk assessment methodology

  • Customer due diligence

  • Enhanced due diligence

  • PEP and sanctions screening

  • Transaction monitoring

  • Blockchain analytics and wallet screening

  • Suspicious activity reporting

  • Fraud controls

  • Correspondent and partner risk

  • Quality assurance

  • MLRO oversight

  • Board reporting

  • Policies, procedures and training

  • Previous findings and remediation

Testing can include customer files, alerts, transactions, risk decisions and governance records.

Thematic compliance reviews

A thematic review provides a deeper assessment of one area of regulatory risk.

Common review areas include:

  • AML and financial crime

  • Sanctions

  • Safeguarding

  • Consumer Duty

  • Complaints

  • Transaction monitoring

  • Customer risk rating

  • Operational resilience

  • DORA

  • Outsourcing

  • Regulatory reporting

  • Financial promotions

  • Crypto custody

  • Travel Rule compliance

  • Market abuse

  • Governance and board effectiveness

The scope can be aligned with a current regulatory priority, an internal concern or a planned product launch.

Product and market launch reviews

A new product can change the firm’s regulatory perimeter and risk profile.

We review the product before launch, including:

  • Product structure and customer proposition

  • Customer journey

  • Funds and asset flows

  • Target market

  • Regulatory permissions

  • Customer disclosures

  • Financial crime controls

  • Safeguarding and custody

  • Complaints handling

  • Technology and outsourcing

  • Governance and approval

  • Regulatory notifications

This gives product and compliance teams a shared view of the requirements and the work needed for launch.

When to commission a compliance review

A review can provide useful assurance when the firm is:

  • Preparing an authorisation application

  • Moving from VASP registration to CASP authorisation

  • Expecting a regulatory visit or interview

  • Responding to a regulatory priorities report

  • Launching a new product

  • Entering another jurisdiction

  • Applying to vary its permissions

  • Preparing for investor due diligence

  • Starting a banking or embedded finance partnership

  • Completing an acquisition

  • Appointing a new CCO or MLRO

  • Assessing whether previous remediation has worked

  • Providing the board with independent assurance

The review can be broad or focused on a specific regulatory question.

What you receive

Executive assessment

A clear summary of the firm’s overall position, material exposures and immediate priorities.

Detailed findings

Each finding explains the requirement, the evidence reviewed, the control weakness and the potential regulatory effect.

Risk-rated action plan

Actions are prioritised according to their seriousness, urgency and effect on customers or the business.

Evidence requirements

We identify what management will need to demonstrate that each issue has been addressed.

Board presentation

Findings can be presented directly to the board or relevant committee, with time for challenge and discussion.

Regulatory preparation

Where the review relates to an upcoming regulatory engagement, we prepare likely questions and help management develop clear, evidence-based responses.

How we conduct the review

Set the scope

We agree the regulatory requirements, products, entities and risk areas to be assessed.

Understand the business

We review the business model, customer journey, funds flow, technology and governance arrangements.

Examine the evidence

Policies are considered alongside customer files, transactions, alerts, reconciliations, reports and decision records.

Speak to the people operating the controls

Interviews and walkthroughs help establish whether responsibilities are understood and how the framework operates day to day.

Test the controls

Sampling and evidence testing are used to assess control design and operating effectiveness.

Report and prioritise

Findings are discussed with management, then converted into a practical action plan for the board and control owners.

Reviews led by experienced practitioners

Clearhaven reviews are led by practitioners with more than 20 years of experience across regulatory supervision, industry and consulting.

The team includes former leaders of regulatory units, Heads of Compliance, MLROs and senior consulting partners. Their experience includes more than 100 supervisory reviews, fintech and crypto authorisation, financial crime investigations and complex regulatory remediation.

This experience helps us anticipate how a regulator is likely to approach the business and which issues will receive the greatest scrutiny.

Know where you stand

Tell us about your business, regulatory status and the assurance you need. We will define a focused review around your products, risks and timetable.

Frequently Asked Questions