Know how your compliance framework will stand up to scrutiny
Clearhaven provides independent compliance reviews and regulatory readiness assessments for fintechs, payment firms and crypto-asset service providers.
We test your framework against current regulatory requirements, supervisory priorities, the risks in your business model and the evidence produced by your controls.
Compliance Reviews and Regulatory Readiness
Know how your compliance framework will stand up to scrutiny.
Clearhaven provides independent compliance reviews and regulatory readiness assessments for fintechs, payment firms and crypto-asset service providers.
We test your framework against current regulatory requirements, supervisory priorities, the risks in your business model and the evidence produced by your controls.
CTA: Discuss a compliance review
A clear view of where the business stands
Policies form only one part of a regulator’s assessment.
Regulators also look at decisions, customer files, transaction alerts, safeguarding records, management information, governance and the level of challenge provided by senior management.
Our reviews examine the same evidence. We establish which parts of the framework are working, where the business is exposed and what should be addressed first.
Independent compliance framework reviews
A full compliance review provides the board and management with an independent assessment of the firm’s regulatory framework.
The review can cover:
Regulatory permissions and business activities
Compliance governance
Board and committee oversight
Management responsibilities
Compliance policies and procedures
Regulatory risk assessments
Compliance monitoring
Regulatory reporting and notifications
Customer onboarding
Consumer outcomes and complaints
Financial promotions
Outsourcing and third-party risk
Operational resilience
Staff training
Record keeping
Management information
Issue management and remediation
The scope is agreed around the firm’s products, permissions, customers and target markets.
Regulatory readiness assessments
A regulatory readiness assessment prepares the firm for a specific application, review, meeting or supervisory event.
We consider the questions a regulator is likely to ask and whether the firm can support its answers with evidence.
This can include:
Mock regulatory interviews
Management and board preparation
Document and evidence reviews
Customer and transaction file testing
Governance record reviews
Regulatory reporting checks
Control walkthroughs
Sample testing
Likely regulator questions
Readiness scoring
Priority actions
Remediation planning
The assessment gives management time to address gaps and prepare the people who will represent the business.
Fintech and payments compliance reviews
We review the regulatory frameworks of payment institutions, electronic money institutions, digital wallets, embedded finance providers, remittance businesses and open banking firms.
Our fintech compliance reviews can cover:
Payment institution and EMI permissions
Regulatory perimeter
Safeguarding and reconciliations
Capital and liquidity
Financial crime risk
Fraud and scam controls
Customer onboarding and KYC
Consumer Duty
Complaints and customer outcomes
Fees, disclosures and communications
Agents and distributors
Banking and commercial partners
Outsourcing arrangements
Operational resilience
Regulatory reporting
Wind-down planning
We follow the movement of customer funds and information through the business, examining the controls that operate at each stage.
Crypto and CASP compliance reviews
MiCA has introduced a broader supervisory framework for crypto businesses operating in Europe.
Clearhaven reviews crypto exchanges, custodians, brokers, wallet providers, trading platforms, stablecoin businesses and other crypto-asset service providers.
A crypto compliance review can cover:
MiCA and CASP requirements
UK cryptoasset regulation
Regulatory permissions and service scope
Governance and local substance
AML and sanctions
Blockchain analytics
Crypto transaction monitoring
Travel Rule compliance
Source of funds and source of wealth
Wallet screening
Custody and client asset protection
Token and asset onboarding
Market abuse surveillance
Conflicts of interest
Complaints handling
Financial promotions
Cross-border activity
Outsourcing
ICT risk and DORA
Regulatory reporting and record keeping
We assess whether the compliance function has the authority, capacity and access it needs to operate effectively.
Financial crime compliance reviews
An independent financial crime review tests whether the AML and sanctions framework reflects the risks in the business.
Our reviews can include:
Business-wide financial crime risk assessment
Customer risk assessment methodology
Customer due diligence
Enhanced due diligence
PEP and sanctions screening
Transaction monitoring
Blockchain analytics and wallet screening
Suspicious activity reporting
Fraud controls
Correspondent and partner risk
Quality assurance
MLRO oversight
Board reporting
Policies, procedures and training
Previous findings and remediation
Testing can include customer files, alerts, transactions, risk decisions and governance records.
Thematic compliance reviews
A thematic review provides a deeper assessment of one area of regulatory risk.
Common review areas include:
AML and financial crime
Sanctions
Safeguarding
Consumer Duty
Complaints
Transaction monitoring
Customer risk rating
Operational resilience
DORA
Outsourcing
Regulatory reporting
Financial promotions
Crypto custody
Travel Rule compliance
Market abuse
Governance and board effectiveness
The scope can be aligned with a current regulatory priority, an internal concern or a planned product launch.
Product and market launch reviews
A new product can change the firm’s regulatory perimeter and risk profile.
We review the product before launch, including:
Product structure and customer proposition
Customer journey
Funds and asset flows
Target market
Regulatory permissions
Customer disclosures
Financial crime controls
Safeguarding and custody
Complaints handling
Technology and outsourcing
Governance and approval
Regulatory notifications
This gives product and compliance teams a shared view of the requirements and the work needed for launch.
When to commission a compliance review
A review can provide useful assurance when the firm is:
Preparing an authorisation application
Moving from VASP registration to CASP authorisation
Expecting a regulatory visit or interview
Responding to a regulatory priorities report
Launching a new product
Entering another jurisdiction
Applying to vary its permissions
Preparing for investor due diligence
Starting a banking or embedded finance partnership
Completing an acquisition
Appointing a new CCO or MLRO
Assessing whether previous remediation has worked
Providing the board with independent assurance
The review can be broad or focused on a specific regulatory question.
What you receive
Executive assessment
A clear summary of the firm’s overall position, material exposures and immediate priorities.
Detailed findings
Each finding explains the requirement, the evidence reviewed, the control weakness and the potential regulatory effect.
Risk-rated action plan
Actions are prioritised according to their seriousness, urgency and effect on customers or the business.
Evidence requirements
We identify what management will need to demonstrate that each issue has been addressed.
Board presentation
Findings can be presented directly to the board or relevant committee, with time for challenge and discussion.
Regulatory preparation
Where the review relates to an upcoming regulatory engagement, we prepare likely questions and help management develop clear, evidence-based responses.
How we conduct the review
Set the scope
We agree the regulatory requirements, products, entities and risk areas to be assessed.
Understand the business
We review the business model, customer journey, funds flow, technology and governance arrangements.
Examine the evidence
Policies are considered alongside customer files, transactions, alerts, reconciliations, reports and decision records.
Speak to the people operating the controls
Interviews and walkthroughs help establish whether responsibilities are understood and how the framework operates day to day.
Test the controls
Sampling and evidence testing are used to assess control design and operating effectiveness.
Report and prioritise
Findings are discussed with management, then converted into a practical action plan for the board and control owners.
Reviews led by experienced practitioners
Clearhaven reviews are led by practitioners with more than 20 years of experience across regulatory supervision, industry and consulting.
The team includes former leaders of regulatory units, Heads of Compliance, MLROs and senior consulting partners. Their experience includes more than 100 supervisory reviews, fintech and crypto authorisation, financial crime investigations and complex regulatory remediation.
This experience helps us anticipate how a regulator is likely to approach the business and which issues will receive the greatest scrutiny.
Know where you stand
Tell us about your business, regulatory status and the assurance you need. We will define a focused review around your products, risks and timetable.
Frequently Asked Questions
-
An independent compliance review assesses whether a firm’s regulatory framework is properly designed and operating effectively.
It is conducted by someone outside the area responsible for the controls being reviewed, giving the board a more objective view of the firm’s position.
-
A regulatory readiness assessment prepares a firm for authorisation, a supervisory review, a regulator meeting or another form of regulatory scrutiny.
It examines the firm’s documents, controls, evidence and management readiness against likely regulatory expectations.
-
Compliance monitoring is an ongoing activity performed by the firm’s compliance function. An independent review provides a broader or deeper assessment by someone who was not responsible for operating the controls.
-
Yes. We can structure the assessment around the approach of the relevant regulator, including document requests, management interviews, control walkthroughs and sample testing.
-
Yes. We review CASP governance, compliance, AML, custody, conflicts, complaints, outsourcing, ICT risk, DORA and other requirements relevant to the crypto services being provided.
-
Yes. A readiness review can identify weaknesses in the application, operating model, governance or control framework before the firm submits or proceeds to management interviews.
-
This depends on the firm, jurisdiction and applicable rules. We agree the required independence, scope and reporting arrangements before beginning the review.
-
Timing depends on the scope, number of entities, products and jurisdictions involved. A focused thematic assessment can be completed more quickly than a full compliance framework review.
-
Yes. We can help management develop and deliver the remediation plan. Where independent validation is required, the remediation and assurance responsibilities are kept separate.

