Get control of the facts, the regulatory response and the work that follows.
Clearhaven supports fintechs, payment firms and crypto-asset service providers through regulatory investigations, supervisory reviews, skilled person reviews and complex remediation programmes.
We help management understand what happened, respond credibly and deliver changes that can be supported by clear evidence.
When regulatory scrutiny increases
Regulatory attention can begin with an information request, a supervisory review, a whistleblowing allegation or a concern raised by an auditor, banking partner or board member.
The issue can escalate quickly if the response is incomplete, inconsistent or unsupported by evidence.
We help firms establish:
What the regulator is concerned about
Which products, customers and periods may be affected
What information needs to be preserved and reviewed
Whether the issue is isolated or systemic
Which controls failed and why
What the board needs to know
How the firm should respond
What remediation is likely to be required
The work is structured around the regulator’s questions, the firm’s wider exposure and the decisions management needs to make.
Regulatory investigation support
Clearhaven can support an investigation from the first regulatory request through to findings, remediation and closure.
Our work can include:
Initial assessment and regulatory response strategy
Investigation governance and reporting
Document and data review
Management and employee interviews
Event chronologies
Root-cause analysis
Customer and transaction population analysis
Assessment of control failures
Regulatory response drafting
Board and committee reporting
Management interview preparation
Regulator meeting support
Remediation planning
Coordination with legal counsel and other advisers
Where potential misconduct or enforcement action is involved, we work closely with the firm’s lawyers so that the regulatory, legal and evidential workstreams remain aligned.
Investigations involving fintech and payments
Fintech investigations often begin when rapid growth exposes weaknesses in systems, governance or operational capacity.
We support matters involving:
AML and financial crime controls
Customer onboarding and KYC
Sanctions and PEP screening
Transaction monitoring
Fraud and scam prevention
Safeguarding and reconciliation
Consumer Duty and customer outcomes
Complaints and customer treatment
Regulatory permissions and perimeter issues
Financial promotions
Regulatory reporting
Outsourcing and third-party arrangements
Operational resilience
Governance and management accountability
Agent and distributor oversight
We examine the customer journey, funds flow, decision-making and control evidence to establish how the issue arose and how far it extends.
Investigations involving crypto and digital assets
Crypto investigations may involve transactions, wallets, entities and customers across several jurisdictions.
Our specialists understand the regulatory and technical questions that arise across crypto exchanges, custodians, brokers, trading platforms, wallet providers and other digital asset businesses.
Our work can cover:
MiCA and CASP compliance
UK cryptoasset regulation
AML and sanctions controls
Blockchain analytics and wallet screening
Crypto transaction monitoring
Source of funds and source of wealth
Travel Rule compliance
Custody and client asset protection
Token and asset onboarding
Market abuse and suspicious trading
Conflicts of interest
Cross-border services
Staking, lending and borrowing
Financial promotions
ICT risk and DORA
Regulatory reporting and record keeping
Where necessary, blockchain data can be combined with customer, transaction and operational records to develop a more complete picture of the activity under review.
Skilled person and Section 166 review support
A skilled person review can place significant demands on management and compliance teams.
We help firms prepare for and respond to Section 166 reviews, including:
Readiness assessments
Review scope analysis
Document and data preparation
Governance and project management
Management interview preparation
Quality review of submissions
Response to information requests
Findings analysis
Remediation programme design
Progress reporting
Closure and validation preparation
We can also support firms responding to independent reviews commissioned by boards, regulators, auditors or banking partners.
Voluntary requirements and business restrictions
A voluntary requirement or regulatory restriction can affect customer onboarding, product launches, transaction volumes or the services a firm is permitted to provide.
Clearhaven can help management understand the operational effect of the restriction, establish the required governance and build a remediation plan around the conditions for release.
This can include:
Analysis of the requirement and affected activities
Customer and transaction controls
Restriction monitoring
Board and regulator reporting
Remediation milestones
Evidence collection
Independent testing coordination
Exit and closure planning
The programme remains focused on the specific regulatory concerns that led to the restriction.
Regulatory remediation
A credible remediation programme addresses the cause of the problem, the customers or transactions affected and the weaknesses that allowed it to continue.
We support the full remediation lifecycle:
Findings and root-cause analysis
Risk and impact assessment
Target control design
Remediation planning
Programme governance
Workstream management
Policy and procedure changes
Technology and data requirements
Customer or transaction lookbacks
Backlog remediation
Staff and resource planning
Training and implementation
Control testing
Management information
Board and regulator reporting
Closure evidence
Post-implementation review
Each action is linked to a finding, an owner, a deadline and the evidence needed to demonstrate completion.
Financial crime remediation
Financial crime remediation often requires changes across data, systems, processes and teams.
We help firms address weaknesses in:
Business-wide financial crime risk assessments
Customer risk-rating models
KYC and due diligence records
Enhanced due diligence
PEP and sanctions screening
Transaction monitoring coverage
Blockchain analytics
Alert investigation and escalation
Suspicious activity reporting
Quality assurance
Financial crime governance
MLRO reporting
Policies, procedures and training
We can also design and manage customer file reviews, transaction lookbacks and alert remediation programmes.
Customer and transaction lookbacks
Where a control has failed, the firm may need to establish which customers or transactions were affected.
We help define the population, review methodology, decision criteria, quality controls and reporting required for a defensible lookback.
This may involve:
Customer file remediation
KYC and CDD refreshes
High-risk customer reviews
Sanctions and PEP rescreening
Transaction monitoring back-testing
Historical alert reviews
Blockchain transaction analysis
Suspicious activity assessments
Customer outcome reviews
Redress population analysis
The approach is proportionate to the risk and supported by a documented methodology.
Independent validation and closure
Completed actions still need to be tested.
We assess whether new controls have been implemented, whether they operate effectively and whether the evidence supports closure of the original finding.
Validation can include:
Design effectiveness testing
Operating effectiveness testing
Sample-based file and transaction reviews
Data quality assessment
Governance and reporting review
Staff interviews
Closure report preparation
Follow-up recommendations
Where formal independence is required, remediation delivery and validation responsibilities are kept separate.
How we work
Stabilise the response
We establish governance, preserve relevant information and agree immediate priorities with senior management and legal counsel.
Establish the facts
We review documents, data, decisions and control evidence to determine what happened and how far the issue extends.
Assess the exposure
We consider regulatory, financial crime, operational and customer implications.
Respond clearly
We help management prepare accurate submissions, board papers and regulator communications.
Deliver the remediation
Findings are converted into a structured programme with accountable owners, realistic milestones and defined evidence requirements.
Prepare for closure
Controls are tested and the firm’s evidence is organised so that progress can be demonstrated to the board, regulator or independent reviewer.
Investigation experience that matters
Our work is led by practitioners with more than 20 years of experience across regulation, industry and consulting.
The team includes former leaders of regulatory units, Heads of Compliance, MLROs and senior consulting partners. Their experience includes leading more than 100 supervisory reviews, supporting skilled person and monitor-led reviews, conducting complex financial crime investigations and delivering regulatory remediation programmes across several jurisdictions.
We understand how regulators investigate, how firms respond and what a remediation programme needs to demonstrate before an issue can be closed.
Respond with control and credibility
Tell us what has happened, what the regulator has requested and where the immediate pressure sits. We will help you establish the facts and define the next steps.
Frequently Asked Questions
-
Establish clear internal ownership, preserve the relevant information and assess the scope of the request. Early responses should be accurate, consistent and reviewed by the appropriate senior stakeholders.
Legal counsel should be involved where the matter may lead to enforcement action, litigation or individual accountability concerns.
-
Section 166 of the Financial Services and Markets Act allows the FCA to obtain an independent report on an area of concern within a regulated firm.
The review may examine governance, financial crime, customer treatment, safeguarding, data, systems or other regulatory matters.
-
That depends on the appointment process, required expertise and any independence considerations. We can also support the firm being reviewed by preparing information, managing the response and delivering the resulting remediation.
-
Regulatory remediation is the work required to correct identified control failures and address their effects. It may involve governance, policies, systems, customer records, transaction reviews, staffing, training and independent testing.
-
Yes. We can help manage the operational impact, deliver the required remediation, report progress and prepare the evidence needed to support an application to vary or remove the requirement.
The regulator makes the final decision.
-
Yes. We can design and manage customer file reviews, transaction lookbacks, sanctions rescreening, historical alert reviews and crypto transaction analysis.
-
Yes. We regularly work alongside legal counsel, forensic technology providers, auditors and other specialists. Responsibilities are agreed at the outset so that each workstream is clear.
-
Regulatory investigations often require a rapid response. We can begin with an urgent scoping and stabilisation phase, then assemble the appropriate team once the facts and required workstreams are clearer.

