Colleagues collaborating during a structured review session

Audit process

A clear path from questionnaire intake to a shareable AML findings pack.

Four stages, fixed before fieldwork

We agree scope, samples, and deliverables in writing so AML audits stay predictable for compliance and commercial calendars.

01

Scope lock

We review your partner ask, product map, and prior findings, then lock control families, sample sizes, and access needs.

02

Fieldwork

Case sampling, system walkthroughs, and interviews with control owners—focused on operating evidence, not policy theatre.

03

Findings pack

You receive written findings, a heat map or scorecard, and remediation language your committee can adopt.

04

Validation option

After fixes land, we re-test agreed items and issue a short validation letter for bank partners.

What we need from you

Access to policies, system configuration summaries, recent alert or CDD samples, committee minutes, and a named owner for each control family in scope. We work under a confidentiality agreement and do not require production secrets beyond what diligence already demands.

Who this process fits

Licensed or licence-seeking fintech firms in Hong Kong that sell to banks, payment partners, or institutional customers and need independent AML assurance—not a general IT health check.

Request a scoped AML audit