01
Scope lock
We review your partner ask, product map, and prior findings, then lock control families, sample sizes, and access needs.
A clear path from questionnaire intake to a shareable AML findings pack.
We agree scope, samples, and deliverables in writing so AML audits stay predictable for compliance and commercial calendars.
01
We review your partner ask, product map, and prior findings, then lock control families, sample sizes, and access needs.
02
Case sampling, system walkthroughs, and interviews with control owners—focused on operating evidence, not policy theatre.
03
You receive written findings, a heat map or scorecard, and remediation language your committee can adopt.
04
After fixes land, we re-test agreed items and issue a short validation letter for bank partners.
Access to policies, system configuration summaries, recent alert or CDD samples, committee minutes, and a named owner for each control family in scope. We work under a confidentiality agreement and do not require production secrets beyond what diligence already demands.
Licensed or licence-seeking fintech firms in Hong Kong that sell to banks, payment partners, or institutional customers and need independent AML assurance—not a general IT health check.