Compliance Gap Analysis & Audits
A gap analysis — a compliance audit, if you prefer the formal name — tells you where you actually stand. We measure what you have against what the legislation asks for, then hand you a list of what to fix with the highest-risk items at the top. The point is to find the gaps while they're still cheap to fix.
What this covers
Do the documents hold up
Whether they exist, whether they're current, whether anyone actually approved them, and whether they say what the law needs them to say. This is the quick half.
Does any of it happen
The half that matters more. Documents get compared against real life: sampling client files, checking screening records, reviewing reporting decisions and talking to the people who do the work.
The registrations that lapse
Your goAML registration and business type, your Information Officer registration, Risk and Compliance Return submissions, notifications about where records are stored. Each one is easy to overlook and very simple for a supervisor to check.
A fix-it list, worst first
Findings ranked by how much regulatory risk they carry rather than listed alphabetically. You have a finite number of hours, and they should go where they buy the most.
- Businesses whose compliance programme has never had an outside look
- Anyone who has had a query or an inspection notice from a supervisor
- Businesses that inherited a programme through an acquisition or restructure
- Boards who want to know that what they're told matches what happens
- A written assessment against your FICA, AML and POPIA duties, as they apply to you
- Every finding tied to the specific requirement behind it
- A fix-it list ordered by risk rather than by chapter
- A clear list of what's already fine, so you don't redo work that's done
Questions we get a lot
A financial audit asks whether your numbers give a fair picture of the business. A compliance audit asks something else: whether you meet your legal obligations — under FICA and POPIA, for instance — and whether the controls you say you operate are actually operating.
Rarely a missing document. Usually a gap between the document and the day job: checks that get done but never written down, screening performed at onboarding and never repeated, training that took place but wasn't recorded, and registrations that went stale after somebody left. None of that is unusual, and all of it is fixable.
Finding a gap yourself and fixing it puts your business in a materially better position than having a supervisor find it. Regulators do distinguish between an institution that is actively managing its compliance and one that isn't.
Let’s take a look at where you stand.
A free consultation works out what applies to your business and what you already have in place — before you commit to anything else.