Compliance Maturity Self-Assessment
Twenty questions across the five domains supervisors examine. Get a maturity level, a score for each domain, and a prioritised list of the gaps worth closing first.
Assess your programme
0 of 20 answeredAnswer the questions above to generate your assessment.
Five levels, five domains
The assessment uses a five-level maturity scale applied across the five domains supervisors examine in almost every thematic review and inspection. The scale deliberately separates having a control from being able to demonstrate that it operated consistently — because that distinction is where most enforcement findings originate.
The five domains
- Governance and risk assessment. Whether there is a current, board-approved business-wide risk assessment; whether the MLRO has authority and resources; whether senior management engages with financial crime risk in substance rather than in minutes.
- Customer due diligence and onboarding. Whether identification and verification are consistent, whether the risk matrix is applied uniformly, whether beneficial ownership is genuinely resolved, and whether periodic refresh is current across the whole book.
- Screening. Coverage, data refresh frequency, match tuning, ongoing rescreening, and whether alert dispositions are evidenced with a rationale.
- Monitoring and reporting. Whether scenarios reflect your actual risk profile, whether alerts are cleared within a defined timeframe, whether escalation to suspicious activity reporting is timely, and whether tuning is reviewed.
- Assurance, training and audit trail. Whether training is role-specific and tested, whether independent testing happens, whether findings are closed, and whether you could produce a complete file history on demand.
Why the audit trail domain scores lowest
Across firms that run this kind of assessment, the assurance and audit trail domain is consistently the weakest — and it is also the domain that determines how an inspection goes. Firms with strong controls and weak evidence are routinely treated as firms with weak controls, because a supervisor can only assess what you can demonstrate. If you can describe your process but cannot reproduce, for a sampled customer, the checks that ran, the risk score applied, the alerts raised, who dispositioned them and on what basis, then the control is unproven regardless of how well it works in practice.
Most of the gap is execution, not policy
Firms scoring at level 2 rarely have a policy problem. They have documented, sensible controls that live in one place and are executed somewhere else, by people, inconsistently.
Policy as configuration
When the risk matrix, the due diligence requirements and the approval hierarchy are configured in the system rather than described in a document, consistency stops being a training problem.
Continuous, not periodic
Screening, country risk and customer risk re-evaluate on change rather than on a calendar, which closes the window between an event and your response to it.
Evidence as a by-product
Every check, decision, approval and override is captured as it happens, so regulator-ready reporting is generated rather than reconstructed.
About compliance maturity
Other free compliance tools
Move up the scale without adding headcount
Book a 30-minute demo and see configured policy, continuous screening and an immutable audit trail working together on a live customer file.
