One Constellation
Free Interactive Tool

Compliance Maturity Self-Assessment

Twenty questions across the five domains supervisors examine. Get a maturity level, a score for each domain, and a prioritised list of the gaps worth closing first.

Takes about five minutes No sign-up required Nothing is stored

Assess your programme

0 of 20 answered
Overall maturity
0%
Maturity level
Level 1 — Initial
Where to start

    Answer the questions above to generate your assessment.

    How to read this. This is a structured self-assessment, not an audit, a certification or a supervisory opinion. It reflects only what you tell it, and self-assessments consistently score higher than independent review of the same programme. Use it to focus a conversation with your MLRO, internal audit or board risk committee, not to conclude that your obligations are met. Nothing you select here is transmitted or stored.
    The model

    Five levels, five domains

    The assessment uses a five-level maturity scale applied across the five domains supervisors examine in almost every thematic review and inspection. The scale deliberately separates having a control from being able to demonstrate that it operated consistently — because that distinction is where most enforcement findings originate.

    Level 1 — InitialControls are absent or applied case by case. Outcomes depend on individuals.
    Level 2 — DevelopingControls exist and are documented, but execution varies and evidence is patchy.
    Level 3 — DefinedControls are consistently applied and the process is understood across the team.
    Level 4 — ManagedControls are measured, monitored and evidenced. Exceptions are tracked and closed.
    Level 5 — OptimisedControls are automated, continuously assured and improved from their own data.

    The five domains

    • Governance and risk assessment. Whether there is a current, board-approved business-wide risk assessment; whether the MLRO has authority and resources; whether senior management engages with financial crime risk in substance rather than in minutes.
    • Customer due diligence and onboarding. Whether identification and verification are consistent, whether the risk matrix is applied uniformly, whether beneficial ownership is genuinely resolved, and whether periodic refresh is current across the whole book.
    • Screening. Coverage, data refresh frequency, match tuning, ongoing rescreening, and whether alert dispositions are evidenced with a rationale.
    • Monitoring and reporting. Whether scenarios reflect your actual risk profile, whether alerts are cleared within a defined timeframe, whether escalation to suspicious activity reporting is timely, and whether tuning is reviewed.
    • Assurance, training and audit trail. Whether training is role-specific and tested, whether independent testing happens, whether findings are closed, and whether you could produce a complete file history on demand.

    Why the audit trail domain scores lowest

    Across firms that run this kind of assessment, the assurance and audit trail domain is consistently the weakest — and it is also the domain that determines how an inspection goes. Firms with strong controls and weak evidence are routinely treated as firms with weak controls, because a supervisor can only assess what you can demonstrate. If you can describe your process but cannot reproduce, for a sampled customer, the checks that ran, the risk score applied, the alerts raised, who dispositioned them and on what basis, then the control is unproven regardless of how well it works in practice.

    From level 2 to level 4

    Most of the gap is execution, not policy

    Firms scoring at level 2 rarely have a policy problem. They have documented, sensible controls that live in one place and are executed somewhere else, by people, inconsistently.

    ⚙️

    Policy as configuration

    When the risk matrix, the due diligence requirements and the approval hierarchy are configured in the system rather than described in a document, consistency stops being a training problem.

    🔁

    Continuous, not periodic

    Screening, country risk and customer risk re-evaluate on change rather than on a calendar, which closes the window between an event and your response to it.

    📊

    Evidence as a by-product

    Every check, decision, approval and override is captured as it happens, so regulator-ready reporting is generated rather than reconstructed.

    Questions

    About compliance maturity

    What is a compliance maturity assessment?+
    It is a structured way of rating how well a financial crime compliance programme is designed and, more importantly, how consistently it operates. Rather than asking whether a control exists, a maturity model asks whether it is applied uniformly, whether it is monitored, and whether its operation can be evidenced. It is a diagnostic for prioritising improvement, not a compliance certification.
    What maturity level should we be at?+
    There is no regulatory minimum expressed in these terms. Proportionality applies: a small firm with a simple, low-risk product set can operate a defensible programme at level three, while a large institution with complex products, cross-border exposure and high volumes will struggle to meet supervisory expectations below level four. The more relevant question is whether your maturity is proportionate to the risk in your own business-wide risk assessment.
    How often should we reassess?+
    At least annually, and additionally whenever something material changes — a new product, a new market, a significant volume increase, an acquisition, or a change in your regulatory perimeter. Many firms run it alongside the annual refresh of the business-wide risk assessment so the two inform each other.
    Is a self-assessment enough?+
    No, and it is not intended to be. Self-assessments consistently score higher than independent review of the same programme, because the people who designed a control are the least well placed to see where it fails in practice. Use this to focus internal discussion and to shape the scope of independent testing, not as a substitute for it.
    Which domain matters most?+
    Governance sets the ceiling for everything else, because an under-resourced MLRO or a stale business-wide risk assessment limits what the other domains can achieve. But assurance and audit trail is usually the domain that determines inspection outcomes, since a supervisor can only credit what you can demonstrate.
    Can One Constellation help us close the gaps?+
    Yes. The platform addresses the execution and evidence layers directly — configured risk methodology, continuous screening, automated periodic review scheduling and a complete audit trail. Bring your assessment results to a demo and our team will map them against what the platform covers and what remains an organisational change. Book a demo.

    Move up the scale without adding headcount

    Book a 30-minute demo and see configured policy, continuous screening and an immutable audit trail working together on a live customer file.

    Scroll to Top