A structured current-state versus required-state assessment for CASPs, fintech, payment institutions and other regulated businesses — mapping applicable requirements, identifying control and documentation gaps, and prioritising the actions required before remediation, licensing or supervisory review.
An AML/CFT gap analysis identifies where the current compliance framework does not fully align with the requirements, risk profile and supervisory expectations relevant to the business.
The assessment is not limited to whether policies exist. Depending on scope, it can review governance, risk assessment, customer due diligence, transaction monitoring, sanctions, suspicious transaction reporting, training, outsourcing, record keeping and the evidence supporting implementation.
LEX ARTA structures the analysis around the client’s regulatory perimeter, jurisdiction, business model and control environment so that findings can be converted into a realistic remediation plan rather than a generic checklist.
The scope is tailored to the client’s jurisdiction, regulated activities, customer and product profile, delivery channels, transaction flows, technology and outsourcing model. A full review is not required where a targeted assessment is more appropriate.
The distinction matters: a gap analysis is not automatically an independent audit, and identifying a gap is not the same as implementing the remediation.
An AML/CFT gap analysis should not use a single universal checklist. The applicable baseline depends on the legal status of the business, regulated activities, jurisdiction, customer and product risks and sector-specific requirements.
For EU businesses, the assessment can be mapped to currently applicable national AML/CFT law and relevant EU requirements, including sector-specific rules such as Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets where applicable.
Future-state readiness for Regulation (EU) 2024/1624 (AMLR), which applies from 10 July 2027 for most obliged entities, can also be included where this is relevant to the client’s implementation planning.
The review is designed to identify what is missing, misaligned or insufficiently evidenced before a wider remediation, audit or regulatory-readiness project begins.
BOOK A CONSULTATION
Share the business context, jurisdiction and support you need. We will reply with a practical next step.