AML/CFT  ·  Current-State Assessment

AML Regulatory Gap Analysis
& Compliance Assessment

A structured current-state versus required-state assessment for CASPs, fintech, payment institutions and other regulated businesses — mapping applicable requirements, identifying control and documentation gaps, and prioritising the actions required before remediation, licensing or supervisory review.

Map
Applicable requirements
& expectations
Assess
Current controls,
documents & evidence
Prioritise
Actions by regulatory
& operational risk
Know the distance between current state and required state

A practical regulatory baseline before remediation begins.

An AML/CFT gap analysis identifies where the current compliance framework does not fully align with the requirements, risk profile and supervisory expectations relevant to the business.

The assessment is not limited to whether policies exist. Depending on scope, it can review governance, risk assessment, customer due diligence, transaction monitoring, sanctions, suspicious transaction reporting, training, outsourcing, record keeping and the evidence supporting implementation.

LEX ARTA structures the analysis around the client’s regulatory perimeter, jurisdiction, business model and control environment so that findings can be converted into a realistic remediation plan rather than a generic checklist.

Current State
What exists today?
Policies, procedures, governance, systems, controls, ownership, evidence and operational practice.
Required State
What should be in place?
Applicable legal requirements, regulatory expectations and risk-based control standards relevant to the business.
Assessment scope

AML/CFT gap analysis across the control framework.

The scope is tailored to the client’s jurisdiction, regulated activities, customer and product profile, delivery channels, transaction flows, technology and outsourcing model. A full review is not required where a targeted assessment is more appropriate.

Regulatory Perimeter & Obligation Mapping
Identify the AML/CFT requirements, sector-specific rules and supervisory expectations that are relevant to the business and agreed review scope.
Governance & MLRO Oversight
Roles, responsibilities, management oversight, MLRO or equivalent authority, escalation lines, reporting arrangements, independence and control ownership.
Enterprise / Business-Wide Risk Assessment
Methodology, risk factors, weighting, documentation, review triggers and alignment between identified ML/TF risks and the control framework.
CDD / KYC & Beneficial Ownership
Identification and verification, beneficial ownership, purpose and nature, onboarding evidence, ongoing due diligence, periodic review and trigger events.
Customer Risk Rating & EDD
Risk classification, higher-risk triggers, PEP controls, source of funds / source of wealth measures, enhanced review, approvals and ongoing monitoring.
Transaction Monitoring & Investigation
Monitoring coverage, alert handling, investigation standards, escalation, decision records, governance of scenarios or rules and evidence of review.
Sanctions & PEP Screening
Screening governance, list coverage, alert handling, escalation, decision-making, restrictions and record keeping, taking account of the relevant sanctions framework.
Suspicious Transaction Reporting
Internal escalation, MLRO review, decision documentation, external reporting process, confidentiality controls and evidence retention.
Policies, Procedures & Record Keeping
Completeness, consistency, approval, version control, operational alignment, retention requirements and evidence that the written framework reflects actual practice.
Training & Staff Responsibilities
Role-based training coverage, frequency, responsibilities, escalation awareness and records demonstrating completion and relevant competence.
Outsourcing & Third-Party Controls
Allocation of responsibility, reliance arrangements where permitted, provider oversight, contractual control points, data flows and evidence of ongoing supervision.
Crypto / CASP & TFR Controls
Where relevant: crypto-asset customer risk, blockchain analytics governance, wallet-risk controls, self-hosted address procedures, Travel Rule / TFR workflows and crypto-specific escalation arrangements.
When a gap analysis is useful

Use it before a regulator, bank or business change exposes the gaps.

Licensing or Authorisation Readiness
Assess whether the existing AML/CFT framework is sufficiently developed for an application, registration or pre-authorisation review.
New Jurisdiction or Market Entry
Map an existing group framework against the requirements and supervisory expectations of a new market before launch.
Regulatory Change
Identify which policies, controls, systems or governance arrangements need to change when the applicable legal framework develops.
New Product or Business Model
Test whether AML/CFT controls remain appropriate after new products, customer segments, payment flows, crypto services, outsourcing or technology changes.
Bank, Investor or Partner Due Diligence
Identify material weaknesses before external parties assess the adequacy and maturity of the AML/CFT framework.
Before Remediation or Audit
Establish a clear baseline and prioritised action plan before launching a broader remediation programme or commissioning independent effectiveness testing.
How the assessment works

Requirement mapping, evidence review and prioritised findings.

01 — Scope & Regulatory Mapping
Confirm the regulated activities, jurisdiction, business model, products, customer types, transaction flows and the legal or supervisory baseline against which the framework will be assessed.
02 — Evidence & Documentation Review
Review the agreed set of policies, procedures, risk assessments, governance materials, workflows, control evidence, system descriptions and relevant records.
03 — Current-State Assessment
Compare the existing framework with the mapped requirements and identify missing, incomplete, inconsistent or insufficiently evidenced controls.
04 — Risk-Based Prioritisation
Classify findings by regulatory significance, financial-crime risk, control dependency and implementation urgency so that management can focus resources on the most material issues first.
05 — Remediation Roadmap & Debrief
Translate findings into sequenced corrective actions and discuss priorities, dependencies and practical next steps with management or the compliance function.
Typical deliverables

A decision-ready view of the gaps and what to fix first.

Management
Executive Summary
Concise overview of the most material weaknesses, regulatory exposure and priority actions for management attention.
Mapping
Requirements & Gap Matrix
Structured mapping of relevant requirements to current controls, evidence, identified gaps and recommended action.
Priorities
Risk-Rated Findings
Findings prioritised according to the agreed methodology and the relative regulatory and financial-crime significance of each issue.
Action
Remediation Roadmap
Sequenced corrective actions covering governance, documentation, process, systems, controls, evidence or training where relevant.
Documentation
Policy & Procedure Recommendations
Identification of documents that should be created, revised, consolidated or aligned with actual operational practice.
Optional
Management Workshop
Walk-through of findings, prioritisation logic, dependencies and next steps with management, MLRO or the wider compliance team.
Deliverables are defined in the engagement scope. A targeted gap analysis may cover only selected regulatory obligations or control areas.
Related but different

Gap Analysis identifies the deficiencies. Other services address different stages.

The distinction matters: a gap analysis is not automatically an independent audit, and identifying a gap is not the same as implementing the remediation.

01
AML Regulatory Gap Analysis
Identify what is missing or misaligned.
Current-state versus required-state assessment with prioritised corrective actions.
02
AML Audit & Compliance Review
Independently assess effectiveness.
Independent review that may test control design, implementation, evidence and operating effectiveness.
03
Policies & Procedures
Build or update the framework.
Design and documentation of governance, control standards and operational procedures.
04
Remediation
Implement the corrective actions.
Support to close identified deficiencies and strengthen the operating framework.
Regulatory basis

Mapped to the rules relevant to the business and jurisdiction.

An AML/CFT gap analysis should not use a single universal checklist. The applicable baseline depends on the legal status of the business, regulated activities, jurisdiction, customer and product risks and sector-specific requirements.

For EU businesses, the assessment can be mapped to currently applicable national AML/CFT law and relevant EU requirements, including sector-specific rules such as Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets where applicable.

Future-state readiness for Regulation (EU) 2024/1624 (AMLR), which applies from 10 July 2027 for most obliged entities, can also be included where this is relevant to the client’s implementation planning.

Jurisdiction-specific
The benchmark should be defined before the review starts. Cross-border groups may require separate mapping for different regulated entities or markets.
Evidence-based
Where the scope includes implementation review, conclusions should be supported by the documents, workflows, governance records and other evidence actually available to the business.
Common questions

AML/CFT Regulatory Gap Analysis — FAQ.

What is an AML/CFT regulatory gap analysis?
+
It is a structured comparison between the AML/CFT framework currently in place and the requirements and supervisory expectations relevant to the business. The purpose is to identify missing, incomplete or misaligned controls and translate the findings into prioritised corrective actions.
How is this different from an AML audit?
+
A gap analysis primarily establishes the distance between current state and required state. An AML audit is an independent assurance exercise and may include deeper testing of control design, implementation, operating effectiveness and evidence. The scope should make clear which level of testing is being performed.
Can you assess only one AML/CFT area?
+
Yes. The review can be full-framework or targeted, for example CDD/EDD, transaction monitoring, sanctions, governance, Enterprise-Wide Risk Assessment, Travel Rule / TFR or selected licensing-readiness requirements.
Can the review cover CASP and crypto-specific controls?
+
Yes. Where relevant, the scope can include CASP AML governance, crypto-asset customer risk, blockchain analytics governance, wallet-risk controls, self-hosted address procedures, Travel Rule / TFR workflows and crypto-specific monitoring or escalation arrangements.
Do you also fix the gaps identified?
+
Remediation can be scoped separately. The gap analysis identifies and prioritises deficiencies; remediation may then include policy updates, procedure design, governance changes, control implementation, training, evidence improvements or support with regulatory readiness.
How is the project priced?
+
Pricing is individually scoped and depends on the jurisdiction, regulatory perimeter, business model, number of entities or control areas, documentation volume and the depth of evidence review or testing required. A defined scope and fee are provided after the initial scoping discussion.
Need a clear view of your AML/CFT gaps?
Define the regulatory baseline, identify material deficiencies and prioritise the actions required for remediation or regulatory readiness.
Why LEX ARTA

Why LEX ARTA for AML Regulatory Gap Analysis.

The review is designed to identify what is missing, misaligned or insufficiently evidenced before a wider remediation, audit or regulatory-readiness project begins.

Structured DiagnosisThe assessment separates legal requirements, documented controls, operating practices and evidence gaps.
Practitioner-Led ReviewFindings are framed by experienced AML and compliance practitioners with regulated-sector context.
Prioritised FindingsMaterial gaps are distinguished from lower-risk improvements so management can sequence remediation.
Connected RemediationWhere required, identified gaps can feed directly into policies, EWRA, controls, training or remediation workstreams.