Knowledge Hub

Compliance,
explained by practitioners

Field guides and risk-assessment tools across BSA/AML, data privacy, cybersecurity, AI, and reporting, written by the people who sat in the chair and cited to the primary law.

100 articles22 regulatory domainscited to primary law
Start here
BSA/AML & Financial Crime
GuideField Guide

Sponsor-Bank Oversight: A CCO's Field Guide

Who owns what between a sponsor bank and its fintech partners, where partnerships fail an exam, and how to build oversight that produces evidence instead of binders.

Read →12 min
GuideField Guide

The BSA/AML Program Pillars, Explained

The five pillars in plain language: internal controls, a designated officer, training, independent testing, and customer due diligence. How each one shows up in an exam.

Read →10 min
Featured
Risk ToolField Guide

BSA/AML Risk Assessment: A Practitioner's Guide

The four risk categories, the inherent-to-residual method, how to score the matrix, and how examiners grade it. What the law actually requires, and where risk assessments fail an exam.

Read →12 min
Featured
Risk ToolField Guide

BSA/AML Independent Testing: The Third Pillar

The third pillar in practice: what independent testing covers, who can perform it, how often it runs, and how examiners and sponsor banks read the findings.

Read →11 min
Risk ToolField Guide

Customer Risk Rating: How to Score Customer Risk

How to score each customer's money-laundering risk: the inputs, the low, moderate, and high tiers and what they trigger, dynamic re-rating, and where ratings fail an exam.

Read →8 min
Risk ToolField Guide

How to Build a BSA/AML Risk Assessment Matrix

A step-by-step build: set the rating scale, rate inherent risk, score controls, derive residual risk, and aggregate to an enterprise rating. With a worked example.

Read →8 min
Risk ToolComparison

AML Audit vs. Independent Testing

The two terms get used interchangeably but are not identical. What each means, where they overlap, and which one satisfies the third pillar.

Read →7 min
GuideField Guide

FinCEN's Proposed AML/CFT Program Rule, Explained

What the proposed program rule (RIN 1506-AB72) would change: an effective, risk-based standard, a mandatory risk assessment tied to the national priorities, and what to do now. A proposal, not yet law.

Read →7 min
GuideField Guide

How to Write a SAR Narrative That Holds Up

The five W's and how, the anatomy of a strong narrative, a before/after example, the mistakes that draw scrutiny, and a filing-ready checklist.

Read →11 min
GuideField Guide

AML Program Gap Analysis: A Practitioner's Guide

What it is, when you need one, the benchmarks to measure against, a step-by-step method, how to score gaps, and how to turn findings into a remediation plan that closes.

Read →12 min
GuideField Guide

BSA/AML Exam Preparation: A Fintech's Field Guide

What the exam tests, how it unfolds, the documents examiners request, where fintechs get caught, and a runbook to be ready before the entry letter arrives.

Read →12 min
GuideField Guide

BaaS Compliance: What Fintechs Need Before Launch

Why compliance is the launch gate, what your sponsor bank checks in diligence, the program you need at go-live, onboarding and monitoring controls, and a pre-launch checklist.

Read →11 min
GuideMoney Transmitter

Money Transmitter Compliance: A Practitioner's Guide

Who needs a license, the state-by-state reality, the federal MSB layer, the BSA/AML obligations that come with it, and how to stay examiner-ready.

Read →13 min
GlossaryMoney Transmitter

Money Transmitter Glossary

The licensing and money-transmission terms in plain language: MSB, MTL, NMLS, surety bond, permissible investments, control person, and more.

Read →
Risk ToolMoney Transmitter

Money Transmitter Risk Assessment (BSA/AML)

What a BSA/AML risk assessment must cover for a money transmitter: the four risk categories weighted for the MSB model, the agent network, the two layers of review, and where these assessments fail an exam.

Read →9 min
GuideAustralia AML/CTF

Australia AML/CTF Compliance: A Practitioner's Guide

Who is a reporting entity, enrolment with AUSTRAC, the Part A / Part B program, the SMR / TTR / IFTI reports, independent review, and Tranche 2.

Read →13 min
GlossaryAustralia AML/CTF

Australia AML/CTF Glossary

The AUSTRAC-regime terms in plain language: reporting entity, designated service, AML/CTF Program, SMR, TTR, IFTI, Tranche 2, and more.

Read →
Risk ToolAustralia AML/CTF

Australia AML/CTF Risk Assessment (ML/TF Risk Assessment)

What an ML/TF risk assessment must cover under the AUSTRAC regime: the four risk factors, how it anchors the Part A program, how the 2024 reforms make it explicit, and where these assessments fall short.

Read →9 min
GlossaryReference

BSA/AML Compliance Glossary

The terms a compliance team actually uses, defined in plain language: SAR, CTR, CDD, EDD, KYC, beneficial ownership, OFAC, sponsor bank, SR 11-7, and more.

Read →
GuideField Guide

AML Compliance Training: A Practitioner's Guide

Why training is a BSA/AML pillar, who must be trained and on what, how to structure and govern the program as it scales, and the evidence an examiner expects.

Read →11 min
GuideField Guide

Training Needs Assessment for Compliance Teams: Mapping Roles to Obligations

A role-to-obligation matrix method for scoping BSA/AML training: a worked example, proportional depth by risk exposure, refresh triggers, and how to document the scoping so it survives an exam.

Read →9 min
Consumer Compliance
GuideCMS

Compliance Management System (CMS): The CFPB Framework

What a CMS is under the CFPB framework: board and management oversight plus a compliance program of policies, training, monitoring and audit, and consumer complaint response. How examiners assess it and how to build one.

Read →12 min
GuideUDAAP

UDAAP: Unfair, Deceptive, or Abusive Acts or Practices

What UDAAP prohibits: the legal standards for unfair, deceptive, and abusive acts or practices under Dodd-Frank, how it differs from the FTC Act, where it shows up, and how to control the risk.

Read →11 min
GuideFair Lending

Fair Lending: ECOA, Regulation B, and the Fair Housing Act

The prohibited bases under ECOA and the Fair Housing Act, disparate treatment versus disparate impact, the methods of proof, adverse action notices, redlining, and where fair-lending programs fall short.

Read →12 min
GuideFCRA

FCRA Compliance: The Fair Credit Reporting Act and Regulation V

Who is covered, permissible purpose, the accuracy and dispute duties of furnishers and credit reporting agencies, adverse action notices, and where FCRA programs fall short.

Read →12 min
GuideRegulation E

Regulation E: Electronic Fund Transfers and Error Resolution

What Regulation E and the EFTA require: scope, disclosures, the error resolution process and its timelines, consumer liability for unauthorized transfers, provisional credit, and where programs fall short.

Read →11 min
GuideFDCPA

FDCPA Compliance: The Fair Debt Collection Practices Act and Regulation F

Who is covered, the prohibited practices, the validation notice, the Regulation F communication and call-frequency limits, and where collection programs fall short.

Read →11 min
GuideField Guide

Which Regulations Actually Require Compliance Training? A Cross-Regime Map

A cross-regime map of which regulations actually mandate compliance training versus supervisory guidance, contractual standard, or unwritten best practice, covering BSA/AML, sanctions, securities, HIPAA, EU DORA, EU AI Act, GDPR, PCI-DSS, anti-corruption, OSHA, and more, each with its citation and legal class.

Read →9 min
Data Privacy
GuideGDPR

GDPR Compliance: A Practitioner's Guide

Who GDPR applies to, the core principles, lawful bases, data-subject rights, DPIAs, the 72-hour breach rule, DPO requirements, and penalties.

Read →14 min
GlossaryGDPR

GDPR Glossary

The data-privacy terms in plain language: controller, processor, lawful basis, DPIA, DPO, DSAR, SCCs, supervisory authority, and more.

Read →
Featured
Risk ToolGDPR

GDPR Data Protection Impact Assessment (DPIA)

When Article 35 requires a DPIA, what it must contain, how to conduct one step by step, when prior consultation is triggered, and where DPIAs go wrong.

Read →10 min
Risk ToolGDPR

GDPR Data Protection Audit: Accountability, ROPA, and the DPO

What a GDPR data protection audit covers: the accountability principle, the record of processing activities under Article 30, the DPO's monitoring role, supervisory-authority audits, and where these audits fall short.

Read →9 min
GuideHIPAA

HIPAA Compliance: A Practitioner's Guide

Who must comply, the Privacy / Security / Breach Notification Rules, the safeguards, risk analysis, BAAs, breach timelines, and enforcement.

Read →14 min
GlossaryHIPAA

HIPAA Glossary

The HIPAA terms in plain language: PHI, ePHI, covered entity, business associate, BAA, the three Rules, safeguards, minimum necessary, and more.

Read →
Featured
Risk ToolHIPAA

HIPAA Security Risk Analysis: A Practitioner's Guide

What 45 CFR 164.308 requires, what it must cover, how to conduct it, how it differs from a gap analysis, and why risk-analysis failures recur in OCR enforcement.

Read →10 min
Risk ToolHIPAA

HIPAA Compliance Audit: The Evaluation and the OCR Audit Protocol

What a HIPAA compliance audit covers: the Security Rule evaluation under 45 CFR 164.308(a)(8), the OCR Audit Protocol, who performs it, what it tests across the three rules, and where it goes wrong.

Read →9 min
GuideCCPA / CPRA

CCPA / CPRA Compliance: A Practitioner's Guide

Who must comply, the consumer rights, sale vs share, service providers vs contractors, notice at collection, the CPPA, and how CCPA differs from GDPR.

Read →13 min
GlossaryCCPA / CPRA

CCPA / CPRA Glossary

The California privacy terms in plain language: personal information, sensitive PI, business, service provider, sale, share, the CPPA, and more.

Read →
Risk ToolCCPA / CPRA

CCPA Risk Assessments: A Practitioner's Guide

When the CCPA and CPRA require a risk assessment, what it must weigh, how to conduct it, and how the CPPA treats submission.

Read →8 min
GuideBrazil LGPD

Brazil LGPD Compliance: A Practitioner's Guide

Territorial scope, the legal bases, data-subject rights, controlador / operador / encarregado roles, the ANPD and sanctions, and how LGPD differs from GDPR.

Read →13 min
GlossaryBrazil LGPD

Brazil LGPD Glossary

The Brazilian privacy terms in plain language: LGPD, ANPD, controlador, operador, encarregado, titular, legal basis, international transfer, and more.

Read →
Risk ToolBrazil LGPD

LGPD Data Protection Impact Report (RIPD)

What a RIPD is, when the ANPD may require it under Article 38, what it must contain, and how to prepare one.

Read →7 min
Cybersecurity & Operational Resilience
GuideNYDFS Cybersecurity

NYDFS Cybersecurity Compliance (23 NYCRR 500)

Who is covered, the cybersecurity program and CISO requirements, MFA and encryption, the 72-hour notice to DFS, and the annual certification.

Read →13 min
GlossaryNYDFS Cybersecurity

NYDFS Cybersecurity Glossary

The Part 500 terms in plain language: Covered Entity, CISO, nonpublic information, MFA, 72-hour notice, certification of compliance, and more.

Read →
Risk ToolNYDFS Cybersecurity

NYDFS Cybersecurity Risk Assessment (23 NYCRR 500.9)

What 500.9 requires, what it must cover, how often it must update after the 2023 amendments, and how it drives the program.

Read →8 min
Risk ToolNYDFS Cybersecurity

NYDFS Annual Certification of Compliance (23 NYCRR 500.17)

What the NYDFS annual submission requires under 500.17(b) after the 2023 amendments: the Certification of Material Compliance or the Acknowledgment of non-compliance, who signs, the evidence behind it, and where it goes wrong.

Read →8 min
GuidePCI DSS

PCI DSS Compliance: A Practitioner's Guide

Who must comply, the cardholder data environment and scope, the 12 requirements and 6 control objectives, merchant levels, SAQ vs ROC, and validation.

Read →13 min
GlossaryPCI DSS

PCI DSS Glossary

The card-security terms in plain language: cardholder data, CDE, PAN, SAD, QSA, ASV, SAQ, ROC, AOC, segmentation, tokenization, and more.

Read →
Risk ToolPCI DSS

PCI DSS Risk Assessment and Targeted Risk Analysis

How v4.0 replaced the annual assessment with the targeted risk analysis (Requirement 12.3.1), what it covers, and how to document it.

Read →8 min
Risk ToolPCI DSS

PCI DSS Assessment: ROC, SAQ, and the QSA

How PCI DSS compliance is validated: the Report on Compliance, the Self-Assessment Questionnaire, the Attestation of Compliance, the role of the QSA and ASV, how merchant level sets the path, and where assessments go wrong.

Read →9 min
GuideEU DORA

EU DORA Compliance

The five pillars of digital operational resilience: ICT risk management, incident reporting, resilience testing, third-party risk, and oversight of critical providers.

Read →14 min
GlossaryEU DORA

EU DORA Glossary

The DORA terms in plain language: ICT risk, critical third-party provider, register of information, major incident, threat-led penetration testing, and more.

Read →
Risk ToolEU DORA

DORA ICT Risk Management

What DORA's ICT risk management framework requires under Articles 5 to 16, the functions from identification to recovery, and how to build it.

Read →9 min
Risk ToolEU DORA

DORA Digital Operational Resilience Testing and TLPT (Articles 24 to 27)

What DORA's resilience testing program requires: the baseline testing every entity runs, threat-led penetration testing for the entities supervisors identify, who performs it, how often, and where it goes wrong.

Read →9 min
AI Governance
Financial Reporting & Controls
ESG & Sustainability
GuideEU CSRD

EU CSRD Compliance

Who is in scope after the Omnibus changes, double materiality, reporting against the ESRS, assurance, digital tagging, and the wave timeline as it stands now.

Read →13 min
GlossaryEU CSRD

EU CSRD Glossary

The sustainability-reporting terms in plain language: double materiality, ESRS, sustainability statement, limited assurance, ESEF tagging, Omnibus I, and more.

Read →
Risk ToolEU CSRD

CSRD Double Materiality Assessment

How impact and financial materiality work, how the assessment scopes what you report against the ESRS, and how to conduct one.

Read →8 min
GuideEU Packaging EPR

Packaging EPR Compliance (EU PPWR)

Who counts as a producer, EPR registration in each Member State, recyclability and recycled-content rules, reuse targets, and the phased PPWR timeline.

Read →13 min
GlossaryEU Packaging EPR

Packaging EPR Glossary (EU PPWR)

The EU packaging-EPR terms in plain language: extended producer responsibility, producer, eco-modulation, recyclability grade, recycled content, reuse target, and more.

Read →
Risk ToolEU Packaging EPR

Packaging Recyclability Assessment (EU PPWR)

How recyclability is assessed under the EU PPWR: the A to C performance grades, what the assessment establishes, how it gates market access and modulates EPR fees, and how to document it.

Read →8 min
GuideUS Packaging EPR

US Packaging EPR Compliance: The State Laws

The seven states with packaging EPR laws (Maine, Oregon, Colorado, California, Minnesota, Maryland, Washington), the producer responsibility organization model, who is an obligated producer, registration and reporting, fees, and the state-by-state timeline.

Read →12 min
GlossaryUS Packaging EPR

US Packaging EPR Glossary

The US state packaging-EPR terms in plain language: obligated producer, producer responsibility organization, Circular Action Alliance, covered material, eco-modulation, reimbursement model, needs assessment, responsible end market, and more.

Read →
Risk ToolUS Packaging EPR

US Packaging EPR Producer Obligation Assessment

How to assess your US packaging EPR obligations: whether you are an obligated producer, in which states, what covered packaging you must report, and your fee exposure under the producer responsibility organization model.

Read →9 min
GuideUS Packaging EPR

California Packaging EPR Requirements (SB 54)

What California's SB 54 requires: who is an obligated producer, the CalRecycle and Circular Action Alliance roles, the 2026 registration and reporting deadlines, the recycling and source-reduction targets, fees, and the up-to-$50,000-per-day penalties.

Read →8 min
GuideUS Packaging EPR

Oregon Packaging EPR Requirements (SB 582)

What Oregon's SB 582 (the Recycling Modernization Act) requires: who is an obligated producer, the live fee program, the May 31 reporting deadline, the uniform statewide collection list, and responsible end markets.

Read →8 min
GuideUS Packaging EPR

Colorado Packaging EPR Requirements (HB 22-1355)

What Colorado's HB 22-1355 requires: the producer-funds-everything model, who is an obligated producer, the January 2026 fee start and the May 31 reporting deadline, and free statewide recycling for residents.

Read →7 min
GuideUS Packaging EPR

Maine Packaging EPR Requirements (LD 1541)

What Maine's LD 1541 requires: the municipal cost-reimbursement model that makes Maine the outlier, the Maine DEP role, and the program timeline toward 2027.

Read →7 min
GuideUS Packaging EPR

Minnesota Packaging EPR Requirements (HF 3911)

What Minnesota's HF 3911 (the Packaging Waste and Cost Reduction Act) requires: who is an obligated producer, the 2025 registration and 2026 reporting, and the later cost-share timeline.

Read →7 min
GuideUS Packaging EPR

Maryland Packaging EPR Requirements (SB 901)

What Maryland's SB 901 requires: the multiple-PRO design, who is an obligated producer, the July 1, 2026 registration deadline, and the May 31, 2026 reporting deadline.

Read →7 min
GuideUS Packaging EPR

Washington Packaging EPR Requirements (SB 5284)

What Washington's SB 5284 (the Recycling Reform Act) requires: who is an obligated producer, the July 1, 2026 registration deadline, and the implementation phasing toward the end of the decade.

Read →7 min
Conduct
Compliance Consulting Practice
GuideField Guide

How to Write an RFP for a Compliance Consulting Engagement

How to write an RFP to source a compliance consulting firm: the five framing questions, the thirteen-section structure, and how to respond to one as a bidder.

Read →11 min
GuideField Guide

How to Write a Compliance Consulting Statement of Work

How to structure a compliance-consulting SOW, section by section: scope and the out-of-scope sentence, deliverables and the four-part acceptance mechanic, charging model, change management, and data safeguards.

Read →12 min
ComparisonField Guide

SOW vs. MSA: What's the Difference and What Goes in Each

The MSA governs the relationship. The SOW governs the work. What belongs in each, how they're supposed to fit together, and where compliance consulting engagements get the split wrong.

Read →10 min
GuideConsulting Practice

What Every Consulting Master Services Agreement Should Cover

The clause-by-clause checklist for a consulting MSA: payment and acceptance terms, IP ownership, liability caps, indemnification, insurance, and the cross-border data-transfer clause old templates still get wrong.

Read →14 min
GuideField Guide

Anatomy of a Real Statement of Work: Lessons from Government and Big-4 Contracts

Five real, public-record Statements of Work, from a DHS federal task order to a Deloitte/university consulting engagement, broken down clause by clause. What a real SOW has that a downloaded template never does.

Read →11 min
GuideField Guide

How to Write Terms of Reference for a Compliance Consulting Engagement

The 11-item Terms of Reference checklist, who should draft it depending on the client relationship, and the two items, exclusions and constraints, that cause scope creep when left blank.

Read →10 min
GuideConsulting Practice

The 5 Phases of a Consulting Engagement, Explained

Entry, Diagnosis, Action Planning, Implementation, Termination: the canonical five-phase shape of a consulting engagement, with the checklists and completion criteria each phase actually requires.

Read →18 min
ComparisonComparison

Daily Rate vs. Fixed Price: Choosing a Consulting Pricing Model

How to choose between daily-rate billing and a fixed price for a consulting engagement: the four contract families, a bottom-up bid sheet, a staffing-pyramid rate card, and how to defend the fee.

Read →11 min
GuideField Guide

How to Plan a Compliance Audit Engagement, Step by Step

The five stages a practitioner runs before a single document request goes out: client and engagement risk screening, independence clearance, a documented offer and acceptance, the pre-engagement meeting, and the signed engagement letter.

Read →11 min
Risk ToolField Guide

Independence and Conflict-of-Interest Checks Before Accepting an Audit Engagement

The two-tier bright-line test before quoting an audit engagement: disclosable conflicts vs. substantial conflicts that bar acceptance, the combination-rule trap, and worked ownership, indebtedness, and prior-employment scenarios.

Read →11 min
GuideConsulting Practice

How to Write a Corrective Action Plan After an Audit Finding

The field-by-field format for a corrective action plan after an audit or exam finding, a worked example, when to escalate to a team CAPA, and what makes examiners reject a CAP.

Read →11 min
GuidePractice Guide

The 8D Problem-Solving Method, Explained (Eight Disciplines for Corrective Action)

The nine disciplines from D0 to D8, why containment comes before root cause, the verify-versus-validate distinction, and how to run an 8D for a client after a vendor failure or an audit finding.

Read →13 min
GuideComparison

8D vs. 5 Whys vs. Fishbone: Choosing a Root Cause Analysis Tool

8D, 5 Whys, and the fishbone diagram get compared as if they compete. They don't. A decision table for when a technique is enough and when a client's exposure needs a governed 8D process.

Read →11 min
Risk ToolConsulting Practice

SOC 2 Report Review Checklist for Vendor Risk Teams

A 7-step method for reviewing a vendor's SOC 2 report: Type I vs. Type II fit, scope and Trust Services Criteria, exception triage, CUEC extraction, subservice organizations, and bridge letters.

Read →13 min
Risk ToolField Guide

The Vendor Risk Categories Every TPRM Program Should Cover

The eight inherent-risk categories a TPRM scoring model should cover, the tier and due-diligence depth each drives, and the separate ISACA threat-category lens a program's controls have to mitigate.

Read →11 min
GuideConsulting Practice

How to Run a Fraud Risk Assessment for a Client (COSO 5-Principle Method)

The COSO/ACFE three-step method for a fraud risk assessment: identify inherent risk across three fraud categories, assess likelihood and significance, map controls, and respond to residual risk. With a worked grid.

Read →10 min
GuideField Guide

How to Run a Compliance Program Effectiveness Review for a Client

The six-step method a consultant uses to test whether a client's compliance program actually works: DOJ ECCP's three questions, the seven §8B2.1 elements, and how to score and report each one.

Read →13 min
GuideField Guide

The Pyramid Principle: How Consultants Structure Recommendations, Slides, and Reports

How the Pyramid Principle, MECE grouping, and SCQ framing structure a consulting deliverable: answer-first writing, action titles, and ghost-deck storyboarding, with worked examples.

Read →13 min
GuideField Guide

Design vs. Operating Effectiveness: The Two Scores That Decide a Training-Program Audit

How auditors grade a training program on two separate scores: design effectiveness (the program as written) and operating effectiveness (the program as run). The regulatory floor, and where best practice takes over.

Read →9 min

Want this applied to your program?

These guides are the thinking. Compliance Command Center is how we put it to work: software-leveraged, practitioner-led, examiner-ready.