BSA/AML Risk Assessment: A Practitioner's Guide
The four risk categories, the inherent-to-residual method, how to score the matrix, and how examiners grade it. What the law actually requires, and where risk assessments fail an exam.
BSA/AML Independent Testing: The Third Pillar
The third pillar in practice: what independent testing covers, who can perform it, how often it runs, and how examiners and sponsor banks read the findings.
GDPR Data Protection Impact Assessment (DPIA)
When Article 35 requires a DPIA, what it must contain, how to conduct one step by step, when prior consultation is triggered, and where DPIAs go wrong.
HIPAA Security Risk Analysis: A Practitioner's Guide
What 45 CFR 164.308 requires, what it must cover, how to conduct it, how it differs from a gap analysis, and why risk-analysis failures recur in OCR enforcement.
Sponsor-Bank Oversight: A CCO's Field Guide
Who owns what between a sponsor bank and its fintech partners, where partnerships fail an exam, and how to build oversight that produces evidence instead of binders.
The BSA/AML Program Pillars, Explained
The five pillars in plain language: internal controls, a designated officer, training, independent testing, and customer due diligence. How each one shows up in an exam.
BSA/AML Risk Assessment: A Practitioner's Guide
The four risk categories, the inherent-to-residual method, how to score the matrix, and how examiners grade it. What the law actually requires, and where risk assessments fail an exam.
BSA/AML Independent Testing: The Third Pillar
The third pillar in practice: what independent testing covers, who can perform it, how often it runs, and how examiners and sponsor banks read the findings.
Customer Risk Rating: How to Score Customer Risk
How to score each customer's money-laundering risk: the inputs, the low, moderate, and high tiers and what they trigger, dynamic re-rating, and where ratings fail an exam.
How to Build a BSA/AML Risk Assessment Matrix
A step-by-step build: set the rating scale, rate inherent risk, score controls, derive residual risk, and aggregate to an enterprise rating. With a worked example.
AML Audit vs. Independent Testing
The two terms get used interchangeably but are not identical. What each means, where they overlap, and which one satisfies the third pillar.
FinCEN's Proposed AML/CFT Program Rule, Explained
What the proposed program rule (RIN 1506-AB72) would change: an effective, risk-based standard, a mandatory risk assessment tied to the national priorities, and what to do now. A proposal, not yet law.
How to Write a SAR Narrative That Holds Up
The five W's and how, the anatomy of a strong narrative, a before/after example, the mistakes that draw scrutiny, and a filing-ready checklist.
AML Program Gap Analysis: A Practitioner's Guide
What it is, when you need one, the benchmarks to measure against, a step-by-step method, how to score gaps, and how to turn findings into a remediation plan that closes.
BSA/AML Exam Preparation: A Fintech's Field Guide
What the exam tests, how it unfolds, the documents examiners request, where fintechs get caught, and a runbook to be ready before the entry letter arrives.
BaaS Compliance: What Fintechs Need Before Launch
Why compliance is the launch gate, what your sponsor bank checks in diligence, the program you need at go-live, onboarding and monitoring controls, and a pre-launch checklist.
Money Transmitter Compliance: A Practitioner's Guide
Who needs a license, the state-by-state reality, the federal MSB layer, the BSA/AML obligations that come with it, and how to stay examiner-ready.
Money Transmitter Glossary
The licensing and money-transmission terms in plain language: MSB, MTL, NMLS, surety bond, permissible investments, control person, and more.
Money Transmitter Risk Assessment (BSA/AML)
What a BSA/AML risk assessment must cover for a money transmitter: the four risk categories weighted for the MSB model, the agent network, the two layers of review, and where these assessments fail an exam.
Australia AML/CTF Compliance: A Practitioner's Guide
Who is a reporting entity, enrolment with AUSTRAC, the Part A / Part B program, the SMR / TTR / IFTI reports, independent review, and Tranche 2.
Australia AML/CTF Glossary
The AUSTRAC-regime terms in plain language: reporting entity, designated service, AML/CTF Program, SMR, TTR, IFTI, Tranche 2, and more.
Australia AML/CTF Risk Assessment (ML/TF Risk Assessment)
What an ML/TF risk assessment must cover under the AUSTRAC regime: the four risk factors, how it anchors the Part A program, how the 2024 reforms make it explicit, and where these assessments fall short.
BSA/AML Compliance Glossary
The terms a compliance team actually uses, defined in plain language: SAR, CTR, CDD, EDD, KYC, beneficial ownership, OFAC, sponsor bank, SR 11-7, and more.
AML Compliance Training: A Practitioner's Guide
Why training is a BSA/AML pillar, who must be trained and on what, how to structure and govern the program as it scales, and the evidence an examiner expects.
Training Needs Assessment for Compliance Teams: Mapping Roles to Obligations
A role-to-obligation matrix method for scoping BSA/AML training: a worked example, proportional depth by risk exposure, refresh triggers, and how to document the scoping so it survives an exam.
Compliance Management System (CMS): The CFPB Framework
What a CMS is under the CFPB framework: board and management oversight plus a compliance program of policies, training, monitoring and audit, and consumer complaint response. How examiners assess it and how to build one.
UDAAP: Unfair, Deceptive, or Abusive Acts or Practices
What UDAAP prohibits: the legal standards for unfair, deceptive, and abusive acts or practices under Dodd-Frank, how it differs from the FTC Act, where it shows up, and how to control the risk.
Fair Lending: ECOA, Regulation B, and the Fair Housing Act
The prohibited bases under ECOA and the Fair Housing Act, disparate treatment versus disparate impact, the methods of proof, adverse action notices, redlining, and where fair-lending programs fall short.
FCRA Compliance: The Fair Credit Reporting Act and Regulation V
Who is covered, permissible purpose, the accuracy and dispute duties of furnishers and credit reporting agencies, adverse action notices, and where FCRA programs fall short.
Regulation E: Electronic Fund Transfers and Error Resolution
What Regulation E and the EFTA require: scope, disclosures, the error resolution process and its timelines, consumer liability for unauthorized transfers, provisional credit, and where programs fall short.
FDCPA Compliance: The Fair Debt Collection Practices Act and Regulation F
Who is covered, the prohibited practices, the validation notice, the Regulation F communication and call-frequency limits, and where collection programs fall short.
Which Regulations Actually Require Compliance Training? A Cross-Regime Map
A cross-regime map of which regulations actually mandate compliance training versus supervisory guidance, contractual standard, or unwritten best practice, covering BSA/AML, sanctions, securities, HIPAA, EU DORA, EU AI Act, GDPR, PCI-DSS, anti-corruption, OSHA, and more, each with its citation and legal class.
GDPR Compliance: A Practitioner's Guide
Who GDPR applies to, the core principles, lawful bases, data-subject rights, DPIAs, the 72-hour breach rule, DPO requirements, and penalties.
GDPR Glossary
The data-privacy terms in plain language: controller, processor, lawful basis, DPIA, DPO, DSAR, SCCs, supervisory authority, and more.
GDPR Data Protection Impact Assessment (DPIA)
When Article 35 requires a DPIA, what it must contain, how to conduct one step by step, when prior consultation is triggered, and where DPIAs go wrong.
GDPR Data Protection Audit: Accountability, ROPA, and the DPO
What a GDPR data protection audit covers: the accountability principle, the record of processing activities under Article 30, the DPO's monitoring role, supervisory-authority audits, and where these audits fall short.
HIPAA Compliance: A Practitioner's Guide
Who must comply, the Privacy / Security / Breach Notification Rules, the safeguards, risk analysis, BAAs, breach timelines, and enforcement.
HIPAA Glossary
The HIPAA terms in plain language: PHI, ePHI, covered entity, business associate, BAA, the three Rules, safeguards, minimum necessary, and more.
HIPAA Security Risk Analysis: A Practitioner's Guide
What 45 CFR 164.308 requires, what it must cover, how to conduct it, how it differs from a gap analysis, and why risk-analysis failures recur in OCR enforcement.
HIPAA Compliance Audit: The Evaluation and the OCR Audit Protocol
What a HIPAA compliance audit covers: the Security Rule evaluation under 45 CFR 164.308(a)(8), the OCR Audit Protocol, who performs it, what it tests across the three rules, and where it goes wrong.
CCPA / CPRA Compliance: A Practitioner's Guide
Who must comply, the consumer rights, sale vs share, service providers vs contractors, notice at collection, the CPPA, and how CCPA differs from GDPR.
CCPA / CPRA Glossary
The California privacy terms in plain language: personal information, sensitive PI, business, service provider, sale, share, the CPPA, and more.
CCPA Risk Assessments: A Practitioner's Guide
When the CCPA and CPRA require a risk assessment, what it must weigh, how to conduct it, and how the CPPA treats submission.
Brazil LGPD Compliance: A Practitioner's Guide
Territorial scope, the legal bases, data-subject rights, controlador / operador / encarregado roles, the ANPD and sanctions, and how LGPD differs from GDPR.
Brazil LGPD Glossary
The Brazilian privacy terms in plain language: LGPD, ANPD, controlador, operador, encarregado, titular, legal basis, international transfer, and more.
LGPD Data Protection Impact Report (RIPD)
What a RIPD is, when the ANPD may require it under Article 38, what it must contain, and how to prepare one.
NYDFS Cybersecurity Compliance (23 NYCRR 500)
Who is covered, the cybersecurity program and CISO requirements, MFA and encryption, the 72-hour notice to DFS, and the annual certification.
NYDFS Cybersecurity Glossary
The Part 500 terms in plain language: Covered Entity, CISO, nonpublic information, MFA, 72-hour notice, certification of compliance, and more.
NYDFS Cybersecurity Risk Assessment (23 NYCRR 500.9)
What 500.9 requires, what it must cover, how often it must update after the 2023 amendments, and how it drives the program.
NYDFS Annual Certification of Compliance (23 NYCRR 500.17)
What the NYDFS annual submission requires under 500.17(b) after the 2023 amendments: the Certification of Material Compliance or the Acknowledgment of non-compliance, who signs, the evidence behind it, and where it goes wrong.
PCI DSS Compliance: A Practitioner's Guide
Who must comply, the cardholder data environment and scope, the 12 requirements and 6 control objectives, merchant levels, SAQ vs ROC, and validation.
PCI DSS Glossary
The card-security terms in plain language: cardholder data, CDE, PAN, SAD, QSA, ASV, SAQ, ROC, AOC, segmentation, tokenization, and more.
PCI DSS Risk Assessment and Targeted Risk Analysis
How v4.0 replaced the annual assessment with the targeted risk analysis (Requirement 12.3.1), what it covers, and how to document it.
PCI DSS Assessment: ROC, SAQ, and the QSA
How PCI DSS compliance is validated: the Report on Compliance, the Self-Assessment Questionnaire, the Attestation of Compliance, the role of the QSA and ASV, how merchant level sets the path, and where assessments go wrong.
EU DORA Compliance
The five pillars of digital operational resilience: ICT risk management, incident reporting, resilience testing, third-party risk, and oversight of critical providers.
EU DORA Glossary
The DORA terms in plain language: ICT risk, critical third-party provider, register of information, major incident, threat-led penetration testing, and more.
DORA ICT Risk Management
What DORA's ICT risk management framework requires under Articles 5 to 16, the functions from identification to recovery, and how to build it.
DORA Digital Operational Resilience Testing and TLPT (Articles 24 to 27)
What DORA's resilience testing program requires: the baseline testing every entity runs, threat-led penetration testing for the entities supervisors identify, who performs it, how often, and where it goes wrong.
AI Model Governance for Compliance: An SR 11-7 Field Guide
What SR 11-7 requires, why it covers AI compliance tools, what validation means, explainability and the audit trail, the human in the loop, and the questions to ask any AI vendor.
EU AI Act Compliance
Who the Act binds, the four risk tiers and Annex III high-risk systems, the obligations on providers and deployers, GPAI model duties, conformity assessment, and the phased timeline.
EU AI Act Glossary
The EU AI Act terms in plain language: AI system, provider, deployer, high-risk AI, Annex III, prohibited practices, GPAI, conformity assessment, CE marking, and more.
EU AI Act Risk Management for High-Risk AI
What Article 9 requires in a risk management system for high-risk AI, how it runs across the lifecycle, and where the FRIA (Article 27) fits.
SOX Compliance: Internal Controls Over Financial Reporting
Who SOX applies to, Sections 302 and 404, the COSO framework, design vs operating effectiveness, deficiency severity, and the audit cycle.
SOX Glossary
The ICFR terms in plain language: Section 302, Section 404, material weakness, significant deficiency, COSO, RCM, key control, PCAOB, and more.
SOX ICFR Risk Assessment
The top-down, risk-based approach that scopes a SOX program: material accounts, relevant assertions, and risks of material misstatement.
SOX ICFR Audit: The External Auditor's Opinion (PCAOB AS 2201)
What the external audit of internal control over financial reporting covers under PCAOB AS 2201: the integrated audit, the top-down approach, management's 404(a) assessment versus the auditor's 404(b) opinion, and how a material weakness is reported.
EU CSRD Compliance
Who is in scope after the Omnibus changes, double materiality, reporting against the ESRS, assurance, digital tagging, and the wave timeline as it stands now.
EU CSRD Glossary
The sustainability-reporting terms in plain language: double materiality, ESRS, sustainability statement, limited assurance, ESEF tagging, Omnibus I, and more.
CSRD Double Materiality Assessment
How impact and financial materiality work, how the assessment scopes what you report against the ESRS, and how to conduct one.
Packaging EPR Compliance (EU PPWR)
Who counts as a producer, EPR registration in each Member State, recyclability and recycled-content rules, reuse targets, and the phased PPWR timeline.
Packaging EPR Glossary (EU PPWR)
The EU packaging-EPR terms in plain language: extended producer responsibility, producer, eco-modulation, recyclability grade, recycled content, reuse target, and more.
Packaging Recyclability Assessment (EU PPWR)
How recyclability is assessed under the EU PPWR: the A to C performance grades, what the assessment establishes, how it gates market access and modulates EPR fees, and how to document it.
US Packaging EPR Compliance: The State Laws
The seven states with packaging EPR laws (Maine, Oregon, Colorado, California, Minnesota, Maryland, Washington), the producer responsibility organization model, who is an obligated producer, registration and reporting, fees, and the state-by-state timeline.
US Packaging EPR Glossary
The US state packaging-EPR terms in plain language: obligated producer, producer responsibility organization, Circular Action Alliance, covered material, eco-modulation, reimbursement model, needs assessment, responsible end market, and more.
US Packaging EPR Producer Obligation Assessment
How to assess your US packaging EPR obligations: whether you are an obligated producer, in which states, what covered packaging you must report, and your fee exposure under the producer responsibility organization model.
California Packaging EPR Requirements (SB 54)
What California's SB 54 requires: who is an obligated producer, the CalRecycle and Circular Action Alliance roles, the 2026 registration and reporting deadlines, the recycling and source-reduction targets, fees, and the up-to-$50,000-per-day penalties.
Oregon Packaging EPR Requirements (SB 582)
What Oregon's SB 582 (the Recycling Modernization Act) requires: who is an obligated producer, the live fee program, the May 31 reporting deadline, the uniform statewide collection list, and responsible end markets.
Colorado Packaging EPR Requirements (HB 22-1355)
What Colorado's HB 22-1355 requires: the producer-funds-everything model, who is an obligated producer, the January 2026 fee start and the May 31 reporting deadline, and free statewide recycling for residents.
Maine Packaging EPR Requirements (LD 1541)
What Maine's LD 1541 requires: the municipal cost-reimbursement model that makes Maine the outlier, the Maine DEP role, and the program timeline toward 2027.
Minnesota Packaging EPR Requirements (HF 3911)
What Minnesota's HF 3911 (the Packaging Waste and Cost Reduction Act) requires: who is an obligated producer, the 2025 registration and 2026 reporting, and the later cost-share timeline.
Maryland Packaging EPR Requirements (SB 901)
What Maryland's SB 901 requires: the multiple-PRO design, who is an obligated producer, the July 1, 2026 registration deadline, and the May 31, 2026 reporting deadline.
Washington Packaging EPR Requirements (SB 5284)
What Washington's SB 5284 (the Recycling Reform Act) requires: who is an obligated producer, the July 1, 2026 registration deadline, and the implementation phasing toward the end of the decade.
FCA Consumer Duty: A Practitioner's Guide
The Consumer Principle, the cross-cutting rules, the four outcomes, and the governance and board-report obligations that evidence good outcomes.
FCA Consumer Duty Glossary
The UK retail-conduct terms in plain language: Consumer Principle, PRIN 2A, cross-cutting rules, the four outcomes, fair value, foreseeable harm, and more.
FCA Consumer Duty Fair Value Assessment
What a fair value assessment must weigh under the price and value outcome (PRIN 2A.4), who must do it, and how to evidence fair value.
How to Write an RFP for a Compliance Consulting Engagement
How to write an RFP to source a compliance consulting firm: the five framing questions, the thirteen-section structure, and how to respond to one as a bidder.
How to Write a Compliance Consulting Statement of Work
How to structure a compliance-consulting SOW, section by section: scope and the out-of-scope sentence, deliverables and the four-part acceptance mechanic, charging model, change management, and data safeguards.
SOW vs. MSA: What's the Difference and What Goes in Each
The MSA governs the relationship. The SOW governs the work. What belongs in each, how they're supposed to fit together, and where compliance consulting engagements get the split wrong.
What Every Consulting Master Services Agreement Should Cover
The clause-by-clause checklist for a consulting MSA: payment and acceptance terms, IP ownership, liability caps, indemnification, insurance, and the cross-border data-transfer clause old templates still get wrong.
Anatomy of a Real Statement of Work: Lessons from Government and Big-4 Contracts
Five real, public-record Statements of Work, from a DHS federal task order to a Deloitte/university consulting engagement, broken down clause by clause. What a real SOW has that a downloaded template never does.
How to Write Terms of Reference for a Compliance Consulting Engagement
The 11-item Terms of Reference checklist, who should draft it depending on the client relationship, and the two items, exclusions and constraints, that cause scope creep when left blank.
The 5 Phases of a Consulting Engagement, Explained
Entry, Diagnosis, Action Planning, Implementation, Termination: the canonical five-phase shape of a consulting engagement, with the checklists and completion criteria each phase actually requires.
Daily Rate vs. Fixed Price: Choosing a Consulting Pricing Model
How to choose between daily-rate billing and a fixed price for a consulting engagement: the four contract families, a bottom-up bid sheet, a staffing-pyramid rate card, and how to defend the fee.
How to Plan a Compliance Audit Engagement, Step by Step
The five stages a practitioner runs before a single document request goes out: client and engagement risk screening, independence clearance, a documented offer and acceptance, the pre-engagement meeting, and the signed engagement letter.
Independence and Conflict-of-Interest Checks Before Accepting an Audit Engagement
The two-tier bright-line test before quoting an audit engagement: disclosable conflicts vs. substantial conflicts that bar acceptance, the combination-rule trap, and worked ownership, indebtedness, and prior-employment scenarios.
How to Write a Corrective Action Plan After an Audit Finding
The field-by-field format for a corrective action plan after an audit or exam finding, a worked example, when to escalate to a team CAPA, and what makes examiners reject a CAP.
The 8D Problem-Solving Method, Explained (Eight Disciplines for Corrective Action)
The nine disciplines from D0 to D8, why containment comes before root cause, the verify-versus-validate distinction, and how to run an 8D for a client after a vendor failure or an audit finding.
8D vs. 5 Whys vs. Fishbone: Choosing a Root Cause Analysis Tool
8D, 5 Whys, and the fishbone diagram get compared as if they compete. They don't. A decision table for when a technique is enough and when a client's exposure needs a governed 8D process.
SOC 2 Report Review Checklist for Vendor Risk Teams
A 7-step method for reviewing a vendor's SOC 2 report: Type I vs. Type II fit, scope and Trust Services Criteria, exception triage, CUEC extraction, subservice organizations, and bridge letters.
The Vendor Risk Categories Every TPRM Program Should Cover
The eight inherent-risk categories a TPRM scoring model should cover, the tier and due-diligence depth each drives, and the separate ISACA threat-category lens a program's controls have to mitigate.
How to Run a Fraud Risk Assessment for a Client (COSO 5-Principle Method)
The COSO/ACFE three-step method for a fraud risk assessment: identify inherent risk across three fraud categories, assess likelihood and significance, map controls, and respond to residual risk. With a worked grid.
How to Run a Compliance Program Effectiveness Review for a Client
The six-step method a consultant uses to test whether a client's compliance program actually works: DOJ ECCP's three questions, the seven §8B2.1 elements, and how to score and report each one.
The Pyramid Principle: How Consultants Structure Recommendations, Slides, and Reports
How the Pyramid Principle, MECE grouping, and SCQ framing structure a consulting deliverable: answer-first writing, action titles, and ghost-deck storyboarding, with worked examples.
Design vs. Operating Effectiveness: The Two Scores That Decide a Training-Program Audit
How auditors grade a training program on two separate scores: design effectiveness (the program as written) and operating effectiveness (the program as run). The regulatory floor, and where best practice takes over.