Regulatory compliance audit of what you do
We will match what your product actually does against the definitions that decide whether it needs a permission, and check that the papers you hold still cover it.
When you need a regulatory compliance audit

A bank asked for your licence
An account application stopped on one question about permissions. Answering it needs a document, and nobody is sure which one is meant.
The product changed, the permission did not
You added a feature that moves money, stores identity or sells to consumers. The paper you hold was written for the product you had before.
A regulator wrote to you
A letter asks what you do and under what authority. The first answer sets the frame for everything that follows, including the tone.
You are opening in a new country
The same activity is free in one place and licensed in the next. Which it is depends on definitions written before your product existed.
Reporting deadlines keep slipping
Returns, filings and notifications sit with whoever remembers them. The condition attached to a permission is what quietly stops holding.
What you get
- Your activities matched to definitions
- The permissions each one needs
- Gaps ranked by what stops
- A calendar of standing duties
- Answers a regulator can read
What the compliance audit answers

The audit answers two questions and writes both down. Does what you actually do require a permission in the places where you do it. And does the permission you already hold still cover the product as it is today.
Neither question is answered by reading your own description of the business. Both are answered by reading the definitions in the rules, because a definition written years ago decides whether your feature falls inside it, and your marketing words have no standing in that comparison.
Where we look first
- What the product actually does, feature by feature, including the parts added after the last time anyone checked.
- Where your customers are and where the money and the data physically move between them and you.
- Every permission, registration and notification you already hold, and what each one is written for.
- The conditions attached to those permissions: reporting, capital, people, records, notice before a change.
- What you have told banks, stores, partners and customers about your regulatory position.
How a permission drifts
A permission is granted for a described activity. When the product grows a feature the description does not cover, the gap can go unnoticed instead of being created on purpose.
The same happens with conditions. A licence carries duties that run for as long as it does, and those duties survive staff changes, redesigns and the loss of whoever used to file them.
Four kinds of finding
Nothing is required
The activity sits outside every definition that would catch it. This finding is worth as much as the others, because it is what lets you answer a bank or a buyer with a sentence instead of a shrug.
A permission you do not hold
The activity falls inside a definition and no paper covers it. What follows is a decision about the route: apply, restructure the feature, or stop offering it in that place.
A permission that no longer fits
You hold something, and the product has moved past what it describes. The fix can be a variation of the existing permission instead of a new application, and the two run on different timetables.
A condition you are missing
The permission is right and a duty attached to it is not being met: a return, a notice, a record, a person who has to hold a role. This is the cheapest kind to close and the easiest to overlook.
Sources: in sectors where a member has undertaken commitments, measures of general application are administered reasonably, objectively and impartially, and a decision on a complete application comes in a reasonable period — article VI of the general agreement on trade in services. Article III adds publication, without that condition. Both bind member states.
Stages of work
Describing what you do — 3–5 working days.
The activity gets written down feature by feature, in words that can be compared with a definition. This step is easy to skip, and every later answer rests on it.
Placing it against the definitions.
For each place where you have customers, we will read the definitions that could catch the activity and say whether it falls inside, outside, or close enough to need a written position.
Reading the permissions you hold.
Each one gets checked for what it authorises, for how long, on what conditions, and whether the entity named on it is still the entity that runs the product.
Checking the standing duties.
Reporting, notification, record-keeping, capital, named roles. We will list what each permission demands and mark the ones nobody has been doing.
Ranking the gaps by what they stop.
A gap that blocks a bank account is not the same as one that blocks a market you enter next year. We will sort them by what they hold up and by how soon it matters.
The report and the answers.
One document with the activity map, the position taken on each definition, the gaps and what closes them.
It ends with the short answers you can give a bank, a store or a buyer, each with the document that supports it.
The wider practice this belongs to is Licensing & Compliance.
FAQ
Two things, and it writes both down. First, whether what you do falls inside a definition that requires a permission in each place you do it. Second, whether the permissions you already hold still describe the product, and whether the duties attached to them are being met. The output is an activity map, a position on each definition with the reasoning behind it, and a list of gaps sorted by what each one holds up.
By comparing the activity with the definition, not with other companies. Definitions are written for categories that existed before your product, and a feature can fall inside one without resembling anything the category was named after. The comparison has to be made separately for every place you have customers, because the same activity is free in one and licensed in the next. Where the answer is close, the useful output is a written position instead of a verdict.
What matters is not its age but its description. A permission authorises a described activity, and over time the product grows features the description never mentioned. When that happens, the fix can be a variation of the permission you hold, which runs on a different timetable from a fresh application. The same check covers the entity named on the document: after a restructuring, the company running the product is sometimes not the one the permission was issued to.
Less than people assume, and more than nothing. Where a state has taken on commitments for a sector, the general agreement on trade in services asks it to administer the rules reasonably, objectively and impartially, to tell an applicant the decision on a complete application within a reasonable period, and to give the status of the application on request. That is an obligation between states, and it reaches you only through the law your country has enacted from it.
Discuss
the Task
Speak to our team
Speak to our team. Tell us about your task –
we’ll help you with it in any jurisdiction.
