Compliance monitoring cycle

Obligations are risk-rated through the CRA. Residual risk drives where controls, monitoring tests, findings and board reporting focus their effort. The cycle closes when test results feed back into the next reassessment.

  1. Obligations
  2. RCSA1/1 submitted
  3. CRA1 accepted
  4. Controls
  5. Monitoring
  6. Findings
  7. Governance
All RCSA cycles

H1 2026 (Sample)

AR
Obligation × Control — first-line ratings

H1 2026 (Sample)

Each row is one control mapped to one obligation. The control owner rates design (is the control set up to work?) and operating (is it working in practice?) on a 1–4 scale, with commentary and an evidence pointer. Compliance then accepts or challenges each rating. Accepted ratings flow through to the CRA as control-effectiveness inputs.

Assessments
1
Submitted
1/1
Accepted (2LoD)
1
Under challenge
0
Challenge notes
0

Self-assessments · 1

  • ed63130d-7892-474e-9705-cda0e3ed0be8
    SEED-CDD-003 · SEED-CTL-0007
    Customer Due Diligence · Source of Funds & Wealth: Onboarding CDD checklist completed
    Design
    4/4
    Operating
    3/4
    Self rating
    4/4
    Review
    accepted