"Compliance risk has been
effectively managed."
JFSC Code Principle 3. At least annually. Documented.
The year-end attestation is the moment your governance meets the page. RegAlign assembles the evidence as you go, so the board statement isn't drafted from memory the week before it's due — it stands on the year's actual record.
One signed attestation, on the chain
The board reads — and signs — a single statement that the firm's compliance risk has been effectively managed during the period. The statement is generated from the live record, not retyped from minutes.
CRA — domain residual ratings
Every domain's residual rating with the change history that drove monitoring cadence across the year.
Monitoring — planned vs delivered
The annual plan, what completed, sample sizes, reproducibility seeds. No gaps unexplained.
Findings — opened, closed, validated
Mean time to close, validation status, remediation evidence. Open items dated and owned.
MLRO activity — aggregate only
Counts and trends, no case detail. The MLRO firewall holds even in the year-end pack.
Signed PDF · SHA-256 on chain · regulator-verifiable
When the board signs, the attestation PDF is hashed and the hash lands in the evidence chain. Your regulator drops the file into/verifyand gets a yes/no — without a call to you.
The Code asks for this — by sector
The JFSC Codes of Practice all carry an explicit "at least annually" board attestation on the effective management of compliance risk. The exact wording differs by sector — RegAlign honours each one.
- JFSC Code of Practice for Trust Company BusinessPrinciple 3 — corporate governance · explicit
"The board must satisfy itself, at least annually, that the registered person has assessed its compliance risk and is satisfied that compliance risk is being effectively managed."
- JFSC Code of Practice for Fund Services BusinessPrinciple 3 — corporate governance · explicit
"The board shall, at least annually, review the effectiveness of the compliance function and assess whether compliance risk has been effectively managed during the period."
- JFSC Code of Practice for Investment BusinessPrinciple 3 — corporate governance · explicit
"The board must assess, at least annually, the extent to which the registered person's compliance risk has been effectively managed and document its conclusion."
- JFSC Code of Practice for General Insurance Mediation BusinessPrinciple 3 · explicit
"The board shall annually review the firm's compliance arrangements and reach a documented view on the effective management of compliance risk."
- JFSC Code of Practice for Money Service BusinessPrinciple 3 · explicit
"The board must satisfy itself at least annually that compliance risk is being effectively managed and that the compliance arrangements remain appropriate."
- JFSC Code of Practice for Deposit-taking Business (Banking)Principle 3 — board responsibility for risk · implicit
"The board has ultimate responsibility for the registered person's compliance with regulatory requirements, including ongoing oversight of the management of compliance risk."
The cycle closes itself
The CRA drove the year's monitoring. Monitoring produced the findings. Findings drove remediation. Remediation fed back into the CRA. The annual attestation is the natural close — not a separate exercise.