A payments firm under a regulatory undertaking had already had one remediation plan rejected. We ran the findings-to-closure program against the regulator's calendar, and the resubmission closed every finding on first review.
Growth had outrun the control environment: onboarding volumes had tripled while KYC operated on the original headcount and tooling. The regulator's findings letter ran to 31 items, and the firm's first response — a policy-rewrite exercise — was returned as insufficient. A second rejection would have triggered restrictions on new customer intake, which for a payments business is the growth engine.
We re-based the program on operational evidence rather than policy text: every finding mapped to a control, every control to an owner in the line, every owner producing evidence as a by-product of the process itself. Remediation ran in weekly increments with an internal challenge panel playing the regulator, so nothing entered the submission that hadn't already survived hostile review. The KYC operation itself was re-tooled so the fixed controls scaled with volume.
“The challenge panel was brutal and I resented every session. It is also why we only had to do this once.”
Facing something similar? Talk to the partner who ran this →