Process

A process built
for speed.

From first contact to active compliance monitoring — onboarding takes less than two weeks. No bureaucracy, no long discovery phases.

5

Business days
for gap report

48h

Response to
access requests

Overview

A typical engagement from access request to ongoing monitoring looks like this.

Day 1–2

Access granted

Onboarding call, intake form, and access to your compliance workspace.

Day 3–7

Framework mapping

We map your operations against applicable regulatory frameworks.

Day 8–10

Gap report delivered

Scored, prioritised findings with remediation paths and owner assignments.

Day 11+

Ongoing watch

Real-time alerts and monthly digests activate. Your compliance posture is live.

I.

Days 1–7

Intake & mapping

Everything starts with understanding your business precisely. We run a structured intake process — not a generic questionnaire — designed to pull out exactly what regulators would look for.

What we collect from you

  • Business model description and product flows
  • Customer types (retail, SME, institutional)
  • Transaction types and average volumes
  • Existing licenses and regulatory history
  • Current data handling and third-party integrations
  • Existing internal policies and documentation

What we map it against

  • CBN licensing categories and conditions
  • NDPC Data Protection Act obligations
  • SCUML AML/CFT registration requirements
  • SEC digital assets framework (where applicable)
  • FIRS digital service VAT obligations
  • CAC corporate structure requirements

Deliverable

A Framework Application Matrix — a structured document showing every applicable regulation mapped to your product, with the coverage status (compliant / gap / not applicable) for each requirement.

II.

Days 8–10

Remediation plan

A gap report is useless without a clear path to close the gaps. The remediation plan translates findings into an actionable, prioritised workbook your team can execute against immediately — with timelines, owners, and template documentation where it exists.

Critical

Regulatory breach risk

Gaps that could attract enforcement action, license suspension, or material fines. Addressed within 30 days with step-by-step remediation paths and ready-to-use policy templates.

Moderate

Operational exposure

Gaps that could cause friction during license applications, investor due diligence, or regulatory examinations. Addressed within 60–90 days with prioritised implementation sequencing.

Informational

Future-proofing

Best-practice gaps and upcoming regulatory changes to plan for. Addressed on a rolling basis as part of ongoing monitoring.

Remediation workbook

Structured spreadsheet with gap ID, severity, owner field, deadline, and status tracker

Policy templates

Ready-to-customise AML policy, privacy notice, data retention policy, and KYC procedure docs

Walkthrough session

60-minute call with your team to walk through findings and assign remediation ownership

III.

Day 11 onwards

Ongoing watch

Compliance isn't a one-time audit. The regulatory environment shifts constantly — new CBN directives, NDPC enforcement actions, SEC rulemaking — and your posture needs to shift with it. Ongoing watch is the perpetual engine that keeps you ahead.

Real-time alerts

Live

Within 2 hours of any publication from the 8 monitored agencies, you receive a plain-English alert with impact assessment and any required action.

Delivered via Slack and email · Relevance filtered to your product category

Monthly digest

Monthly

A consolidated view of everything that moved in the regulatory landscape that month — new circulars, enforcement actions, upcoming consultation deadlines, and what it means for your posture.

Delivered first week of each month · Archived in your compliance workspace

Posture reviews

Quarterly

Every quarter, we review your remediation progress, update your framework application matrix for any regulatory changes, and surface new gaps introduced by product changes.

60-min call + updated gap workbook delivery

Ad-hoc support

On-demand

New license application? Investor due diligence? CBN examination? Respond to ad-hoc compliance questions within one business day — without escalating to an external law firm every time.

Included in ongoing retainer · Escalation to legal counsel available

Common questions

Do we need a lawyer before engaging Komply?

No. Komply operates as a compliance intelligence and advisory function, not a law firm. For most startups at seed or Series A, we can handle the day-to-day regulatory workload without external legal counsel. We flag when legal escalation is genuinely necessary.

What if we already have an internal compliance officer?

Komply works well alongside internal compliance leads — we provide the regulatory intelligence and framework depth that's difficult to maintain in-house without a dedicated team. Many clients use us to augment their compliance officer rather than replace them.

How do alerts get filtered to our specific business?

During intake, we build a product and business model profile. Every regulatory publication is assessed against this profile before alerting — you won't receive a notification about a banking circular that doesn't apply to your payment product category.

How quickly can we get started?

We respond to access requests within 48 hours. Once confirmed, onboarding takes a single call and an intake form. Your first gap report is delivered within five business days of that call.

Start the process
today.

Fill in a short access request. We'll match you to the right starting point — gap analysis, monitoring, or licensing roadmap — based on your situation.

Request early access