See everything, prove everything
Compliance, managed. For you. And your clients.
A compliance management platform for regulated firms: your own compliance function and your clients'. Obligations, risks, controls, monitoring, actions and reports in one system, with one audit trail behind every number.
Risks Inherent. Residual. Entity-scoped.
A pre-built risk taxonomy mapped to your obligations, with inherent and residual scoring against your risk appetite.
- Inherent is likelihood times impact on the 4×4. Residual is inherent less the deduction your controls earn.
- Read against the entity's own appetite bands, never a house average.
- A heatmap your committee will actually open.
Residual Risks by Appetite Band
Risk counts grouped by residual appetite band, across top-level (L1) risks.
Top 10 Residual Risks
L1 risks ranked by residual score (highest first).
| # | Risk | Category | Residual | Obligations | Controls | Open actions |
|---|---|---|---|---|---|---|
| 1 | Financial Crime Governance | Financial Crime | 12/16 | 161 | 3 | 1 |
| 2 | Resilience | Governance, Risk and Compliance | 12/16 | 30 | 2 | 2 |
| 3 | Customer Due Diligence | Financial Crime | 12/16 | 716 | 5 | 1 |
| 4 | Sanctions | Financial Crime | 9/16 | 19 | 1 | 1 |
| 5 | Audit & Accounts | Governance, Risk and Compliance | 9/16 | 171 | 1 | 3 |
| 6 | Outsourcing | Governance, Risk and Compliance | 8/16 | 277 | 2 | 1 |
| 7 | Client Assets | Conduct of Business | 8/16 | 142 | 3 | 0 |
| 8 | Conflicts of Interest | Conduct of Business | 8/16 | 58 | 2 | 1 |
| 9 | Data Protection | Governance, Risk and Compliance | 6/16 | 96 | 2 | 0 |
| 10 | Business Continuity | Prudential | 6/16 | 41 | 1 | 1 |
Inherent vs Residual by Appetite Band
L1 risk counts by appetite band — inherent vs residual.
| Band | Inherent | Residual |
|---|---|---|
| Accepted | 9 | 24 |
| Within | 20 | 21 |
| Approaching | 17 | 9 |
| Outside | 11 | 3 |
Upcoming Reviews / Risk Alerts
Scheduled review dates, soonest first.
| Risk | Level | Next review |
|---|---|---|
| Sanctions | L1 | in 3 days |
| Screening Vendor Outage | L2 | in 6 days |
| Customer Due Diligence | L1 | in 13 days |
| Resilience | L1 | in 27 days |
Worst Risk Score by Category
| Category | Inherent | Residual |
|---|---|---|
| Governance, Risk and Compliance | 16/16 | 12/16 |
| Financial Crime | 16/16 | 12/16 |
| Conduct of Business | 12/16 | 8/16 |
| Prudential | 9/16 | 6/16 |
Actions Corrective. Monitoring. Escalation. One workflow.
Corrective, monitoring and escalation actions. Each with an owner, a deadline and a trail back to what triggered it.
- Linked to the trigger: the test result, the breach record, the regulatory change.
- Owners, deadlines and automatic reminders so nothing sits unowned.
- The trail of escalations sits next to the trail of fixes, so auditors see both.
| Action name | Trigger | Owner(s) | Due date | Priority | Status |
|---|---|---|---|---|---|
| Investigate NAV pricing error on Meridian Global Bond Fund | NAV Calculation Accuracy Test — Q4 2025 | 18/08/2026 | Urgent | Active | |
| Enhanced due diligence on PEP-connected trust structure | Governance & Risk | 19/08/2026 | Urgent | Active | |
| File MLRO notification for PEP-connected trust structure | MLRO Function & External SAR Submission | 19/08/2026 | Urgent | Active | |
| Complete KYC remediation for 8 medium-risk corporate clients | KYC Remediation Programme — Phase 2 | 21/08/2026 | High | Active | |
| Remediate Q3 2025 CDD file review findings | AML/CFT CDD File Review — Q4 2025 | 22/08/2026 | High | Active | |
| Update Business Continuity Plan following failover test | Business Continuity Plan | 26/08/2026 | High | Active | |
| Refresh sanctions screening watchlist configuration | Sanctions list update — OFSI | 28/08/2026 | Medium | Active | |
| Close out investor complaint — delayed redemption payment | Complaints | 01/09/2026 | High | Active | |
| Review outsourcing agreement for transfer agency provider | Outsourcing (L1) | 04/09/2026 | Low | Draft | |
| Prepare board paper on revised risk appetite statement | JFSC Code of Practice Compliance Review | 05/09/2026 | Medium | Draft | |
| Refresh sanctions screening thresholds after OFSI list update | Sanctions list update — OFSI | 09/09/2026 | High | Draft |
CMP Doing it right.
Design the plan, schedule the tests, record the findings, evidence the outcome. Effectiveness shown by what the testing achieves.
- Tests linked to controls, controls linked to obligations, so the plan addresses what matters.
- Calendar view with alerts when tests fall due.
- Findings raise actions automatically; a CMP report is ready for the committee or the regulator at any point in the year.
| Title | Plan | Owner(s) | Status | Conclusion | Start Date | Due Date |
|---|---|---|---|---|---|---|
| Sanctions Screening Test | Q1 2026 AML/CFT Testing Programme | Active | In Progress | 04/08/2026 | 18/08/2026 | |
| CDD File Review — Q3 Sample | Q1 2026 AML/CFT Testing Programme | Active | Fail - Needs Review | 20/07/2026 | 21/08/2026 | |
| NAV Calculation Accuracy Test | NAV Accuracy Testing Programme Q1 2026 | Complete | Pass | 01/06/2026 | 12/06/2026 | |
| Pricing Source Reconciliation | NAV Accuracy Testing Programme Q1 2026 | Active | In Progress | 10/08/2026 | 28/08/2026 | |
| Client Asset Segregation Check | JFSC Code of Practice Compliance Review | Complete | Fail Critical | 08/06/2026 | 26/06/2026 | |
| Complaints Handling Timeliness | JFSC Code of Practice Compliance Review | Complete | Pass | 22/06/2026 | 10/07/2026 | |
| KID Accuracy Check | Investor Communications Review | Draft | In Progress | 01/09/2026 | 18/09/2026 | |
| Trust Instrument Execution Sample | Annual Trust Administration Review 2026 | Active | Pass - Minor Issues | 27/07/2026 | 14/08/2026 | |
| Registry Filing Deadlines Check | Annual Trust Administration Review 2026 | Complete | Pass | 06/07/2026 | 24/07/2026 | |
| Payment Dual-Control Test | – | Complete | Pass | 13/07/2026 | 31/07/2026 | |
| Screening Vendor Fallback Test | – | Draft | In Progress | 07/09/2026 | 25/09/2026 |
Controls Mapped to what they satisfy.
A control register mapped to obligations and risks. Control mapping and gap analysis without the workshop.
- Design and operating-effectiveness ratings, with the lower of the two driving residual risk.
- Obligations without controls, controls without recent tests, risks without owners: all answered from the same data.
| Title | Risk(s) | Description | Owner(s) | Frequency | Rating | Status | Actions |
|---|---|---|---|---|---|---|---|
| AML/CFT/CPF Policy & Procedures Manual | Suitability (L1)Risk Assessment (L2) | Board-approved AML/CFT/CPF policy and procedures manual, maintained… | Annually | Established | Draft | 2 | |
| Anti-Bribery & Corruption Arrangements | – | Board-approved policy prohibiting bribery and corruption in any form,… | – | Established | Active | 2 | |
| Auditor Appointment & Engagement | Financial Resources (L1)Resilience (L1) | Control governing the appointment of the auditor and engagement letter… | – | Established | Active | 1 | |
| Best Execution & Order Handling Procedure | Financial Crime Monitoring (L1) | Procedure ensuring client orders are executed promptly, fairly and in due turn… | – | Established | Active | 2 | |
| Business Continuity Plan | Client Assets (L1) | Documented and tested business continuity and operational resilience… | – | Established | Active | 2 | |
| Capital & Liquidity Monitoring Control | Financial Crime Governance (L1) | Ongoing monitoring of minimum capital, net asset and (where applicable)… | – | Established | Active | 1 | |
| CDD Exemptions & Simplified Measures Control | Customer Due Diligence (L1) | Control governing the application of CDD exemptions and concessions… | Annually | Established | Active | 2 | |
| Client Asset Reconciliation | Client Assets (L1) | Daily reconciliation of client money and custody assets against external… | Daily | Established | Active | 0 | |
| Complaints Handling Procedure | Resilience (L1) | Documented procedure for logging, acknowledging, investigating and… | – | Developing | Active | 1 | |
| Conflicts of Interest Register Review | Suitability (L1) | Periodic review of the conflicts register and the effectiveness of… | Quarterly | Established | Active | 0 | |
| Data Protection Impact Assessment | Resilience (L1) | DPIA carried out before any new processing likely to result in high… | – | Developing | Draft | 1 |
Registers Pre-built registers. Configurable fields.
Breaches, complaints, gifts, conflicts, PEPs, sanctions, outsourcing, each with a default schema, configurable fields and alerts you can set.
- An audit trail on every record.
- One-click export for the auditor or the regulator.
- Build your own register with the form builder.
| Name | Owner(s) | Draft | Active | Complete | Archived |
|---|---|---|---|---|---|
| Breaches | 1 | 3 | 8 | 2 | |
| CDD Reliance | 0 | 4 | 11 | 3 | |
| Complaints | 1 | 2 | 5 | 1 | |
| Conflicts | 0 | 3 | 6 | 2 | |
| Data Subject Access Requests | 1 | 2 | 7 | 4 | |
| Error/Loss | 2 | 5 | 12 | 3 | |
| Exceptions | 1 | 4 | 6 | 0 | |
| Gifts and Entertainment Register | 3 | 9 | 17 | 2 | |
| Insurance | 0 | 1 | 4 | 1 | |
| Litigation | 0 | 1 | 2 | 1 | |
| Outsourcing | 1 | 3 | 5 | 0 | |
| People | 0 | 8 | 1 | 0 |
Regulatory library Pre-built. Kept current.
A pre-built obligations library, kept current. When a rule changes, the system flags it and the action to deal with it is one click away.
- Jersey Codes of Practice pre-built (Trust Company Business, Investment Business, Fund Services, Banking), with Guernsey, the Isle of Man and further jurisdictions to follow.
- Mapped to the risk taxonomy and a starter set of controls, so you are assessing risk on day one.
- Add your own obligations for internal policies and non-regulatory standards.
| Title | Regulator | Status | Pending approvals | Regulatory activities |
|---|---|---|---|---|
| AML/CFT/CPF Handbook | JFSC | Active | 5 | Accountant, Alternative Investment … |
| Code of Practice for Alternative Investment Funds and AIF Services Business - EU/EEA regime | JFSC | Active | – | Alternative Investment Funds |
| Code of Practice for Alternative Investment Funds and AIF Services Business - UK regime | JFSC | Active | – | Alternative Investment Funds |
| Code of Practice for Certified Funds - Schedule 1 | JFSC | Active | – | Certified Investment Funds |
| Code of Practice for Certified Funds - Schedule 2: Jersey Expert Fund Guide | JFSC | Active | – | Certified Investment Funds |
| Code of Practice for Certified Funds - Schedule 3: Jersey Listed Fund Guide | JFSC | Active | – | Certified Investment Funds |
| Code of Practice for Certified Funds - Schedule 4: OCIF Guide | JFSC | Active | – | Certified Investment Funds |
| Code of Practice for Certified Funds - Schedule 5: Jersey Eligible Investor Fund Guide | JFSC | Active | – | Certified Investment Funds |
| Code of Practice for Deposit-taking Business: Appointment of Auditor | JFSC | Active | – | Deposit Taking |
| Code of Practice for Deposit-taking Business: Declaration of Compliance | JFSC | Active | – | Deposit Taking |
| Code of Practice for Deposit-taking Business: Financial Statements | JFSC | Active | – | Deposit Taking |
Reports Live data. Committee-ready.
Board packs and committee dashboards, pulled from live data, formatted to send.
- Seven report types: risk register, risk appetite, controls effectiveness, monitoring plan, obligations coverage, actions, audit trail.
- Per-entity views for client boards; consolidated views for group governance.
- Every report reads from the same underlying data, so the numbers reconcile.
Risk Heatmap
Each L1 risk plotted by its inherent likelihood × impact, with cells coloured by the appetite band that score falls into.
Residual risk by category
Worst residual score in each category, out of 16.
Top 10 Residual Risks
L1 risks ranked by residual score (highest first).
| # | Risk | Category | Residual | Obligations | Controls | Open actions |
|---|---|---|---|---|---|---|
| 1 | Financial Crime Governance | Financial Crime | 12/16 | 161 | 3 | 1 |
| 2 | Resilience | Governance, Risk and Compliance | 12/16 | 30 | 2 | 2 |
| 3 | Customer Due Diligence | Financial Crime | 12/16 | 716 | 5 | 1 |
| 4 | Sanctions | Financial Crime | 9/16 | 19 | 1 | 1 |
| 5 | Audit & Accounts | Governance, Risk and Compliance | 9/16 | 171 | 1 | 3 |
| 6 | Outsourcing | Governance, Risk and Compliance | 8/16 | 277 | 2 | 1 |
| 7 | Client Assets | Conduct of Business | 8/16 | 142 | 3 | 0 |
| 8 | Conflicts of Interest | Conduct of Business | 8/16 | 58 | 2 | 1 |
| 9 | Data Protection | Governance, Risk and Compliance | 6/16 | 96 | 2 | 0 |
| 10 | Business Continuity | Prudential | 6/16 | 41 | 1 | 1 |
Inherent vs Residual by Appetite Band
L1 risk counts by appetite band — inherent vs residual.
| Band | Inherent | Residual |
|---|---|---|
| Accepted | 9 | 24 |
| Within | 20 | 21 |
| Approaching | 17 | 9 |
| Outside | 11 | 3 |
Entities One system. Yours and your clients'.
Your firm and your clients': each entity with its own registers, risk assessment and monitoring plan, access and reporting controlled at entity level.
- Per-entity access for client boards.
- Consolidated reporting internally; a board-ready pack for each client.
- Modular AML/CFT/CPF-only scope for firms that need just that.
| Name | Description | Type | Country of incorporation | Jurisdiction |
|---|---|---|---|---|
| Meridian Trust Group Ltd | Jersey-incorporated holding company for the Meridian Trust Group. Provides group-le… | Internal | 🇯🇪 Jersey | 🇯🇪 Jersey |
| Meridian Corporate Services Ltd | Corporate administration and company secretarial services for Jersey and international … | Internal | 🇯🇪 Jersey | 🇯🇪 Jersey |
| Meridian Fund Services Ltd | Fund administration services including NAV calculation, investor servicing, transfer age… | Internal | 🇯🇪 Jersey | 🇯🇪 Jersey |
| Meridian Trust Company Ltd | JFSC-regulated trust company providing trust administration, fiduciary services, and tr… | Internal | 🇯🇪 Jersey | 🇯🇪 Jersey |
| Harbourview Capital Ventures Ltd | BVI-incorporated private equity holding vehicle administered for an institutional client. | External | 🇻🇬 Virgin Islands (British) | 🇰🇾 Cayman Islands |
| Harbourview Capital GP Ltd | General partner vehicle for the Harbourview limited partnership fund structures. | External | 🇰🇾 Cayman Islands | 🇰🇾 Cayman Islands |
| Meridian Nominees Ltd | Nominee holding company providing bare trustee and nominee shareholder services fo… | Internal | 🇯🇪 Jersey | 🇯🇪 Jersey |
| Oakvale Family Holdings Ltd | Jersey holding company for the Oakvale family office structure, administered under a tr… | External | 🇯🇪 Jersey | 🇯🇪 Jersey |
| Oakvale Marine Ltd | Guernsey-incorporated yacht-owning SPV administered on behalf of the Oakvale family. | External | 🇬🇬 Guernsey | 🇬🇬 Guernsey |
| Oakvale Property Investments Ltd | UK-incorporated property-holding SPV owning UK real estate assets within the Oakvale struct… | External | 🇬🇧 United Kingdom | 🇬🇧 United Kingdom |
| Meridian Wealth Management Ltd | Discretionary and advisory investment management services for private clients and inst… | Internal | 🇯🇪 Jersey | 🇯🇪 Jersey |
| Meridian Investment Advisers Ltd | FCA-authorised advisory-only subsidiary providing investment advice to trust and fund str… | Internal | 🇬🇧 United Kingdom | 🇬🇧 United Kingdom |
Audit trail Audit by design.
Every record change timestamped, attributed and exportable.
- ISO/IEC 27001 certified for information security; aligned to ISO 37301 (the methodology spine) and ISO 31000.
- Data resides in your own region (UK data in the UK, EU data in the EU, US data in the US) and stays there.
- Role-based, entity-scoped access, with SAML single sign-on.
- Every record change timestamped, attributed and exportable.
- Regulatory change flagged — Section 3.4 (Enhanced CDD for PEPs) amended by the JFSC; 5 obligations affected
- Approval requested — 5 obligation updates pending compliance sign-off
- Action opened — Update PEP approval procedure for amended Section 3.4
- Obligation approved — 4.3.1 Ongoing monitoring of business relationships
- Obligation excerpt linked — Section 4.3.1 → AML/CFT/CPF Policy & Procedures Manual
- Risk mapped — Section 7 (Sanctions) → Sanctions (L1)
- Control linked — CDD Exemptions & Simplified Measures Control → Section 4.5
- Approval completed — Section 2 (Corporate governance) obligations, 12 approved
- Note added — “Cross-check against the Handbook Q2 consultation paper”
- Section approved for use — Section 4 (Customer due diligence), 38 obligations
- Source status changed — Draft → Active
- Obligations imported — 12 sections, mapped to the risk taxonomy
- Source created — AML/CFT/CPF Handbook (JFSC)
Runs with what you already run.
Run something else? Tell us what your stack looks like. Integration scoping is part of the onboarding conversation, not a change request after it.
Client book
Quantios Core
Your administered book syncs from Quantios Core. The entities you run there are the entities you monitor here. Nothing re-keyed.
SAML · every tier
Single sign-on
Microsoft Entra ID or any SAML identity provider. Access is role-based and entity-scoped from the first login.
One-click export
Excel
Every register and report exports to Excel: the committee pack, the auditor, the regulator return.
Imported at onboarding
Your existing data
Registers, risk assessments and monitoring histories come across from your spreadsheets and systems. Done for you, checked with you.
Live in days. Not months.
No consulting day-rates. No six-month implementation plan. No tool your team quietly avoids.
Day one, your firm is modelled and the licence type populates the library, the risk taxonomy and the starter controls. Your existing data comes across in the first week, done for you and checked with you. By the first month the CMP is signed off and running, and the old estate is retired.
After go-live, structured support sits behind the platform, and a named customer-success contact where the scale of the book calls for one.
Day one
Model the firm
Jurisdiction, entity structure, licence type. The obligations register, risk taxonomy and starter controls populate from it.
The first week
Bring the data across
Registers, the risk assessment, the monitoring history. Imported for you, checked with you. Nothing re-keyed.
The first month
Run the CMP
Signed off and on the calendar. Access scoped per entity, and per client board where you run a book.
Then
Retire the old estate
The spreadsheets close. One system, one data model, one audit trail.
Ongoing
Support that stays
Structured support behind the platform, and a named customer-success contact where the scale of the book calls for one.
The committee pack used to take a week to assemble. Now it pulls live the day before the meeting, and every number in it traces back to a record.
Twelve client entities, each with its own registers and monitoring plan, and for the first time one view across all of them that I can put in front of the audit committee.
I run six client functions on it. Same methodology on every engagement, and each client keeps their own data and audit trail. That is how outsourced compliance should work.
30 minutes. Tailored. No deck.
A short demo in the context of your firm: your entity structure, your licences, the obligations that actually apply to you. You bring a real workflow; we show you how Vantage Point runs it.