Products / Compliance X-Ray

See your program the way an examiner reads it.

An expert-led diagnostic of your compliance framework, across every jurisdiction you operate in, with technology doing the reading. We trace the whole chain, from obligation to risk, policy, procedure, control, evidence, testing and issue, and show where it holds, where it breaks and what matters most.

Who it’s for

For programs that have grown in layers.

  • A framework built over years by different people, where nobody is certain everything still connects.
  • A firm facing an examination, an acquisition, a new market or a new license that needs the program to hold together under someone else’s reading.
  • A new compliance officer inheriting a program and wanting an honest picture in the first month.
  • A firm regulated in more than one country, where the rulebooks overlap and the framework has to answer to all of them at once.

What you get

What you receive.

Findings ordered by significance, not by volume, and a plan that separates what must be fixed now from what can reasonably wait.

  • Executive diagnostic

    A short management view of program health, the major exposures and the themes that run through them.

  • Heat map

    Exposure across regulatory domains, entities and jurisdictions, on one page.

  • Regulatory coverage map

    The connections, and the broken connections, between the requirements that apply to you and your policies, procedures, controls, owners, evidence and testing.

  • Prioritized findings

    Each material finding with its regulatory context, the evidence behind it, the exposure it creates and the action we recommend.

  • Remediation roadmap

    What needs attention immediately, what to remediate in the next 30 to 90 days, what to strengthen over three to six months, and what belongs in a longer plan.

  • Executive readout

    A working session with senior Taft practitioners to challenge the findings, answer your questions and agree the priorities.

Options

Three depths.

Every X-Ray is configured around your business model, regulated activities, licenses, products, customers, entities and jurisdictions. There is no generic checklist.

Focused X-Ray

  • One regulatory area, entity, jurisdiction or specific concern
  • Typically five to seven business days

Compliance X-Ray 360

  • End-to-end assessment across your applicable framework
  • Typically 10 to 15 business days

Global X-Ray

  • Multiple entities, licenses, regulators and jurisdictions
  • Group requirements against local ones
  • Typically three to six weeks

What we check

Every area that applies to you, and none that does not.

The scope is set by what you do and where you are licensed. Within it, we look at the areas below wherever they apply.

  • Regulatory framework and licensing

    Regulatory perimeter, licenses, registrations, obligations, commitments and regulatory change.

  • Governance and accountability

    Board and management oversight, chief compliance officer and MLRO responsibilities, committees, escalation, reporting and accountability.

  • Compliance risk management

    Risk assessments, regulatory mapping, policies, procedures, controls, monitoring, testing and issue management.

  • Financial crime

    Anti-money laundering and counter-terrorist financing, customer due diligence at every level, sanctions, transaction monitoring, suspicious activity, fraud controls and financial crime governance.

  • Conduct, markets and customer protection

    Conflicts, fiduciary obligations, market conduct, suitability and Regulation Best Interest, communications, consumer protection, disclosures and complaints.

  • Operational, data and technology risk

    Third parties, outsourcing, operational resilience, ICT, data, cybersecurity dependencies and technology-enabled controls.

  • AI and emerging regulation

    AI governance, use-case risk, accountability, controls and the requirements now arriving.

Built for more than one regulator

One business. Several rulebooks. One consolidated view.

A firm often answers to more than one regulator, with requirements that overlap and sometimes conflict. The X-Ray identifies what applies and assesses how the requirements work together. Depending on scope, that can include:

  • United States

    SEC, FINRA, FinCEN, OFAC, CFTC, CFPB, and federal and state banking requirements.

  • European Union

    The AML framework and AMLR, MiCA, MiFID II, DORA, the EU AI Act, GDPR and consumer protection.

  • United Kingdom

    FCA and PRA rules, the Consumer Duty, financial crime, operational resilience, and data and conduct requirements.

  • Other markets

    The local frameworks that follow from your footprint, licenses and activities.

When to X-Ray

Eight moments when the picture matters.

  • Before an examination

    Find the weaknesses before the examiner does.

  • After regulatory change

    Understand what DORA, AMLR, the Consumer Duty, the AI Act or another new requirement changes for your firm in particular.

  • Before a new market or license

    Find out whether the framework you have can carry the expansion.

  • After an acquisition or restructuring

    Surface inconsistent obligations, policies, controls and governance across the combined business.

  • After rapid growth or a new product

    See whether compliance kept pace with the business.

  • After a change of compliance leadership

    Give new leadership a clear view of what they inherited.

  • When issues keep recurring

    Learn whether isolated problems point to a structural weakness.

  • As a periodic health check

    Test whether the program still reflects your business, your risks and your obligations.

How it runs

How it runs.

  1. Scope

    We establish your entities, activities, products, licenses, regulators and jurisdictions, and settle what applies before assessing anything.

  2. Analyze

    Technology reads the regulations, policies, procedures, risk assessments, controls, testing, findings and evidence, and flags inconsistencies, missing connections and possible gaps. This is where the speed is.

  3. Challenge

    Taft practitioners test what exists on paper against how the program operates. Does the control exist? Who owns it? How does it work? What happens when it fails? Can you prove it operated? Has it been tested?

  4. Prioritize

    We separate drafting imperfections from genuine regulatory exposure and rank the findings by significance. This is where the judgment is.

  5. Act

    The findings become a remediation roadmap: what to address now, what comes next and what can reasonably wait.

Questions

Asked before, answered plainly.

Does AI do the assessment?
No. AI does the reading and the mapping, at a scale and speed no team can match. Finding a possible gap is not the same as making a compliance judgment. Which requirements apply to you, whether the business does what the policy says, whether a finding is a drafting issue or a material exposure, and what to do about it: those calls are made by experienced chief compliance officers, former regulators and industry practitioners. Nothing reaches you unreviewed.
Is this an audit?
No. It is an independent, technology-enabled view of where your compliance program stands and what to do next. It does not replace the independent testing your regulator may require, and it is not an attestation.
How is our documentation handled?
Through a secure channel, under a confidentiality agreement, and used for nothing other than your engagement. The details are agreed before anything is shared.

The Compliance X-Ray is an assessment by compliance practitioners assisted by analysis tools. It is not an audit, not legal advice, and it does not replace independent testing required by your regulator.

Not an audit. Not a checklist. A clear view of where you stand.