Qantid

Service catalogue

123 published engagements across 6 practice areas. Sign in to the portal to choose a service, complete the intake form, and see the fee before you pay.

AML, CFT and Financial Crime

Policy, risk assessment, transaction monitoring, sanctions screening and independent testing, aligned to the requirements of each regulator you answer to.

ServiceDeliveryTurnaround
AML/CFT Gap Assessment and Remediation Roadmap

A measured comparison of your current programme against what your regulator expects, with a prioritised, costed plan to close the difference.

Documentation and assessment5 business days
AML/CFT Training Curriculum and Materials

Role-differentiated training content with assessment, built so you can evidence competence to an examiner rather than just attendance.

Documentation and assessment5 business days
AML/CFT/CPF Policy and Procedures Manual

A board-ready anti-money-laundering, counter-terrorist-financing and counter-proliferation-financing manual written against the regulations that apply to your licence.

Documentation and assessment5 business days
Board and Senior Management AML Briefing Pack

A briefing that tells your board what it is personally accountable for, in language that does not require them to be compliance specialists.

Documentation and assessment5 business days
Crypto Travel Rule Compliance Framework

Travel Rule compliance design for virtual asset service providers: originator and beneficiary data, counterparty due diligence and unhosted wallet handling.

Documentation and assessment5 business days
Enterprise-Wide ML/TF/PF Risk Assessment

A documented assessment of your inherent money-laundering, terrorist-financing and proliferation-financing risk, the controls against it, and the residual risk your board must accept.

Documentation and assessment5 business days
KYB and Beneficial Ownership Framework

Know-your-business procedures and a workable method for identifying ultimate beneficial owners through layered corporate structures.

Documentation and assessment5 business days
KYC/CDD/EDD Programme and Customer Risk Rating Model

Customer due diligence procedures and a documented, defensible risk-rating model that your systems can actually implement.

Documentation and assessment5 business days
Sanctions and PEP Screening Programme Design

Screening programme design covering list coverage, matching thresholds, alert handling and the governance around tuning decisions.

Documentation and assessment5 business days
STR/SAR Filing Playbook and goAML Guide

A working procedure for identifying, escalating and filing suspicious transaction reports, including practical goAML submission guidance.

Documentation and assessment5 business days
Transaction Monitoring Model Validation

Independent validation of your monitoring system, including above-the-line and below-the-line testing to establish whether thresholds are set where they should be.

Documentation and assessment5 business days
Transaction Monitoring Rules Design and Tuning

Scenario design and threshold calibration for your monitoring system, with the statistical basis for every threshold documented.

Documentation and assessment5 business days
Wolfsberg CBDDQ Completion Pack

A completed Correspondent Banking Due Diligence Questionnaire with the supporting evidence pack correspondent banks actually ask for.

Documentation and assessment5 business days
AML Alert Backlog and Look-Back Review

Clearance of an alert backlog or a historic transaction look-back, usually following an examination finding.

Scoped engagementAs scoped
Independent AML/CFT Audit

The periodic independent test of your AML/CFT programme that regulation requires, conducted by a team with no involvement in building what is being tested.

Scoped engagementAs scoped
Full Compliance Function

MLRO, Data Protection Officer and virtual CISO delivered as one function, with a single point of accountability.

RetainerOngoing
Outsourced Money Laundering Reporting Officer

A named, qualified MLRO carrying out the role for your firm, including regulator-facing responsibility and board reporting.

RetainerOngoing

Licensing support and regulatory affairs

Help preparing and facilitating regulatory licence applications, and staying compliant with licence conditions. Qantid does not issue licences — regulators do.

ServiceDeliveryTurnaround
Bank of Ghana DEMI Licence Application Support

Facilitation of the application for a Dedicated Electronic Money Issuer licence with the Bank of Ghana.

Scoped engagementAs scoped
Bank of Ghana PSP Enhanced Licence Application Support

Facilitation of the application for a Payment Service Provider licence at the Enhanced tier with the Bank of Ghana.

Scoped engagementAs scoped
CBE / FRA Fintech Authorisation

Authorisation management with the Central Bank of Egypt or the Financial Regulatory Authority, depending on activity.

Scoped engagementAs scoped
CBK Digital Credit Provider Licence Application Support

Facilitation of the application for a Digital Credit Provider licence, including pricing model and debt collection conduct evidence.

Scoped engagementAs scoped
CBK Money Remittance Provider Licence Application Support

Facilitation of the application for a Money Remittance Provider licence with the Central Bank of Kenya.

Scoped engagementAs scoped
CBK Payment Service Provider Licence Application Support

Facilitation of the application for a Payment Service Provider licence with the Central Bank of Kenya.

Scoped engagementAs scoped
CBN International Money Transfer Operator Licence Application Support

Facilitation of the application for an International Money Transfer Operator licence, including corridor structure and correspondent arrangements.

Scoped engagementAs scoped
CBN Mobile Money Operator Licence Application Support

Facilitation of the application for a Mobile Money Operator licence, including e-money issuance structure and trust account arrangements.

Scoped engagementAs scoped
CBN Payment Service Bank Licence Application Support

Facilitation of the application for a Payment Service Bank licence, the most capital-intensive and most scrutinised of the CBN payment categories.

Scoped engagementAs scoped
CBN Payment Solution Service Provider Licence Application Support

Facilitation of the licence application with the regulator — preparation, evidence and process management. The regulator alone decides the outcome.

Scoped engagementAs scoped
CBN Payment Terminal Service Provider Licence Application Support

Facilitation of the application for a Payment Terminal Service Provider licence, including terminal deployment and support capability evidence.

Scoped engagementAs scoped
CBN Super-Agent Licence Application Support

Facilitation of the application for a Super-Agent licence, covering agent network structure, agent due diligence and monitoring capability.

Scoped engagementAs scoped
CBN Switching and Processing Licence Application Support

Facilitation of the application for a Switching and Processing licence, including scheme and interoperability readiness.

Scoped engagementAs scoped
Change in Control and Shareholding Approval

Regulatory approval for a change in control or significant shareholding transfer — the filing most often forgotten after a funding round.

Scoped engagementAs scoped
Digital Microfinance Bank Licence Application Support

Facilitation of the application for a microfinance banking licence operating a digital model, including prudential and capital planning.

Scoped engagementAs scoped
FCCPC Digital Lending Registration

Registration management for digital lending operations with the Federal Competition and Consumer Protection Commission.

Scoped engagementAs scoped
Finance Company Licence Application Support

Facilitation of the application for a Finance Company licence covering lending, leasing and related activities.

Scoped engagementAs scoped
Fit and Proper Pack

A complete fit-and-proper submission for one director or key officer, assembled and checked before it reaches the regulator.

Scoped engagementAs scoped
FSCA Crypto Asset Service Provider Licence Application Support

Facilitation of the application for a Crypto Asset Service Provider licence with the FSCA.

Scoped engagementAs scoped
FSCA Financial Services Provider Licence Application Support

Facilitation of the application for an FSP licence with the Financial Sector Conduct Authority, across categories I to IV.

Scoped engagementAs scoped
Licence Maintenance and Returns Filing

Annual management of your licence conditions and regulatory returns calendar, so nothing is missed and nothing is filed late.

Scoped engagementAs scoped
Mock Regulatory Examination

A simulated regulatory examination run the way the regulator runs it, so the first time you experience one is not the real one.

Scoped engagementAs scoped
Multi-Market Entry and Regulatory Feasibility Study

A comparative study of three markets covering licensing routes, capital requirements, tax, foreign exchange and profit repatriation.

Scoped engagementAs scoped
NAICOM Insurance, Insurtech or Broker Licence Application Support

Facilitation of the application for an insurance, insurtech or broking licence with the National Insurance Commission.

Scoped engagementAs scoped
NCR Credit Provider Registration

Registration management for a credit provider with the National Credit Regulator.

Scoped engagementAs scoped
Regulatory Examination Remediation Programme

Management of a remediation programme to close examination findings, through to regulator acceptance.

Scoped engagementAs scoped
Regulatory Sandbox Application

Preparation and management of a regulatory sandbox application in any of the five markets, including test design and exit planning.

Scoped engagementAs scoped
SEC Nigeria Crowdfunding Portal Licence Application Support

Facilitation of the application for a crowdfunding portal licence, including issuer onboarding and investor limit controls.

Scoped engagementAs scoped
SEC Nigeria Digital Asset and VASP Registration

Registration management for a virtual asset service provider under the SEC Nigeria digital asset rules.

Scoped engagementAs scoped
Compliance Calendar and Returns Filing Service

Your full obligations calendar, maintained and filed against, so nothing is missed.

RetainerOngoing
Regulatory Change Monitoring

Monitoring of regulatory developments in one market, with an assessment of what each change means for your specific licence.

RetainerOngoing

Cybersecurity and Assurance

Penetration testing, ISO 27001, SOC 2, PCI DSS and the CBN Risk-Based Cybersecurity Framework — readiness, remediation and certification support.

ServiceDeliveryTurnaround
Business Continuity and Disaster Recovery Plan

Continuity and recovery planning built from a business impact analysis, with recovery objectives that reflect what your infrastructure can actually deliver.

Documentation and assessment5 business days
CBN Risk-Based Cybersecurity Framework Assessment

An assessment against the CBN Risk-Based Cybersecurity Framework, producing the evidence base for your annual return.

Documentation and assessment5 business days
Incident Response Plan and Playbooks

An incident response plan with scenario playbooks, written so an on-call engineer at 3am can follow it.

Documentation and assessment5 business days
Information Security Policy Suite

A complete information security policy set, sized to your organisation rather than copied from a multinational.

Documentation and assessment5 business days
ISO 27001 Internal Audit

The internal audit an ISO 27001 management system requires before certification or surveillance, conducted against the standard rather than a checklist.

Documentation and assessment5 business days
ISO 27001 ISMS Documentation Suite

The full documented information set an ISO/IEC 27001:2022 information security management system requires, including all Annex A controls in scope.

Documentation and assessment5 business days
PCI DSS v4.x Gap Assessment and Scoping

Cardholder data environment scoping and a gap assessment against PCI DSS v4.0.1, including the requirements that became mandatory in 2025.

Documentation and assessment5 business days
Secure SDLC Programme Design

A secure development lifecycle your engineering team will actually follow, with the gates placed where they catch problems rather than where they slow releases.

Documentation and assessment5 business days
SOC 2 Readiness Assessment

A readiness assessment mapped to the Trust Services Criteria, telling you exactly what will fail before the auditor tells you at a higher price.

Documentation and assessment5 business days
Third-Party Security Assessment

An independent security assessment of one of your suppliers, producing a decision you can put in front of a risk committee.

Documentation and assessment5 business days
API Penetration Test

Schema-driven testing of an API including an authorisation matrix across every role and endpoint — the class of flaw automated scanners consistently miss.

Technical testing10 business days
Cloud Configuration and Security Review

A configuration review of an AWS, Azure or GCP account against CIS benchmarks, covering identity, network, storage exposure and logging.

Technical testing10 business days
Dependency and Container Security Assessment

Software composition analysis and container image scanning, with exploitability triage rather than a raw CVE dump.

Technical testing10 business days
External Network Penetration Test

Testing of your internet-facing perimeter: exposed services, patch currency, TLS posture and default credentials.

Technical testing10 business days
Internal Network Penetration Test

Assumed-breach testing from inside your network: lateral movement, privilege escalation and directory service configuration.

Technical testing10 business days
Mobile Application Penetration Test

Static and dynamic testing of a mobile application against OWASP MASVS, covering local storage, certificate pinning and the backend it talks to.

Technical testing10 business days
PCI ASV External ScanningPartner signed

Quarterly external vulnerability scanning of your cardholder data environment, delivered through an Approved Scanning Vendor.

Technical testing
Phishing Simulation Campaign

A controlled phishing campaign measuring click, credential submission and reporting rates, with follow-up training for those who engage.

Technical testing10 business days
Platform Configuration Review

A hardening review of a single platform — Active Directory, a database, a Kubernetes cluster or a firewall estate — against CIS benchmarks.

Technical testing10 business days
Remediation Validation Retest

A retest of previously reported findings, producing a validation letter stating what was fixed, what remains and what is new.

Technical testing10 business days
Secure Source Code Review

Static analysis with manual review of security-critical paths: authentication, authorisation, cryptography and payment handling.

Technical testing10 business days
Web Application Penetration Test

Authenticated and unauthenticated testing of a web application against OWASP ASVS, combining an automated toolchain with manual validation of every critical and high finding by a named consultant.

Technical testing10 business days
Wireless Security Assessment

Assessment of wireless networks at a site: authentication strength, segmentation from corporate systems and rogue access point detection.

Technical testing10 business days
Card Scheme and EMV Certification Support

Support through Visa, Mastercard, Verve, NIBSS and EMV Level 2 and 3 certification.

Scoped engagementAs scoped
ISO 27001 Full Implementation to CertificationPartner signed

End-to-end ISO/IEC 27001:2022 implementation: risk assessment, controls, documentation, internal audit and support through the certification audit.

Scoped engagementAs scoped
PCI DSS Report on CompliancePartner signed

A managed route to a PCI DSS Report on Compliance: scoping, remediation and evidence assembly, with the assessment performed by a Qualified Security Assessor.

Scoped engagementAs scoped
Red Team and Adversary Simulation

An objective-based adversary simulation testing detection and response, not just whether vulnerabilities exist.

Scoped engagementAs scoped
SOC 2 Type I AuditPartner signed

A point-in-time SOC 2 Type I report, usually the fastest route to satisfying an enterprise procurement requirement.

Scoped engagementAs scoped
SOC 2 Type II AuditPartner signed

A managed route to a SOC 2 Type II report, covering readiness, the observation period and the audit itself.

Scoped engagementAs scoped
Continuous Attack Surface Monitoring

Ongoing discovery and monitoring of your internet-facing estate, with alerting on new exposure.

RetainerOngoing
Incident Response Retainer

A four-hour response commitment with a pre-agreed team, contract and access model, so the paperwork is done before the incident.

RetainerOngoing
Virtual Chief Information Security Officer

A named senior security leader accountable for your security programme, governance and regulator-facing security obligations.

RetainerOngoing
Vulnerability Management as a Service

A managed vulnerability management programme: scanning, triage, tracking and verification of remediation.

RetainerOngoing

Data Protection and Privacy

NDPA, POPIA, Kenya DPA and GDPR compliance: audits, data mapping, impact assessments, breach response and outsourced Data Protection Officer.

ServiceDeliveryTurnaround
Breach Response Playbook and Notification Templates

A playbook that gets you to a defensible regulator notification inside the statutory window, written before you need it.

Documentation and assessment5 business days
Cross-Border Transfer Impact Assessment

An assessment of your international data transfers and the mechanism each one relies on, including cloud processing outside the country.

Documentation and assessment5 business days
Data Protection Impact Assessment

A documented impact assessment for a high-risk processing activity, with mitigations and a residual risk conclusion your DPO can sign.

Documentation and assessment5 business days
DSAR Handling Process and Templates

A process for handling data subject access requests within the statutory period, including identity verification and redaction.

Documentation and assessment5 business days
Kenya DPA Readiness and ODPC Registration Pack

Readiness assessment against the Kenya Data Protection Act with the controller or processor registration pack for the ODPC.

Documentation and assessment5 business days
NDPA/NDPR Compliance Gap Assessment

An assessment of your processing against the Nigeria Data Protection Act 2023, with the specific actions needed before your annual audit return.

Documentation and assessment5 business days
POPIA Readiness Assessment

A readiness assessment against South Africa's Protection of Personal Information Act, including Information Officer obligations.

Documentation and assessment5 business days
Privacy Notice and Consent Framework Suite

Privacy notices and a consent framework that meet the transparency standard without being unreadable.

Documentation and assessment5 business days
ROPA, Data Mapping and Retention Schedule

A record of processing activities built from how your systems actually work, with a retention schedule you can defend and operate.

Documentation and assessment5 business days
NDPA Compliance Audit and Annual Return FilingPartner signed

The annual data protection compliance audit and the filing of your Compliance Audit Return with the NDPC.

Scoped engagementAs scoped
Outsourced Data Protection Officer

A named Data Protection Officer discharging the statutory role, including regulator contact and data subject escalation.

RetainerOngoing

Financial Audit and Tax

IFRS 9 modelling, capital adequacy, safeguarding reconciliation, internal audit and tax compliance for regulated balance sheets.

ServiceDeliveryTurnaround
Capital Adequacy and Prudential Ratio Review

A review of your regulatory capital position and prudential ratios against the requirements attached to your licence.

Documentation and assessment5 business days
IFRS 9 ECL Model Documentation and Validation

Expected credit loss model documentation and independent validation, at the standard your auditor will require.

Documentation and assessment5 business days
Internal Audit Plan and Risk-Based Audit Universe

A risk-based audit universe and annual plan that your audit committee can approve and your team can deliver.

Documentation and assessment5 business days
Investor Compliance Due Diligence Pack

A compliance due diligence pack for a funding round or acquisition — either preparing your side or assessing a target.

Documentation and assessment5 business days
Safeguarding and Trust Account Reconciliation Review

An independent review of how you hold and reconcile customer funds — the single control most likely to end a payment licence if it fails.

Documentation and assessment5 business days
Tax Health Check and Compliance Review

A review of your tax position across companies income tax, VAT, withholding tax and payroll obligations.

Documentation and assessment5 business days
Transfer Pricing Documentation

Transfer pricing documentation for intra-group transactions, meeting local file requirements.

Documentation and assessment5 business days
Forensic Investigation and Fraud Examination

A forensic investigation into suspected fraud or misappropriation, conducted to a standard that survives challenge.

Scoped engagementAs scoped
IFRS 17 ImplementationPartner signed

IFRS 17 implementation for insurance contracts, delivered with actuarial partners.

Scoped engagementAs scoped
Internal Audit Outsourcing

A full outsourced internal audit function delivering an annual programme approved by your audit committee.

Scoped engagementAs scoped
Statutory External AuditPartner signed

A managed statutory audit of your financial statements, delivered through a registered audit firm.

Scoped engagementAs scoped

Risk and Governance

Enterprise risk frameworks, board and committee governance, internal control design, model risk validation and consumer protection.

ServiceDeliveryTurnaround
AI/ML Model Risk Validation

Independent validation of a machine learning model in production: performance, stability, explainability and the governance around it.

Documentation and assessment5 business days
Anti-Bribery and Corruption Programme

An anti-bribery programme aligned to ISO 37001, covering gifts, facilitation payments, third-party intermediaries and whistleblowing.

Documentation and assessment5 business days
Consumer Protection and Complaints Framework

A complaints and fair-treatment framework meeting the CBN Consumer Protection Framework, with the reporting your regulator expects.

Documentation and assessment5 business days
Corporate Governance Framework and Board Charters

Board and committee charters, delegation of authority and a governance framework compliant with the codes that apply to your entity.

Documentation and assessment5 business days
Credit Scoring Model Validation and Bias Audit

Validation of a credit scoring model including fairness testing across protected characteristics.

Documentation and assessment5 business days
Digital Lending Compliance Assessment

An assessment against the digital lending rules in your market, covering pricing disclosure, data use and debt collection conduct.

Documentation and assessment5 business days
ERM Framework, Risk Register and KRI Library

An enterprise risk management framework with a populated risk register and key risk indicators that produce a usable board report.

Documentation and assessment5 business days
ESG and IFRS S1/S2 Reporting Readiness

Readiness for sustainability disclosure under IFRS S1 and S2, including climate-related risk identification.

Documentation and assessment5 business days
Financial Promotions and Marketing Compliance Review

A review of your marketing and in-product messaging against financial promotions rules, before a regulator does it for you.

Documentation and assessment5 business days
Fraud Risk Management Framework

A fraud risk framework covering first-party, third-party and internal fraud, with chargeback and dispute handling.

Documentation and assessment5 business days
Internal Control Framework Design

An internal control framework built on COSO, with controls documented at a level that supports testing rather than assertion.

Documentation and assessment5 business days
Operational Resilience and Critical Service Mapping

Identification of your important business services, the resources they depend on, and the maximum disruption each can tolerate.

Documentation and assessment5 business days
Outsourcing and Third-Party Risk Framework

A framework for managing outsourced and third-party relationships, including the material-outsourcing notifications your regulator requires.

Documentation and assessment5 business days
Board and Executive Briefing

A briefing session for your board on a specific regulatory topic and the personal accountability attached to it.

RetainerOngoing
Certification Exam Preparation

Structured preparation for CAMS, CISA, CISM or ICA certification.

RetainerOngoing
Open-Enrolment Course Seat

A single seat on a scheduled open-enrolment course.

RetainerOngoing
Outsourced Compliance Officer

A named compliance officer covering conduct, consumer protection and licence conditions outside the AML perimeter.

RetainerOngoing
Policy Library Subscription

Access to the maintained policy library with an annual refresh reflecting regulatory change.

RetainerOngoing
Private Cohort Training

A private course delivered for your team, tailored to your products and risks.

RetainerOngoing
Security and Compliance Training Programme

An annual training programme across AML, privacy and security, with completion tracking you can show an examiner.

RetainerOngoing