Service catalogue
123 published engagements across 6 practice areas. Sign in to the portal to choose a service, complete the intake form, and see the fee before you pay.
AML, CFT and Financial Crime
Policy, risk assessment, transaction monitoring, sanctions screening and independent testing, aligned to the requirements of each regulator you answer to.
| Service | Delivery | Turnaround |
|---|---|---|
| AML/CFT Gap Assessment and Remediation Roadmap A measured comparison of your current programme against what your regulator expects, with a prioritised, costed plan to close the difference. | Documentation and assessment | 5 business days |
| AML/CFT Training Curriculum and Materials Role-differentiated training content with assessment, built so you can evidence competence to an examiner rather than just attendance. | Documentation and assessment | 5 business days |
| AML/CFT/CPF Policy and Procedures Manual A board-ready anti-money-laundering, counter-terrorist-financing and counter-proliferation-financing manual written against the regulations that apply to your licence. | Documentation and assessment | 5 business days |
| Board and Senior Management AML Briefing Pack A briefing that tells your board what it is personally accountable for, in language that does not require them to be compliance specialists. | Documentation and assessment | 5 business days |
| Crypto Travel Rule Compliance Framework Travel Rule compliance design for virtual asset service providers: originator and beneficiary data, counterparty due diligence and unhosted wallet handling. | Documentation and assessment | 5 business days |
| Enterprise-Wide ML/TF/PF Risk Assessment A documented assessment of your inherent money-laundering, terrorist-financing and proliferation-financing risk, the controls against it, and the residual risk your board must accept. | Documentation and assessment | 5 business days |
| KYB and Beneficial Ownership Framework Know-your-business procedures and a workable method for identifying ultimate beneficial owners through layered corporate structures. | Documentation and assessment | 5 business days |
| KYC/CDD/EDD Programme and Customer Risk Rating Model Customer due diligence procedures and a documented, defensible risk-rating model that your systems can actually implement. | Documentation and assessment | 5 business days |
| Sanctions and PEP Screening Programme Design Screening programme design covering list coverage, matching thresholds, alert handling and the governance around tuning decisions. | Documentation and assessment | 5 business days |
| STR/SAR Filing Playbook and goAML Guide A working procedure for identifying, escalating and filing suspicious transaction reports, including practical goAML submission guidance. | Documentation and assessment | 5 business days |
| Transaction Monitoring Model Validation Independent validation of your monitoring system, including above-the-line and below-the-line testing to establish whether thresholds are set where they should be. | Documentation and assessment | 5 business days |
| Transaction Monitoring Rules Design and Tuning Scenario design and threshold calibration for your monitoring system, with the statistical basis for every threshold documented. | Documentation and assessment | 5 business days |
| Wolfsberg CBDDQ Completion Pack A completed Correspondent Banking Due Diligence Questionnaire with the supporting evidence pack correspondent banks actually ask for. | Documentation and assessment | 5 business days |
| AML Alert Backlog and Look-Back Review Clearance of an alert backlog or a historic transaction look-back, usually following an examination finding. | Scoped engagement | As scoped |
| Independent AML/CFT Audit The periodic independent test of your AML/CFT programme that regulation requires, conducted by a team with no involvement in building what is being tested. | Scoped engagement | As scoped |
| Full Compliance Function MLRO, Data Protection Officer and virtual CISO delivered as one function, with a single point of accountability. | Retainer | Ongoing |
| Outsourced Money Laundering Reporting Officer A named, qualified MLRO carrying out the role for your firm, including regulator-facing responsibility and board reporting. | Retainer | Ongoing |
Licensing support and regulatory affairs
Help preparing and facilitating regulatory licence applications, and staying compliant with licence conditions. Qantid does not issue licences — regulators do.
| Service | Delivery | Turnaround |
|---|---|---|
| Bank of Ghana DEMI Licence Application Support Facilitation of the application for a Dedicated Electronic Money Issuer licence with the Bank of Ghana. | Scoped engagement | As scoped |
| Bank of Ghana PSP Enhanced Licence Application Support Facilitation of the application for a Payment Service Provider licence at the Enhanced tier with the Bank of Ghana. | Scoped engagement | As scoped |
| CBE / FRA Fintech Authorisation Authorisation management with the Central Bank of Egypt or the Financial Regulatory Authority, depending on activity. | Scoped engagement | As scoped |
| CBK Digital Credit Provider Licence Application Support Facilitation of the application for a Digital Credit Provider licence, including pricing model and debt collection conduct evidence. | Scoped engagement | As scoped |
| CBK Money Remittance Provider Licence Application Support Facilitation of the application for a Money Remittance Provider licence with the Central Bank of Kenya. | Scoped engagement | As scoped |
| CBK Payment Service Provider Licence Application Support Facilitation of the application for a Payment Service Provider licence with the Central Bank of Kenya. | Scoped engagement | As scoped |
| CBN International Money Transfer Operator Licence Application Support Facilitation of the application for an International Money Transfer Operator licence, including corridor structure and correspondent arrangements. | Scoped engagement | As scoped |
| CBN Mobile Money Operator Licence Application Support Facilitation of the application for a Mobile Money Operator licence, including e-money issuance structure and trust account arrangements. | Scoped engagement | As scoped |
| CBN Payment Service Bank Licence Application Support Facilitation of the application for a Payment Service Bank licence, the most capital-intensive and most scrutinised of the CBN payment categories. | Scoped engagement | As scoped |
| CBN Payment Solution Service Provider Licence Application Support Facilitation of the licence application with the regulator — preparation, evidence and process management. The regulator alone decides the outcome. | Scoped engagement | As scoped |
| CBN Payment Terminal Service Provider Licence Application Support Facilitation of the application for a Payment Terminal Service Provider licence, including terminal deployment and support capability evidence. | Scoped engagement | As scoped |
| CBN Super-Agent Licence Application Support Facilitation of the application for a Super-Agent licence, covering agent network structure, agent due diligence and monitoring capability. | Scoped engagement | As scoped |
| CBN Switching and Processing Licence Application Support Facilitation of the application for a Switching and Processing licence, including scheme and interoperability readiness. | Scoped engagement | As scoped |
| Change in Control and Shareholding Approval Regulatory approval for a change in control or significant shareholding transfer — the filing most often forgotten after a funding round. | Scoped engagement | As scoped |
| Digital Microfinance Bank Licence Application Support Facilitation of the application for a microfinance banking licence operating a digital model, including prudential and capital planning. | Scoped engagement | As scoped |
| FCCPC Digital Lending Registration Registration management for digital lending operations with the Federal Competition and Consumer Protection Commission. | Scoped engagement | As scoped |
| Finance Company Licence Application Support Facilitation of the application for a Finance Company licence covering lending, leasing and related activities. | Scoped engagement | As scoped |
| Fit and Proper Pack A complete fit-and-proper submission for one director or key officer, assembled and checked before it reaches the regulator. | Scoped engagement | As scoped |
| FSCA Crypto Asset Service Provider Licence Application Support Facilitation of the application for a Crypto Asset Service Provider licence with the FSCA. | Scoped engagement | As scoped |
| FSCA Financial Services Provider Licence Application Support Facilitation of the application for an FSP licence with the Financial Sector Conduct Authority, across categories I to IV. | Scoped engagement | As scoped |
| Licence Maintenance and Returns Filing Annual management of your licence conditions and regulatory returns calendar, so nothing is missed and nothing is filed late. | Scoped engagement | As scoped |
| Mock Regulatory Examination A simulated regulatory examination run the way the regulator runs it, so the first time you experience one is not the real one. | Scoped engagement | As scoped |
| Multi-Market Entry and Regulatory Feasibility Study A comparative study of three markets covering licensing routes, capital requirements, tax, foreign exchange and profit repatriation. | Scoped engagement | As scoped |
| NAICOM Insurance, Insurtech or Broker Licence Application Support Facilitation of the application for an insurance, insurtech or broking licence with the National Insurance Commission. | Scoped engagement | As scoped |
| NCR Credit Provider Registration Registration management for a credit provider with the National Credit Regulator. | Scoped engagement | As scoped |
| Regulatory Examination Remediation Programme Management of a remediation programme to close examination findings, through to regulator acceptance. | Scoped engagement | As scoped |
| Regulatory Sandbox Application Preparation and management of a regulatory sandbox application in any of the five markets, including test design and exit planning. | Scoped engagement | As scoped |
| SEC Nigeria Crowdfunding Portal Licence Application Support Facilitation of the application for a crowdfunding portal licence, including issuer onboarding and investor limit controls. | Scoped engagement | As scoped |
| SEC Nigeria Digital Asset and VASP Registration Registration management for a virtual asset service provider under the SEC Nigeria digital asset rules. | Scoped engagement | As scoped |
| Compliance Calendar and Returns Filing Service Your full obligations calendar, maintained and filed against, so nothing is missed. | Retainer | Ongoing |
| Regulatory Change Monitoring Monitoring of regulatory developments in one market, with an assessment of what each change means for your specific licence. | Retainer | Ongoing |
Cybersecurity and Assurance
Penetration testing, ISO 27001, SOC 2, PCI DSS and the CBN Risk-Based Cybersecurity Framework — readiness, remediation and certification support.
| Service | Delivery | Turnaround |
|---|---|---|
| Business Continuity and Disaster Recovery Plan Continuity and recovery planning built from a business impact analysis, with recovery objectives that reflect what your infrastructure can actually deliver. | Documentation and assessment | 5 business days |
| CBN Risk-Based Cybersecurity Framework Assessment An assessment against the CBN Risk-Based Cybersecurity Framework, producing the evidence base for your annual return. | Documentation and assessment | 5 business days |
| Incident Response Plan and Playbooks An incident response plan with scenario playbooks, written so an on-call engineer at 3am can follow it. | Documentation and assessment | 5 business days |
| Information Security Policy Suite A complete information security policy set, sized to your organisation rather than copied from a multinational. | Documentation and assessment | 5 business days |
| ISO 27001 Internal Audit The internal audit an ISO 27001 management system requires before certification or surveillance, conducted against the standard rather than a checklist. | Documentation and assessment | 5 business days |
| ISO 27001 ISMS Documentation Suite The full documented information set an ISO/IEC 27001:2022 information security management system requires, including all Annex A controls in scope. | Documentation and assessment | 5 business days |
| PCI DSS v4.x Gap Assessment and Scoping Cardholder data environment scoping and a gap assessment against PCI DSS v4.0.1, including the requirements that became mandatory in 2025. | Documentation and assessment | 5 business days |
| Secure SDLC Programme Design A secure development lifecycle your engineering team will actually follow, with the gates placed where they catch problems rather than where they slow releases. | Documentation and assessment | 5 business days |
| SOC 2 Readiness Assessment A readiness assessment mapped to the Trust Services Criteria, telling you exactly what will fail before the auditor tells you at a higher price. | Documentation and assessment | 5 business days |
| Third-Party Security Assessment An independent security assessment of one of your suppliers, producing a decision you can put in front of a risk committee. | Documentation and assessment | 5 business days |
| API Penetration Test Schema-driven testing of an API including an authorisation matrix across every role and endpoint — the class of flaw automated scanners consistently miss. | Technical testing | 10 business days |
| Cloud Configuration and Security Review A configuration review of an AWS, Azure or GCP account against CIS benchmarks, covering identity, network, storage exposure and logging. | Technical testing | 10 business days |
| Dependency and Container Security Assessment Software composition analysis and container image scanning, with exploitability triage rather than a raw CVE dump. | Technical testing | 10 business days |
| External Network Penetration Test Testing of your internet-facing perimeter: exposed services, patch currency, TLS posture and default credentials. | Technical testing | 10 business days |
| Internal Network Penetration Test Assumed-breach testing from inside your network: lateral movement, privilege escalation and directory service configuration. | Technical testing | 10 business days |
| Mobile Application Penetration Test Static and dynamic testing of a mobile application against OWASP MASVS, covering local storage, certificate pinning and the backend it talks to. | Technical testing | 10 business days |
| PCI ASV External ScanningPartner signed Quarterly external vulnerability scanning of your cardholder data environment, delivered through an Approved Scanning Vendor. | Technical testing | — |
| Phishing Simulation Campaign A controlled phishing campaign measuring click, credential submission and reporting rates, with follow-up training for those who engage. | Technical testing | 10 business days |
| Platform Configuration Review A hardening review of a single platform — Active Directory, a database, a Kubernetes cluster or a firewall estate — against CIS benchmarks. | Technical testing | 10 business days |
| Remediation Validation Retest A retest of previously reported findings, producing a validation letter stating what was fixed, what remains and what is new. | Technical testing | 10 business days |
| Secure Source Code Review Static analysis with manual review of security-critical paths: authentication, authorisation, cryptography and payment handling. | Technical testing | 10 business days |
| Web Application Penetration Test Authenticated and unauthenticated testing of a web application against OWASP ASVS, combining an automated toolchain with manual validation of every critical and high finding by a named consultant. | Technical testing | 10 business days |
| Wireless Security Assessment Assessment of wireless networks at a site: authentication strength, segmentation from corporate systems and rogue access point detection. | Technical testing | 10 business days |
| Card Scheme and EMV Certification Support Support through Visa, Mastercard, Verve, NIBSS and EMV Level 2 and 3 certification. | Scoped engagement | As scoped |
| ISO 27001 Full Implementation to CertificationPartner signed End-to-end ISO/IEC 27001:2022 implementation: risk assessment, controls, documentation, internal audit and support through the certification audit. | Scoped engagement | As scoped |
| PCI DSS Report on CompliancePartner signed A managed route to a PCI DSS Report on Compliance: scoping, remediation and evidence assembly, with the assessment performed by a Qualified Security Assessor. | Scoped engagement | As scoped |
| Red Team and Adversary Simulation An objective-based adversary simulation testing detection and response, not just whether vulnerabilities exist. | Scoped engagement | As scoped |
| SOC 2 Type I AuditPartner signed A point-in-time SOC 2 Type I report, usually the fastest route to satisfying an enterprise procurement requirement. | Scoped engagement | As scoped |
| SOC 2 Type II AuditPartner signed A managed route to a SOC 2 Type II report, covering readiness, the observation period and the audit itself. | Scoped engagement | As scoped |
| Continuous Attack Surface Monitoring Ongoing discovery and monitoring of your internet-facing estate, with alerting on new exposure. | Retainer | Ongoing |
| Incident Response Retainer A four-hour response commitment with a pre-agreed team, contract and access model, so the paperwork is done before the incident. | Retainer | Ongoing |
| Virtual Chief Information Security Officer A named senior security leader accountable for your security programme, governance and regulator-facing security obligations. | Retainer | Ongoing |
| Vulnerability Management as a Service A managed vulnerability management programme: scanning, triage, tracking and verification of remediation. | Retainer | Ongoing |
Data Protection and Privacy
NDPA, POPIA, Kenya DPA and GDPR compliance: audits, data mapping, impact assessments, breach response and outsourced Data Protection Officer.
| Service | Delivery | Turnaround |
|---|---|---|
| Breach Response Playbook and Notification Templates A playbook that gets you to a defensible regulator notification inside the statutory window, written before you need it. | Documentation and assessment | 5 business days |
| Cross-Border Transfer Impact Assessment An assessment of your international data transfers and the mechanism each one relies on, including cloud processing outside the country. | Documentation and assessment | 5 business days |
| Data Protection Impact Assessment A documented impact assessment for a high-risk processing activity, with mitigations and a residual risk conclusion your DPO can sign. | Documentation and assessment | 5 business days |
| DSAR Handling Process and Templates A process for handling data subject access requests within the statutory period, including identity verification and redaction. | Documentation and assessment | 5 business days |
| Kenya DPA Readiness and ODPC Registration Pack Readiness assessment against the Kenya Data Protection Act with the controller or processor registration pack for the ODPC. | Documentation and assessment | 5 business days |
| NDPA/NDPR Compliance Gap Assessment An assessment of your processing against the Nigeria Data Protection Act 2023, with the specific actions needed before your annual audit return. | Documentation and assessment | 5 business days |
| POPIA Readiness Assessment A readiness assessment against South Africa's Protection of Personal Information Act, including Information Officer obligations. | Documentation and assessment | 5 business days |
| Privacy Notice and Consent Framework Suite Privacy notices and a consent framework that meet the transparency standard without being unreadable. | Documentation and assessment | 5 business days |
| ROPA, Data Mapping and Retention Schedule A record of processing activities built from how your systems actually work, with a retention schedule you can defend and operate. | Documentation and assessment | 5 business days |
| NDPA Compliance Audit and Annual Return FilingPartner signed The annual data protection compliance audit and the filing of your Compliance Audit Return with the NDPC. | Scoped engagement | As scoped |
| Outsourced Data Protection Officer A named Data Protection Officer discharging the statutory role, including regulator contact and data subject escalation. | Retainer | Ongoing |
Financial Audit and Tax
IFRS 9 modelling, capital adequacy, safeguarding reconciliation, internal audit and tax compliance for regulated balance sheets.
| Service | Delivery | Turnaround |
|---|---|---|
| Capital Adequacy and Prudential Ratio Review A review of your regulatory capital position and prudential ratios against the requirements attached to your licence. | Documentation and assessment | 5 business days |
| IFRS 9 ECL Model Documentation and Validation Expected credit loss model documentation and independent validation, at the standard your auditor will require. | Documentation and assessment | 5 business days |
| Internal Audit Plan and Risk-Based Audit Universe A risk-based audit universe and annual plan that your audit committee can approve and your team can deliver. | Documentation and assessment | 5 business days |
| Investor Compliance Due Diligence Pack A compliance due diligence pack for a funding round or acquisition — either preparing your side or assessing a target. | Documentation and assessment | 5 business days |
| Safeguarding and Trust Account Reconciliation Review An independent review of how you hold and reconcile customer funds — the single control most likely to end a payment licence if it fails. | Documentation and assessment | 5 business days |
| Tax Health Check and Compliance Review A review of your tax position across companies income tax, VAT, withholding tax and payroll obligations. | Documentation and assessment | 5 business days |
| Transfer Pricing Documentation Transfer pricing documentation for intra-group transactions, meeting local file requirements. | Documentation and assessment | 5 business days |
| Forensic Investigation and Fraud Examination A forensic investigation into suspected fraud or misappropriation, conducted to a standard that survives challenge. | Scoped engagement | As scoped |
| IFRS 17 ImplementationPartner signed IFRS 17 implementation for insurance contracts, delivered with actuarial partners. | Scoped engagement | As scoped |
| Internal Audit Outsourcing A full outsourced internal audit function delivering an annual programme approved by your audit committee. | Scoped engagement | As scoped |
| Statutory External AuditPartner signed A managed statutory audit of your financial statements, delivered through a registered audit firm. | Scoped engagement | As scoped |
Risk and Governance
Enterprise risk frameworks, board and committee governance, internal control design, model risk validation and consumer protection.
| Service | Delivery | Turnaround |
|---|---|---|
| AI/ML Model Risk Validation Independent validation of a machine learning model in production: performance, stability, explainability and the governance around it. | Documentation and assessment | 5 business days |
| Anti-Bribery and Corruption Programme An anti-bribery programme aligned to ISO 37001, covering gifts, facilitation payments, third-party intermediaries and whistleblowing. | Documentation and assessment | 5 business days |
| Consumer Protection and Complaints Framework A complaints and fair-treatment framework meeting the CBN Consumer Protection Framework, with the reporting your regulator expects. | Documentation and assessment | 5 business days |
| Corporate Governance Framework and Board Charters Board and committee charters, delegation of authority and a governance framework compliant with the codes that apply to your entity. | Documentation and assessment | 5 business days |
| Credit Scoring Model Validation and Bias Audit Validation of a credit scoring model including fairness testing across protected characteristics. | Documentation and assessment | 5 business days |
| Digital Lending Compliance Assessment An assessment against the digital lending rules in your market, covering pricing disclosure, data use and debt collection conduct. | Documentation and assessment | 5 business days |
| ERM Framework, Risk Register and KRI Library An enterprise risk management framework with a populated risk register and key risk indicators that produce a usable board report. | Documentation and assessment | 5 business days |
| ESG and IFRS S1/S2 Reporting Readiness Readiness for sustainability disclosure under IFRS S1 and S2, including climate-related risk identification. | Documentation and assessment | 5 business days |
| Financial Promotions and Marketing Compliance Review A review of your marketing and in-product messaging against financial promotions rules, before a regulator does it for you. | Documentation and assessment | 5 business days |
| Fraud Risk Management Framework A fraud risk framework covering first-party, third-party and internal fraud, with chargeback and dispute handling. | Documentation and assessment | 5 business days |
| Internal Control Framework Design An internal control framework built on COSO, with controls documented at a level that supports testing rather than assertion. | Documentation and assessment | 5 business days |
| Operational Resilience and Critical Service Mapping Identification of your important business services, the resources they depend on, and the maximum disruption each can tolerate. | Documentation and assessment | 5 business days |
| Outsourcing and Third-Party Risk Framework A framework for managing outsourced and third-party relationships, including the material-outsourcing notifications your regulator requires. | Documentation and assessment | 5 business days |
| Board and Executive Briefing A briefing session for your board on a specific regulatory topic and the personal accountability attached to it. | Retainer | Ongoing |
| Certification Exam Preparation Structured preparation for CAMS, CISA, CISM or ICA certification. | Retainer | Ongoing |
| Open-Enrolment Course Seat A single seat on a scheduled open-enrolment course. | Retainer | Ongoing |
| Outsourced Compliance Officer A named compliance officer covering conduct, consumer protection and licence conditions outside the AML perimeter. | Retainer | Ongoing |
| Policy Library Subscription Access to the maintained policy library with an annual refresh reflecting regulatory change. | Retainer | Ongoing |
| Private Cohort Training A private course delivered for your team, tailored to your products and risks. | Retainer | Ongoing |
| Security and Compliance Training Programme An annual training programme across AML, privacy and security, with completion tracking you can show an examiner. | Retainer | Ongoing |