Compass
Risk assessment

Control library

Controls in place to mitigate compliance risks. Editing a control moves every assessment that relies on it back to Draft.

C-5001Active

Four-eye review of onboarding files

Effective

A second analyst reviews each onboarding file for completeness of ID&V and UBO documentation before activation.

PreventiveSemi automatedAt time of event
Owner
Marc Lefèvre
Mitigates
Incomplete customer due diligence
C-5002Active

Enhanced due diligence for high-risk clients

Partially effective

High-risk and PEP clients require source-of-wealth evidence and CCO sign-off.

PreventiveManualAt time of event
Owner
Claire Dubois
Mitigates
Incomplete customer due diligence
C-5003Active

Daily sanctions list screening

Strong

All clients and counterparties are screened against EU, UN, OFAC and UK lists each night.

DetectiveAutomatedDaily
Owner
Claire Dubois
Mitigates
Onboarding of sanctioned parties
C-5004Active

Transaction monitoring alert review

Effective

TM alerts are reviewed, documented and either closed with rationale or escalated for SAR.

DetectiveSemi automatedWeekly
Owner
Marc Lefèvre
Mitigates
Suspicious transactions not escalated
C-5005Active

Insider list and watch list maintenance

Partially effective

Insider lists are opened per project and personal account dealing is checked against the watch list.

PreventiveManualOngoing
Owner
Sofia Martins
Mitigates
Insider dealing by staff
C-5006Active

Trade surveillance alert review

Effective

Surveillance scenarios for spoofing, layering and wash trades are reviewed daily.

DetectiveSemi automatedDaily
Owner
Sofia Martins
Mitigates
Market manipulation through order flow
C-5007Active

Quarterly recorded-line sampling

Not rated

A sample of order-related calls and chats is reviewed to confirm recording coverage.

DetectiveManualQuarterly · 15 Jan, 15 Apr, 15 Jul, 15 Oct
Owner
Sofia Martins
Mitigates
Unrecorded client communications
C-5008Active

Annual data retention purge

Effective

Client records past their retention period are identified and deleted or anonymised.

CorrectiveSemi automatedAnnual · 31 Mar
Owner
Thomas Becker
Mitigates
Client data retained beyond legal period
C-5009Active

Semi-annual access recertification

Strong

Line managers recertify access rights to client data systems for each team member.

DetectiveSemi automatedSemi annual
Owner
Thomas Becker
Mitigates
Unauthorised access to client records
C-5010Active

Data loss prevention monitoring

Effective

DLP rules block and flag outbound transfers of client data to unapproved destinations.

PreventiveAutomatedOngoing
Owner
Thomas Becker
Mitigates
Unauthorised access to client records