Since 1998

Licensed provider of company formation and corporate services

Audits and Assessments: AML, DORA, ICT and GDPR

Independent, evidence-led audits across risk and governance, AML and financial crime, ICT/DORA, on-chain assurance and data protection.Following ISO 19011 audit principles, with findings you can act on and re‑test.

  • Local compliance teams in 4 EU hubs
  • ISO 19011 audit principles
  • 500+ licensing projects
View audit typesGet a free assessment

Free, no-obligation assessmentWe reply within 1 business day

8 audit types
Across 4 domains
ISO 19011
Audit principles
1 to 2 weeks
To start once scoped
Fixed scope
Priced per engagement
Re-test
To confirm closure

Overview

Evidence-led audits for licensing and oversight

MAXCORP delivers independent audits and assessments across risk and governance, AML and financial crime, ICT/DORA, on-chain assurance and data protection. Our method follows ISO 19011 and references EU supervisory guidance (EBA, ESMA, ECB), with evidence mapped to your obligations, control owners and deadlines.

Compliance audit documents in a white folder with a clipboard symbol and the MAXCORP logo
  • Scope set to the minimum useful set of tests, mapped to your obligations and control owners

  • Least-privilege access in your environment, with logging and segregation of your data

  • Findings ranked by risk, each with evidence references, owners and practical guidance

  • A concise evidence pack you can reuse for supervisory requests and later audits

  • Re-test options that confirm findings are closed before the regulator asks

  • One-off audits or recurring assurance, from pre-licence readiness to deep dives

Supervisors expect firms to show that controls work, not only that policies exist. Whether you need pre-licence readiness, a post-licence health check or a deep dive, our audits help you meet licensing conditions and answer supervisory requests. Each audit uses least-privilege access and ends with an evidence pack of risk-ranked findings, owners and a re-test. Every finding comes with evidence you can trace and close.

Audits

Audit and assessment services

Eight audit types in four domains: regulatory and financial crime, ICT and operational resilience, on-chain and security, and data protection. Each has a defined scope, deliverables and test approach.

AML and corporate governance

Regulatory and financial crime. For a full independent AML audit, see AML audit.

Scope and tests

  • CDD/EDD playbooks, onboarding and remediation, PEP and adverse media checks
  • Transaction monitoring rules, alert and case quality, STR timeliness
  • The MLRO mandate and support, registers and escalation logs

Deliverables

  • Findings ranked by risk with evidence references
  • KPIs for turnaround, quality and backlog thresholds
  • An inspection-ready evidence pack

What we do in practice: we re-perform KYC samples, validate transaction monitoring rules and review STR timeliness against the standards.

Risk management and sanctions oversight

Regulatory and financial crime. Board-level oversight of risk management and sanctions, with evidence you can trace.

Scope and tests

  • Risk framework, registers, appetite and tolerance, KRIs, escalation and reporting
  • Sanctions governance: list sourcing, thresholds, alert QA and case handling
  • Incident and case management, exception handling and independence safeguards

Deliverables

  • A risk and controls map, issue register and remediation plan
  • Sanctions QA guidance
  • A summary for the board

What we do in practice: we sample alerts end to end, check escalation timeliness and test governance registers for completeness.

DORA / ICT assurance

ICT and operational resilience. DORA-aligned controls across ICT governance, testing and recovery. To build the framework itself, see DORA compliance.

Scope and tests

  • ICT risk governance, incident management and BCP/DR
  • Third-party criticality and audit rights
  • Scenario testing and TLPT readiness

Deliverables

  • A report mapped to DORA obligations and owners
  • A third-party scorecard and testing roadmap
  • A summary for the board pack

What we do in practice: we reconcile ICT registers with contracts, review post-mortems and sample resilience test evidence.

Cyber incident response and recovery audit

ICT and operational resilience. How well you detect, escalate, notify and recover.

Scope and tests

  • Incident response playbooks and escalation paths
  • Testing evidence: tabletop exercises, drills, red and blue team exercises
  • Notification flows and timeliness, post-incident reviews and lessons learned

Deliverables

  • A response maturity scorecard
  • A gap analysis against regulatory expectations
  • A playbook improvement plan

What we do in practice: we test escalation routes, review drill evidence and validate the timelines for notifying regulators.

Proof of reserves (PoR)

On-chain and security. Assurance over crypto reserves held by exchanges and custodians.

Scope and tests

  • Wallet ownership verification and on‑chain balance confirmation
  • Construction of the liabilities set with Merkle-tree sampling and exclusion rules
  • Reserve ratio analysis, timestamping and re‑test cadence

Deliverables

  • A methodology report with a disclosure of limitations
  • A public summary and verifiable hashes (if agreed)
  • Internal working papers and an evidence pack

What we do in practice: we reconcile exchange, custodian and on-chain data, test how the proof is built and publish verifiable outputs (if agreed).

Smart contract security assessment

On-chain and security. Secure delivery of smart contracts and the infrastructure around them.

Scope and tests

  • Threat modelling, access controls, upgrade paths and pause or kill switches
  • Static and dynamic analysis, unit and integration tests, testnet validation
  • Dependency and tooling hygiene, CI/CD and secrets management

Deliverables

  • Findings with severity and exploit paths
  • A fix-validation re‑test and attestations
  • Hardening recommendations and an owner map

What we do in practice: we replicate exploits, review patches together with your developers and provide proofs for critical fixes before mainnet.

Privacy programme governance and DPIA review

Data protection. GDPR-aligned review of how privacy risk is governed and documented.

Scope and tests

  • DPIA methodology and risk decisions, RoPA quality, LIA and consent records
  • Privacy by design in change management and vendor onboarding
  • Data subject requests, breach response and contact with the regulator

Deliverables

  • A DPIA and RoPA gap list with priorities
  • A template pack and workflow improvements
  • A readiness summary for the board

What we do in practice: we sample DPIAs and RoPAs, trace risk decisions to controls and rehearse data subject request and breach scenarios.

Records of processing and retention audit

Data protection. Whether your records of processing and retention match what your systems actually do.

Scope and tests

  • Accuracy and completeness of processing records against the systems
  • Legal bases, retention triggers, deletion evidence and suppression rules
  • Third-country transfers, SCCs and oversight of processors

Deliverables

  • A corrected RoPA and retention schedule
  • A deletion evidence pack and controls map
  • A summary for the regulator with owners and timelines

What we do in practice: we walk the data lifecycle, collect deletion evidence and align contract clauses with the real data flows.

Approach

How our audits work

Work can be commissioned as a one-off audit or recurring assurance. Scope follows your regulatory obligations, risk profile and operational footprint, calibrated to give sufficient assurance without unnecessary disruption.

Scoped to your obligations

We set the scope to the minimum useful set of tests and map each test to specific control owners and evidence items.

Least-privilege access

We work in your environment under least-privilege access with logging and segregation, in line with your GDPR and contractual requirements.

Evidence pack

A concise pack with risk-ranked findings, evidence references and practical guidance, linking every finding to an owner and a deadline.

Re-test and closure

Optional re-tests confirm that findings are closed, so you can show the regulator that remediation worked.

FAQ

Audits & assessments: frequently asked questions

Can your auditors access our systems?

Yes, under least-privilege access with logging and segregation, and in line with your GDPR and contractual requirements. DORA also requires your ICT provider contracts to include access, inspection and audit rights, so an audit can reach the provider too.

When is a GDPR DPIA required?

When processing is likely to result in a high risk to individuals, GDPR Article 35(3) names three cases: automated evaluation or profiling with legal or similarly significant effects, large-scale processing of special category or criminal data, and systematic large-scale monitoring of publicly accessible areas. The EDPB guidelines give more examples.

How often should we run AML audits?

Regulators expect an independent AML/CFT audit on a risk-based cadence that tests whether controls are effective. FATF Recommendation 18 calls for an independent audit function, and some countries set fixed intervals. See AML audit for details.

What does DORA change in ICT contracts?

DORA requires specific clauses with ICT providers, including audit and access rights, cooperation duties and exit and termination strategies. They are set out directly in Regulation (EU) 2022/2554.

Can an audit be recurring?

Yes. Any audit can be commissioned once or as recurring assurance on an agreed cycle, reusing the evidence pack and re-testing earlier findings to confirm they are closed.

How do you set the scope of an audit?

MAXCORP starts from your regulatory obligations, risk profile and operational footprint, then map the tests to specific control owners and evidence items. The plan is calibrated to give sufficient assurance without unnecessary disruption.

How should incident response be tested?

Through periodic exercises such as tabletops, followed by lessons learned that improve detection, response and recovery. NIST incident response guidance recommends building exercises into normal risk management and refining the plan continuously.

What evidence do regulators expect?

Typically policies and procedures, governance records, logs and configuration exports, samples of case files or alerts, and proof of testing or remediation. We package this into a traceable evidence set that links findings to owners and deadlines.

Contact

Plan your audit or assessment

After a discovery meeting we send a tailored plan with the assessments needed, responsibilities and the evidence required to close findings.

What can we help with?

We reply within 1 business day.

By submitting this form you agree to our Privacy Policy. We use your details to reply to your enquiry.

Send an enquiry

Tell us about your project. We reply with next steps and a budget.

By sending this form, you agree to our Privacy Policy.We use your details to reply to your enquiry.

Book a free call

Open in a new tab

Loading the calendar…

Cookie settings

Choose which cookies we may use. Necessary cookies are always on, because the website cannot work securely without them. Cookie Policy