Licensed by the Estonian FIU · FIU000117Operating since 2014Punane 6, Tallinn

info@micaconsult.com+372 5089565

LexorCorp Global

Guide

Compliance audit for regulated firms

An internal compliance review before or after the supervisor looks: scope, method, report and remediation.

LexorCorp Global OÜ · published 27 September 2026

A regulated firm learns about the gaps in its compliance in one of two ways: from its own review, or from the supervisor's inspection. A compliance audit is the first way. This guide explains what an internal compliance review covers, how the scope is chosen, what the report contains and what happens with the findings.

The guide is general information, not legal advice. A compliance review is not a statutory financial audit and does not replace the auditor required by the Auditors Activities Act or the sector law.

When a review makes sense

  • before applying for a licence, to test the documents against the law;
  • in the first year after authorisation, when policies meet practice for the first time;
  • before a supervisory inspection, or after one, to close the findings;
  • when AML rules require an independent check of the internal control system (RahaPTS), or before a bank's periodic review of the firm;
  • before a sale, as part of the buyer's due diligence.

Scope in three classes

  • Class 1 scope — : AML/CFT framework, governance and the core policies of a firm with limited services;
  • Class 2 scope — : adds safeguarding or custody, outsourcing, ICT and complaints, with sample testing;
  • Class 3 scope — : the full regulatory perimeter of a complex firm, including market conduct and trading platform rules where relevant.

The class of the review follows the firm's services, not its size alone; we confirm it in the quote.

The method and the report

  • document review against the applicable law, regulations and supervisory guidelines;
  • written questionnaires to the management and key function holders, with follow-up questions by email;
  • sample testing of files: customer due diligence, monitoring alerts, safeguarding reconciliations, complaints;
  • a report with findings rated by risk, the legal basis of each, and a recommendation.

Closing the findings

The remediation plan () turns the findings into a prioritised plan with owners and deadlines, and we update the documents where needed. Firms under DORA often combine the review with the DORA framework; crypto firms with ongoing MiCA compliance support.

What you receive

  • an independent compliance review report with rated findings;
  • where ordered, the remediation plan and updated documents.

Prices are starting prices confirmed in a written quote and exclude VAT. All communication takes place by email.

Ready to start? Choose the scope class of the compliance audit. Open the quote form.

Frequently asked questions

Is a compliance audit the same as a financial audit?

No. A compliance review checks the firm's regulatory framework and practice against the law and supervisory guidelines. It does not replace the statutory financial audit required by the Auditors Activities Act or the sector law.

What happens after the compliance audit?

The findings are rated by risk. The remediation plan turns them into prioritised actions with owners and deadlines, and we update the documents where needed.

Related guides

More on this topic: Compliance services.

Request a quote

Choose the scope class of the compliance audit.

Open the quote form Compliance services