Is the firm's own compliance evidenced, not just the clients'?
Yes. The compliance monitoring programme runs its tests nightly against the files themselves and records the ones a person performs; the board report draws its figures from those tests. The registers the Rules name, staff training and declarations, and the GFSC's own regulatory feed sit beside the client files, on the same record.
| Test | Basis | Result |
|---|---|---|
| Periodic reviews on time | All files | Pass |
| Identity current on high-risk files | All High | Pass |
| Rescreening ran as scheduled | Weekly runs | Pass |
| Staff training current | 6 staff | Pass |
| Sample file review | 10 files, Sept | Sample review due |
The monitoring programme, as data
Each test has a basis, a result and a way of running. Computed tests run nightly against the files: reviews on time, identity current on high-risk files, rescreening ran, training current. Manual tests, a sample of files reviewed by a person, or an attestation with a document, are recorded with who and when. The programme is a page, not a Word file.
- Computed tests nightly, from the files
- Sample reviews and attestations recorded
- Failures show on the dashboard
| Test | Basis | Result | Run |
|---|---|---|---|
| Periodic reviews on time | All files | 1 overdue of 128 | Nightly |
| Identity current on high-risk files | All High | Pass | Nightly |
| Rescreening ran as scheduled | Weekly runs | Pass | Nightly |
| Sample file review | 10 files, Sept | 8 of 10 recorded | Manual, S. Ashton |
| Staff training current | 6 staff | Pass | Nightly |
The board report, from the same figures
The quarterly board report is generated from the programme's results and the registers: position, movement since last quarter, open items. It is signed on the server at generation, so the board reads the figures the programme computed and not a retyped version of them.
- Generated, not assembled by hand
- Signed at generation
- The same numbers the MLRO sees
| Area | Position | Movement |
|---|---|---|
| Files and reviews | 128 structures, 412 names, 1 review overdue | From 3 overdue in Q2 |
| Screening | 13 weekly runs, 2 alerts, both decided | No open alerts |
| Staff | 6 trained, 6 declarations current | One new joiner completed induction |
| Registers | 0 disclosures, 1 breach closed, 0 complaints | Breach: late filing, remediated |
Signed on the server by Flarion at generation; the board sees the same figures the programme computed.
The registers the Rules name
Disclosures, breaches and complaints, each with the typed columns its rule requires, so an entry cannot be saved half-complete. The disclosures register is the most sensitive data the firm holds: MLRO-only, and never included in an inspection link.
- Handbook Rule 16.17, Fiduciary Rules 2.2(2)(d) and 3.6(1)(b)
- Typed columns, validated
- Disclosures MLRO-only
| Date | What | Cause | Remediation | Status |
|---|---|---|---|---|
| 4 Aug 2026 | Annual return filed late for Herm Holdings Ltd | Diary error | Filed 6 Aug, diary moved to Flarion | Closed |
Disclosures (Handbook Rule 16.17), MLRO-only, never leaves through an inspection link. Breaches (Fiduciary Rules 2.2(2)(d)). Complaints (Fiduciary Rules 3.6(1)(b)). Each with the columns the rule names.
Staff training, declarations and screening
Courses are set by role and expire; declarations belong to a period; each staff member is screened after the client book on the same schedule, with results visible to the MLRO only and never mixed with client alerts. Overdue means the same thing on the staff list, the dashboard and the programme.
- Courses by role, with expiry
- Annual declarations by period
- Staff screening, MLRO-only
| Person | Role | AML training | Declaration | Screened |
|---|---|---|---|---|
| S. Ashton | MLRO | Current, Jun 2026 | 2026 signed | Clear |
| R. Falla | Analyst | Current, Feb 2026 | 2026 signed | Clear |
| T. Ozanne | Analyst, joined Sep | Induction due | Not yet | Clear |
The GFSC feed, in the same tab
The Commission's RSS feeds are polled hourly and each item lands in the Monitoring tab: sanctions notices, Handbook amendments, consultations. Marking one noted records who read it and whether anything changed at the firm, which is the evidence an inspector asks for when a notice was published.
- Polled hourly from the GFSC
- Noted with who and what changed
- Sanctions notices flagged
| Published | Source | Item | Status |
|---|---|---|---|
| Today | Sanctions notices | Financial sanctions notice: Russia regime, amendment | Unread |
| Tue | Handbook | Handbook amendment: proof of address guidance | Noted |
| 12 Sep | Consultation | Consultation paper on fiduciary rules | Noted |
Questions about firm compliance
What is the compliance monitoring programme?
The set of tests the firm runs to satisfy itself its controls work, kept as data rather than as a document. Most tests compute nightly from the files themselves: reviews on time, identity current, rescreening ran, training current. Sample reviews and attestations are recorded by a person. The quarterly board report draws its figures from the same tests.
Which registers does Flarion keep?
The three a rule names: disclosures under Handbook Rule 16.17, breaches under Fiduciary Rules 2.2(2)(d) and complaints under 3.6(1)(b), each with the columns the rule requires. The disclosures register is MLRO-only and never leaves through an inspection link, because tipping off is a criminal offence.
Does it cover our own staff?
Yes. Training courses by role, annual declarations by period, and screening of staff members themselves, run after the client book and visible to the MLRO only. A person's training and declaration status is on the staff list and in the monitoring programme.
Where do regulatory updates come from?
The GFSC's own RSS feeds, polled hourly: sanctions notices, Handbook amendments, consultations and news. Each item is a line in the Monitoring tab until someone marks it noted, with a note on what, if anything, changed at the firm.
See your monitoring programme drawn from real files.
Load your spreadsheet in the demo and watch the programme's tests compute on it.