Compliance & Governance — Principle Legal
Compliance & Governance

Policies that pass audits.
Not PDFs that sit.

We build compliance and governance packs for operators — AML/KYC readiness, risk-based controls, and clean evidence mapping — aligned to your business model and jurisdiction scope.

AML/CFT program packs KYC onboarding templates Risk assessments (RBA) Governance matrix Evidence map
Compliance documentation
What “ready” means

Policy set + templates + register formats + evidence trail — structured for operations, not marketing.

Audit-friendly Evidence map makes audits faster and cleaner.
Operational Templates, registers, and SOPs used daily.
Modular Pick modules based on product and risk profile.
AML/CFT packs KYC templates RBA matrices Evidence mapping
Policy modules
Build a complete compliance system.
Select modules based on your activity type. Outputs come as a labelled pack with templates and registers.
AML/CFT Program Policy + procedures + reporting triggers.
Covers the full program design:
  • Onboarding, monitoring, and escalation
  • Sanctions & PEP screening approach
  • SAR/STR decision triggers and workflow
KYC Intake Kit Forms, checklists, registers, and templates.
Operator-ready onboarding:
  • Individual & corporate KYC forms
  • Document checklist and verification notes
  • Beneficial ownership collection templates
Risk-Based Assessment Customer, product, channel, geography risk.
Build a defensible RBA:
  • Risk scoring matrix + controls mapping
  • Enhanced due diligence triggers
  • Residual risk and review cadence
Governance Matrix Who approves what, when, and how.
Governance that works:
  • Delegations, approvals, escalation
  • Committee / officer roles and cadence
  • Register and minutes formats
Recordkeeping SOP What to store, where, for how long.
Evidence discipline:
  • File naming and index conventions
  • Retention schedule and access control
  • Audit trail and handover protocols
Incident & Reporting Internal reporting, external triggers, logs.
Make issues trackable:
  • Incident logging templates
  • Regulator/reporting triggers (as applicable)
  • Corrective action register
Evidence board
Turn policies into proof.
An evidence map connects policies to the exact files, registers, and logs you maintain.
Select a view

Click a view to see how evidence is structured and what you keep on file.

Deliverables
Two packs: policy + evidence.
You get policy documents and templates, plus a practical evidence map so compliance is provable.
Policy pack
Policy Pack

Core policies and procedures in a consistent, operator-first format.

  • AML/CFT manual + SOPs
  • KYC forms + checklists + registers
  • Risk assessment matrix and review cadence
  • Governance matrix and approvals
Used for: internal ops, onboarding, audits, partner due diligence.
Evidence map
Evidence Map

A structured index connecting each policy clause to real files, logs, and records.

  • Evidence checklist per control
  • Register formats + log templates
  • Folder structure + naming conventions
  • Audit response “where it is” sheet
Used for: audits, regulatory requests, bank/PSP onboarding.
Want a compliance pack sized to your model? Email your activity type + jurisdiction + current process (even if messy). We’ll reply with modules, inputs, turnaround, and quote.
FAQ
What people ask before they buy.
Short answers. No fluff. Scope depends on activity type and jurisdiction.
Is this “one-size-fits-all” AML?

No. The program is aligned to your activity type and your exposure (geography, products, counterparties). You pick modules and we size controls accordingly.

Do you provide templates and registers too?

Yes. Packs include operator-ready templates: onboarding forms, checklists, risk scoring, logs, registers, and an evidence map so you can prove controls are followed.

Will this help with bank/PSP onboarding?

It improves your documentation posture significantly — especially the evidence map and “where it lives” sheet. Final acceptance depends on each counterparty’s risk rules.

Can you review what we already have and fix it?

Yes. We can do a gap heatmap and then deliver a rewrite pack: before/after clauses, reasons, and a remediation checklist.