Compliance Effectiveness Review
The periodic independent review of the compliance programme, its scope and how findings are closed.
1. Purpose
This document sets out FLOWA PAY INC.'s policy position and control objectives, published for transparency and to support institutional due diligence. It is reviewed periodically and does not constitute legal advice. FLOWA PAY INC. makes no representation that it holds any licence, authorisation or certification except the FINTRAC Money Services Business registration expressly stated in the Regulatory Disclosures.
A compliance programme has to be tested, not merely written. Canadian requirements provide for a review of the effectiveness of the compliance programme at least every two years, and this policy sets out how FLOWA PAY INC. conducts that review, who performs it, what it covers and how findings are tracked to closure.
2. Independence
The review is performed by a person independent of the activities being reviewed: an internal party who does not own the controls in question, or an external reviewer. The compliance officer does not review their own programme. The reviewer has unrestricted access to policies, procedures, records, systems and staff.
3. Scope
- The written policies and procedures: whether they exist, are current, and reflect what is actually done.
- The risk assessment: whether it is current, covers products, customers, channels and geographies, and drives the controls applied.
- Customer due diligence and beneficial ownership, tested on a sample of real files.
- Screening: coverage, list currency, match handling and the quality of recorded clearances.
- Transaction monitoring: rule coverage, alert quality, timeliness of review and the documentation of outcomes.
- Reporting: whether reportable matters were identified and reported within the required timeframes.
- Record keeping: completeness, retention and retrievability.
- Training: coverage, currency and evidence of completion.
- Whether findings from the previous review were actually closed.
4. Method
The review combines document examination, system walkthroughs, interviews and sample testing of files and alerts. Sampling is risk-weighted rather than uniform. Testing establishes whether a control operated, not merely whether it was documented.
5. Findings and closure
Findings are rated by severity, assigned an owner and a due date, and recorded in a tracked register. Remediation is verified rather than assumed closed on the owner's say-so. Overdue findings are escalated to senior management and governance.
6. Reporting
The results of the review, the findings and the remediation status are reported to senior management and to those charged with governance, and the report and supporting material are retained with our compliance records. The outcome also informs the next update of the risk assessment and of this programme.