A structured self-assessment against what CBE, FRA, EGX and the EMLCU actually inspect — run before the regulator arrives, so findings are yours to fix rather than theirs to raise.
The point of the exercise is to find your own findings first. A finding you self-identify and are already remediating is a fundamentally different conversation with a supervisor.
Build the register of every law, circular, decision and licence condition that binds you, mapped to an internal owner.
For each obligation, locate the policy, the control, the evidence it operated, and the person accountable. Missing any one is a gap.
Rate each obligation compliant, partially compliant or non-compliant, with severity weighted by supervisory focus.
Every gap gets an action, an owner, a due date and a defined evidence requirement for closure.
Run the actual inspection experience — document requests under time pressure, interviews with control owners, and evidence retrieval.
Supervisory attention is not evenly distributed. These are the areas most consistently examined.
AML/CFT programme, risk management and capital adequacy, cybersecurity framework, consumer protection SLAs and reporting timeliness.
Licensing conditions, corporate governance code alignment, ESG disclosure completeness and non-banking sector conduct.
Disclosure timeliness, material event reporting, insider trading controls and governance code compliance.
STR quality and timeliness, enterprise risk assessment, transaction monitoring calibration and record keeping.
These are retrieved under time pressure. If retrieval takes days, that itself becomes a finding.
Every engagement is led by a senior practitioner and closes with documented, regulator-ready evidence of what was built.