Methodology and user guide

AML/CFT Compliance Check-up

This document does two jobs: it explains the assessment methodology behind the application down to the formula level, and it walks through every feature of all seventeen screens. No technical knowledge is required; your AML knowledge is enough.

Applicationcheckup.alpgiraykocal.com
Scope17 screens · 218 questions · 25 risk factors
Time needed3–5 working days for the first period
Reference pack2026.1 · Version 2.10.7

What this tool does

And, more importantly, what it does not do.

The application answers three questions in order: how much risk does your business carry by its very nature, how well do your controls work against that risk, and what is left over. If the remaining risk exceeds the limit your institution has accepted, a finding and an action come out of it.

You end up with three things: a printable executive report, an inventory of 218 controls matched to evidence references, and an action plan with named owners and due dates. When an examiner asks “how do you know that?”, the answer lives in those three.

What it does not replace

This is a self-assessment tool. It does not replace independent audit, internal inspection or regulatory examination. Its scores rest on the answers and evidence you enter; a false declaration produces a false score. The value it adds is that it ties declarations to written evidence, tests them against samples, and puts the result on a repeatable formula.

What it is based on

The question bank, risk factors, sampling rates and thresholds were derived from a source workbook; the scoring engine matches that workbook's formulas exactly. The methodological frame is aligned with FATF Recommendations 1 and 7, the EBA ML/TF risk factors guidelines, the Basel approach to AML/CFT risk management, the Wolfsberg effectiveness statement and the IIA three lines model. Regulatory citations are indicative; article numbers must be checked against the legislation in force.


Methodology

The chain, the formulas, and why each step is there.

The assessment is a chain with seven links. Each link takes the previous one's output as its input; no link can be skipped, and if one is, the next link reports “not measured” and stays empty.

LinkWhat it producesScreen
1 · ScopeWhich questions, factors and business lines enter the assessmentProfile
2 · ExposureCustomer, country, channel and transaction volumes; score suggestionsPortfolio · Transactions
3 · Inherent risk1–5 scores across 5 dimensions plus PFInherent Risk
4 · Control declarationDeclared control effectiveness per domainQuestionnaire · Extra Controls
5 · Independent testingTest-adjusted effectiveness and assurance coverageQA Plan · Questionnaire
6 · Residual riskRemaining risk and appetite breachesControl Scores · Residual Risk
7 · ActionFinding, root cause, owner, due date, verificationAction Plan

Setting the scope

Scoring a control as “absent” for business you do not conduct depresses the score unfairly; scoring it as “present” is a false declaration. That is why scope is set first, and in writing. A “No” to five of the six business scope questions in the Profile screen automatically takes the related question sections, inherent risk factors, business lines and extra control sets out of scope. The sixth (foreign branches/subsidiaries) does not scope anything out automatically; for the group-level policy and information sharing questions you are expected to record the reason for a “No” as a note.

Profile field answered “No”Question section taken out of scopeInherent risk factor taken out of scope
Trade finance activityD6 · Trade Finance · D3 · Trade FinanceTrade finance product volume
Correspondent bankingD2 · Correspondent BankingGeographic risk of the correspondent network
Virtual asset activityD3 · Virtual AssetsVirtual asset products and services
Remote customer onboardingD3 · Digital ChannelShare of remote onboarding
Agent / representative networkD3 · Intermediated Channel · D1 · Outsourcing and AgentsShare of the agent and representative channel

A question taken out of scope counts as “Not applicable”: it enters neither the numerator nor the denominator, and moves the score neither up nor down. The rule binds only records you have not filled in manually — if you answered a question or scored a factor yourself, the automatic scope rule no longer applies to that record. That way the “we generally don't, but there is this one relationship” case is not lost.

Scope decisions get examined

Saying “No” is a declaration and it appears in the report. If the activity started during the period, update the Profile: the section you excluded reopens immediately, its questions become unanswered, and the progress badge drops.

Inherent risk

Inherent risk is the risk the business carries when you imagine there are no controls at all. It is measured across five dimensions with 25 factors in total: Customer, Geography and Sanctions, Product, Channel, Transaction. Each factor is scored from 1 to 5 and each factor carries its own weight.

Dimension score = Σ(factor score × weight) ÷ Σ(weights of scored factors)
OVERALL = plain average of the measured dimension scores

Scoring anchors

Each of the 25 factors has a written rubric defining what every score from 1 to 5 means (for example “share of high-risk customers 3–7% → 3”). The rubric makes scoring independent of the person and defensible in an examination. Do not score a factor without reading its rubric.

Mandatory rationale

A rationale/evidence note is treated as mandatory for scores of 4 and 5. This is the first thing an examiner asks: “what did you base this score on?” High scores without a rationale are counted as a warning on the dashboard.

Changing weights

Factor weights are editable. A changed weight is tagged “weight changed”, written to the CSV export alongside the default, and reverted with one click. Changing a weight is a methodology decision of the institution and should be approved in writing.

Score suggestions

The figures entered on the Portfolio and Transactions screens produce score suggestions for 16 factors (12 from the portfolio, 4 from operations). A suggestion is derived by placing the calculated ratio into the rubric bands, and it is applied with one click. Suggestions are not binding; you still write the rationale. If there is no portfolio data, the figures from the Profile screen step in.

Control declaration

The control side is measured with 218 questions across 11 domains. Every question carries a weight and a criticality; 40 questions are rated “Critical”.

AnswerCoefficientMeaning
Yes1.00The control is defined, applied, and evidenced
Partial0.50Present but incomplete: narrow coverage, undocumented, or applied irregularly
No0.00The control does not exist or does not work
Not applicable—Excluded from scoring entirely; enters neither numerator nor denominator
Control effectiveness = points earned ÷ applicable total weight (per domain)

This value is the declared effectiveness: it is the institution's own statement and is not evidence on its own. An unrecognised answer value (a hand-edited file, a different version) is treated as unanswered; a silently broken score is never produced.

Maturity bands

EffectivenessMaturity
≥ 90%Advanced
≥ 75%Adequate
≥ 60%Needs improvement
≥ 40%Weak
< 40%Critically weak

The maturity label is derived from the test-adjusted effectiveness; it always comes from the same source as the percentage shown on the dashboard, in the heatmap, in the score table and in the report.

Open critical control

Any question rated “Critical” whose test-adjusted coefficient is not full counts as an open critical: answers other than “Yes”, and “Yes” declarations that the QA test rated “Partly confirmed” or “Contradicted”. Action need is read from the same coefficient; the action list looks at what the score, maturity and residual risk look at. Where the reason is the QA test, the card shows a “Due to QA test” marker, the source of a bulk-generated finding records both the declaration and the test result, and the report’s open-critical table shows the test result. Criticality is assigned by a written rule: a control is critical only if its absence on its own creates a direct legal breach or an exposure that cannot be remedied. What is important but recoverable — governance, methodology, an approval step, measurement — is rated “High”. Open criticals are listed separately even when the overall score looks good, and they get their own section in the report.

Independent testing: challenging the declaration

This is the backbone of the methodology: a questionnaire answer alone does not count as control effectiveness. Of the 218 questions, 115 require file testing. The test result applies a cap to the declaration.

QA file test resultCap applied to the declarationEffect
Confirmed—The declaration stands as given
Partly confirmed0.50A “Yes” declaration earns at most half a point
Contradicted0.00Whatever the declaration says, the control does not count as effective
Not tested—The declaration stands, but it does not enter assurance coverage

Three separate numbers are therefore reported for each domain, and none of them substitutes for another:

A contradiction is a state that must be corrected

If the answer is “Yes” but the file test says “Contradicted”, a red warning appears on the question card and the contradiction count shows on the dashboard and in the questionnaire summary. The right response is not to leave the score as it is, but to correct the declaration: the answer should be “Partial” or “No”. A report signed off with open contradictions cannot be defended. Even if the declaration is not corrected, the question counts as needing action and — when critical — as an open critical, and it enters bulk finding generation.

Basis: the Wolfsberg effectiveness statement (separating what is declared from what is demonstrated), the IIA three lines model (the second line's declaration being challenged by the third line), and the independent testing pillar of BSA/AML programmes.

Residual risk and the 95% cap

Residual risk = inherent risk × (1 − applied control effectiveness)
Applied effectiveness = MIN(test-adjusted effectiveness, 95%)

Controls reduce risk; they do not eliminate it. FATF Recommendation 1, the EBA ML/TF risk factors guidelines and the Basel approach are explicit on this. Without the cap, a domain with full marks would show 0.00 residual risk, which is indefensible in any examination. The cap applies only to the residual risk calculation, not to the effectiveness score itself — you see 98% on the Control Scores screen, and on the Residual Risk screen that row carries a “capped at 95%” note.

The inherent risk source of each domain

DomainInherent risk source
D1 · Governance and Compliance ProgrammeOVERALL
D2 · Customer Profile and Geographic RiskCustomer + Geography and Sanctions
D3 · Product and Channel RiskProduct + Channel
D4 · Transaction Universe and Data IntegrityTransaction
D5 · Customer Lifecycle (CDD/EDD)Customer
D6 · Financial Sanctions and ScreeningGeography and Sanctions
D7 · AML Transaction MonitoringTransaction + Product
D8 · STR, Freezing and Customer ExitCustomer + Transaction
D9 · Regulatory Events and Law Enforcement RequestsOVERALL
D10 · Training, Awareness and FeedbackOVERALL
D11 · Enterprise-Wide Risk Assessment (EWRA)OVERALL

For domains with two sources, inherent risk is the average of the two dimensions. If even one of the source dimensions is unmeasured, that domain's residual risk is not calculated.

Residual risk bands

Residual risk (0–5)Level
≥ 3.50Very high
≥ 2.50High
≥ 1.50Medium
< 1.50Low

The institution-wide figure is never read on its own

Overall residual risk is calculated with the source workbook's formula: overall inherent risk × (1 − MIN(overall test-adjusted effectiveness, 95%)). That formula can dilute a concentrated weakness through averaging. This is why the dashboard also shows the highest domain residual risk, and a separate warning appears when the overall figure hides a domain breach. In an enterprise-wide risk assessment, a breach at domain level cannot be closed off by the overall average.

Risk appetite

The default appetite limit is 1.50 for every domain and for PF; it is a starting value based on industry practice, not your institution's decision. On the Residual Risk screen the limit can be changed on every row; a changed limit is tagged as an “institution decision” and appears that way in the report. If you enter a value equal to the default, no override is stored.

When residual risk exceeds the limit, the row is flagged OVER — ACTION, the sidebar badge shows the number of breaches, and the report lists breaches in their own section. A breach requires a finding in the action plan.

Why proliferation financing (PF) is separate

The 2020 revision of FATF Recommendation 1 and Recommendation 7 require PF risk to be assessed separately from money laundering and terrorist financing risk. The application keeps that separation:

Business line assessment and the method choice

The EBA ML/TF risk factors guidelines and the Basel approach expect risk to be assessed at business line and product level and then aggregated to the institution weighted by business volume. In the matrix on the Inherent Risk screen you activate 12 business lines; for each you enter a business share (%) and 1–5 scores across the five dimensions.

Exposure weighting option — off by default

When the option on the Inherent Risk screen is switched on, dimension scores are computed not from factor weights but from the business line level, weighted by business volume. With it on, the result no longer matches the source workbook, and comparison with previous period files is only meaningful if both periods use the same method. The option is only actually applied when there is scored business line data with shares; the method used is written into the executive report, and a method difference produces a warning in the period comparison.

Why extra control sets are scored separately

Beyond the main question bank there are eight complementary sets with 44 questions: terrorist financing and NPOs, staff and internal reporting, sanctions lookback and model governance, and five sector-specific sets (insurance/pensions, e-money and payments, VASPs, currency exchange offices, brokerage and portfolio management).

Sets open and close automatically according to the obliged entity type and the business scope answers in the Profile; the reason for an out-of-scope set is shown on screen. Unlike sections of the main questionnaire, an out-of-scope set does not reopen through a manual answer: its scope is the type of institution, not a business choice — an insurance set does not apply to a bank. If the obliged entity type changes later, answers entered earlier are not deleted; the set card shows how many there are, but they do not count toward the score, finding generation or the report.

These sets do not enter the denominator of the main score. If they did, domain effectiveness would shift, breaking both the exact match with the source workbook and comparability with previous period files. The set is reported with its own coverage and effectiveness ratio: a tile on the dashboard, a separate table in the executive report, and rows tagged with the set name in the questionnaire CSV. The same QA caps and the same maturity bands apply within this set.

QA sampling methodology

There are 24 defined populations. Each population has a domain, a risk rating, a sampling rule and a testing frequency.

The sampling is stratified: rates and minimum counts are higher for high-risk populations. The sampling plan tells you how many files to test, not which ones; file selection should be random or risk-stratified, and the selection method should be documented.

Findings, criticality and due dates

A finding that can be defended in an examination has five fields filled in: root cause, action, owner, due date and verification method. The application counts findings with missing fields in a separate tile.

CriticalityClosure time (suggested due date)Error class definition
Critical5 working daysA gap creating a legal breach or an exposure that cannot be remedied
High30 daysA recoverable gap that defeats the purpose of the control
Medium90 daysA process or documentation gap with limited impact
Low180 days (the next QA cycle)An improvement opportunity

For a new finding the due date is suggested automatically by this rule; for critical findings five working days are counted, skipping weekends. The suggested date can be changed by hand. A finding past its due date and not closed counts as “OVERDUE”.

Closure discipline. A closed finding has a closure date and an open one does not; the date cannot be in the future. A closed finding without a closure date counts as having missing fields. When the status is set to “Closed” and the date is empty, today is suggested.

Risk acceptance. The “Risk accepted” status is for a finding that is not remediated but is accepted with management approval; it counts as neither open nor closed. It is never overdue, is excluded from the open and open-critical counts, and enters neither the numerator nor the denominator of the closure rate — the rate measures remediation. On acceptance the approval reference (decision no., date, approver) goes in the Verification field and the decision date in the closure date; since nothing is remediated, an empty action field does not count as missing. A critical finding is by definition a legal breach and cannot be closed by risk acceptance; it must be remediated. Accepted findings are listed in a separate table in the executive report, with their approval reference.

Freshness of the reference data

It is not the code that expires but the external facts it rests on. Country risk flags, regulatory citations and the question bank are tied to a dated reference data pack. Each section ages on its own publication cycle: FATF lists change at every plenary, regulatory citations yearly, the question bank more slowly.

The pack version is shown on the Settings screen and at the bottom of the executive report. When a section passes its own threshold, a warning appears; the job then is to verify the lists against primary sources and update them on the Settings screen. Country flags the institution has changed itself are preserved as “institution decisions”.

Formula summary

QuantityFormula
Answer coefficientYes 1.00 · Partial 0.50 · No 0.00 · Not applicable excluded
Question pointsweight × coefficient
Test-adjusted question pointsweight × MIN(coefficient, QA cap)
Control effectivenessΣ points earned ÷ Σ applicable weight
Assurance coveragequestions tested ÷ questions requiring a test (Not applicable excluded)
Dimension inherent riskΣ(score × weight) ÷ Σ(scored weight)
OVERALL inherent riskplain average of the measured dimensions
Residual riskinherent risk × (1 − MIN(test-adjusted effectiveness, 0.95))
Volume-weighted inherent riskΣ(business line score × share) ÷ Σ(share)
Annual QA samplefull coverage: the volume; otherwise MIN(volume, MAX(volume × rate, minimum))
Sample per testROUNDUP(annual sample ÷ number of tests)
Action closure rateclosed findings ÷ (total findings − accepted risks)

Known limitations of the methodology


Before you start

Half an hour of preparation prevents three days of searching.

Before opening the application, gather these three sets on your desk. You may not have all of them; a missing field can stay empty, but starting with a clear picture of what is missing is faster than hunting for it later.

Institution details

Figures

Documents

Make the evidence reference a habit

Next to every “Yes” answer, write where the evidence sits: policy name and clause number, procedure code, screenshot file name, report number. In an examination this field is your first line of defence, and it will not be remembered later.


Where your data lives

No server. That is a security feature and a responsibility.

The application makes no network requests at all: no external fonts, no CDN, no analytics. All data is held only in the local storage of the browser you use. Institutional data never leaves the device. This is not only a promise: the pages carry a content security policy, and the browser refuses any outbound connection or script from another origin.

The price of that is this: if browser data is cleared, the assessment is gone. The automatic backups sit in the same storage, so they go with it. There is only one way to take a durable backup: Data and backup → Download JSON.

How the application protects you

If you share a computer

Data is tied to the browser profile. Anyone who opens that profile sees the assessment. On shared machines, work in your own user profile; at period end download the JSON and clear the machine with Reset.

Moving to another device

Download the JSON on the old device and open it on the new one with Load working file. The file is the complete working file: answers, scores, notes, findings, settings and the change log are all inside it.


Shell and navigation

The things that stay in the same place on every screen.

The left sidebar

Screens are listed in four groups: Overview (Dashboard, How to Read), Input (Profile, Portfolio, Transactions, Inherent Risk, Questionnaire, Extra Controls, QA Plan), Results (Control Scores, Residual Risk, Action Plan, Period Comparison, Team and Merge, Change Log, Executive Report) and Settings.

What the menu badges mean

ScreenBadge
Questionnaireanswered / total questions; amber while incomplete
Inherent Riskscored / applicable factors; amber if incomplete
Transactionsfilled / total metrics
Portfolionumber of score suggestions produced
Residual Risknumber of appetite breaches (red)
Action Planopen findings; red if any are overdue
Settingscountries changed by institution decision

The bottom of the sidebar

The top bar

The address bar and shareable links

Screen addresses look like #/anket?d=D6&st=gap. Questionnaire filters are carried in the address bar: you can send a colleague a direct link to “the questions that came out as gaps in D6”, and the filter survives a page refresh.


Screen-by-screen reference

Seventeen screens and every feature on them.

1 · Dashboard

The whole assessment on one page. No input is taken, with two exceptions.

The four headline measures

The second row of measures

Progress (answered/total), open criticals, appetite breaches, open actions (with overdue and critical counts), closure rate, and — if the extra control sets have been filled in — extra control effectiveness.

Warning strips

WarningWhen it appears
Backup reminderAt 15 records if no backup exists; after 25 new records or 7 days if one does. The button on the strip downloads the JSON immediately.
Getting startedWhen no question has been answered
Missing factorsWhen inherent risk scoring has started but is not finished
High score without rationaleWhen factors scored 4–5 have an empty rationale
Open criticalWhen critical questions are not answered “Yes”, or a “Yes” declaration failed QA testing
Overall score hides a breachWhen the institution figure is within appetite but a domain is over
QA contradictionWhen a “Yes” declaration meets a “Contradicted” file test

The start card

While the assessment is empty it walks through five steps in order, each linking to the relevant screen. Once work has begun it gives way to a “Last question” button that returns you to the question you worked on most recently.

Heatmap, dimension bars and the KPI table

2 · How to Read

The methodology summarised inside the application. It holds the chain that explains why the screens are in this order, the definition of eight core concepts and where each appears, four formulas, the scale thresholds (inherent 1–5, residual 0–5, maturity bands) and calibration notes.

The same screen defines 26 industry terms that appear in the question texts without explanation: CBDDQ, nested relationship, payable-through account, SoF/SoW, BTL/ATL, the 50 Percent Rule, the Travel Rule, unhosted wallet, dual-use, mirror trade, FOP, NPO and others. Have whoever fills in the questionnaire read this screen first.

3 · Profile

The institution profile: 26 fields in six groups, five of them mandatory. Every field carries a description of what to write and a sample value; in numeric fields the value you enter is read back with thousands separators.

GroupContents
Institution identityLegal name, obliged entity type, geography of operations
AssessmentPeriod start/end, assessor, compliance officer
Scale and exposureCustomer, high-risk and PEP counts, transaction and cross-border counts, compliance headcount (FTE)
SystemsMonitoring, screening and KYC system names and versions
Business scopeSix Yes/No questions — these set the scope
Audit and model historyDates of the last audit, EWRA, scenario tuning and screening threshold calibration

What the screen produces

The obliged entity type opens the extra sets

The obliged entity type in the Profile determines which sector-specific sets apply on the Extra Controls screen. A bank gets three universal sets; an insurance company additionally gets the insurance set. Choose the type carefully.

4 · Portfolio

Four tables, all optional; as much as you enter is used.

  1. Customer distribution — 7 customer types × 4 risk bands. The total, the high-risk share and the legal entity share come from here; a deviation of more than 1% from the customer count in the Profile raises a warning.
  2. Risk segments — 12 segments (PEPs and close associates, non-residents, complex ownership structures, cash-intensive sectors, offshore structures, VASPs, private banking, NPOs, new customers, rejected applications, exits, dormant accounts). Customer and high-risk counts are entered per segment; values exceeding the segment base raise a warning.
  3. Country exposure — for every country you touch: relationship type (6 options), customer count and inbound/outbound transaction counts. Risk flags are read from the Settings screen and only displayed here. Countries flagged “domestic” do not enter the cross-border share.
  4. Branch and unit network — 7 unit types; for each unit the country, customer count, high-risk customers, compliance FTE and last audit date. Customers per FTE and audit ages over 24 months are flagged.

The top tiles

Total customers, high-risk share, number of countries touched, share of transactions with FATF-listed countries, cross-border transaction share, number of units, units with overdue audits, and the number of score suggestions produced.

The 12 factors it feeds

SourceInherent risk factor it feeds
Share of high-risk customersCustomer — share of high-risk segments
PEP segmentCustomer — PEP exposure
Non-resident segmentCustomer — non-resident ratio
Complex ownership segmentCustomer — complex ownership ratio
Cash-intensive segmentCustomer — share of cash-intensive sectors
Offshore segmentGeography — offshore-linked volume
Private banking segmentProduct — wealth management volume
Transaction share with FATF-listed countriesGeography — business volume with FATF grey/black list countries
Transaction share with sanctions regimesGeography — trade with sanctioned countries
Share of flagged correspondent countriesGeography — geographic risk of the correspondent network
Cross-border transaction shareGeography — cross-border transfer share · Transaction — cross-border intensity

5 · Transactions

101 operational metrics in eight groups. Each metric is entered as a count, an amount, days or hours; which fields are open depends on the metric.

GroupMetricsCoverage
Transaction universe13Total and monitored transactions, cash, above/below threshold, cross-border out and in, transfers with missing information, suspended, unsupervised channel, agent, virtual asset, unhosted wallet
Sanctions screening and blocking14Customers and transactions screened, alerts, true matches, blocked and rejected transactions, released, alert closure time, list reflection time, rescreening, 50 Percent Rule detections
Trade finance17Letters of credit, documentary collections, guarantees, acceptances, goods/vessel/port/end-user screening, dual-use, high-risk corridors, price reasonableness, transit and free zones, red flags, rejected files
Correspondent banking14Active/new/closed relationships, relationships terminated by the correspondent, CBDDQ, nested detection, inbound and outbound RFIs and response times, returned transactions, payable-through accounts
Monitoring10Active and changed scenarios, alerts generated/closed, converted to cases, bulk closures, backlog, closure time, internal suspicion reports
STR, freezing, law enforcement15STR count and amount, filing time, late filings, cases without an STR, freezing decisions and amounts, law enforcement requests and response times, exits, rejected applications, tipping-off breaches
Onboarding and review11New accounts, remote accounts, failed liveness checks, EDD files, senior management approvals, undetermined beneficial ownership, risk overrides, periodic reviews, overdue KYC, adverse media
Quality assurance7Files tested, critical/major/minor errors, re-tests, training population and completions

What is derived

6 · Inherent Risk

Three blocks: the five ML/TF dimensions, the PF block and the business line matrix.

Dimension cards (25 factors)

On every factor row:

The card header carries the dimension score, its level and the scored/applicable factor count. A separate card lists the dominant risk drivers: the factors with the highest weighted contribution. When management asks “why is this high?”, that list is the answer.

The PF block

Five factors, a separate score, a separate average. It never mixes into the dimension averages; its control side is D6. The mandatory rationale applies here too.

The business line matrix

12 business lines as rows, five dimensions as columns. For each line you enter an active flag, a business share (%) and the dimension scores. The card shows the volume-weighted institutional inherent risk, the riskiest business line, the sum of the shares and the gap against the dimension average. A gap above 0.50 points raises a warning.

The method option

The same screen carries the “weight dimensions by business volume” option. It is off by default. When switched on with sufficient business line data, all dimension scores are aggregated from the business line level; the chosen method appears in the report and in the period comparison.

7 · Questionnaire

218 questions across 11 domains. The longest screen of the assessment.

The filter bar

Free-text search (across question text, evidence, source and section), domain, section, criticality, status and QA requirement. The status filter options are: unanswered, answered, gaps, open critical, no evidence reference, QA test pending, contradicted by QA. Filters are carried in the address bar and can be shared.

Selection summary

When a filter is applied, five tiles appear: number of questions selected, answered, the effectiveness of the selection, the number requiring action (including open criticals) and QA coverage (with the contradiction count).

The question card

Navigation

The list is divided by section headings; each heading shows that section's progress and stays on screen while you scroll. When the filter bar scrolls out of view, a floating “next unanswered” button appears showing how many questions remain. For keyboard shortcuts see Filling in the questionnaire.

8 · Extra Controls

Eight sets, 44 questions. The top tiles: how many sets apply, coverage, test-adjusted effectiveness and the number of open criticals. Each set has its own card, and the card header states why the set was added.

9 · QA Plan

24 populations are listed: population name and focus, domain, risk rating, sampling rule, frequency. You enter only the period volume; the annual sample and the sample per test are calculated automatically.

Four tiles at the top: number of populations and how many have volumes entered, total volume, total annual sample, total sample per test. Below, a table of error classes (Critical / High / Medium / Low) with definitions and closure times.

10 · Control Scores

A derived screen; there is no input. The columns per domain are:

The bottom row carries the institution total, and below it a reminder of the maturity bands. Clicking a domain name opens the questionnaire filtered to that domain.

11 · Residual Risk

Per domain: inherent risk, test-adjusted effectiveness (with a note if capped at 95%), residual risk, level, an appetite limit input and the status (OVER / within appetite). Rows in breach carry a “see the gaps” link that opens the filtered questionnaire directly.

Below, PF sits in its own table with its own appetite limit. Then come the residual risk bands and a methodology card explaining the method in use. If there are breaches, a red strip appears at the top; if the overall figure hides a breach, an amber strip appears as well.

12 · Action Plan

Finding → root cause → action → owner → due date → verification.

The top tiles

Total findings, open, overdue, findings with missing fields and the closure rate (risk acceptance excluded). Findings closed by risk acceptance, if any, are counted in a separate tile.

Filters and bulk generation

The finding form

FieldNote
IdAssigned automatically; must be unique
Domain · Question idIf a question id is entered, the question text echoes below. Ids from both the main questionnaire and the extra control sets (e.g. D6-04, EK-TF-01) are recognised.
Finding (required)What is missing, and which evidence shows it
SourceQuestionnaire question, QA test, audit report…
Root cause (required)Chosen from a list
CriticalityDetermines the due date
ActionWhat will be done
Owner (required)A person or a unit
Due date (required)Suggested from the criticality
StatusOpen / In progress / Closed etc. “Risk accepted” requires an approval reference and cannot be chosen for a critical finding
VerificationHow the closure will be tested
Closure date · Residual risk after closureDate required once closed or accepted; not allowed on an open finding, cannot be in the future

Before saving, the form checks the required fields, and rows with missing fields are flagged in the list. Adding, editing and deleting findings are written to the change log.

13 · Period Comparison

The previous period's working file (JSON) is loaded and kept as a summary. Six tiles read the two periods side by side: test-adjusted effectiveness, inherent risk, residual risk, appetite breaches, open criticals and assurance coverage — each with the delta and a direction arrow.

14 · Team and Merge

The application has no server; parallel work runs through files.

15 · Change Log

Append-only; never edited. The events recorded are: questionnaire answers (extra controls included), inherent risk and PF scores, the scoring method choice, adding/editing/deleting findings (bulk-generated findings included), merges and file loads. Each row carries the date and time, who, what, which record, the old value and the new value.

16 · Executive Report

A printable single-flow page. The sections in order:

  1. Institution and period details, the assessor
  2. Portfolio and exposure summary
  3. Inherent risk profile (dimensions, PF)
  4. The risk model and method used
  5. Domain results: effectiveness, assurance, maturity, residual risk
  6. Appetite breaches
  7. Open critical controls
  8. Action plan summary; any findings closed by risk acceptance (with approval reference)
  9. Extra control sets (separate table)
  10. Prepared by / reviewed by / approved by signature block
  11. At the bottom, the reference data pack version and any stale sections

Use the print button in the top bar to send it to paper or PDF. The names in the signature block come from the Profile; if empty they are left blank for handwriting.

17 · Settings

Country risk settings and the reference data pack details live here.


Filling in the questionnaire

218 questions do not have to be clicked one by one.

What the four answers mean

AnswerWhenCommon mistake
YesThe control is defined, applied, and you can show the evidenceAnswering “Yes” because it is written in the procedure. Being documented is not the same as being applied.
PartialPresent but incomplete: narrow coverage, irregular, or undocumentedAnswering “Yes” because it is “almost complete”. Partial is the honest answer and it produces an action.
NoThe control does not exist or does not workLeaving it blank out of embarrassment. A blank question does not lower the score, but it shows as incomplete in an examination.
Not applicableThe activity the control addresses does not exist at the institution at allUsing N/A to skip a hard question. N/A is a scope declaration and it appears in the report.

Keyboard shortcuts

While the questionnaire screen is open and focus is outside a text field:

KeyAction
1 2 3 4Yes / Partial / No / Not applicable
J / KNext / previous question
NNext unanswered question
EJump to the evidence reference field
EscLeave the text field
?Open the shortcut list

The active question is the card at the top of the screen, marked with a thin border. The “Last question” button on the dashboard returns you to the question you worked on most recently.

An efficient order

  1. Use the domain filter to focus on one domain; finish one domain per sitting.
  2. Filter to critical questions first and answer those — open criticals are the backbone of the action plan.
  3. Then come back with the “no evidence reference” filter and complete the references.
  4. Once the QA tests are done, enter the results using the “QA test pending” filter.
  5. Finally, empty the “contradicted by QA” filter: every contradiction is closed either by correcting the declaration or by repeating the test.

Working as a team

Nobody works in the same file at the same time; you work in parallel and merge.

  1. Assign. Name an owner for each domain on the Team and Merge screen. Have one person fill in the Profile, the Portfolio and the Inherent Risk.
  2. Distribute. Download the JSON of that first file and send it to everyone. Each person loads it in their own browser and fills in only their domain.
  3. Collect. When finished, everyone sends their JSON to the merger.
  4. Merge. The merger loads the files one by one, chooses “mine / theirs” per part, reviews every conflict, and applies. An automatic backup is taken before each merge.
  5. Verify. After merging, check on the Control Scores screen that the answer counts have reached the expected total; the merge appears in the Change Log.
Avoid version confusion

Put the date and the owner's name in file names. Keep the merge direction one-way: everyone sends to the merger, and the merger sends back to no one — they only publish the merged file.


Period-end checklist

Before sending the report for signature.


The next period

Do not start from scratch.

  1. Open the new period with this period's JSON: answers, evidence references and settings stay in place.
  2. Load the same file as the baseline on the Period Comparison screen — that fixes the “before” picture.
  3. Update the period dates, the figures and the audit dates in the Profile.
  4. Close the findings that have been remediated; record the closure date and the residual risk after closure. Those left open show as “still open” in the comparison.
  5. Clear the QA results and enter this period's tests — last period's test is not this period's assurance.
  6. Review the inherent risk scores: if the portfolio has changed, so have the suggestions.
  7. Do not change the method option; if you must, write in the report that the comparison is limited.

When something goes wrong

“My work has disappeared”

First make sure you are in the same browser and the same profile; data is tied to the profile. Then check the automatic backups list in the Data and backup dialog: the last five versions sit there with their dates and any of them can be restored. If you have a JSON, open it with Load working file.

A “save failed” warning keeps appearing

The browser storage is full. Download the JSON straight away. Then clear unnecessary site data in that browser, or continue in another profile and load the file there.

The file will not load

The file must be a JSON produced by this application. In hand-edited files, unrecognised answer values count as unanswered; the score is not silently corrupted, but the record does not appear either. An unrecognised QA result counts as not tested. Out-of-range values — scores outside 1–5, factor weights outside 0–10, business line shares outside 0–100, appetite limits outside 0–5 — are not used; they are shown with an “invalid value” strip on the dashboard and the Inherent Risk screen and a marker on the row concerned. Fields of the wrong type (text instead of a list, say) are corrected on load, and an unreadable reference-period summary is dropped. A corrupt file does not crash the application — it produces a warning.

The scores are not what I expected

I want a larger display

The browser zoom (Ctrl/⌘ and +) scales everything together without breaking the layout. The dark theme is on the button in the top bar.


Appendices and tables

Domains and question distribution

CodeDomainQuestions
D1Governance and Compliance Programme20
D2Customer Profile and Geographic Risk20
D3Product and Channel Risk18
D4Transaction Universe and Data Integrity18
D5Customer Lifecycle (CDD/EDD)26
D6Financial Sanctions and Screening26
D7AML Transaction Monitoring24
D8STR, Freezing and Customer Exit22
D9Regulatory Events and Law Enforcement Requests14
D10Training, Awareness and Management Feedback14
D11Enterprise-Wide Risk Assessment (EWRA)16
Total218 (115 QA-tested, 40 critical)

QA populations and sampling rules

PopulationDomainRuleFrequency
STRs filedD8Full coverageQuarterly
Closed cases above the threshold with no STR filedD815% · minimum 25Quarterly
Freezing and asset restriction decisionsD8Full coverageQuarterly
Sanctions true match casesD6Full coverageQuarterly
Closed sanctions alertsD610% · minimum 30Quarterly
PEP customer filesD5Full coverageSemi-annual
Customer exit decisionsD8Full coverageSemi-annual
Law enforcement and judicial information requestsD9Full coverageQuarterly
EDD filesD510% · minimum 25Quarterly
Closed monitoring alertsD75% · minimum 30Quarterly
High-risk new customer account openingsD510% · minimum 25Quarterly
Correspondent banking relationshipsD2Full coverageAnnual
Trade finance filesD610% · minimum 20Semi-annual
Customers with an overridden risk scoreD515% · minimum 20Semi-annual
Overdue periodic KYC filesD510% · minimum 20Quarterly
Remotely opened accountsD35% · minimum 25Semi-annual
Wire transfers with missing informationD410% · minimum 20Quarterly
Virtual asset transfersD310% · minimum 20Quarterly
Standard new customer account openingsD52% · minimum 30Semi-annual
Cash transactions above the thresholdD32% · minimum 25Semi-annual
Rejected customer applicationsD810% · minimum 15Annual
Training completion recordsD105% · minimum 15Annual
Closed audit and validation findingsD9Full coverageSemi-annual
Data reconciliation and feed error recordsD410% · minimum 20Quarterly

Export options

ExportContents
JSONThe complete working file; restorable, mergeable, usable as a comparison baseline
CSV · Questions218 questions plus the extra set questions: answer, evidence, note, QA result, weight, criticality
CSV · Domain scoresEffectiveness, test-adjusted effectiveness, assurance, maturity, residual risk
CSV · PortfolioCustomer distribution, segments, countries, units
CSV · Operations101 metrics and 16 derived ratios
CSV · CountriesCountry risk flags and institution decisions
CSV · Inherent riskFactor scores, weights (with defaults), rationales
CSV · QA planPopulation, volume, sample, sample per test
CSV · Action planFindings and all their fields
CSV · Change logThe audit trail
Print / PDFThe executive report

CSV files are produced with a BOM and in the Excel format of the interface language: a semicolon separator and comma decimals in Turkish, a comma separator and dot decimals in English. Columns and numbers therefore split correctly in both locales. Free-text cells are never run as formulas.

Scope in numbers

Screens17
Questionnaire questions218 (11 domains) + 44 extra control questions (8 sets)
Questions requiring a QA test115
Critical questions40
Inherent risk factors25 (5 dimensions) + 5 PF factors
Business lines12 × 5 dimensions
Profile fields26 (5 mandatory, 6 groups)
Operational metrics101 (8 groups) · 16 derived ratios
Portfolio7 customer types × 4 risk bands · 12 segments · 7 unit types
Countries211 defined · 137 pre-flagged · 6 risk flags
QA populations24
KPIs15 (3 fully automatic, 12 from the Transactions screen)
Glossary26 terms (on the How to Read screen)

This guide describes version 2.10.7 of the application and reference data pack 2026.1. The formulas in the methodology section match the scoring engine exactly. Regulatory citations are indicative and must be verified against the legislation in force. The tool supports detection, prioritisation and remediation tracking; it does not replace an independent audit.