Regulatory, risk and assurance work for companies that answer to a regulator.
Qantid delivers AML/CFT, licensing, cybersecurity, data protection and audit engagements to fintechs, banks, lenders, insurtechs and virtual asset service providers across Nigeria, Kenya, Ghana, South Africa and Egypt.
Prices are published. Turnaround is stated in business days. Every deliverable is approved by a named person whose credentials appear on the report, and where a signature is a regulated act, it is provided by a named accredited partner firm rather than implied.
The firm, in numbers
- Published services
- 5
- Practice areas
- 6
- Launched markets
- 4
- Class A standard turnaround
- 5 business days
- Class B standard turnaround
- 10 business days
- Revision rounds included
- Two
How engagements are delivered
Four delivery classes, each with its own turnaround and payment terms
| Class | What it covers | Standard | Express | Payment |
|---|---|---|---|---|
| A | Documentation and assessment | 5 business days | 48–72 hours, +75% | 100% in advance |
| B | Technical testing. Automated toolchain plus manual validation of every critical and high finding by a named consultant. | 10 business days | 5 business days, +60% | 100% in advance |
| C | Scoped engagements: licence applications, certifications, audits with fieldwork, look-back reviews. | Milestone-based | — | 40 / 40 / 20 |
| D | Retainers: outsourced MLRO, Data Protection Officer, virtual CISO and monitoring services. | Ongoing | — | Monthly, 12-month term |
Six practice areas
AML, CFT and Financial Crime
Policy, risk assessment, transaction monitoring, sanctions screening and independent testing, aligned to the requirements of each regulator you answer to.
3 published services
Licensing and Regulatory Affairs
Licence category advice, application dossiers, fit-and-proper filings, change-in-control approvals and regulatory returns across five markets.
0 published services
Cybersecurity and Assurance
Penetration testing, ISO 27001, SOC 2, PCI DSS and the CBN Risk-Based Cybersecurity Framework — readiness, remediation and certification support.
1 published service
Data Protection and Privacy
NDPA, POPIA, Kenya DPA and GDPR compliance: audits, data mapping, impact assessments, breach response and outsourced Data Protection Officer.
1 published service
Financial Audit and Tax
IFRS 9 modelling, capital adequacy, safeguarding reconciliation, internal audit and tax compliance for regulated balance sheets.
0 published services
Risk and Governance
Enterprise risk frameworks, board and committee governance, internal control design, model risk validation and consumer protection.
0 published services
Fixed-price engagements you can start today
All 5 services| Service | Turnaround | Price |
|---|---|---|
| AML/CFT Gap Assessment and Remediation Roadmap A measured comparison of your current programme against what your regulator expects, with a prioritised, costed plan to close the difference. | 5 business days | ₦5,600,000 |
| AML/CFT/CPF Policy and Procedures Manual A board-ready anti-money-laundering, counter-terrorist-financing and counter-proliferation-financing manual written against the regulations that apply to your licence. | 5 business days | ₦8,000,000 |
| Enterprise-Wide ML/TF/PF Risk Assessment A documented assessment of your inherent money-laundering, terrorist-financing and proliferation-financing risk, the controls against it, and the residual risk your board must accept. | 5 business days | ₦10,400,000 |
| CBN Risk-Based Cybersecurity Framework Assessment An assessment against the CBN Risk-Based Cybersecurity Framework, producing the evidence base for your annual return. | 5 business days | ₦11,200,000 |
| NDPA/NDPR Compliance Gap Assessment An assessment of your processing against the Nigeria Data Protection Act 2023, with the specific actions needed before your annual audit return. | 5 business days | ₦5,600,000 |
Prices exclude 7.5% VAT on Nigerian invoices. Nigerian clients deduct 5% withholding tax on professional services; invoices show the gross amount, VAT, the expected deduction and the net receipt.
Markets
CBN · NFIU · SCUML · SEC Nigeria · NDPC
CBK · ODPC · CMA · IRA
Bank of Ghana · Data Protection Commission · SEC Ghana
SARB · FSCA · FIC · Information Regulator · NCR
Egypt
ExpansionCBE · FRA
What you should check before engaging any firm, including this one
Ask who signs the deliverable and what they are licensed to sign. A Report on Compliance is valid only from a PCI SSC-registered Qualified Security Assessor. An ISO 27001 certificate comes from an accredited certification body, which cannot be the same party that implemented the management system. A statutory audit opinion requires a firm registered with the Financial Reporting Council.
Qantid states which of its engagements carry a partner signature on the service page itself, before you buy. Our own security and confidentiality posture, sub-processors and data residency are published on the trust page.