Jul 17
/
Evdokia Pitsillidou
Compliance Monitoring Program and Assessment in 2026
about the author
Evdokia, a partner at SALVUS Funds, is actively advising and working on all matters related to licensing, regulatory compliance, and internal audit for investment firms, funds, Electronic Money Institutions (EMI) & Crypto-Asset Services Providers (CASP).
- Member of the Global Institute of Internal Auditors (IIA)
- Member of the Cyprus Investment Funds Association (CIFA)
- Certified Actuarial Analyst (CAA)
- CySEC Advanced Certified Person
- CySEC certified Anti-Money Laundering Compliance Officer (AMLCO)
As regulatory expectations continue to evolve, compliance is no longer a once-a-year exercise. For regulated firms, effective compliance monitoring is a practical necessity. It helps firms identify weaknesses early, manage regulatory risk, evidence oversight, and demonstrate that policies and procedures are not only documented but applied in practice.
A well-designed Compliance Monitoring Program supports the Compliance Function in moving beyond checklists. It creates a structured, risk-based approach to reviewing the firm’s activities, assessing whether controls remain effective, and ensuring that findings are properly reported, followed up, and remediated.
In this blog, Evdokia Pitsillidou, Global Chief Risk & Compliance Officer and Partner at SALVUS Funds, introduces the key themes covered in the online course “Compliance Monitoring Program and Assessment in 2026”, now available through the Institute for Professional Excellence platform.
Advance your compliance expertise by enrolling in the course and mastering key monitoring and assessment practices.
The importance of a Compliance Monitoring Program
A Compliance Monitoring Program helps assess whether the firm operates in line with its legal and regulatory obligations, and whether its policies, procedures, systems, controls, governance arrangements, and resources remain effective.
In practice, the program should reflect the firm’s:
It should also be driven by the Compliance Risk Assessment, so that higher-risk areas are prioritised and compliance resources are used effectively.
Monitoring may include:
The key is to evidence what was reviewed, why, how, what was found, and what action followed.
Compliance Risk Assessment and its connection to monitoring
A Compliance Risk Assessment is the foundation of an effective Compliance Monitoring Program. It helps define where the Compliance Function should focus, how often reviews should take place, and which areas require closer monitoring.
The assessment should consider the firm’s regulatory obligations, policies and procedures, systems and controls, previous monitoring results, and internal or external audit findings. It should also be reviewed regularly and updated when changes arise, such as new business areas, products, IT systems, organisational changes, or regulatory developments.
In the course, participants learn how the Compliance Risk Assessment shapes the Compliance Monitoring Program in practice, from identifying and rating risks to documenting findings and turning them into clear inspection priorities.
What is the “Compliance Monitoring Program and Assessment in 2026” course and what does it include?
Developed and delivered by Evdokia Pitsillidou, Global Chief Risk & Compliance Officer and Partner at SALVUS Funds, this course is designed for professionals who are directly or indirectly involved in compliance oversight within regulated firms.
It is particularly relevant for Compliance Officers and Assistant Compliance Officers in Cyprus Investment Firms and Crypto-Asset Service Providers, Executive Directors and Board members responsible for compliance oversight, Internal Auditors, Risk Managers, legal and regulatory professionals, and professionals seeking to enhance their practical compliance skills or obtain CySEC CPD hours.
By completing the course, participants will be able to explain the purpose of a Compliance Monitoring Program under MiFID II and CySEC requirements, identify key regulatory sources including ESMA Guidelines and CySEC Circulars, design an annual Compliance Monitoring Program aligned with the firm’s risk profile, apply good practices to detect and remediate compliance weaknesses, and use practical tools to support implementation.
The syllabus of the course is as follows:
- Purpose & Objectives of the Compliance Risk Assessment (CRA)
- How the Compliance Risk Assessment (CRA) affects the Compliance Monitoring Program (CMP)?
- Responsibilities- Effectiveness, permanence & independence
- Organizational requirements
- Monitoring obligations Compliance Function
– Q&As
- Compliance Function responsibilities
- Compliance Function organisational requirements
- Competent authority review of the compliance function
- Compliance Monitoring Program
- Aim & Characteristics
- Type and frequency of monitoring activities
- Tools and methodologies
- Compliance reports
A well-designed Compliance Monitoring Program supports the Compliance Function in moving beyond checklists. It creates a structured, risk-based approach to reviewing the firm’s activities, assessing whether controls remain effective, and ensuring that findings are properly reported, followed up, and remediated.
In this blog, Evdokia Pitsillidou, Global Chief Risk & Compliance Officer and Partner at SALVUS Funds, introduces the key themes covered in the online course “Compliance Monitoring Program and Assessment in 2026”, now available through the Institute for Professional Excellence platform.
Advance your compliance expertise by enrolling in the course and mastering key monitoring and assessment practices.
The importance of a Compliance Monitoring Program
A Compliance Monitoring Program helps assess whether the firm operates in line with its legal and regulatory obligations, and whether its policies, procedures, systems, controls, governance arrangements, and resources remain effective.
In practice, the program should reflect the firm’s:
- business model
- investment and ancillary services
- financial instruments
- client categories
- distribution channels
- cross-border activities
It should also be driven by the Compliance Risk Assessment, so that higher-risk areas are prioritised and compliance resources are used effectively.
Monitoring may include:
- desk-based reviews
- onsite inspections
- recurring or ad-hoc reviews
- continuous monitoring
- trade surveillance
- staff interviews
- issues logs and remedial action reviews
The key is to evidence what was reviewed, why, how, what was found, and what action followed.
Compliance Risk Assessment and its connection to monitoring
A Compliance Risk Assessment is the foundation of an effective Compliance Monitoring Program. It helps define where the Compliance Function should focus, how often reviews should take place, and which areas require closer monitoring.
The assessment should consider the firm’s regulatory obligations, policies and procedures, systems and controls, previous monitoring results, and internal or external audit findings. It should also be reviewed regularly and updated when changes arise, such as new business areas, products, IT systems, organisational changes, or regulatory developments.
In the course, participants learn how the Compliance Risk Assessment shapes the Compliance Monitoring Program in practice, from identifying and rating risks to documenting findings and turning them into clear inspection priorities.
What is the “Compliance Monitoring Program and Assessment in 2026” course and what does it include?
Developed and delivered by Evdokia Pitsillidou, Global Chief Risk & Compliance Officer and Partner at SALVUS Funds, this course is designed for professionals who are directly or indirectly involved in compliance oversight within regulated firms.
It is particularly relevant for Compliance Officers and Assistant Compliance Officers in Cyprus Investment Firms and Crypto-Asset Service Providers, Executive Directors and Board members responsible for compliance oversight, Internal Auditors, Risk Managers, legal and regulatory professionals, and professionals seeking to enhance their practical compliance skills or obtain CySEC CPD hours.
By completing the course, participants will be able to explain the purpose of a Compliance Monitoring Program under MiFID II and CySEC requirements, identify key regulatory sources including ESMA Guidelines and CySEC Circulars, design an annual Compliance Monitoring Program aligned with the firm’s risk profile, apply good practices to detect and remediate compliance weaknesses, and use practical tools to support implementation.
The syllabus of the course is as follows:
- Compliance Risk Assessment (CRA)
- Purpose & Objectives of the Compliance Risk Assessment (CRA)
- How the Compliance Risk Assessment (CRA) affects the Compliance Monitoring Program (CMP)?
- Compliance Function
- Responsibilities- Effectiveness, permanence & independence
- Organizational requirements
- Monitoring obligations Compliance Function
– Q&As
- CySEC Circular C553 – Guidelines on certain aspects of the compliance function requirements
- Compliance Function responsibilities
- Compliance Function organisational requirements
- Competent authority review of the compliance function
- Compliance Monitoring Program features
- Compliance Monitoring Program
- Aim & Characteristics
- Type and frequency of monitoring activities
- Tools and methodologies
- Compliance reports
- Inspection areas & Compliance tips
- Policies & Procedures
- Organizational requirements – Inspection areas & - Methodology
- Operating conditions – Inspection areas & Methodology
- Client accounts: opening & closing
- Back Office Department
- AML Department
- Accounting & Finance
- Provision of Services
- Business Development & Marketing
- Customer Support
- Information Technology
- Common deficiencies
- Good practices
The course is delivered through online video recordings and downloadable PDF study material, allowing professionals to learn whenever and wherever it suits them best. Participants can progress at their own pace, revisit topics as needed, and reinforce their knowledge through accessible and structured learning resources.
Upon successful completion, participants receive a certificate awarding 5 CPD hours, recognised by CySEC, the Central Bank of Cyprus, and other professional supervisory bodies. The course contributes towards the annual CPD requirements of CySEC Advanced and Basic Certification holders, as well as professionals registered with ICPAC and the Cyprus Bar Association.
- Organizational requirements – Inspection areas & - Methodology
- Operating conditions – Inspection areas & Methodology
- Client accounts: opening & closing
- Departmental inspection areas & Compliance tips
- Back Office Department
- AML Department
- Accounting & Finance
- Provision of Services
- Business Development & Marketing
- Customer Support
- Information Technology
- CySEC Desk-based Reviews – Circular C441
- Common deficiencies
- Good practices
The course is delivered through online video recordings and downloadable PDF study material, allowing professionals to learn whenever and wherever it suits them best. Participants can progress at their own pace, revisit topics as needed, and reinforce their knowledge through accessible and structured learning resources.
Upon successful completion, participants receive a certificate awarding 5 CPD hours, recognised by CySEC, the Central Bank of Cyprus, and other professional supervisory bodies. The course contributes towards the annual CPD requirements of CySEC Advanced and Basic Certification holders, as well as professionals registered with ICPAC and the Cyprus Bar Association.
Get in touch
If you have any questions about Evdokia's course or any other questions related to your training requirements, please contact us; we would love to help.
If you have any questions about Evdokia's course or any other questions related to your training requirements, please contact us; we would love to help.
From all of us at IforPE, the Institute for Professional Excellence,
Ancora Imparo
Ancora Imparo
#1 for CySEC, CBC, ICPAC & CBA CPD education
The Institute for Professional Excellence (IforPE)
Copyright © 2019-2026
The Institute for Professional Excellence (IforPE)
Copyright © 2019-2026
navigate
The Institute for Professional Excellence is protected under a registered European trade mark. The figurative trade mark registration number is 018854840. This trade mark is protected under the European Union's legislation.
