Qantid

Regulatory, risk and assurance work for companies that answer to a regulator.

Qantid delivers AML/CFT, licensing, cybersecurity, data protection and audit engagements to fintechs, banks, lenders, insurtechs and virtual asset service providers across Nigeria, Kenya, Ghana, South Africa and Egypt.

Prices are published. Turnaround is stated in business days. Every deliverable is approved by a named person whose credentials appear on the report, and where a signature is a regulated act, it is provided by a named accredited partner firm rather than implied.

The firm, in numbers

Published services
5
Practice areas
6
Launched markets
4
Class A standard turnaround
5 business days
Class B standard turnaround
10 business days
Revision rounds included
Two

How engagements are delivered

Four delivery classes, each with its own turnaround and payment terms

ClassWhat it coversStandardExpressPayment
ADocumentation and assessment5 business days48–72 hours, +75%100% in advance
BTechnical testing. Automated toolchain plus manual validation of every critical and high finding by a named consultant.10 business days5 business days, +60%100% in advance
CScoped engagements: licence applications, certifications, audits with fieldwork, look-back reviews.Milestone-based40 / 40 / 20
DRetainers: outsourced MLRO, Data Protection Officer, virtual CISO and monitoring services.OngoingMonthly, 12-month term

Six practice areas

AML, CFT and Financial Crime

Policy, risk assessment, transaction monitoring, sanctions screening and independent testing, aligned to the requirements of each regulator you answer to.

3 published services

Licensing and Regulatory Affairs

Licence category advice, application dossiers, fit-and-proper filings, change-in-control approvals and regulatory returns across five markets.

0 published services

Cybersecurity and Assurance

Penetration testing, ISO 27001, SOC 2, PCI DSS and the CBN Risk-Based Cybersecurity Framework — readiness, remediation and certification support.

1 published service

Data Protection and Privacy

NDPA, POPIA, Kenya DPA and GDPR compliance: audits, data mapping, impact assessments, breach response and outsourced Data Protection Officer.

1 published service

Financial Audit and Tax

IFRS 9 modelling, capital adequacy, safeguarding reconciliation, internal audit and tax compliance for regulated balance sheets.

0 published services

Risk and Governance

Enterprise risk frameworks, board and committee governance, internal control design, model risk validation and consumer protection.

0 published services

Fixed-price engagements you can start today

All 5 services
ServiceTurnaroundPrice
AML/CFT Gap Assessment and Remediation Roadmap

A measured comparison of your current programme against what your regulator expects, with a prioritised, costed plan to close the difference.

5 business days₦5,600,000
AML/CFT/CPF Policy and Procedures Manual

A board-ready anti-money-laundering, counter-terrorist-financing and counter-proliferation-financing manual written against the regulations that apply to your licence.

5 business days₦8,000,000
Enterprise-Wide ML/TF/PF Risk Assessment

A documented assessment of your inherent money-laundering, terrorist-financing and proliferation-financing risk, the controls against it, and the residual risk your board must accept.

5 business days₦10,400,000
CBN Risk-Based Cybersecurity Framework Assessment

An assessment against the CBN Risk-Based Cybersecurity Framework, producing the evidence base for your annual return.

5 business days₦11,200,000
NDPA/NDPR Compliance Gap Assessment

An assessment of your processing against the Nigeria Data Protection Act 2023, with the specific actions needed before your annual audit return.

5 business days₦5,600,000

Prices exclude 7.5% VAT on Nigerian invoices. Nigerian clients deduct 5% withholding tax on professional services; invoices show the gross amount, VAT, the expected deduction and the net receipt.

Markets

CBN · NFIU · SCUML · SEC Nigeria · NDPC

CBK · ODPC · CMA · IRA

Bank of Ghana · Data Protection Commission · SEC Ghana

SARB · FSCA · FIC · Information Regulator · NCR

Egypt

Expansion

CBE · FRA

What you should check before engaging any firm, including this one

Ask who signs the deliverable and what they are licensed to sign. A Report on Compliance is valid only from a PCI SSC-registered Qualified Security Assessor. An ISO 27001 certificate comes from an accredited certification body, which cannot be the same party that implemented the management system. A statutory audit opinion requires a firm registered with the Financial Reporting Council.

Qantid states which of its engagements carry a partner signature on the service page itself, before you buy. Our own security and confidentiality posture, sub-processors and data residency are published on the trust page.