Requirements · Controls · Evidence
Compliance should enable the business to operate — not remain a folder of policies.
VM.Capital helps companies identify regulatory obligations, obtain the required approvals and build proportionate internal controls for operations in Kyrgyzstan and across borders.
We translate legislation, regulator expectations and contractual requirements into responsibilities, procedures, records and management decisions that can be applied in day-to-day work and demonstrated when questioned.
The Regulatory Perimeter
First determine which rules apply — and why
Obligations depend on the activity, licence, customers, products, payment flows, counterparties, data and countries involved.
- licences, permits, registrations and notifications;
- corporate governance and responsible officers;
- customer and counterparty verification;
- anti-money laundering and financial crime controls;
- sanctions, anti-bribery and conflict-of-interest controls;
- personal data, confidentiality and information security;
- consumer, advertising and sector-specific requirements;
- records, reports and regulator communications.
How We Assist
From regulatory analysis to an operating control system
Regulatory mapping
Identify applicable laws, authorities, approvals, reporting duties and material exposure arising from the business model.
Licensing and permissions
Assess whether authorisation is required and prepare a practical route for application, notification or remediation.
Policies and procedures
Develop proportionate internal rules, responsibilities, escalation routes, control steps and supporting forms.
KYC and financial crime
Design customer and counterparty checks, risk classification, enhanced review, monitoring and record-keeping processes.
Sanctions and integrity
Establish screening, approval and escalation procedures for sanctions, bribery, gifts, conflicts and higher-risk relationships.
Inspections and enquiries
Prepare information, coordinate responses, support management and address findings or corrective measures.
Implementation
A practical path from obligations to evidence
Scope
Understand the business model, licences, jurisdictions and risk appetite.
Gap review
Compare current practice and documents with applicable requirements.
Remediation plan
Prioritise critical gaps, owners, actions, dependencies and deadlines.
Implementation
Prepare procedures, controls, forms, registers and staff guidance.
Testing and review
Check operation, evidence, exceptions and changes requiring updates.
Proportionate Compliance
Controls must reflect the actual risk and operating model
A payment business, trading company and technology service provider do not need identical procedures. We calibrate the system to the company’s regulatory status, scale, products, customers, channels and geographic exposure.
- clear allocation of board, management and employee responsibilities;
- risk-based rather than purely formal controls;
- approval and escalation thresholds;
- documented reasons for higher-risk decisions;
- records showing that procedures were actually followed;
- change management when law, products or markets evolve.
When Support Is Needed
Before launch, during growth and when scrutiny increases
Market entry
Understanding the local requirements before establishing or acquiring a business in Kyrgyzstan.
Regulated activity
Preparing a financial, payment, virtual-asset, telecom, healthcare, education or another licensed operation.
New product or channel
Testing the regulatory impact of a new service, customer group, payment route or distribution model.
Bank or investor review
Preparing evidence of governance, ownership, controls and legitimate operating processes.
Regulator enquiry
Organising a timely, accurate and coordinated response to an inspection, request or identified breach.
System improvement
Turning fragmented documents and informal practices into a coherent control framework.
Management and Training
People must understand what to do, not merely acknowledge a policy
We prepare role-specific guidance for directors, responsible officers and operational teams. Training is built around the decisions employees actually make, warning signs they may encounter and the escalation route available to them.
- management briefings on responsibility and oversight;
- onboarding for employees in controlled functions;
- practical scenarios and warning indicators;
- handling exceptions and internal reports;
- records of training and confirmation of understanding;
- targeted updates after regulatory or process changes.
Connected Advice
Regulatory requirements aligned with the transaction and operations
We coordinate compliance work with licensing, corporate structuring, contracts, due diligence, banking arrangements and closing. Where foreign law advice or specialist technical certification is required, we work with appropriately qualified advisers.
Our work is scoped to the agreed business, jurisdictions and information. Final regulatory decisions remain with the competent authority.
Initial Regulatory Review
Understand the requirements before they become a barrier to operations
Describe your activity, customers, jurisdictions, payment flows, licences and current procedures. We will identify the initial regulatory questions and propose an appropriate review or implementation stage.