Booking options
€240
+ VAT
€240
+ VATLive Online
5 CPD Units | 5 Hours
The EIMF Live Online Learning Experience
Participants will receive access to the recorded sessions of the course.
EIMF subject-matter experts deliver engaging and interactive courses across a broad spectrum of areas, that can be enjoyed in the comfort of your own chosen environment. Read more
Course Overview
This programme is designed for Cyprus Investment Firms that want to convert Internal Audit, External Audit and CySEC inspection findings into measurable control improvements. It updates the audit lifecycle with current EU and Cyprus requirements, including MiFID II, Law 87(I)/2017 as amended, Commission Delegated Regulation (EU) 2017/565, IFD/IFR, Law 165(I)/2021, DORA, GDPR, the EU AI Act and the MiFID II/MiFIR Review. The course focuses on audit scoping, fieldwork, evidence standards, root cause analysis, action plan ownership, C-level reporting, Board challenge, and closure validation. It also explains how audit functions should test areas such as safeguarding, best execution, product governance, complaints, AML interfaces, DORA resilience, outsourcing and AI-assisted controls. Participants receive a practical methodology for building findings registers, remediation trackers and inspection-ready data rooms that demonstrate an effective three-lines-of-defence environment.
Training Objectives
By the end of the webinar, participants will be able to:
Explain the roles and boundaries of Internal Audit, External Audit, Compliance, Risk Management, Finance, Operations, C-level management and the Board.
Translate audit and inspection findings into risk-rated, time-bound and evidence-driven remediation plans.
Design an annual Internal Audit plan aligned with the firm’s risk profile, business model, regulatory obligations and CySEC supervisory priorities.
Assess audit evidence quality for safeguarding, best execution, product governance, AML interfaces, complaints, prudential reporting, DORA and outsourcing.
Use root-cause analysis to distinguish policy gaps, operating failures, data defects, ownership gaps and governance weaknesses.
Build a defensible Audit Findings Register, Remediation Tracker and Board/Committee reporting pack.
Integrate DORA, AI Act and data-governance risks into audit universe planning and assurance testing.
Prepare for CySEC onsite/offsite inspections through data-room discipline, consistent responses, interview readiness and closure evidence.
Training Outline
Governance, Audit Roles and Regulatory Expectations
Three lines of defence in Cyprus Investment Firms: business ownership, Compliance/Risk challenge and Internal Audit assurance.
MiFID II, Delegated Regulation (EU) 2017/565 and Law 87(I)/2017 organisational requirements.
IFD/IFR and Law 165(I)/2021: prudential governance, reporting and internal control implications.
Board and C-level accountability for audit findings, risk acceptance and remediation.
Internal Audit Planning and Fieldwork
Risk-based audit universe: safeguarding, best execution, product governance, complaints, AML interfaces, data quality, outsourcing and prudential reporting.
Audit scoping, sampling, walkthroughs, control design testing and operating effectiveness testing.
Evidence standards: contemporaneous records, system logs, reconciliations, approvals, MI and minutes.
How to write findings that are accurate, defensible and actionable.
External Audit, Specialist Reviews and Assurance Engagements
Interaction with statutory auditors, specialist compliance reviews and independent expert assessments.
Handling audit queries, management representations and supporting evidence.
Using external audit outputs to strengthen control design and governance rather than treating them as isolated findings.
Alignment between external audit observations, internal audit plan and Board risk appetite.
DORA, AI Act and Technology Assurance
DORA audit coverage: ICT risk management, incident response, business continuity, third-party ICT providers and resilience testing.
AI Act audit relevance: AI inventory, intended use, human oversight, data quality, explainability, logs and accountability.
Testing automated compliance tools, surveillance systems, transaction monitoring, marketing review tools and client profiling systems.
Evidence needed for outsourced systems, vendor assurances, access controls and change management.
Turning Findings into Action and CySEC Readiness
Root-cause analysis: process, people, data, systems, governance and culture.
Findings register: severity, owner, deadline, client impact, regulatory impact, interim controls and validation criteria.
Board/Committee MI: open findings, overdue actions, repeated issues, risk acceptance and closure validation.
CySEC inspection preparation: data room, interview conduct, consistent narrative, remediation evidence and follow-up.
Who Should Attend
This programme is designed for:
Chief Executive Officers, Chief Operating Officers, Chief Financial Officers, Chief Risk Officers, Chief Compliance Officers and other C-level officers of Cyprus Investment Firms.
Executive Directors and Non-Executive Directors responsible for governance, control effectiveness and remediation oversight.
Internal Auditors, Internal Audit Managers and members of Internal Audit functions within Cyprus Investment Firms.
Heads of Compliance, Compliance Officers, Risk Managers and Operational Risk Officers.
Finance Managers, Operations Managers, Back-Office Managers and officers responsible for evidence production or external-audit coordination.
Heads of Dealing, Portfolio Management, Product Governance, ICT/DORA and Client Operations where their areas are subject to audit or supervisory review.
Training Style
The seminar uses concise technical presentations, short videos, Cyprus investment-firm case studies, audit-report examples, guided root-cause analysis and remediation workshops. Participants practise converting findings into action plans, building Board MI and preparing CySEC-ready evidence files with clear ownership, deadlines and closure criteria.
CPD Recognition
This programme may be approved for up to 5 CPD units in Financial Regulation. Eligibility criteria and CPD Units are verified directly by your association, regulator or other bodies which you hold membership.
In-house Training
For groups within the same organisation, this course may be customized to meet any specific needs and delivered in-house.
Panagiotis Nikolaou
GRC Expert and Auditor
Panagiotis Nikolaou is an accomplished Governance, Risk and Compliance Lead Auditor, strategic advisor, regulatory investigator, approved internal auditor, technical expert, ISQM 1 implementation specialist, and vocational trainer with more than 15 years of experience in the international financial services sector. His professional background encompasses financial technology (FinTech), investment services, financial markets, internal audit, regulatory compliance, risk management, market surveillance, financial crime prevention, quality management, and executive leadership within regulated financial institutions and professional services firms. Since 2018, he has served, during various periods, as a selected Associate Expert in Market Surveillance and Investigations for the Cyprus Securities and Exchange Commission (CySEC) through public tenders awarded to MAP S.Platis Group. In this capacity, he has contributed to complex regulatory investigations, on-site and off-site inspections, compliance assessments, market-conduct reviews, and evaluations of business relationships involving Cyprus Investment Firms, financial institutions, Payment Institutions, Electronic Money Institutions, and other regulated or higher-risk entities. Panagiotis has developed substantial experience in the payments and electronic money sectors, advising and auditing Payment Institutions (PIs) and Electronic Money Institutions (EMIs) in relation to governance, safeguarding of client funds, AML/CTF controls, risk management, outsourcing, operational resilience, regulatory reporting, internal control arrangements, and compliance with the supervisory expectations of the Central Bank of Cyprus. He has been approved by the Central Bank of Cyprus to act as an Internal Auditor for regulated Electronic Money Institutions and Payment Institutions, demonstrating his ability to independently assess governance, regulatory compliance, safeguarding, financial crime, operational, outsourcing, information and communication technology, and risk-management frameworks within Central Bank-supervised entities. In addition, Panagiotis has served as an ISQM 1 standards implementer and advisor for various accounting and audit firms, supporting the design, documentation, implementation, and continuous improvement of their quality management systems. His work includes conducting firm-wide quality risk assessments; identifying quality objectives, risks, and appropriate responses; developing policies and procedures; defining governance and leadership responsibilities; strengthening ethical and independence controls; establishing client acceptance and continuance procedures; enhancing engagement performance and review arrangements; and developing monitoring, remediation, documentation, and annual evaluation processes. He assists accounting and audit firms in translating the principles of the International Standard on Quality Management 1 (ISQM 1) into practical, proportionate, and sustainable control frameworks suited to their size, structure, client portfolio, and regulatory obligations. His experience is further strengthened by previous appointments as Executive Director, Risk Manager, Head of Portfolio Management, broker, technical analyst, and senior dealer within the investment services industry. This combination of supervisory, investigative, audit, advisory, executive, and frontline financial-market experience enables him to assess regulated institutions and professional services firms from both regulatory and operational perspectives. His principal areas of expertise include AML/CTF and sanctions compliance, financial crime and fraud risk, MiFID II and MiFIR, payment services and electronic money regulation, product governance, suitability and appropriateness, best execution, investor protection, safeguarding of client funds and financial instruments, complaint handling, conflicts of interest, financial promotions, internal governance, regulatory remediation, outsourcing, quality management, and operational resilience. He has also developed significant expertise in emerging regulatory areas, including crypto-assets, blockchain-based financial services, virtual-asset risk management, and the Markets in Crypto-Assets Regulation (MiCA). His international advisory work has extended to regulated entities and public authorities in the European Union, Cyprus, Israel, Russia, South Africa, Singapore, Thailand, Seychelles, Vanuatu and other jurisdictions. Panagiotis has also participated as a technical expert in legal proceedings and disputes concerning the investment services sector. His work has included the independent assessment of trading practices, order execution, pricing, best-execution obligations, financial instruments, brokerage operations, liquidity-provider arrangements, transaction costs, rollover and financing charges, and the application of the relevant European and Cyprus regulatory frameworks. Through these engagements, he assists legal professionals, courts, regulated entities, and other stakeholders in understanding complex financial market practices, trading data, and regulatory requirements by presenting technically grounded findings in a clear, evidence-based manner. As a Level 5 Vocational Trainer certified by the Human Resource Development Authority of Cyprus, Panagiotis has designed and delivered specialised professional training to a broad international audience across the financial services, regulatory, law enforcement, and professional services sectors. His training experience includes programmes delivered to personnel from some of the world’s largest internationally operating investment firms, banking institutions, Payment Institutions, Electronic Money Institutions, accounting and audit firms, and other regulated financial organisations. He has also delivered specialised training to the Cyprus Police Academy, as well as to professionals and representatives from Cyprus’s supervisory authorities, regulatory institutions, and self-regulatory and professional bodies. His audiences have included regulators, investigators, compliance officers, internal auditors, risk managers, senior executives, board members, legal professionals, and other specialists responsible for governance, financial crime prevention, investor protection, and regulatory compliance. His programmes combine detailed regulatory analysis with practical case studies, investigative methodologies, risk-based assessments, control-testing procedures, and guidance on operational implementation. The subject matter covered includes AML/CTF, sanctions compliance, bribery and corruption, fraud prevention, MiFID II and MiFIR, product governance, suitability and appropriateness, best execution, safeguarding of client assets, complaints handling, vulnerable-client protection, market conduct, payment services, electronic money, crypto-assets, MiCA, internal audit, corporate governance, and operational resilience. Through these engagements, Panagiotis has developed the ability to adapt complex regulatory and technical content to audiences ranging from supervisory and law-enforcement personnel to board members, senior management, compliance professionals, and operational teams within major international financial institutions. He has also co-authored a professional guide concerning ESMA’s knowledge and competence assessment guidelines in collaboration with the European Institute of Management and Finance and the Chartered Institute for Securities & Investment. Panagiotis holds a Bachelor’s degree in Economics, an MSc in Financial Services, and an MBA, and is currently pursuing a Doctorate in Business Administration in Strategic Management at the University of Limassol. His professional qualifications include the CySEC Advanced and AML certifications, the Certified Governance, Risk and Compliance Auditor designation, ISO 31000 Risk Management Lead Auditor, ISO 9001, ISO/IEC 27001 and ISO 45001 Lead Auditor qualifications, GDPR Lead Auditor and specialised studies in criminology, forensic science, fraud investigation, and identity-theft prevention. He is also a Chartered Member of the Chartered Institute for Securities & Investment and a full member of the Society of Technical Analysts. He is also a member of academic societies such as the Academy of Management, IFERA and others. Combining regulatory insight, investigative discipline, internal audit and quality-management expertise, legal-case support, industry experience, and strategic leadership, Panagiotis assists investment firms, financial institutions, PIs, EMIs, accounting and audit firms, supervisory stakeholders, and professional advisers in strengthening governance arrangements, enhancing regulatory compliance, implementing ISQM 1 systems of quality management, safeguarding client assets, managing financial and operational risks, and establishing practical, proportionate, and sustainable control frameworks.
The invoice is issued on the day the course starts.
Payments can be made by bank transfer, cheque, or credit card.
Certificates are issued within 7–10 days after the course has been completed, provided that the invoice has been paid.
Once your certificate has been issued, you will receive an automated email from Cademy notifying you that it is available.
Click the Get Your Certificate button in the email to download your certificate.
You can also access it from your Cademy account:
To access the course materials, such as presentations and recordings: