About ARCAD

Luxembourg expertise in the fields of audit, compliance and governance.

ARCAD supports organisations in structuring, assessing and strengthening their audit, control, compliance and governance frameworks.

Our approach is based on experience, independence, the seniority of our personnel, the documentation of our work, and our ability to formulate concrete recommendations that can be followed and acted upon by management.
In brief
  • 01
    Luxembourg A local presence within regulated environments
  • 02
    Since 2007 An experience built over time
  • 03
    Audit and compliance Targeted, structured, and documented interventions
  • 04
    Governance Support for decision-making and action monitoring
Local experience A presence in Luxembourg and knowledge of regulated environments.
Independence An external, structured and useful perspective for governance bodies.
Method Work that is framed, documented, and actionable over time.
Pragmatism Recommendations relating to relevant processes and operational priorities.
Who is ARCAD

A Luxembourg-based firm specialising in audit, control, and governance.

ARCAD provides assistance to organisations that need to structure, evaluate or strengthen their internal audit, control, regulatory compliance, risk management and governance systems.

The firm caters in particular to financial institutions, regulated professions and organisations seeking independent expertise, a clear methodology and deliverables that can be put to immediate use.

A decision-oriented approach.

ARCAD projects are designed to help management and governing bodies understand the findings, prioritise actions and monitor the implementation of recommendations over time.

Our services

Targeted interventions around audit, compliance, and governance.

ARCAD services meet concrete needs: auditing, documenting, structuring, supporting and strengthening processes over the long term.

01

Internal audit

Full outsourcing, co-sourcing or occasional reinforcement of the internal audit function, with planning, execution, reporting and follow-up of recommendations.

02

IT Audit, DORA, ethical hacking & CAATs

IT reviews, digital operational resilience, access rights, application controls, technical tests and data-assisted analytics.

03

AML Audit

Independent reviews of AML/CFT measures, governance, risk analysis, KYC files, screening, controls, procedures and remediation.

04

ESG & Social Audit

Review of ESG governance, sustainability data, CSRD readiness, HR processes, social compliance and improvement plans.

05

RC Mandate & RC as a Service

Provision of a RC, partial outsourcing or support for the existing RC: control plan, reviews, reporting, documentation and monitoring of actions.

06

Non-Executive Director & Audit Committee

Support for governance bodies, preparation of files, critical reading of reports, follow-up of recommendations and formalisation of conclusions.

Method of working

A clear, documented and proportionate framework for intervention.

Each mission begins with a precise definition of the need, scope, stakeholders, necessary documents, work to be carried out, and expected deliverables.

The findings are qualified, the recommendations are prioritised, and actions can be tracked over time in order to improve the clarity of the system for management and governance bodies.

  • Clearly defined mission scope and objectives.
  • Documented work and centralised evidence.
  • Findings qualified according to their impact and priority.
  • Concrete and directly actionable recommendations.
  • Tracking of actions, statuses, responsible parties and deadlines.
  • Clear reporting for senior management and governing bodies.
JS
Managing Director

Joseph Stevens

Joseph Stevens has extensive experience in internal audit, risk & compliance, internal control, fund governance, financial services and regulated environments in Luxembourg and internationally.

Certifications and expertise: CISA, COBIT 5, ITIL Foundation, Train the Trainer, artificial intelligence and business strategy, internal audit, internal control, risk management, compliance, AML/CFT, governance and social audit.

CISA
COBIT 5
ITIL Foundation
Risk and Compliance
Internal control
Governance
AML/CTF
Social audit
Sectors supported

Interventions tailored for regulated environments and demanding organisations.

ARCAD primarily supports organisations facing requirements for control, documentation, compliance, reporting and governance.

PSF
AIFM / ManCos
Management companies
Payment institutions
Investment funds
SICAV
Trustees
Accountants
Family offices
Governing Bodies
Exchange

Let's discuss your audit, compliance, or governance challenges.

Do you wish to structure an audit function, assess a control system, strengthen your compliance, or professionalise your governance? ARCAD can support you with an independent, methodical, and documented approach.