Our Services
M&M Consulting provides comprehensive risk management services for financial institutions. Our subject matter experts and robust audit programs go far beyond a “check the box” review, and all at very competitive rates.
Internal Audit
Ensuring Effective Internal Controls And Preparation For The Unexpected
Proper financial controls are at the heart of every great financial institution. M&M Consulting has been performing audits of community financial institutions since 1996. Our team is experienced; most of our staff members have worked for institutions as well as for third party auditors, so we know how to give practical advice that can be implemented quickly and efficiently.
M&M has helped financial institutions maintain proper checks and balances since 1996 with a team of auditors trained in adding value to the client’s operations. We are independent auditors, but we are also strategic partners that help build strong foundations for healthy institutions. We care deeply about striking the right balance between efficient operations and sound financial controls.
Outsourcing Program
M&M offers financial institutions a complete internal outsourcing model that includes the following elements:
Audit Plan Development
Scheduling
Planning Individual Audits
Performing Individual Audits
Internal Quality Control Review
Report Issuance
Audit Committee Presentation
Coordination with External Auditors
Co-Sourcing
M&M offers a co-sourcing approach that provides financial institutions with experienced internal auditors focusing their experience on critical risk areas within a financial institution. A partial list of our offerings appears below:
Information Technology Audits
Our information technology audit process follows the guidelines issued by the Federal Financial Institutions Examination Council (FFIEC) in the FFIEC Information Technology Examination Handbook for the areas of planned coverage. Each phase would be completed by one or more of M&M’s certified information systems auditors (CISAs). Our IT auditors average approximately 15 years of relevant information technology management and/or IT audit experience. M&M typically prepares an IT audit risk assessment with management’s participation as part of our planning of every IT audit. This ensures that the most significant risks are covered. Certain topics may be reviewed annually while others may only be reviewed every second or third year.
Information Security including GLBA
Wealth Management Audits
Asset and Liability Management (ALM) Audits
Allowance for Loan and Lease Losses (ALLL) / Allowance for Credit Losses (ACL)
Automated Clearing House (ACH) Processing
Wire Transfers
Loan Origination Audits
Operational Audits
Accounting Audits
Consulting and Ancillary Services
M&M offers financial institutions experienced senior consultants that can assist management in several critical risk areas . Depending on the engagement we may not be able to offer all services to all audit clients due to independence concerns. A partial list of our offerings appears below:
FDICIA/SOX/COSO 2013 Compliance
Ancillary Services
M&M Consulting's Secure Portals
Commercial Loan Review
Building A Foundation Of Safety And Stability To Grow Revenues And Relationships
All good loan review consultants ensure that the institution’s risk ratings are solid, but not all firms go the extra mile.
M&M’s approach to loan review covers the highest level of governance regarding policy, trend analysis and migration analysis. We provide detailed reviews of every loan type, every lending officer, and every member of the support team. Our goal is to catch a weakness at an early stage before it becomes a systemic problem for the institution. Our team works with speed and accuracy and is given high marks from our clients for clear and consistent communication. Let us show you how we help credit professionals and boards of directors achieve peace of mind with the following added benefits:
Policy and Procedure Review
Fair Lending Review
Portfolio Stress Testing
Government Guarantee Review
Quality Assurance
Special Projects
Complete coverage of loan types, teams, and administration staff
Migration Analysis
Validation of Allowance for Loan and Lease Losses
CECL Advisory Services
Due Diligence Acquisition Review
Proprietary Software to Ensure Consistency and Thoroughness
M&M Consulting’s Secure Portals
Compliance Auditing & Monitoring
A Team Of Experts In All Areas Of Regulatory Compliance
Regulatory compliance for financial institutions is continuously evolving and increasing in complexity. Our Compliance Division encompasses a team of industry experts with high level knowledge and experience in regulatory compliance. We take a risk-based approach tailored specifically to the financial institution; we never look for a “one size fits all” solution. Our goal is to develop the right program for your financial institution so that safety and efficiency go hand in hand.
Our Regulatory Compliance Services Include:
Bank Secrecy Act/Anti-Money Laundering (BSA/AML) Audits
Anti-Money Laundering Software Validations
Loan-Related Audits
Fair Lending Reviews
Fair Lending receives heightened scrutiny by regulators these days; let M&M help your financial institution in developing effective Fair Lending reviews with comprehensive analysis of historic lending data, including originated and non-originated applications. We analyze lending within the financial institution’s designated lending area and identify potential weaknesses. We have also assisted many financial institutions in the development of a Fair Lending risk assessment.
Commercial Lending-Related Audits
Community Reinvestment Act (CRA) Performance Reviews
Compliance Training Programs
M&M provides a range of compliance training programs designed specifically for financial institutions. Our courses are tailored to meet the needs of both employees and board members, ensuring that all levels of your organization remain informed and compliant.
- General Compliance Training: Broad coverage of essential regulatory requirements to build a strong foundation of knowledge across your team.
- Procedure‑Specific Training: Customized sessions focused on your institution’s internal processes, helping staff apply compliance standards directly to daily operations.
Whether you need high‑level guidance for leadership or detailed instruction for frontline employees, M&M’s training solutions support regulatory adherence, risk management, and operational efficiency.
Cannabis-Related Business Program Reviews
Cannabis-related business banking receives heightened attention from regulators, and institutions must be prepared to demonstrate compliance. Having seen regulatory feedback first-hand, we are available to review your program to ensure it meets regulatory expectations and requirements. In addition, we can validate your automated cannabis-related business software to confirm that it is functioning as intended and supporting compliance objectives.
Deposit-Related Audits
Other Compliance-Related Audits
M&M Consulting’s Secure Portals
“M&M Has Always Aspired To Help Our Clients Succeed On The Regulatory Battlefield.”
To That End M&M Provides The Following Ancillary Services To Our Clients:
Answer Person
Answers to your compliance questions are available at the click of a button at any time during the business day from the M&M Answer Person.
Practical Compliance Newsletter/Calendar
We provide a comprehensive newsletter addressing recent and pending regulatory changes, compliance hot topics, and common Answer Person Q&As every other month. In the other months, we deliver a Compliance Calendar that provides upcoming important dates to be aware of in the regulatory world.
Compliance and Risk Conference
An annual school covering various topics intended for both senior and junior compliance staff, bank management, and boards of directors is offered to our clients. The school provides continuing education credits for CRCM/CAFP certification holders.
Compliance Program Development
M&M Consulting delivers a team of independent experts to deal with all of your regulatory challenges by providing comprehensive assistance in developing a more effective compliance program including, but not limited to:
- In depth independent reviews
- Risk assessments
- Policy & procedure development
- Training
- Open issue tracking programs
- In house monitoring programs
- Board/audit committee reporting guidance
- Form/disclosure review and development

Listen to our Podcast