Practice area 04 · AML & Financial Crime Compliance
Independent AML/CFT Audit
An independent view of whether your AML/CFT framework works as documented — tested on real files and transactions, with findings you can act on and evidence that regulators and banks recognise.
Typical deliverables
- Audit plan and agreed scope
- Summary of testing and sample results
- Audit report with rated findings
- Prioritised remediation plan
- Board presentation of results
Overview
Why it matters
Many AML/CFT regimes expect regulated firms to have their framework tested independently, and banks, acquirers and partners increasingly ask for the latest audit report during onboarding and periodic reviews. An audit that only checks whether policies exist gives little assurance; its value lies in testing whether the controls operate as designed.
Our audits test the framework end to end — from the enterprise-wide risk assessment to customer files, monitoring alerts, sanctions screening and suspicious activity reporting — and are carried out independently of the people who designed and operate it.
Method
How the audit runs
- 1.
Scoping
The applicable requirements, previous findings, changes in the business and the risks that matter most, agreed before fieldwork starts.
- 2.
Design review
Risk assessment, policies, procedures and governance reviewed against the applicable law and supervisory guidance.
- 3.
Effectiveness testing
Sample testing of customer files, monitoring alerts, screening results, internal and external reports, and training records.
- 4.
Reporting
Findings rated by severity, with root causes identified and a prioritised remediation plan agreed with management.
- 5.
Follow-up
Where agreed, validation that remediation actions have been completed and evidenced.
Coverage
What the audit tests
- 1.
Governance and the MLRO function
Management oversight, the MLRO's role, resources and reporting, and how issues are escalated and resolved.
- 2.
Risk assessment
Whether the enterprise-wide and customer risk assessments reflect the business and drive the controls.
- 3.
Customer due diligence
Onboarding, verification, beneficial ownership, enhanced due diligence and ongoing monitoring of customers.
- 4.
Monitoring and screening
Transaction monitoring scenarios and alert handling, sanctions and PEP screening, and their calibration.
- 5.
Reporting and records
Internal suspicion reporting, external reports to the financial intelligence unit, and record-keeping.
- 6.
Training and awareness
Content, coverage and completion of training for staff, management and the board.
Considerations
Planning an audit
- Some regimes set the frequency of the audit or the qualifications of the auditor; confirm the requirement that applies to you.
- Banks and partners may ask for the report itself, so decide on its audience before the audit starts.
- The audit must be independent of the framework it tests. Where we have designed or operate part of your framework, we will say so and agree how independence is preserved.
- Findings are only useful if they feed a tracked remediation plan with owners and dates.
Jurisdictions
Supported across jurisdictions
Supported across the jurisdictions in our directory as part of our AML & Financial Crime Compliance capability, and tested against the AML/CFT requirements that apply in each. Where a regime prescribes who may carry out the audit, or its scope or frequency, we confirm that when scoping.
- Europe18
- Asia & Middle East4
- Americas & Caribbean11
- Africa & Indian Ocean6
Industries
Where we apply it
- 01iGaming & GamingB2C operators, B2B suppliers, platforms, aggregators and affiliates.
- 02Fintech & PaymentsPayment and e-money institutions, PSPs and acquirers, payment facilitators and embedded finance.
- 03Crypto & Digital AssetsCASPs and VASPs, exchanges, custodians, wallets, token projects and crypto payments.
- 04Forex & InvestmentsForex and CFD brokers, investment firms, trading and investment platforms.
- 05Digital Platforms & MarketplacesOnline marketplaces, platform operators and intermediary business models.
- 07High-Risk & Regulated Digital BusinessesBusiness models that banks, payment providers and regulators treat with enhanced scrutiny.
Questions
Frequently asked
How often should an independent AML/CFT audit be carried out?
It depends on the rules that apply to you and on your risk profile. Some regimes set a frequency or expect an audit after significant change, and banks and payment partners may set their own expectations. We confirm the applicable requirement when scoping the audit.
Will the report be accepted by our regulator or bank?
The report is prepared to the standard supervisors and banks expect: a clear scope, methodology, sample sizes and rated findings. Where a regulator prescribes a format or qualifications for the auditor, we confirm that at scoping.
Related
Part of AML & Financial Crime Compliance
Discuss your matter with a senior advisor.
Share a few details about your business and plans. We will come back to arrange a confidential initial conversation.
