Skip to content

Practice area 04 · AML & Financial Crime Compliance

Independent AML/CFT Audit

An independent view of whether your AML/CFT framework works as documented — tested on real files and transactions, with findings you can act on and evidence that regulators and banks recognise.

Typical deliverables

  • Audit plan and agreed scope
  • Summary of testing and sample results
  • Audit report with rated findings
  • Prioritised remediation plan
  • Board presentation of results
Discuss your matter

Overview

Why it matters

Many AML/CFT regimes expect regulated firms to have their framework tested independently, and banks, acquirers and partners increasingly ask for the latest audit report during onboarding and periodic reviews. An audit that only checks whether policies exist gives little assurance; its value lies in testing whether the controls operate as designed.

Our audits test the framework end to end — from the enterprise-wide risk assessment to customer files, monitoring alerts, sanctions screening and suspicious activity reporting — and are carried out independently of the people who designed and operate it.

Method

How the audit runs

  1. 1.

    Scoping

    The applicable requirements, previous findings, changes in the business and the risks that matter most, agreed before fieldwork starts.

  2. 2.

    Design review

    Risk assessment, policies, procedures and governance reviewed against the applicable law and supervisory guidance.

  3. 3.

    Effectiveness testing

    Sample testing of customer files, monitoring alerts, screening results, internal and external reports, and training records.

  4. 4.

    Reporting

    Findings rated by severity, with root causes identified and a prioritised remediation plan agreed with management.

  5. 5.

    Follow-up

    Where agreed, validation that remediation actions have been completed and evidenced.

Coverage

What the audit tests

  1. 1.

    Governance and the MLRO function

    Management oversight, the MLRO's role, resources and reporting, and how issues are escalated and resolved.

  2. 2.

    Risk assessment

    Whether the enterprise-wide and customer risk assessments reflect the business and drive the controls.

  3. 3.

    Customer due diligence

    Onboarding, verification, beneficial ownership, enhanced due diligence and ongoing monitoring of customers.

  4. 4.

    Monitoring and screening

    Transaction monitoring scenarios and alert handling, sanctions and PEP screening, and their calibration.

  5. 5.

    Reporting and records

    Internal suspicion reporting, external reports to the financial intelligence unit, and record-keeping.

  6. 6.

    Training and awareness

    Content, coverage and completion of training for staff, management and the board.

Considerations

Planning an audit

  • Some regimes set the frequency of the audit or the qualifications of the auditor; confirm the requirement that applies to you.
  • Banks and partners may ask for the report itself, so decide on its audience before the audit starts.
  • The audit must be independent of the framework it tests. Where we have designed or operate part of your framework, we will say so and agree how independence is preserved.
  • Findings are only useful if they feed a tracked remediation plan with owners and dates.

Jurisdictions

Supported across jurisdictions

Supported across the jurisdictions in our directory as part of our AML & Financial Crime Compliance capability, and tested against the AML/CFT requirements that apply in each. Where a regime prescribes who may carry out the audit, or its scope or frequency, we confirm that when scoping.

Questions

Frequently asked

How often should an independent AML/CFT audit be carried out?

It depends on the rules that apply to you and on your risk profile. Some regimes set a frequency or expect an audit after significant change, and banks and payment partners may set their own expectations. We confirm the applicable requirement when scoping the audit.

Will the report be accepted by our regulator or bank?

The report is prepared to the standard supervisors and banks expect: a clear scope, methodology, sample sizes and rated findings. Where a regulator prescribes a format or qualifications for the auditor, we confirm that at scoping.

Discuss your matter with a senior advisor.

Share a few details about your business and plans. We will come back to arrange a confidential initial conversation.