Back to Advisory

    AML internal audit

    Independent AML internal audit — test the framework before your regulator does.

    We deliver risk-based AML internal audits that test the design and operating effectiveness of your AML/CFT and Sanctions framework — with practical, prioritised remediation your team can act on.

    Outcomes

    What you get out of this engagement.

    • Independent view of framework effectiveness for the board and regulator
    • Findings rated by severity with clear root cause
    • Practical remediation plan with owners and deadlines
    • Assurance evidence for the audit committee and regulator

    Deliverables

    • AML internal audit report
    • Findings tracker with owners and deadlines
    • Board / audit-committee presentation
    • Working papers retained for regulator inspection

    Scope

    What's included.

    Governance

    Board oversight, MLRO independence, resourcing and training.

    EWRA & policies

    Methodology, currency and alignment to legislation.

    Onboarding & CDD

    Sample-based file testing across risk segments and product lines.

    Screening & TM

    Coverage, thresholds, alert quality and disposition.

    Reporting

    SAR/STR handling, regulator reporting and record-keeping.

    Process

    How the engagement runs.

    1. 1

      Audit plan

      Risk-based scope aligned to the EWRA and prior findings.

    2. 2

      Fieldwork

      Interviews, walkthroughs, control testing and file sampling.

    3. 3

      Findings

      Rated findings with root cause and management response.

    4. 4

      Reporting

      Written audit report, tracker and board briefing.

    Frequently asked questions.

    Are you independent from our first and second line?

    Yes. As an external advisor we sit outside your first and second line, providing the independence your regulator expects for AML internal audit.

    How often should AML internal audit be performed?

    Most regulators expect at least an annual internal audit, with additional thematic reviews on high-risk areas such as Sanctions, EDD and Transaction Monitoring.

    Do you follow a specific audit methodology?

    Yes. Our audits follow a documented risk-based methodology aligned to IIA standards and adjusted to your regulator's specific expectations.

    Ready to scope this engagement?

    Share your licence, jurisdiction and current pain points. We'll come back with a fixed-scope proposal, timeline and price within two working days.