AML audit FAQs
Answers to the questions we hear most about independent AML audits under CIMA's AML Rule, based on the Rule and CIMA's published FAQs.
Independent AML audits: questions and answers
Is the independent AML audit a new requirement?
No. CIMA says the requirement to carry out effective, risk-based AML audits already exists under the Anti-Money Laundering Regulations. Rule 12 of the new AML Rule adds clarity on what CIMA expects and how effectiveness should be demonstrated (CIMA FAQ 32).
Do we need an audit now that the AML Rule is in force?
Not simply because the Rule took effect on 18 September 2026. CIMA says your risk assessment should drive when audits happen, how often, and what they cover. CIMA can still require an audit, for example after an inspection (CIMA FAQ 34).
How often should an AML audit be carried out?
There is no fixed frequency. You decide and document it based on your risk profile (AML Rule 12.2(a)). CIMA gives examples: roughly every two years for higher-risk entities, every three for medium and every four for low risk. Annual audits are not mandated (CIMA FAQs 35 and 38).
Who can perform an AML audit?
CIMA lists internal audit functions, external auditors, independent consultants, or other suitably qualified and competent independent parties. Whoever does it must be independent of the AML/CFT/CPF/TFS function and must not be involved in operating, managing or overseeing the programme (AML Rule 12.2(b); CIMA FAQs 40–41).
Can our AMLCO, MLRO or DMLRO carry out the audit?
No. CIMA says the AML officers form part of the compliance programme and cannot independently audit activities they are responsible for, whether they are employees or outsourced (CIMA FAQ 39).
How many internal audits can we do in a row?
An internal audit can be used for no more than two consecutive audit cycles. The next audit must be carried out by an external service provider (AML Rule 12.3; CIMA FAQ 47).
What does an AML audit cover?
The scope must be proportionate. CIMA lists governance and oversight; AMLCO, MLRO and DMLRO effectiveness; the enterprise-wide risk assessment and risk-based approach; customer risk methodology; CDD and EDD; sanctions screening; transaction and ongoing monitoring; SAR escalation; training; employee screening; and oversight of outsourced AML functions (CIMA FAQ 37).
Can the audit use sampling?
Yes. CIMA accepts risk-based sampling if it is proportionate and gives enough coverage to assess effectiveness. Outsourced functions must be tested as they operate for your entity (CIMA FAQ 45).
Our fund outsources everything. Does it still need an AML audit?
Yes. CIMA says a regulated fund must still have an AML audit even if all or substantially all of its operations are outsourced. Scope and frequency are set using a risk-based approach (CIMA FAQ 42).
Can we rely on our administrator's AML audit?
Only if it covers all elements of your fund's own programme with fund-specific testing. An audit of the service provider's general framework, or a population-based review, is not enough on its own (CIMA FAQs 43, 45 and 46).
Is there a prescribed audit report format?
No. CIMA does not prescribe a format or methodology. It expects the report to assess the effectiveness of every applicable part of the compliance programme and to document the deficiencies found clearly (CIMA FAQ 36).
Does the audit report have to be filed with CIMA?
Yes. The regulated entity must file the audit report with CIMA as soon as practically possible after the audit is completed, or as CIMA otherwise prescribes (AML Rule 12.2(d)). CIMA has not set an industry-wide first filing date (CIMA FAQ 33).
What happens if the audit finds deficiencies?
Findings do not invalidate the audit (CIMA FAQ 48). You must put effective remediation in place within timeframes that match how serious and risky each finding is (AML Rule 12.4), and the board should track it to completion.
Are there fines for breaching the new AML Rule?
The Rule has the force of law (AML Rule 13.2), and breaches fall under CIMA's Enforcement Manual (13.1). However, CIMA has said that the administrative fines framework for breaches of the Rule is not yet in effect, and that it does not intend a blanket enforcement approach from the effective date (CIMA FAQ 4).
Is this a financial statement audit?
No. Our AML audits are independent AML compliance programme audits under Rule 12 of the CIMA AML Rule. They do not express an opinion or assurance on financial statements, and they do not replace your fund's annual financial statement audit.
Do you audit entities where you are the AML officer or a director?
No. We do not audit an entity where we act as its AMLCO, MLRO, DMLRO or director, or where we designed or wrote its compliance programme. See our independence standard.
How much does an independent AML audit cost?
We quote per engagement. The fee depends on the entity type, risk profile, number of entities, outsourcing arrangements and sample sizes. Request a quote and we will propose a scope and fee.
These answers summarise the Rules and CIMA's FAQs as at 30 September 2026. They are general information, not legal advice.
Ready to scope your independent AML audit?
Tell us about your entity. We will come back with a proposed scope, timetable and quote. No obligation.