How our independent AML audit works
A clear, structured process from the first call to the final report prepared for filing with CIMA. Scope and effort depend on your entity, risk profile and outsourcing model, so every engagement is quoted individually.
-
1. Enquiry and conflict check
You tell us about the entity through our quote form or by phone. Before anything else we check independence: we will not audit an entity where we act as its AMLCO, MLRO, DMLRO or director, or where we designed or wrote its programme (see our independence standard).
-
2. Scoping
We review your risk assessment, structure, service providers and prior audit findings, then agree a risk-based scope drawing on CIMA's list of areas to consider (FAQ 37). For funds, the scope includes fund-specific testing of outsourced arrangements (FAQs 43–45).
-
3. Proposal and engagement
You receive a written proposal with the scope, approach, deliverables and fee. On acceptance we issue an engagement letter and a written independence confirmation.
-
4. Document request and planning
A tailored document list covering policies, risk assessments, board minutes, AMLCO reports, registers, training records and outsourcing agreements, plus the population lists we need to select samples.
-
5. Fieldwork and testing
Walkthroughs and interviews with the AMLCO, MLRO and key staff or service providers. Risk-based sample testing of customer or investor files, screening and re-screening, alerts, escalations, SARs, training and employee screening. CIMA accepts proportionate risk-based sampling that gives sufficient coverage (FAQ 45).
-
6. Draft findings
Findings rated by risk, with the evidence behind them and practical recommendations. We discuss them with you so management responses and remediation owners can be agreed.
-
7. Final report and filing
A final report that assesses each applicable component of the programme and clearly documents deficiencies (FAQ 36), with the independence statement and a remediation tracker. You file the report with CIMA as soon as practically possible after completion (AML Rule 12.2(d)).
-
8. Remediation follow-up (optional)
Where helpful, we can verify that agreed actions have been completed, so your board can evidence remediation under AML Rule 12.4.
What we will need from you
- Current AML/CFT/CPF manual and sanctions policy
- Enterprise-wide risk assessment and customer risk methodology
- AML officer appointment records and recent AMLCO reports
- Board minutes covering AML matters
- Outsourcing and service agreements
- Training plan and records; registers under AML Rule 8.5
- Previous audit reports and remediation status
Ready to scope your independent AML audit?
Tell us about your entity. We will come back with a proposed scope, timetable and quote. No obligation.