Independent AML compliance programme audit

A risk-based, independent audit of your AML/CFT/CPF and sanctions compliance programme under Rule 12 of the CIMA AML Rule. It tests whether your controls are adequate and work in practice, and produces a report prepared for filing with CIMA.

What Rule 12 requires

Under CIMA's Rule on an Effective Compliance Programme, in force since 18 September 2026, every CIMA-regulated financial services provider must "establish and maintain independent audit procedures … to review and test the Compliance Programme, ensuring its adequacy, effectiveness and alignment with the applicable legislative and regulatory obligations" (Rule 12.1). The Rule then requires that:

  • Frequency is risk-based. Audits happen at a frequency that matches your size, complexity, structure, business and risk profile, as your risk assessment determines or CIMA requires (12.2(a)).
  • The auditor is independent. The audit is carried out by suitably qualified people who are separate from the design, implementation and operation of the controls being audited and free of conflicts (12.2(b)).
  • Independence is documented. On request, you must give CIMA documentation of the auditor's independence and the basis on which it was determined (12.2(c)).
  • The report goes to CIMA. The audit report is filed with CIMA as soon as practically possible after completion (12.2(d)).
  • Internal audits are limited. An internal audit may be used for no more than two consecutive cycles. The next must be carried out by an external service provider (12.3).
  • Findings are remediated. Deficiencies must be fixed within timeframes that reflect their materiality and risk. The entity remains responsible even when the audit is outsourced (12.4–12.5).

CIMA's FAQs confirm the audit obligation already existed under the Anti-Money Laundering Regulations. The Rule clarifies how effectiveness should be demonstrated (FAQ 32). CIMA also says the Rule does not require an audit solely because it took effect: your risk assessment should drive the timing (FAQ 34).

What our audit covers

We build the scope from your risk assessment and CIMA's list of areas to consider (FAQ 37), and tailor it to your structure:

AreaWhat we test
Governance and oversightBoard approval of policies, AMLCO reporting at least annually, board challenge and remediation tracking (Rules 7.1, 8.8, 10.2)
AML officersAMLCO, MLRO and DMLRO designation, management level, fitness evidence, authority, access and resources (7.1(c)–(d), 8.1–8.11)
Risk assessment and RBAEnterprise-wide risk assessment, use of the National Risk Assessment, inherent and residual risk, trigger-event updates (9.1–9.8)
Customer due diligenceCustomer risk methodology, CDD, EDD for higher risk and PEPs, SDD conditions, ongoing monitoring, sample file testing (10.3, 10.5)
SanctionsScreening scope, re-screening on list updates, true-match handling, freezing and CRF reporting (Sanctions Rule 7.1–7.23)
Monitoring and SARsTransaction alerts, internal escalation to the MLRO or DMLRO, external SARs to the FRA without delay, tipping-off controls (10.3(f), 12.6–12.8)
RecordsRecord keeping, and registers for declined business, PEPs, competent authority requests, SARs and alerts (8.5, 10.6)
Training and employee screeningTraining plan, delivery and records, and employee screening (11.1–11.14)
OutsourcingDue diligence on providers, agreements, CIMA access, notification of material outsourced functions, and how outsourced controls operate for you (10.3(d)–(e), 10.4, 10.7)

What you receive

  • An audit report that assesses each applicable component of your programme and clearly documents any deficiencies, as CIMA expects (FAQ 36)
  • Findings rated by risk, with practical recommendations and your management responses
  • A written statement of the basis of our independence, for your records and for CIMA on request (12.2(c))
  • A remediation tracker your board can use to evidence oversight (CIMA FAQ 7)
  • A recommended audit frequency based on your risk profile

Please note: our AML audits are independent AML compliance programme audits under Rule 12. They are not audits of financial statements and do not express an opinion or assurance on financial statements.

Choose the right audit for your entity

Investment funds

Fund-specific evidence, including testing of administrator controls for your fund.

Funds

SIBs and fund managers

Entities with their own staff, clients, systems and training programmes.

SIBs and managers

Frequently asked questions

What does an AML audit cover?

The scope must be proportionate. CIMA lists governance and oversight; AMLCO, MLRO and DMLRO effectiveness; the enterprise-wide risk assessment and risk-based approach; customer risk methodology; CDD and EDD; sanctions screening; transaction and ongoing monitoring; SAR escalation; training; employee screening; and oversight of outsourced AML functions (CIMA FAQ 37).

How often should an AML audit be carried out?

There is no fixed frequency. You decide and document it based on your risk profile (AML Rule 12.2(a)). CIMA gives examples: roughly every two years for higher-risk entities, every three for medium and every four for low risk. Annual audits are not mandated (CIMA FAQs 35 and 38).

Who can perform an AML audit?

CIMA lists internal audit functions, external auditors, independent consultants, or other suitably qualified and competent independent parties. Whoever does it must be independent of the AML/CFT/CPF/TFS function and must not be involved in operating, managing or overseeing the programme (AML Rule 12.2(b); CIMA FAQs 40–41).

Can our AMLCO, MLRO or DMLRO carry out the audit?

No. CIMA says the AML officers form part of the compliance programme and cannot independently audit activities they are responsible for, whether they are employees or outsourced (CIMA FAQ 39).

How many internal audits can we do in a row?

An internal audit can be used for no more than two consecutive audit cycles. The next audit must be carried out by an external service provider (AML Rule 12.3; CIMA FAQ 47).

Does the audit report have to be filed with CIMA?

Yes. The regulated entity must file the audit report with CIMA as soon as practically possible after the audit is completed, or as CIMA otherwise prescribes (AML Rule 12.2(d)). CIMA has not set an industry-wide first filing date (CIMA FAQ 33).

Is this a financial statement audit?

No. Our AML audits are independent AML compliance programme audits under Rule 12 of the CIMA AML Rule. They do not express an opinion or assurance on financial statements, and they do not replace your fund's annual financial statement audit.

Ready to scope your independent AML audit?

Tell us about your entity. We will come back with a proposed scope, timetable and quote. No obligation.