Independent AML audits for SIBs, fund managers and other FSPs
Independent AML/CFT/CPF and sanctions compliance programme audits for securities investment businesses, fund managers and other CIMA-regulated financial services providers with their own people, clients and systems.
Built for operating businesses
Unlike a fully outsourced fund, a SIB or manager usually runs its own onboarding, monitoring and reporting. It employs staff who need training and screening, and its board and senior management are directly responsible for day-to-day controls. Our audit tests those controls where they actually operate.
Governance and the AMLCO
Governance framework, AMLCO authority and access, reporting to the board at least annually, and approval of policies (AML Rule 7.1, 8.2, 8.8, 10.2).
Risk assessment
Enterprise-wide and customer risk assessments, updates after trigger events, and consideration of sanctions exposure (AML Rule 9; Sanctions Rule 7.2–7.3).
CDD and monitoring
Sample testing of client files, EDD for higher-risk clients and PEPs, ongoing monitoring, alert handling and SAR escalation (AML Rule 10.3, 10.5, 12.6–12.8).
People
Training plan, annual delivery, records, and employee screening at recruitment and on an ongoing basis (AML Rule 11.1–11.14).
Sanctions
Screening of clients, beneficial owners, transactions and service providers, and re-screening without delay (Sanctions Rule 7.4–7.13).
Outsourcing and reliance
Oversight of outsourced functions and evidence that relied-upon functions meet the Rule (AML Rule 10.4, 10.7).
Internal audit and the external cycle
Larger firms may have an internal audit function able to perform the AML audit. The AML Rule allows internal audits for no more than two consecutive cycles, after which the next audit must be carried out by an external service provider (12.3). "Internally" covers anyone employed, contracted or otherwise within the firm's structure and subject to its direction (Rule 12.3, footnote 7). We can act as your external auditor for that cycle, or co-source specialist testing alongside your internal auditors where our independence allows.
Groups and multiple regulated entities
For groups with several CIMA-regulated entities, we plan one coordinated engagement with shared walkthroughs of common controls, while testing and reporting separately for each entity. CIMA says group risk assessments may be used, but risks specific to the Cayman operations must be identified and addressed (FAQ 20).
Frequently asked questions
Who can perform an AML audit?
CIMA lists internal audit functions, external auditors, independent consultants, or other suitably qualified and competent independent parties. Whoever does it must be independent of the AML/CFT/CPF/TFS function and must not be involved in operating, managing or overseeing the programme (AML Rule 12.2(b); CIMA FAQs 40–41).
How many internal audits can we do in a row?
An internal audit can be used for no more than two consecutive audit cycles. The next audit must be carried out by an external service provider (AML Rule 12.3; CIMA FAQ 47).
Do you test staff training and employee screening?
Yes. Where you have staff, we test the training plan, delivery records and content against AML Rule section 11, and your employee screening arrangements (Rules 11.3–11.4, 11.14).
Ready to scope your independent AML audit?
Tell us about your entity. We will come back with a proposed scope, timetable and quote. No obligation.