The filing requirement
Under Rule 12.2(d) of CIMA's Rule on an Effective Compliance Programme, the regulated entity must ensure that "the audit report is filed with the Authority as soon as practically possible after the completion of the audit, or as otherwise prescribed by the Authority". The obligation sits with the entity, not the auditor. Even if the audit is outsourced, the entity remains responsible for the adequacy and effectiveness of its programme (Rule 12.5).
Is there a deadline for everyone?
No. CIMA's FAQ 33 states that the Rule "does not prescribe a universal first-filing date, an industry-wide completion date, or a simultaneous submission requirement". Entities may submit the final report for an audit completed under their existing risk-based audit plan. Where an entity is having its first audit, that audit must meet the pre-existing requirements and the report must be submitted after completion. After that, reports follow the entity's audit cycle.
CIMA also confirms that the Rule does not require an audit solely because it has taken effect (FAQ 34). The practical question is therefore not "when is the industry deadline?" but "when is our next audit due under our risk assessment, and are we ready to file promptly when it is done?". Our article on audit frequency covers the first part.
We recommend checking CIMA's website and any notices for the current submission channel and any prescribed format or cover information before filing. CIMA may prescribe filing arrangements under the "as otherwise prescribed" wording of Rule 12.2(d).
What should the report contain?
CIMA does not prescribe a standard format or methodology (FAQ 36), but it does set expectations. The report should "include an assessment of the effectiveness of all applicable components" of the programme outlined in the Rule and any applicable regulatory requirements, and "clearly document the deficiencies identified, including instances of substantive non-compliance".
In our view a well-structured report includes:
- Scope and basis: the entity, period covered, the Rules and Regulations tested against, and how the scope was set from the risk assessment (FAQ 37 lists the areas to consider).
- Independence statement: the basis on which the auditor's independence was determined. Under Rule 12.2(c), CIMA can ask for this.
- Methodology and sampling: walkthroughs, interviews and risk-based samples, and why the coverage is sufficient (FAQ 45).
- Component-by-component assessment: governance, AML officers, risk assessment, CDD and EDD, sanctions, monitoring and SARs, records, training, employee screening and outsourcing.
- Findings: each deficiency described clearly, with evidence, risk rating, the requirement breached and a recommendation.
- Management responses: agreed actions, owners and target dates.
- For funds: fund-specific conclusions, including how outsourced controls operate for that fund (FAQs 43–45).
Findings do not sink the audit
Entities sometimes worry that filing a report with findings will count against them. CIMA's FAQ 48 is reassuring on the point: findings, exceptions or deficiencies "do not automatically invalidate an AML Audit". They highlight areas needing remediation and may inform CIMA's supervisory assessment. What matters next is how the entity responds.
After filing: remediation and oversight
Rule 12.4 requires "effective remediation measures to address any deficiencies, breaches, or weaknesses identified through the audit within appropriate timeframes commensurate with their nature, materiality, and associated risk". CIMA's FAQ 7 expects the governing body to oversee the timely implementation of corrective actions, evidenced through minutes, reports, documented decisions and remediation tracking.
A practical post-audit routine:
- present the final report to the board and minute its discussion and approval of the action plan;
- file the report with CIMA promptly;
- track each action with an owner and date, and report progress to the board, for example in the AMLCO's periodic reports (Rule 8.8);
- close findings with evidence, not just a status update;
- feed significant findings back into the risk assessment and, if appropriate, the timing of the next audit.
Common pitfalls
- Filing a service provider's general report as your own. Without entity-specific testing it will not meet CIMA's expectations (FAQs 43, 46).
- No evidence of independence. Have the auditor's independence documentation ready before CIMA asks (Rule 12.2(c)).
- Letting the report sit. "As soon as practically possible" means promptly after completion, not at the next board meeting months later.
- Findings without owners. Remediation that is not tracked is hard to evidence at inspection.
Key takeaways
- The entity files the report with CIMA as soon as practically possible after completion.
- There is no industry-wide first-filing date. Your audit cycle drives timing.
- There is no prescribed format, but the report must assess every applicable component and document deficiencies clearly.
- Findings do not invalidate an audit. Remediate, track and evidence it.
Our independent AML compliance programme audit ends in a report prepared for filing with CIMA, with an independence statement and a remediation tracker.
This article is general information, not legal advice, and reflects the Rules and CIMA FAQs as at 30 September 2026.