The short answer
There is no single answer. Rule 12.2(a) of CIMA's Rule on an Effective Compliance Programme requires the independent audit to be carried out "at a frequency commensurate with its size, complexity, structure, nature of business, and the risk profile, as determined by the FSP's risk assessment or as otherwise required by the Authority". CIMA's FAQs confirm that the Rule does not mandate annual audits (FAQ 35) and that there is no prescribed frequency (FAQ 38).
CIMA does, however, give examples. In FAQ 38 it says that for an entity rated higher risk it "might be reasonable" for an AML audit to be carried out every two years, and that for medium and low risk the frequency may be every three and four years respectively.
| Overall risk rating | Example frequency |
|---|---|
| Higher risk | About every 2 years |
| Medium risk | About every 3 years |
| Low risk | About every 4 years |
These are examples, not safe harbours. CIMA adds that "the frequency and intensity of an AML Audit should depend on the FSP's overall risk rating while incorporating the nature, size and complexity of the operations".
Your risk assessment drives the cycle
CIMA expects an entity's risk assessment to inform its audit programme: when an audit should be carried out, how often, and what it should cover (FAQ 34). In practice, that means the enterprise-wide risk assessment required by section 9 of the Rule should do more than rate risk. It should lead to a documented decision on audit frequency and scope.
Factors that commonly justify a shorter cycle include:
- a higher-risk investor or client base, for example significant PEP exposure, complex ownership structures or investors from higher-risk jurisdictions;
- higher-risk products, delivery channels or transaction patterns;
- material changes since the last audit, such as a new administrator, new AML officers, a merger, new strategies or a rapid increase in assets or investors;
- significant findings in the last audit or a CIMA inspection, or slow remediation;
- sanctions exposure, which the Sanctions Rule requires you to consider in your risk assessment (Sanctions Rule 7.2).
A stable, low-risk entity with clean prior results may reasonably sit at the longer end of the range, provided the reasoning is written down.
The external cycle rule
Frequency interacts with another requirement. The audit "may be conducted internally but must not be undertaken internally for more than two (2) consecutive audit cycles" (Rule 12.3). After two internal audits, the next must be carried out by an external service provider. CIMA explains that this guards against familiarity, self-review and loss of objectivity (FAQ 47).
"Internally" is defined broadly in footnote 7 to Rule 12.3. It covers any individual or unit employed by, engaged under contract by, or otherwise forming part of the entity's organisational structure and subject to its direction, control or oversight. If you plan to use an internal audit function, map out the cycles so you know which audit must be external.
Do you need an audit now that the Rule is in force?
Not simply because the Rule took effect on 18 September 2026. CIMA says the Rule "does not require FSPs to conduct or commission an AML/CFT/CPF audit solely because the Rule has become effective" (FAQ 34). CIMA also notes that the audit requirement already existed under the Anti-Money Laundering Regulations (FAQ 32). If your existing, risk-based plan says an audit is due, it is due. If it is not, you do not need to bring it forward just because of the Rule.
Two points cut the other way. First, CIMA can still require an audit, for example as a result of an inspection or supervisory review (FAQ 34). Second, if your entity has never had an AML audit, CIMA says the first audit must be completed in line with the pre-existing requirements and the report submitted after completion. After that, reports follow your audit cycle (FAQ 33).
How to document your decision
CIMA says entities should "determine and document" their audit frequency (FAQ 38). A defensible record usually includes:
- the overall ML/TF/PF/TFS risk rating from your current risk assessment and the main drivers behind it;
- the chosen audit frequency and how it links to that rating;
- the triggers that would bring the next audit forward, such as a change of administrator or AML officers, a significant finding, a new business line or a regulatory request;
- whether the next audit will be internal or external, with reference to Rule 12.3;
- governing body approval, recorded in the minutes, consistent with the board's oversight role (FAQ 7).
Review the decision whenever the risk assessment is updated. Section 9 of the Rule requires risk assessments to be kept up to date.
Frequency is not the same as depth
A longer cycle does not mean a lighter audit when it happens. Whatever the frequency, the audit must test the programme's adequacy and effectiveness (Rule 12.1). The report must assess every applicable component of the programme and clearly document deficiencies (FAQ 36). For funds, the audit must produce fund-specific evidence, not just rely on a service provider's general review (FAQs 43–46).
Key takeaways
- No annual requirement and no fixed cycle. Frequency follows your documented risk assessment.
- CIMA's examples: about 2 years for higher, 3 for medium and 4 for low risk.
- No more than two consecutive internal audits. The third must be external.
- Write down the decision, the triggers for an earlier audit and the board's approval.
If you would like help planning your next audit, see our independent AML compliance programme audit or request a quote.
This article is general information, not legal advice, and reflects the Rules and CIMA FAQs as at 30 September 2026.