AML Audit
We check whether your system would survive a meeting with a supervisor. Not against a checklist of documents, but against the way your rules were applied to real customers and real transactions.
- Duration
- Two to six weeks
- Format
- Remote, on site when needed
- Result
- Report and a remediation plan
When firms commission an independent audit
In the AIFC, testing the effectiveness of the AML programme is mandatory at least once every two years under the AIFC AML Rules. Other supervised financial monitoring entities review their internal control system annually, as their own internal rules require.
An external independent audit is usually commissioned in one of three situations:
- A partner bank asks for it;
- An enforcement notice has been received;
- Management wants to know the real state of affairs before the regulator does.
There is a fourth trigger that firms remember too late: a change in the business model. A new product, a new market or a new acquisition channel changes the risk profile, while the internal control rules stay as they were. The gap between what is written and what happens grows quietly and surfaces at the worst possible moment.
What is actually tested
A formal review checks that documents exist. That is close to useless, because the documents usually do exist. The problems sit elsewhere.
We take the system apart in four layers:
Documents
Internal control rules and every earlier version, the risk assessment, onboarding procedures, the training programme and its records, the order appointing the responsible officer.
Systems
How transaction monitoring and sanctions screening are built, which scenarios run, what an analyst sees on screen and what trail their decisions leave behind.
Practice
A sample of customers across risk levels and the transactions behind them, so we can see how the requirements were applied in reality.
Evidence
Whether you can reconstruct who took a decision, when, and on what basis.
An audit looks for the places where the layers do not meet: the rules say one thing and practice does another.
- The rules require enhanced due diligence for a high-risk customer, and the file does not show it.
- A monitoring scenario is tuned so tightly that it has not fired once in a year.
- Training was delivered, and the only evidence is a signature.
On an inspection each of these becomes a question with no good answer.
How the work runs
We start by requesting a document pack. It is large and known in advance, so you can assemble it before the project starts:
- Internal control rules and every earlier version.
- The structure of the AML function and the order appointing the responsible officer.
- The ML/TF risk assessment and the business profile.
- Onboarding procedures for individuals, legal entities, sole traders and non-residents, with the customer questionnaire templates.
- A description of monitoring and sanctions screening with alert logs.
- Registers of suspicious and threshold reports.
- The training programme and its records.
- Results of previous internal and external reviews.
The list is refined after the first pass, and further requests happen along the way. We then read the documents, look at the systems your analysts actually work in, and compare what we see against the requirements and market practice. After that we take a sample of customers across risk levels, with their transactions, and check how the rules were applied in real cases.
Interviews are held with the responsible officer and the head of the function, and where it helps, with the people who work in the system hands on. Usually two or three conversations. People say what documents never record: where the process is bypassed, and why.
Findings are discussed before the final report, not after it. Some observations fall away in that discussion because you have an explanation or a document we had not seen. That is a normal part of the work, not a concession: the final report should contain only what survives an argument. Every observation carries a reference to specific evidence.
What we find most often
Five findings repeat in almost every project. Read the list as a checklist and tick the points you are not sure about.
- The rules have fallen behind the law. Internal rules were not updated after changes in legislation or in the regulator's requirements.
- Customer risk rating is a formality. The scoring method is not documented anywhere, so there is nothing to explain a rating with.
- Monitoring scenarios were never revisited. The system barely produces suspicious activity reports of its own.
- Sanctions hits are not worked through. The procedure for alerts and refusals is incomplete or not written down.
- Enhanced measures have gaps. Politically exposed persons, holders of multiple wallets, payment agents.
If you are unsure about three of the five, an audit will find more than you expect.
What usually happens after an audit
An audit shows the gaps, it does not close them. What normally follows is rewriting the internal control rules against the findings, training the staff with those gaps in mind, and recalibrating monitoring and screening scenarios.
Three or six months later, if you want it, we run a follow-up review and confirm that the findings are genuinely closed. That is separate work for a separate fee, and not everyone needs it: if the remediation plan has been carried out, a second review adds nothing.
What you get
Independent audit report
An overall conclusion on compliance, an assessment by key area, a register of findings prioritised by risk, and practical recommendations.
Remediation roadmap
A plan of work with priorities and deadlines that can be shown to a regulator or a partner bank.
Findings with evidence
Every observation is backed by a reference to a specific document, file or log, and is discussed with your team before the final report.
Duration and format
The clock runs from the document request to the final report. A small payment institution or fintech usually takes two or three weeks, a medium or large firm four to six. The duration depends on the volume of data, the complexity of the systems and how quickly you hand over documents. The scope and the shape of the report are fixed in the engagement terms before the work starts.
Frequently asked questions
What does an audit cost and what is included?
The fee depends on the size of the firm and the volume and complexity of the work. We name an exact figure after a short conversation about the task, and fix the scope in the engagement terms so that the boundaries are not argued about later. Scope also drives depth: the number of interviews and the size of the sample, for example.
Who will work on the project?
The work is led by a senior AML practitioner with more than six years of experience. Who exactly will take your project, and who answers for the result, is named before the work starts and written into the engagement terms. We cap the number of parallel projects, so the dates we name are dates we can hold.
What do you need from us?
The document pack at the start, and read access to the monitoring and screening systems. Plus the time of two or three people for interviews, usually an hour each. Without access to data and systems we do not take the project: an audit without them turns into a check that documents exist.
How is an AML audit different from a financial audit?
A financial audit confirms that the accounts are true and fair. An AML audit assesses whether the anti money laundering system works: the rules, the risk assessment, customer due diligence, transaction monitoring, training and reporting. Different subject, different specialists.
We have received an enforcement notice. Will an audit help?
The task is a different one there. We work out what exactly is alleged, look for the cause rather than the symptom, and build a remediation plan that can be presented and defended. That is a separate service, inspection support and remediation, though it often runs alongside an audit.
Will our data stay confidential?
Yes. The NDA is signed before any substantive conversation. Where anonymised extracts are enough for the conclusions, we work with anonymised data. Client names and recognisable details are never disclosed, in our materials or in conversations with other clients.
Shall we look at your case?
Tell us the task and we will say whether it needs the full piece of work or a narrower one.
Book a consultationNorthhold Advisory is an independent consultancy. We are not affiliated with, and do not represent, the AFM of Kazakhstan, the AIFC (AFSA) or the National Bank of Kazakhstan.