03 · Audit & Assurance
Independent, risk-based audits of your anti-money laundering framework — testing that your systems, controls and processes meet regulatory expectations and actually work in practice.
At a glance
Overview
Regulators — and increasingly banking partners — expect an independent AML audit at regular intervals. In the UK that expectation sits in the Money Laundering Regulations 2017 and the FCA’s SYSC 6.3 and Financial Crime Guide; in the EU it flows from the AMLD framework and the incoming AMLR; in Canada, from the PCMLTFA and FINTRAC’s guidance. None of them fix an exact interval in black-letter law, but annual testing is the practical industry standard — and the cadence we scope for — because it demonstrates ongoing effectiveness rather than a point-in-time sign-off.
We deliver targeted audits of your AML/CFT framework, controls and processes against those obligations and your own policies, with clear, risk-rated findings and a practical remediation plan to close gaps and strengthen effectiveness.
The service in detail
Independent AML testing isn’t optional for a regulated firm — the FCA and its EU and Canadian equivalents expect it at intervals proportionate to your risk. The only real choice is who does it, and how much you actually get from the exercise beyond a checkbox.
Client types
Jurisdictions
FCA SYSC 6.3 — and its EU and Canadian equivalents — don’t just recommend independence, they require the audit function to sit apart from whoever designed or runs the controls being tested. A self-review from the same team, however thorough, doesn’t meet that bar.
What we review
AML/CFT policies, the business-wide risk assessment, roles and MLRO oversight, benchmarked against the Money Laundering Regulations 2017 and FCA SYSC 6.3.
Customer due diligence, KYC/KYB, EDD triggers and beneficial-ownership checks.
Rules, thresholds, alert handling and the effectiveness of your monitoring tooling.
Screening coverage, list management, fuzzy matching and alert disposition against UK, EU and Canadian sanctions regimes.
Internal escalation, SAR/STR decision-making, quality and reporting to the NCA, FINTRAC or the relevant EU FIU.
Staff training, records, management information and the wider compliance culture.
What you actually get
Every finding follows the same format — risk rating, root cause, evidence and a named owner — so nothing gets lost between the report and your next board pack. Here’s an illustrative example of one entry.
Alert thresholds were last reviewed before the last material increase in transaction volume, raising the risk that genuinely suspicious activity now falls below the alerting line.
Our methodology
A typical audit runs over three to six weeks depending on scope and firm size. On frequency — we scope for an annual cadence as standard, regardless of size, since that’s the practical industry benchmark for demonstrating ongoing effectiveness. Higher-risk models, such as crypto/CASP-permissioned firms or cross-border payments businesses, should treat annual as a firm minimum rather than a target.
Agree the scope, risk focus and sample sizes with your MLRO, map which regulations and internal policies apply, and request the documentation, system access and case data we'll need before fieldwork starts.
Assess your AML/CFT policies, procedures and business-wide risk assessment against the Money Laundering Regulations, FCA guidance (or your EU/Canadian equivalent), and flag gaps before we ever open a case file.
Test a risk-based sample of real files and cases — onboarding decisions, transaction-monitoring alerts, sanctions/PEP screening and SARs — to see how the framework performs in practice, not just on paper.
Grade every issue by risk and impact, document the root cause and the evidence behind it, and agree draft findings with your team before anything is finalised in the report.
Agree a prioritised remediation plan with owners and deadlines, then — for higher-risk findings — re-test once fixes are in place to confirm the gap is actually closed.
What you receive
Tested against the MLRs, FCA guidance (or your EU/Canadian equivalent) and your own policies — built to stand up to direct regulator scrutiny.
Every issue graded high / medium / low with evidence, so your MLRO knows exactly what to fix first.
A prioritised, practical plan with owners and timelines — the same document a banking partner or investor will want to see progress against.
An executive summary the board and regulator can both rely on without translation.
Who does the work
Every audit is scoped, tested and signed off by senior team members who understand fintech and the regulation that governs it — never delegated to a junior bench.
FAQ
Annually, for most regulated firms — that's the industry standard and the cadence we scope for and push our clients toward, regardless of size. Neither the FCA nor its EU and Canadian equivalents write a fixed number into the letter of the rules, but annual testing is what actually demonstrates ongoing effectiveness rather than a point-in-time sign-off, and it's where every conversation with us starts. If your risk profile genuinely warrants something different, we'll say so directly — we won't default you to a longer gap just because the rules allow it.
Consulting & Assurance covers your whole compliance framework on an ongoing, advisory basis. An AML Audit is the single, formal, independent test of your AML/CFT programme specifically — the discrete, regulator-facing report the Money Laundering Regulations and FCA guidance expect annually, delivered by a team with no role in building the controls being tested.
Yes — that's deliberate. The full report is written to stand up to direct regulator scrutiny, and the board-ready executive summary is the same document banking partners and investors typically ask for during due diligence. You don't need two versions.
Every finding is risk-rated, not just listed, so you know what to fix first rather than facing everything at once. For higher-risk findings we'll agree an interim mitigation with you immediately, then build the fix into the remediation roadmap and re-test once it's closed.
Yes. We've picked up engagements with a regulator deadline already on the calendar after another firm withdrew. Tell us the timeline and what's already been done, and we'll scope what's realistically achievable rather than restart everything from zero.
Request an independent AML audit and get a clear, risk-rated picture of your controls.