AML Audit
An AML audit is the independent testing of an anti-money-laundering program — a review carried out by people with no responsibility for running it, to establish whether the program works rather than whether it exists on paper. It is one of the five pillars of a U.S. BSA/AML compliance program, and the pillar most often found wanting.
| Also called | BSA/AML independent testing, AML independent review |
| Status | One of the five pillars of a BSA/AML compliance program |
| The five pillars | Internal controls; a designated compliance officer; ongoing training; independent testing; customer due diligence and beneficial ownership |
| Fifth pillar added | May 2018, by FinCEN’s Customer Due Diligence Rule |
| Who may perform it | Anyone independent of the AML function — internal audit, or an external firm |
| Required frequency | None is set by statute or regulation |
| Sound practice | Generally every 12 to 18 months, scaled to the institution’s risk profile |
| Also triggered by | Significant change in risk profile, systems, processes or compliance staffing |
The frequency question, answered properly
Almost every summary of this topic states that AML audits are required every 12 to 18 months. That is not what the rules say, and the distinction matters if you are defending a program.
There is no regulatory requirement establishing a testing frequency. The FFIEC manual describes 12 to 18 months as a sound practice, commensurate with the institution’s BSA/AML risk profile, and adds that testing should also follow significant changes in risk profile, systems, processes or compliance staffing. The obligation is that testing is independent, risk-based and adequate — not that it happens on a particular calendar.
The practical consequence runs both ways. A higher-risk institution testing every eighteen months because the internet said eighteen months was the rule has a weak answer for an examiner. A lower-risk one may reasonably test less often, provided the reasoning is documented.
What independence actually requires
The word is doing real work. The reviewer must not be responsible for the program being reviewed — which rules out the BSA officer, their team, and anyone reporting to them. It does not require an external firm; a properly independent internal audit function can perform it.
What it does require is that findings reach the board or a board committee without passing through the people whose work is being assessed. An audit whose conclusions are edited by the function under review is not independent testing regardless of who wrote it.
What audits find
| Finding | What it usually means |
|---|---|
| Untuned or unvalidated monitoring scenarios | Thresholds set at implementation and never revisited against actual outcomes |
| Alert and case backlogs | Volume exceeds analyst capacity, so the program generates work rather than detection |
| Coverage gaps | A product, channel or entity type that no scenario monitors |
| Weak CIP and CDD data | Identifying information incomplete, unverified, or never refreshed |
| Risk assessment not driving the program | The assessment exists but the controls do not follow from it |
| Training that is generic | Delivered to everyone identically rather than by role and risk exposure |
The fourth row is the one that recurs across institutions and the one this glossary keeps returning to. Weak customer data at onboarding is not only a finding in its own right — it is the root cause behind several of the others. Transaction monitoring compares activity against a profile built from that data. Screening matches names taken from it. Regulatory reporting identifies subjects using it. An audit that finds monitoring ineffective has often found an onboarding problem wearing a monitoring costume.
Why this matters for identity verification
The Customer Identification Program is the foundation the other pillars stand on, and it is testable in a way that is uncomfortably concrete: an auditor can pull a sample of accounts and ask what evidence was relied on to establish each identity, and whether it was retained.
Programs that verified identity documentarily, authenticated the document, and kept a record of what was checked can answer that. Programs that accepted a photograph of a document and a name-and-number match against a database will answer it less well — and the answer will be the same for every account in the sample, which turns one finding into a systemic one.
This is the case for treating identity document verification as an audit control as much as a fraud control. KYC and AML workflows that capture what was checked, and why it was sufficient, produce the evidence an independent review needs without a reconstruction exercise.
What an AML audit can’t do
It is not an examination. A regulator’s findings carry consequences an internal audit does not, and a clean audit is not a defense against an adverse examination.
It does not fix anything. Testing identifies gaps. Remediation is separate work, and unremediated repeat findings are worse than the original finding.
Scope determines value. A review that samples files without testing whether monitoring scenarios actually detect what they claim to detect has checked the paperwork.
It is retrospective. Audits examine a period that has closed. Everything found has already been happening.
Frequently asked questions
How often is an AML audit required?
No statute or regulation sets a frequency. The FFIEC manual describes independent testing every 12 to 18 months as a sound practice, scaled to the institution’s risk profile, and recommends testing after significant changes to risk profile, systems, processes or compliance staffing. The requirement is that testing be independent, risk-based and adequate.
Who can perform an AML independent test?
Anyone independent of the AML function being reviewed — which excludes the BSA officer, their team and anyone reporting to them. An external firm is not required; a properly independent internal audit function can perform it, provided findings reach the board without being filtered through the reviewed function.
What are the five pillars of a BSA/AML program?
Internal controls; a designated BSA/AML compliance officer; ongoing employee training; independent testing; and customer due diligence including beneficial ownership, which FinCEN’s CDD Rule added as the fifth pillar in May 2018.
What do AML audits most commonly find?
Monitoring scenarios that were never tuned or validated, alert backlogs, coverage gaps where a product or channel is unmonitored, and weak customer identification data. The last is frequently the root cause of the others, since monitoring and screening both depend on the quality of what was captured at onboarding.
Related reading
- Customer Identification Program — the pillar an audit can test most concretely, account by account
- Transaction monitoring — where tuning and coverage findings usually land
- Regulatory reporting — the output whose quality an audit assesses
- Compliance officer — the second pillar, and the role independent testing must sit outside