Independent AML audits and targeted reviews to assess whether your controls address your business risks and work in practice.

Identify weaknesses early, while you can still plan the work, prioritise spending and manage the response.
Commissioned Skilled Person reviews concerned financial crime.
Average cost of completed Skilled Person reviews across all subjects.
Across all subjects, 19 completed reviews cost firms £47.6 million. The FCA sets the scope, while the firm must absorb the cost. The potential burden extends beyond the review fee - management time, remediation work and restrictions on business activity can add to the cost.
An independent AML audit gives you an opportunity to identify and address weaknesses before they escalate into regulatory concerns. Where the concern is specific, a targeted review can focus the work and budget on the controls that need examination.
Published FCA findings show what deserves scrutiny:
Our reviews follow the evidence from the written framework to the decisions and records supporting it.
For payment firms: read Independent AML audits for payment firms: what FCA findings tell us to test
A report for the MLRO, Board or partners that makes clear:
We discuss the findings with you before finalising the report, checking factual accuracy while retaining independent judgement.
Review the design and operation of your AML framework across governance, risk assessments, policies and controls. Includes risk based sample testing to assess whether controls work in practice.
Focus on a specific area, such as customer risk assessment, EDD, sanctions screening or transaction monitoring. The review can examine documented arrangements, test how controls operate, or combine both.
A documentary review of your risk assessments, policies, procedures and allocated responsibilities. We assess gaps, consistency and control design. This does not include sample testing or assess whether staff apply the arrangements effectively in practice.
We can test selected customer or matter files, transactions, alerts and decisions against applicable requirements and your procedures. Testing can form part of a full framework audit or targeted review, or be commissioned as a standalone exercise.
The agreed scope can cover:
Sanctions and other wider financial crime areas are included where agreed.
Our AML audit for payment firms, including payment institutions, EMIs and remittance businesses, reflects how money moves through the business. Particular attention is given to customer and merchant relationships, payment corridors, transaction flows, agents and distributors, outsourced controls and the way unusual activity is identified and escalated.
Our AML audit for cryptoasset firms reflects the additional risks created by wallet activity, asset provenance, blockchain transactions and exposure to other cryptoasset counterparties. Testing considers how the firm assesses wallet and transaction risk, establishes source of funds, investigates alerts and manages sanctions and other financial crime exposure.
For authorised financial services firms and Annex 1 financial institutions, the audit is tailored to the products and services offered, the types of customers served and the way funds or assets move through the business. This may include particular focus on complex ownership, customer risk, source of funds and the risks arising from the firm's financial activities.
For legal, accountancy and trust and company service providers, the audit reflects the risks arising from the services being provided as well as the client relationship itself. Thisincludes higher risk matters, property transactions, client accounts, company and trust structures, formation activity and the handling of source of funds and beneficial ownership.
Our AML audit for estate agents and letting agencies reflects the parties, funds and ownership structures involved in property transactions and qualifying letting activity. Particular attention is given to customer and beneficial ownership checks, transaction risk, source of funds and how higher risk property activity is identified and handled.
We also audit other businesses subject to the Money Laundering Regulations, including high value dealers, art market participants and other in scope businesses. The audit is tailored to the relevant regulatory category and to the particular products, transactions, customers and money laundering risks arising from the business activity.
The FCA expects the professional services transfer to begin in autumn 2028 and complete around 2030, subject to legislation. Existing supervision and obligations continue meanwhile. An audit can assess your current arrangements without waiting for the transition.
fca.org.uk/firms/aml-supervisory-reformYour review is led by a practising MLRO with experience of senior compliance responsibilities and independent Regulation 21 audits in financial services, including brokerage.
That experience includes direct FCA engagement on AML and sanctions matters, and responding to FCA appointed Skilled Persons.
The lead practitioner is an ICA Fellow and ICA Certified MLRO and has also passed the CAMS examination.
You work directly with the practitioner responsible for the review, from agreeing the scope to discussing the conclusions.
Regulation 21(1)(c) requires an independent audit function where appropriate to the size and nature of the business. Its responsibilities cover evaluating AML policies, controls and procedures, recommending improvements and monitoring compliance with those recommendations. It does not impose an identical annual external audit on every firm.
An AML compliance audit examines the adequacy and effectiveness of your policies, controls and procedures. The agreed scope determines whether the work covers the complete framework or a specific area, and whether it includes testing how controls operate in practice.
It can contribute to your audit arrangements, but a narrow review does not automatically address the whole requirement. We agree how the work fits your wider assurance coverage and identify what remains outside scope.
Yes. We can provide remediation support under a separate engagement. We assess prior involvement before accepting independent audit work. Any later independent review of controls we helped design or implement needs appropriate independence arrangements.
No. It provides conclusions within an agreed scope, supported by the evidence reviewed. It cannot guarantee that a supervisor will reach the same conclusions or that regulatory intervention will be avoided.
Tell us about your business, the concern you want examined and any deadline. We will propose the scope, testing approach, timetable and fee.