Send RFI

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Independent AML Audit
Full Framework or Targeted Review

Independent AML audits and targeted reviews to assess whether your controls address your business risks and work in practice.

Gold badge with a white check mark.
Framework and governance review, sample testing or both
Gold badge with a white check mark.
Scope matched to your business and the question you need answered
Gold badge with a white check mark.
Findings that explain what needs attention, why it matters and what to do next
MLRO-led delivery • ICA Fellow • ICA Certified MLRO
Abstract background with diagonal dark blue and teal stripes intersected by a gold stripe on the bottom right.

Where AML frameworks break down

Identify weaknesses early, while you can still plan the work, prioritise spending and manage the response.

12 of 31

Commissioned Skilled Person reviews concerned financial crime.

2025/26

£2.5m

Average cost of completed Skilled Person reviews across all subjects.

2025/26

Source: FCA Skilled Person reports, 2025/26

Across all subjects, 19 completed reviews cost firms £47.6 million. The FCA sets the scope, while the firm must absorb the cost. The potential burden extends beyond the review fee - management time, remediation work and restrictions on business activity can add to the cost.

An independent AML audit gives you an opportunity to identify and address weaknesses before they escalate into regulatory concerns. Where the concern is specific, a targeted review can focus the work and budget on the controls that need examination.

Published FCA findings show what deserves scrutiny:

White gear above an open hand icon on a gold rounded square background.
Risk assessments disconnected from decisions. Risks are documented, but their effect on customer ratings, controls and business decisions is unclear.
White gear above an open hand icon on a gold rounded square background.
Due diligence that cannot be evidenced. Files do not adequately explain the relationship or demonstrate the enhanced checks performed.
White gear above an open hand icon on a gold rounded square background.
Weak oversight of delegated work. Agents, distributors and outsourced functions need active oversight and challenge.
White gear above an open hand icon on a gold rounded square background.
Screening trusted without sufficient testing. Configuration, data coverage and reliance on vendors or group systems leave gaps.
White gear above an open hand icon on a gold rounded square background.
Reviews lacking independence or depth. The staff responsible for onboarding also check their own work.

Our reviews follow the evidence from the written framework to the decisions and records supporting it.

For payment firms: read Independent AML audits for payment firms: what FCA findings tell us to test

What you get


A report for the MLRO, Board or partners that makes clear:

What was reviewed, how it was tested and where the conclusions are limited.
Which controls are supported by evidence and where weaknesses remain.
The significance of each finding, with a clear distinction between compliance gaps and enhancements.
Recommended actions, priorities and arrangements for follow up.


We discuss the findings with you before finalising the report, checking factual accuracy while retaining independent judgement.

Choose the scope of your AML review

01

Full framework AML audit

Review the design and operation of your AML framework across governance, risk assessments, policies and controls. Includes risk based sample testing to assess whether controls work in practice.

02

Targeted control review

Focus on a specific area, such as customer risk assessment, EDD, sanctions screening or transaction monitoring. The review can examine documented arrangements, test how controls operate, or combine both.

03

Targeted AML framework review: policies, procedures and governance

A documentary review of your risk assessments, policies, procedures and allocated responsibilities. We assess gaps, consistency and control design. This does not include sample testing or assess whether staff apply the arrangements effectively in practice.

AML control testing and file reviews

We can test selected customer or matter files, transactions, alerts and decisions against applicable requirements and your procedures. Testing can form part of a full framework audit or targeted review, or be commissioned as a standalone exercise.

Areas we can review

The agreed scope can cover:

  • ✓Business wide risk assessment, risk appetite and governance.
  • ✓Customer or matter risk assessment, beneficial ownership, CDD and EDD.
  • ✓Source of funds, source of wealth and ongoing monitoring.
  • ✓Transaction monitoring, screening and sanctions controls.
  • ✓Suspicious activity escalation, reporting and recordkeeping.
  • ✓Staff screening, training, third party oversight and action tracking.

Sanctions and other wider financial crime areas are included where agreed.

Preparing an FCA application? We also provide AML framework support for FCA authorisation.

Who is this for?

Our AML audits assess whether your policies, controls and procedures meet the applicable Money Laundering Regulations and work effectively in practice. The core audit approach is consistent across sectors, while the scope and testing reflect your business model, activities, customers and specific money laundering risks.

Payment firms and EMIs

Our AML audit for payment firms, including payment institutions, EMIs and remittance businesses, reflects how money moves through the business. Particular attention is given to customer and merchant relationships, payment corridors, transaction flows, agents and distributors, outsourced controls and the way unusual activity is identified and escalated.

Cryptoasset firms

Our AML audit for cryptoasset firms reflects the additional risks created by wallet activity, asset provenance, blockchain transactions and exposure to other cryptoasset counterparties. Testing considers how the firm assesses wallet and transaction risk, establishes source of funds, investigates alerts and manages sanctions and other financial crime exposure.

FSMA firms and Annex 1 financial institutions

For authorised financial services firms and Annex 1 financial institutions, the audit is tailored to the products and services offered, the types of customers served and the way funds or assets move through the business. This may include particular focus on complex ownership, customer risk, source of funds and the risks arising from the firm's financial activities.

Law firms, accountants and TCSPs

For legal, accountancy and trust and company service providers, the audit reflects the risks arising from the services being provided as well as the client relationship itself. Thisincludes higher risk matters, property transactions, client accounts, company and trust structures, formation activity and the handling of source of funds and beneficial ownership.

Estate agents and letting agencies

Our AML audit for estate agents and letting agencies reflects the parties, funds and ownership structures involved in property transactions and qualifying letting activity. Particular attention is given to customer and beneficial ownership checks, transaction risk, source of funds and how higher risk property activity is identified and handled.

Other businesses within the MLRs

We also audit other businesses subject to the Money Laundering Regulations, including high value dealers, art market participants and other in scope businesses. The audit is tailored to the relevant regulatory category and to the particular products, transactions, customers and money laundering risks arising from the business activity.

Preparing for future FCA supervision?

The FCA expects the professional services transfer to begin in autumn 2028 and complete around 2030, subject to legislation. Existing supervision and obligations continue meanwhile. An audit can assess your current arrangements without waiting for the transition.

fca.org.uk/firms/aml-supervisory-reform

How we work

  • Scope. A no cost call establishes your business model, concern, existing assurance and required coverage. We confirm independence, deliverables, timetable and fees.
  • Review and test. We examine documents and, where included, interview staff, walk through processes and test samples. Any proposed expansion of scope is discussed with you first.
  • Report and discuss. You receive the report and a close out discussion of the findings, priorities and next steps. Follow up or retesting arrangements are agreed explicitly.
  • Typical delivery. Two to eight weeks, depending on complexity, testing and information availability.
  • Fees: Based on scope, firm size and testing requirements.

Why askMLRO?

FAQs

Your review is led by a practising MLRO with experience of senior compliance responsibilities and independent Regulation 21 audits in financial services, including brokerage.

That experience includes direct FCA engagement on AML and sanctions matters, and responding to FCA appointed Skilled Persons.

The lead practitioner is an ICA Fellow and ICA Certified MLRO and has also passed the CAMS examination.

You work directly with the practitioner responsible for the review, from agreeing the scope to discussing the conclusions.

Regulation 21(1)(c) requires an independent audit function where appropriate to the size and nature of the business. Its responsibilities cover evaluating AML policies, controls and procedures, recommending improvements and monitoring compliance with those recommendations. It does not impose an identical annual external audit on every firm.

An AML compliance audit examines the adequacy and effectiveness of your policies, controls and procedures. The agreed scope determines whether the work covers the complete framework or a specific area, and whether it includes testing how controls operate in practice.

It can contribute to your audit arrangements, but a narrow review does not automatically address the whole requirement. We agree how the work fits your wider assurance coverage and identify what remains outside scope.

Yes. We can provide remediation support under a separate engagement. We assess prior involvement before accepting independent audit work. Any later independent review of controls we helped design or implement needs appropriate independence arrangements.

No. It provides conclusions within an agreed scope, supported by the evidence reviewed. It cannot guarantee that a supervisor will reach the same conclusions or that regulatory intervention will be avoided.

Need an independent AML review?

Tell us about your business, the concern you want examined and any deadline. We will propose the scope, testing approach, timetable and fee.