What does an AML audit involve?

Woman on laptop with man in background


We love an AML audit and really enjoy reviewing law firms’ policies and procedures to see the different approaches they take in respect of AML. Most of all, we find it extremely interesting to see how a firms’ culture surrounding compliance is changing.

In this blog, we delve into what an AML audit is, and what an AML audit involves. 

What is an AML Audit?

The AML audit process is a way to strengthen or improve a firm’s AML programme. It is a way of assessing whether Firm’s AML policies, controls and procedures are up to date, comply with The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLR) and are functioning in practice as intended.

What's the purpose of an AML audit?

The purpose of the Audit is to:

  • Examine and evaluate the adequacy and effectiveness of the policies, controls and procedures adopted by the Firm to ensure compliance with the requirements of the Money Laundering Regulations;
  • Make recommendations in relation to those policies, controls and procedures; and
  • Monitor compliance with those recommendations.

Why conduct an AML audit?

There are two types of audit: 

Mandatory Audit

Regulation 21 of the MLR requires a relevant person, where appropriate to the size and nature of the business, to establish an independent audit function. This does not necessarily need to be an external audit, however, it will need to be conducted by someone in the firm who is independent of the Risk/Compliance/Anti Money Laundering (AML) function, but equally has enough AML knowledge to be able to conduct the audit. It is important to note that any findings in an Audit Report carried out under regulation 21 are disclosable to the Regulator.

Non-Mandatory Audit (Internal Audit)

A Firm may choose to conduct an internal Money Laundering Audit as routine procedure, being a way of checking whether the Firm’s policies, controls and procedures are up to date and comply with the MLR. The Audit report in these circumstances would remain for internal purposes only and confidential to the firm.

What's does an AML audit involve?

There are four stages involved in an AML audit: 

1. Review of policies and procedures

Firstly, a review of all the firm’s AML policies and procedures, Firm Risk Assessment and the Firm’s matter-based Risk Assessment is conducted by the auditor.

When carrying out the review the auditor will assess whether the firm’s AML policies and procedures meet the requirements of the MLR.

The auditor will use a list/table of each specific regulation and check this against the firm’s AML policies and procedures to confirm whether or not the firm has met that requirement.

2. Test

As part of the audit the auditor should test the knowledge, understanding and application of the firm’s processes. This is normally tested through staff interviews and matter file reviews.


Interviewing staff will help the auditor assess the staff’s knowledge and understanding of money laundering, money laundering red flags and the firm’s processes.

File reviews

The auditor will carry out a review of files and assess whether the matters comply with the firm’s AML policies and procedures.

The auditor may also request to review some closed files. Reviewing a closed matter will assist the auditor in assessing whether there was on-going monitoring of risk and whether the completion instructions to accounts included information as to risk.

3. The Audit Report

The audit will result in a written report on whether:

  • The firm’s risk assessment and AML policies, controls and procedures comply with the minimum requirements of the MLR.
  • Changes which are required as a result of deficiencies identified (if any).

The audit report should:

  • Set out the law (what specific regulations of the MLR were checked against).
  • Explain what was examined for that specific regulation.
  • Document findings of areas of compliance and non-compliance as well as identifying areas for recommended improvement in behaviour and practice. It should be made clear which areas the firm is compliant, non-compliant or partially compliant.
  • Include an indication of where there are potential failings and a recommended course of action.

4. Review

The firm should conduct a review following an implementation period to establish compliance with the recommendations. As part of the review the auditor will be assessing whether the recommendations have been carried out and whether there is any evidence to show whether they are effective.

Get in touch

If you would like to discuss this further or feel your firm requires an independent AML audit, please get in touch and we’ll be happy to help.


Testimonial from Right Legal
"We have been using Teal to support our compliance frameworks, and every aspect of our experience with them has been fantastic. From the training to the audits, and especially the ‘Ask Teal’ helpline, nothing is too much trouble, and you get quick support from some of the industry’s best compliance experts. Just having them there to support our continued growth takes a huge weight off my mind. Highly recommend to firms of all size and structure!"
Get in touch
Testimonial from Constantine Law
"We rely on Teal Compliance to provide responsive, practical compliance services to Constantine Law (we do not have an in-house compliance officer/function). I would encourage all solicitor firms without their own resource to engage with Teal: they know what they are doing and they provide peace of mind regarding day-to-day compliance matters as well as responses to unforeseen (tricky) compliance matters. They have become an indispensable partner to Constantine Law in our growth journey."
Get in touch
Testimonial from Streathers Solicitors
"We have worked with Teal for several years. They have provided us with AML training and also helped us put together our firm-wide AML risk assessment and our updated AML policy, along with assisting us with various issues as and when they arose. We have always found them to be very helpful, friendly, responsive and knowledgeable, and are happy to recommend them."
Get in touch
Testimonial from Streathers Solicitors
"We have had a relationship with Teal for a number of years and they have provided a valuable resource to our compliance team. Teal combine the delivery of a personal and friendly service with city level expertise."
Get in touch
Previous slide
Next slide