Case Study: AML/CFT Compliance Audit
How an AML/CFT Compliance Audit Helped a Multi-Jurisdictional VASP Meet an Institutional Counterparty’s Due Diligence Requirement
Regulatory registration does not, by itself, demonstrate that an AML/CFT program is operating effectively in practice. Often, virtual asset service providers (VASPs) learn this from an institutional counterparty rather than from a regulator. During due diligence, that counterparty may ask a simple question. Can you show us your program actually works?
Below, this case study explains how an AML/CFT compliance audit helped a multi-jurisdictional VASP group answer that question. Compliance7 acted as lead auditor throughout.
Engagement at a Glance
- Client: Virtual Digital Asset Service Provider, part of a wider multi-jurisdictional group
- Registration: FIU-IND
- Group footprint: Several jurisdictions, including Europe and North America
- Trigger: European institutional counterparty due diligence condition
- Original scope: AML/CFT policy framework review
- Re-scoped to: Comprehensive operational AML/CFT compliance audit
- Role: Compliance7 as lead auditor
The Problem
A Registered Program, Tested for the First Time
The client was a Virtual Digital Asset Service Provider registered with FIU-IND. It operated as part of a wider group, with entities across several jurisdictions including Europe and North America. Initially, the engagement had a limited scope. Compliance7 would review the client’s existing AML/CFT policy framework.
Partway through, however, the scope requirement changed. The client needed a working relationship with a European institutional counterparty. That counterparty then made a comprehensive, independently conducted AML/CFT compliance audit a condition of doing business. A policy document review alone would not suffice.
This is a recurring due diligence scenario. Institutional counterparties, banks and payment partners may require evidence that a compliance program is operating effectively. Consequently, policy documentation alone may not satisfy them.
Once the audit began testing the program’s actual operation, rather than its documentation, the gaps became clearer, particularly on transaction monitoring, travel-rule compliance and blockchain analytics. That raised multiple questions. Did the monitoring, travel-rule compliance and blockchain analytics approach remain appropriate for the client’s transaction volumes, operational scale and risk profile?
Furthermore, the client had not filed a Suspicious Transaction Report (STR). Transaction activity during the review period was nonetheless substantial.
The absence of STR filings was not, by itself, treated as evidence of a compliance failure. However, it required independent testing to determine whether potentially suspicious activity was being identified, investigated, documented and escalated appropriately.
The Solution
How Compliance7 Ran the AML/CFT Compliance Audit
The client engaged Compliance7 as lead auditor. Compliance7 then re-scoped the work, turning a policy framework review into a comprehensive operational audit. The audit covered governance and oversight, customer due diligence and KYC, transaction monitoring, sanctions and PEP screening, travel-rule compliance, blockchain analytics, suspicious transaction reporting, record-keeping and staff training. It also covered other core program areas required under the applicable FIU-IND/PMLA framework.
Methodology
The methodology combined document and policy review with direct testing. Specifically, Compliance7 examined transaction monitoring logs and escalation records. In addition, it sampled customer files against stated CDD procedures. Above all, it tested whether the STR/SAR decision-making process operated as designed. A policy statement alone was not treated as proof.
Findings and Reporting
Compliance7 documented each finding against the applicable regulatory requirement. It then rated each finding by severity and attached a specific, actionable recommendation. As a result, the client’s leadership gained a clear view of what needed remediation and why.
Support for the Counterparty
The counterparty’s due diligence process was time-sensitive. To support it, Compliance7 issued formal confirmation of the audit engagement. That confirmation set out the agreed scope, methodology, deliverables and target completion timeline.
What the AML/CFT Compliance Audit Covered
The audit tested core program areas required under the applicable FIU-IND/PMLA framework. Where direct testing was possible, Compliance7 used it in place of document review alone.
| Program Area | Audit Approach |
|---|---|
| Governance and oversight | Document and policy review |
| Customer due diligence and KYC | Customer files sampled against stated CDD procedures |
| Transaction monitoring | Monitoring logs and escalation records examined directly |
| Sanctions and PEP screening | Document and policy review |
| Suspicious transaction reporting | STR/SAR decision-making tested against its design |
| Record-keeping | Document and policy review |
| Staff training | Document and policy review |
Other core program areas required under the applicable FIU-IND/PMLA framework were also within scope.
The Result
An Evidence-Based View of the Program in Practice
For the first time, the audit gave the client’s leadership an evidence-based, independently tested picture of its AML/CFT program. That picture showed where the program stood in practice, not just on paper.
Two findings mattered most: gaps in transaction monitoring, travel-rule compliance, blockchain analytics; and the absence of STR filings against transaction volumes. Compliance7 documented both with supporting evidence and a regulatory basis. Consequently, the client could prioritise remediation. It could also respond credibly to its institutional counterparty’s due diligence questions.
For VASPs, DNFBPs and fintechs operating across multiple jurisdictions, this is a pattern worth planning for rather than reacting to. An existing registration or a documented policy is a starting point. It is not proof that a program performs under independent testing.
Compliance7 conducts these audits against the framework applicable to each client’s jurisdiction and business model. These include FIU-IND/PMLA, AUSTRAC, FinCEN, applicable UAE regulatory requirements and other FATF-aligned AML/CFT frameworks. Above all, the methodology is built to withstand scrutiny from regulators and institutional counterparties alike.
Frequently Asked Questions (FAQ)
What is the difference between a policy review and a full AML/CFT compliance audit?
A policy review assesses whether written procedures meet regulatory requirements. A full operational audit goes further. It tests whether those procedures are actually being followed in practice. Specifically, it uses transaction sampling, file testing and review of escalation and reporting decisions.
Why would an institutional counterparty require an independent AML/CFT compliance audit?
Institutional counterparties, banks and payment partners increasingly treat independent audit evidence as part of their own due diligence and regulatory obligations. This applies particularly when they work with VASPs or other higher-risk regulated entities. It also applies when those entities operate across multiple jurisdictions.
Can an AML/CFT compliance audit uncover gaps in a registered or licensed entity?
Yes. Regulatory registration or licensing does not necessarily demonstrate that every AML/CFT control is operating effectively in practice. Independent testing can assess whether documented policies are being followed. It can also assess whether controls are operating as intended. Finally, it can identify gaps that require remediation.
Facing a Similar Due Diligence Requirement?
Has a counterparty, partner or regulator asked for independent evidence that your AML/CFT program works in practice, not just in policy? If so, Compliance7 can scope an AML/CFT compliance audit for you. Compliance7 calibrates it to your jurisdiction, business model and transaction risk profile.