Use Cases

AML/CFT Compliance Audit & Framework Enhancement: A Multi-Jurisdictional VASP Case Study

Case Study: AML/CFT Compliance Audit

How an AML/CFT Compliance Audit Helped a Multi-Jurisdictional VASP Meet an Institutional Counterparty’s Due Diligence Requirement

Regulatory registration does not, by itself, demonstrate that an AML/CFT program is operating effectively in practice. Often, virtual asset service providers (VASPs) learn this from an institutional counterparty rather than from a regulator. During due diligence, that counterparty may ask a simple question. Can you show us your program actually works?

Below, this case study explains how an AML/CFT compliance audit helped a multi-jurisdictional VASP group answer that question. Compliance7 acted as lead auditor throughout.

Engagement at a Glance

  • Client: Virtual Digital Asset Service Provider, part of a wider multi-jurisdictional group
  • Registration: FIU-IND
  • Group footprint: Several jurisdictions, including Europe and North America
  • Trigger: European institutional counterparty due diligence condition
  • Original scope: AML/CFT policy framework review
  • Re-scoped to: Comprehensive operational AML/CFT compliance audit
  • Role: Compliance7 as lead auditor

The Problem

A Registered Program, Tested for the First Time

The client was a Virtual Digital Asset Service Provider registered with FIU-IND. It operated as part of a wider group, with entities across several jurisdictions including Europe and North America. Initially, the engagement had a limited scope. Compliance7 would review the client’s existing AML/CFT policy framework.

Partway through, however, the scope requirement changed. The client needed a working relationship with a European institutional counterparty. That counterparty then made a comprehensive, independently conducted AML/CFT compliance audit a condition of doing business. A policy document review alone would not suffice.

This is a recurring due diligence scenario. Institutional counterparties, banks and payment partners may require evidence that a compliance program is operating effectively. Consequently, policy documentation alone may not satisfy them.

Once the audit began testing the program’s actual operation, rather than its documentation, the gaps became clearer, particularly on transaction monitoring, travel-rule compliance and blockchain analytics. That raised multiple questions. Did the monitoring, travel-rule compliance and blockchain analytics approach remain appropriate for the client’s transaction volumes, operational scale and risk profile?

Furthermore, the client had not filed a Suspicious Transaction Report (STR). Transaction activity during the review period was nonetheless substantial.

The absence of STR filings was not, by itself, treated as evidence of a compliance failure. However, it required independent testing to determine whether potentially suspicious activity was being identified, investigated, documented and escalated appropriately.

The Solution

How Compliance7 Ran the AML/CFT Compliance Audit

The client engaged Compliance7 as lead auditor. Compliance7 then re-scoped the work, turning a policy framework review into a comprehensive operational audit. The audit covered governance and oversight, customer due diligence and KYC, transaction monitoring, sanctions and PEP screening, travel-rule compliance, blockchain analytics, suspicious transaction reporting, record-keeping and staff training. It also covered other core program areas required under the applicable FIU-IND/PMLA framework.

Methodology

The methodology combined document and policy review with direct testing. Specifically, Compliance7 examined transaction monitoring logs and escalation records. In addition, it sampled customer files against stated CDD procedures. Above all, it tested whether the STR/SAR decision-making process operated as designed. A policy statement alone was not treated as proof.

Findings and Reporting

Compliance7 documented each finding against the applicable regulatory requirement. It then rated each finding by severity and attached a specific, actionable recommendation. As a result, the client’s leadership gained a clear view of what needed remediation and why.

Support for the Counterparty

The counterparty’s due diligence process was time-sensitive. To support it, Compliance7 issued formal confirmation of the audit engagement. That confirmation set out the agreed scope, methodology, deliverables and target completion timeline.

What the AML/CFT Compliance Audit Covered

The audit tested core program areas required under the applicable FIU-IND/PMLA framework. Where direct testing was possible, Compliance7 used it in place of document review alone.

Program AreaAudit Approach
Governance and oversightDocument and policy review
Customer due diligence and KYCCustomer files sampled against stated CDD procedures
Transaction monitoringMonitoring logs and escalation records examined directly
Sanctions and PEP screeningDocument and policy review
Suspicious transaction reportingSTR/SAR decision-making tested against its design
Record-keepingDocument and policy review
Staff trainingDocument and policy review

Other core program areas required under the applicable FIU-IND/PMLA framework were also within scope.

The Result

An Evidence-Based View of the Program in Practice

For the first time, the audit gave the client’s leadership an evidence-based, independently tested picture of its AML/CFT program. That picture showed where the program stood in practice, not just on paper.

Two findings mattered most: gaps in transaction monitoring, travel-rule compliance, blockchain analytics; and the absence of STR filings against transaction volumes. Compliance7 documented both with supporting evidence and a regulatory basis. Consequently, the client could prioritise remediation. It could also respond credibly to its institutional counterparty’s due diligence questions.

For VASPs, DNFBPs and fintechs operating across multiple jurisdictions, this is a pattern worth planning for rather than reacting to. An existing registration or a documented policy is a starting point. It is not proof that a program performs under independent testing.

Compliance7 conducts these audits against the framework applicable to each client’s jurisdiction and business model. These include FIU-IND/PMLA, AUSTRAC, FinCEN, applicable UAE regulatory requirements and other FATF-aligned AML/CFT frameworks. Above all, the methodology is built to withstand scrutiny from regulators and institutional counterparties alike.

Frequently Asked Questions (FAQ)

What is the difference between a policy review and a full AML/CFT compliance audit?

A policy review assesses whether written procedures meet regulatory requirements. A full operational audit goes further. It tests whether those procedures are actually being followed in practice. Specifically, it uses transaction sampling, file testing and review of escalation and reporting decisions.

Why would an institutional counterparty require an independent AML/CFT compliance audit?

Institutional counterparties, banks and payment partners increasingly treat independent audit evidence as part of their own due diligence and regulatory obligations. This applies particularly when they work with VASPs or other higher-risk regulated entities. It also applies when those entities operate across multiple jurisdictions.

Can an AML/CFT compliance audit uncover gaps in a registered or licensed entity?

Yes. Regulatory registration or licensing does not necessarily demonstrate that every AML/CFT control is operating effectively in practice. Independent testing can assess whether documented policies are being followed. It can also assess whether controls are operating as intended. Finally, it can identify gaps that require remediation.

Facing a Similar Due Diligence Requirement?

Has a counterparty, partner or regulator asked for independent evidence that your AML/CFT program works in practice, not just in policy? If so, Compliance7 can scope an AML/CFT compliance audit for you. Compliance7 calibrates it to your jurisdiction, business model and transaction risk profile.

Ajith Abraham is a Financial Crime Compliance professional with over 14 years of experience in Anti-Money Laundering (AML), Counter-Terrorist Financing (CFT), KYC, Customer Due Diligence (CDD), Enhanced Due Diligence (EDD), Transaction Monitoring, Sanctions Screening and Financial Crime Investigations. He is a Certified Anti-Money Laundering Specialist (CAMS) and Merkle Science Certified Crypto Investigator (CCI). Ajith has worked with Big Four consulting firms and advises Financial Institutions, fintechs, DNFBPs and Virtual Asset Service Providers (VASPs) on AML/CFT compliance, risk assessments, regulatory audits, financial crime risk management, crypto compliance, blockchain investigations and FATF-aligned compliance frameworks through Compliance7 Consulting LLP.