Why examiners scrutinize your independent AML audit report and what they expect to find
Blogs

Why examiners scrutinize your independent AML audit report and what they expect to find

Key takeaway

Your independent AML audit report is among the first documents examiners review. Under the U.S. OCC’s 2026 community bank procedures, examiners may leverage satisfactory independent testing to reduce certain examination procedures. Weak testing makes the gap between expectations and performance immediately visible.

Your independent AML audit report is among the first documents a regulator reviews when assessing your BSA/AML compliance program. During examination scoping and planning, examiners review the independent testing report, its scope and supporting workpapers. They use this information, together with other available data, to assess the institution’s BSA/AML compliance program and determine the appropriate scope of examination testing.

Independent testing, often called an independent AML audit, is one of the four core components of an AML program identified in 31 U.S.C. § 5318(h): internal controls, a designated compliance officer, employee training and an independent audit function. Customer due diligence and beneficial ownership requirements are also important components of the broader AML/CFT compliance framework, with specific requirements varying by type of financial institution. Independent testing provides an important mechanism for assessing whether these elements are appropriately designed and operating effectively.

For U.S. banking organizations, the FFIEC BSA/AML Examination Manual provides the principal examination framework discussed in this article. Other regulated financial institutions are subject to sector-specific AML requirements and supervisory frameworks.

The 2026 OCC community bank development

That dynamic evolved further in 2026 for OCC-supervised community banks. OCC Bulletin 2025-37 took effect for examinations beginning 1 February 2026. It introduced Community Bank Minimum BSA/AML Examination Procedures that expressly emphasize examiner discretion. Specifically, examiners may place reliance on satisfactory independent testing when reaching conclusions on specific examination procedures. This does not mean complete exemption from examination; examiners retain discretion over examination scope and the extent of additional testing.

For OCC-supervised institutions with thorough and well-documented testing, this may allow examiners to reduce or redirect certain examination procedures. For institutions with weak or incomplete testing, the gap between expectations and the work product becomes immediately visible.

OCC Bulletin 2025-37 applies to OCC-supervised community banks, including national banks, federal savings associations and federal branches and agencies of foreign banking organizations. The bulletin defines community banks as institutions with up to $30 billion in assets. It does not create a universal FFIEC requirement for every US financial institution. The FFIEC framework discussed below is the principal BSA/AML examination framework for US banking organizations; other financial institutions are subject to sector-specific requirements and supervisory frameworks.

What the FFIEC examination manual requires

The FFIEC BSA/AML Examination Manual sets out seven examination procedures for independent testing. Together, they provide the principal examination framework examiners use to assess the adequacy of an institution’s independent-testing function. Understanding these procedures is essential for any compliance team preparing for examination.

Independence and conflict of interest

Examiners first assess whether the testing is genuinely independent. The manual requires that a person not involved with the function under review perform the testing. Testers must also be separate from other BSA-related functions that could create a conflict of interest.

The FFIEC manual contemplates several arrangements that satisfy this requirement. These include internal audit, outside auditors, consultants, other qualified independent parties and qualified bank staff in certain circumstances. Either internal or external testers can meet the standard. The key conditions are independence from the functions being tested and from other BSA-related functions that could create a conflict of interest, and direct reporting to the board of directors or a designated board committee.

Scope and adequacy

Examiners then evaluate whether the independent testing addresses overall program adequacy. The manual states that the report should typically include an explicit statement about the bank’s overall compliance with BSA requirements. At a minimum, it must contain sufficient information to reach a conclusion about overall adequacy.

Many institutions fall short here. A narrow scope that tests only a few areas while ignoring others signals a lack of risk understanding. Depending on risk profile, independent testing may evaluate the BSA/AML risk assessment, changes in bank activities since the last test and adherence to reporting requirements. It may also cover IT systems, training adequacy and management’s progress on prior findings. The FFIEC manual lists these as considerations “as applicable.”

Transaction monitoring and SAR review

Two of the seven examination procedures focus on suspicious activity monitoring. Examiners want to see that independent testing evaluates the transaction monitoring system’s methodology and reporting capabilities. They also check whether filtering criteria are reasonable, risk-tailored and cover higher-risk products, services, customers and locations.

Beyond the system itself, examiners expect the testing to review the entire SAR process. This includes alert identification, alert management, research, SAR decision making, filing and monitoring of continuous activity. It also covers how staff refer potentially suspicious activity from business lines to evaluation personnel.

Where transaction monitoring and SAR processes are material risk areas, the testing methodology should include appropriate substantive testing to determine whether controls operate effectively. This may involve sampling transactions, reviewing alert dispositions and evaluating SAR decisions. Scope and depth will vary with risk profile, size and complexity.

Workpapers and documentation

Examiners do not evaluate the testing report in isolation. The FFIEC manual states that all testing documentation and supporting workpapers should be available for review. The OCC’s 2026 community bank procedures specifically contemplate reviewing auditor reports, scope documentation, workpapers, management responses and testing results when deciding what to leverage. Thin, incomplete or unavailable workpapers undermine even a well-written report.

What the 2026 OCC community bank procedures change

OCC Bulletin 2025-37 applies to OCC-supervised community banks and represents a notable development for independent testing. By expressly allowing examiners to leverage satisfactory testing for specific procedures, the bulletin increases the practical importance of independent-testing quality.

How leveraging works in practice

The effect is more nuanced than a blanket reduction in examination burden. Examiners determine which aspects of testing are adequate and may leverage some areas but not others. For example, the OCC notes that examiners may leverage CTR-process testing while declining to leverage suspicious-activity-monitoring testing if the latter is inadequate.

As a practical matter, the ability to leverage independent testing makes the quality and documentation of that testing more consequential for OCC-supervised community banks. The 2026 OCC procedures make this discretion more explicit for OCC-supervised community banks. Examiners must still assess the quality and scope of the independent testing before determining whether and to what extent it can be leveraged. A weak test may cause examiners to question reliability and perform additional examination procedures.

Enforcement actions that illustrate the consequences

The FFIEC/OCC discussion above applies to banks. Broker-dealers face separate independent-testing requirements under FINRA rules. However, recent FINRA enforcement actions show how inadequate AML testing creates regulatory exposure across institution types.

Recent FINRA actions

In March 2025, FINRA censured and fined Redbridge Securities $475,000 for AML and supervisory deficiencies. The regulator alleged that the firm failed to conduct reasonable independent testing over multiple years. Separately, FINRA fined Sanctuary Securities $150,000 after finding that the firm retained an outside consultant for testing, but the test failed to address material aspects of the AML program. In January 2026, FINRA separately censured three Cetera broker-dealers and imposed a combined $1.1 million fine for supervisory and AML program deficiencies, including failures involving suspicious activity detection and reporting.

Recurring deficiencies identified through AML testing and examinations

Across these actions and broader examination findings, several patterns emerge. Recurring AML deficiencies include incomplete CDD documentation, inconsistent customer risk ratings and inadequate enhanced due diligence files. Weak transaction monitoring investigations, delayed SAR submissions and ineffective sanctions screening also appear frequently.

Three testing-specific issues recur. First, a lack of genuine independence on the part of the tester. Second, scope that fails to cover all material risk areas. Third, reliance on policy review rather than substantive sampling of alerts, SARs and customer files.

Testing AI and machine learning in transaction monitoring

Institutions increasingly deploy AI and machine-learning models for transaction monitoring. These approaches may reduce false positives and improve alert prioritization. However, their effectiveness depends on data quality, model design, validation, monitoring and governance.

Model risk governance expectations

Where institutions use AI or machine-learning models for AML monitoring, they should address model governance, validation, ongoing monitoring, data quality and explainability. Where appropriate based on the model’s risk and use, institutions should also maintain effective human oversight of material model-driven decisions. If model risk management guidance applies, independent testing should assess whether appropriate validation, monitoring and governance arrangements are in place.

OCC Bulletin 2026-13 and the revised interagency Model Risk Management guidance provide updated supervisory guidance relevant to institutions that use AI or other models in compliance and transaction-monitoring activities. The revised guidance is expected to be most relevant to banking organizations, but it may also apply to smaller institutions with significant model risk because of the complexity or prevalence of their models. The guidance is risk-based and does not establish prescriptive model-validation requirements. Notably, the 2026 guidance does not currently cover generative AI or agentic AI models, which the agencies identify as novel and rapidly evolving. Independent testers should assess not only whether the model produces results but whether those results hold up under regulatory scrutiny. Weak data quality or unreliable training labels can produce misleading performance metrics and undermine the effectiveness of model outputs.

Building an independent AML audit report that examiners can leverage

Given the evolving supervisory framework, compliance teams and their testing partners should aim for a higher standard. Several elements are essential.

Scope and methodology

First, the report should contain an explicit statement about the institution’s overall compliance with BSA regulatory requirements. This is one of the matters examiners consider in their review. A report that describes procedures without reaching an overall conclusion may leave the examiner without the clear assessment the independent testing is expected to provide.

Second, teams should clearly document a risk-based scope. The report should explain why the team selected specific areas for testing and how the scope aligns with the current risk assessment. If the institution has introduced new products, entered new markets or experienced significant changes, the scope should address those developments.

Third, where transaction monitoring and SAR processes present material risk, the testing methodology should include appropriate substantive testing. This may involve sampling transactions, reviewing alert dispositions and evaluating SAR decisions to determine whether controls operate effectively.

Findings and follow-up

Findings should be specific, prioritized and accompanied by actionable recommendations. The report should track the status of prior findings and note whether management addressed them in a timely manner. Examiners also assess management’s progress in addressing prior independent-testing and examination findings.

Delivery and workpapers

All supporting workpapers should be complete, well-organized and available for examiner review. Workpapers are not a secondary deliverable. Under the OCC’s 2026 community bank procedures, they are part of what examiners evaluate when determining whether to leverage independent testing.

Finally, the testing team should deliver the report directly to the board of directors or a designated board committee. Board-level visibility is both an FFIEC examination procedure and a regulatory expectation.

What compliance teams should do now

The OCC’s 2026 community bank procedures apply to OCC-supervised institutions, but the underlying FFIEC principles extend across banking regulators. Changes to applicable AML and beneficial ownership requirements, including the 2026 beneficial ownership reporting changes, should be considered when determining whether the scope of independent testing remains current. Across the banking examination framework, the core principles are consistent: independent testing should be appropriately independent, risk-based, sufficiently comprehensive and well-documented.

Compliance officers should review their most recent independent testing against the seven FFIEC examination procedures. If the testing does not adequately address the areas applicable to the institution’s risk profile, if it lacks an explicit compliance statement, or if transaction testing was limited relative to risk profile, strengthen the next testing cycle before the next examination.

For institutions using external testers, evaluate whether the firm has the expertise and resources to deliver testing that examiners would consider reliable. Institutions relying on internal audit should ensure structural independence and confirm that testers have no operational involvement in the BSA/AML program. The FFIEC framework does not prescribe a universal testing frequency; frequency should be commensurate with the bank’s ML/TF and other illicit-financial-activity risk profile and overall risk-management strategy.

Independent testing is not valuable merely because it exists. Its value lies in whether the scope, methodology, evidence, findings and workpapers give examiners a reasonable basis to assess the quality of the institution’s BSA/AML program.

Strengthen Your Independent AML Testing

Prepare for regulatory scrutiny with independent AML testing designed around your risk profile, applicable requirements and examiner expectations.

Our CAMS-certified AML specialists can assess your AML testing framework, identify gaps and help strengthen the evidence, methodology and documentation behind your program.

Book a free consultation

This article is for informational purposes only and does not constitute legal or regulatory advice. For guidance specific to your business, consult a qualified compliance professional.

Sources (10)

 

Ajith Abraham is a Financial Crime Compliance professional with over 14 years of experience in Anti-Money Laundering (AML), Counter-Terrorist Financing (CFT), KYC, Customer Due Diligence (CDD), Enhanced Due Diligence (EDD), Transaction Monitoring, Sanctions Screening and Financial Crime Investigations. He is a Certified Anti-Money Laundering Specialist (CAMS) and Merkle Science Certified Crypto Investigator (CCI). Ajith has worked with Big Four consulting firms and advises Financial Institutions, fintechs, DNFBPs and Virtual Asset Service Providers (VASPs) on AML/CFT compliance, risk assessments, regulatory audits, financial crime risk management, crypto compliance, blockchain investigations and FATF-aligned compliance frameworks through Compliance7 Consulting LLP.

Leave a Reply

Your email address will not be published. Required fields are marked *