– Last Updated: July 2026
Anti-Money Laundering (AML), Countering the Financing of Terrorism (CFT) and Countering Proliferation Financing (CPF) compliance frameworks have evolved beyond static documentation and routine transaction monitoring. Regulatory bodies worldwide now evaluate whether an entity’s internal controls function effectively under operational conditions.
An independent AML/CFT/CPF review provides an objective evaluation of an organization’s risk assessment, customer due diligence (CDD) procedures, transaction monitoring systems and governance structures.
The baseline for this expectation stems from Financial Action Task Force (FATF) Recommendation 18 (which establishes internal control and independent audit function requirements for financial institutions) read together with Recommendation 23 (which extends these preventive control and independent testing obligations to designated non-financial businesses and professions or DNFBPs, to the extent applicable under national law).
Despite this unified principle, cross-border businesses face significant regulatory nuance. FATF sets high-level guidance, leaving individual national regulators to define review frequencies, independence criteria and reviewer qualifications across four distinct operational tiers:
| Evaluation Tier | Legal Framework & Scope |
| 1. Statutory Requirement | Explicit statutory law or binding primary regulation establishing control testing rules. |
| 2. Regulatory Guidance | Formal supervisory guidelines, sectoral codes or rulebook criteria. |
| 3. Supervisory Expectation | Operational scrutiny and testing standards applied during routine examinations. |
| 4. Market Practice | Common governance and testing benchmarks established across high-risk industry sectors. |
Key findings
- No Universal FATF Cycle: FATF Recommendations 18 and 23 require an independent audit function to test controls, but do not prescribe a mandatory 12-month audit cycle.
- Prescribed Statutory & Multi-Year Cycles: Canada (2-year FINTRAC effectiveness review), Mauritius (2-year cycle) and New Zealand (3-year default audit cycle under Section 59, extendable to 4 years upon supervisory notification) are among the few markets with explicit multi-year statutory or regulatory review intervals.
- Supervisory Practice in Offshore Centers: Financial centers such as the UAE, Bermuda, Cayman Islands and BVI frequently expect annual independent reviews through supervisory practice and license-specific rulebooks.
- Risk-Based Flexibility: Major jurisdictions, including the United States, United Kingdom, Singapore and Australia, rely on a Risk-Based Approach (RBA), where review frequency is determined by the entity’s enterprise risk assessment.
- Internal vs. External Review: Internal audit teams generally satisfy independence criteria across most jurisdictions, provided the reviewers are operationally separated from daily AML execution and report directly to the Board or Audit Committee.
Terminology used in this article
Different jurisdictions and regulatory bodies use different terminology for independent assessments of financial crime controls. Depending on the applicable legislation or supervisory guidance, these assessments may be referred to as:
- Independent AML Audit
- Independent Review
- Independent Testing
- Effectiveness Review
- Compliance Program Review
Although the terminology differs across regions, each generally refers to an objective assessment of the design and operational effectiveness of an organization’s AML/CFT/CPF framework. Throughout this article, these terms are used in the context of the relevant jurisdiction’s legal or regulatory language.
Does FATF mandate an annual AML audit?
A common misconception among compliance officers is that FATF mandates a strict 12-month audit cycle across all regulated entities.
FATF Recommendation 18 requires financial institutions to maintain an “independent audit function to test the system,” but FATF does not prescribe a mandatory annual frequency.
Instead, FATF relies on the Risk-Based Approach (RBA):
- Higher-Risk Entities: Complex financial groups, major payment gateways or Virtual Asset Service Providers (VASPs) are expected to undergo frequent, rigorous testing proportional to their risk profile.
- Lower-Risk Entities: Institutions with simpler business models may conduct independent reviews on multi-year cycles, provided the interval is supported by a comprehensive Enterprise-Wide Risk Assessment (EWRA).
Because FATF issues international standards rather than direct legislation, member states transpose Recommendations 18 and 23 differently. Certain authorities dictate specific calendar intervals, while others assess review frequency during routine risk-based supervision.
Global comparison table
Methodology & regulatory disclaimer: This comparison is based on publicly available legislation, regulatory guidance and supervisory publications available as of July 2026. Organizations should always consider sector-specific requirements and seek legal or regulatory advice where appropriate, as implementation may vary by license type, operational scale and supervisory authority.
| Jurisdiction | Independent AML Testing Required under Framework?* | Primary Regulatory Body | Expected Review Frequency | Common Market Practice | Relevant Statutory / Regulatory Source |
| United Arab Emirates (UAE) | Yes | CBUAE / Ministry of Economy | Annual | Annual independent review | Cabinet Decision No. (10) of 2019; CBUAE Guidance |
| DIFC / ADGM (UAE Free Zones) | Yes | DFSA / FSRA | Annual or Risk-Based | Annual independent testing | DFSA AML Module; FSRA Anti-Money Laundering Rules |
| Bermuda | Yes | BMA | Risk-Based | Annual review for DABs & Banks | Proceeds of Crime (AML/ATF) Regulations 2008 |
| Cayman Islands | Yes | CIMA | Risk-Based | Annual review for Funds & FSPs | Cayman Islands Anti-Money Laundering Regulations |
| British Virgin Islands (BVI) | Yes | BVI FSC | Risk-Based | Annual review for licensed TCSPs & Funds | BVI AML Regulations & Code of Practice |
| Jersey | Yes | JFSC | Risk-Based | Annual or biennial testing | Money Laundering (Jersey) Order 2008 |
| Guernsey | Yes | GFSC | Risk-Based | Biennial or annual review | GFSC Handbook on Countering Financial Crime |
| Isle of Man | Yes | IOMFSA | Risk-Based | Periodic review (1-2 year cycle) | Anti-Money Laundering and Countering Financing of Terrorism Code |
| Gibraltar | Yes | GFSC (Gibraltar) | Risk-Based | Annual for DLT Providers & Banks | Proceeds of Crime Act 2015 |
| Labuan (Malaysia) | Yes | Labuan FSA | Risk-Based / Event-Driven | Regular review based on key risk indicators | Labuan FSA Guidelines on AML/CFT/CPF |
| Qatar Financial Centre (QFC) | Yes | QFCRA | Risk-Based | Annual independent review commonly expected for higher-risk firms | QFCRA Anti-Money Laundering & CFT Rules 2019 |
| United States | Yes | FinCEN / FFIEC Agencies | Risk-Based | Many institutions perform annual testing; lower-risk use longer intervals | 31 C.F.R. § 1020.210; FFIEC BSA/AML Manual |
| United Kingdom | Yes | FCA / HMRC / Gambling Comm. | Risk-Based (Reg 21) | Periodic review (1-2 years for high risk) | Money Laundering Regulations 2017 (Reg 21) |
| Australia | Yes | AUSTRAC | Risk-Based | Independent review every 1-3 years based on risk | AML/CTF Act 2006; AML/CTF Rules Chapter 8 |
| Canada | Yes | FINTRAC | Every 2 Years | Biennial compliance program effectiveness review | PCMLTFA Regulations (s. 156 / FINTRAC Guidance) |
| Ireland | Yes | Central Bank of Ireland | Risk-Based | Periodic review based on EWRA | Criminal Justice (Money Laundering and Terrorist Financing) Act |
| European Union | Yes | National Supervisors / AMLA | Risk-Based | Periodic review based on risk | Directive (EU) 2015/849; Regulation (EU) 2024/1620; Regulation (EU) 2024/1624 (AMLR) |
| Luxembourg | Yes | CSSF / AED | Risk-Based | Periodic independent review | Law of 12 November 2004; CSSF Regulation 12-02 |
| Switzerland | Yes | FINMA | Risk-Based / Annual | External regulatory audit paired with internal audit control testing | Anti-Money Laundering Act (AMLA); FINMA AMLO |
| Estonia | Yes | Financial Intelligence Unit | Risk-Based | Annual or biennial testing | Money Laundering and Terrorist Financing Prevention Act |
| Lithuania | Yes | Bank of Lithuania | Risk-Based | Annual or periodic review | Law on the Prevention of Money Laundering (No. VIII-275) |
| Cyprus | Yes | CySEC / Central Bank of Cyprus | Risk-Based | Periodic independent review | Prevention and Suppression of Money Laundering Activities Law |
| Singapore | Yes | MAS | Risk-Based | Annual testing common among major FIs | MAS Act; MAS Sectoral AML/CFT Notices (e.g., Notice 626) |
| Hong Kong | Yes | HKMA / SFC | Risk-Based | Annual review common for AIs & Licensed Firms | Anti-Money Laundering and Counter-Terrorist Financing Ordinance |
| New Zealand | Yes | DIA (sole supervisor) / RBNZ / FMA | Every 3 Years (4 years if notified) | Independent audit conducted every 3 years | AML/CFT Act 2009, section 59; Sector Audit Guidance |
| Mauritius | Yes | FSC / Bank of Mauritius | Risk-Based | Commonly undertaken every two years by regulated entities | Financial Intelligence and Anti-Money Laundering Act 2002 |
| India | Integrated | RBI / SEBI | Supervisory / Concurrent Audit | Concurrent / Internal Audit integration | RBI Master Direction – KYC; SEBI AML Guidelines |
| South Africa | Yes | FIC / Prudential Authority | Risk-Based | Periodic independent testing or assurance consistent with supervisory expectations | Financial Intelligence Centre Act 38 of 2001 (FICA) |
*A “Yes” entry indicates that the jurisdiction’s AML/CFT framework requires independent testing, review, audit or equivalent control assurance, although specific terminology, scope and operational implementation vary by sector and underlying statutory language.
–
Are you looking for AML audit compliance?
Whether you operate in a strict annual jurisdiction or navigate a risk-based framework, Compliance7 provides expert, independent AML/CFT/CPF audit and review services tailored to your specific regulatory footprint.
Schedule a consultation with Compliance7 team today
–
Jurisdictions with prescribed or high-frequency supervisory expectations
While explicit statutory mandates vary, several financial centers maintain high supervisory expectations regarding independent review cycles.
United Arab Emirates (Onshore, DIFC, ADGM)
Under Cabinet Decision No. (10) of 2019 and guidelines from the Central Bank of the UAE (CBUAE) and Ministry of Economy, regulated entities must maintain an independent audit function. In supervisory practice, regulators generally expect reporting entities to conduct an independent review annually to evaluate internal controls, policies and risk assessments. In the financial free zones (DIFC/DFSA and ADGM/FSRA), independent reviews are similarly assessed during routine risk-based supervision.
Bermuda
Under the Proceeds of Crime (Anti-Money Laundering and Anti-Terrorist Financing) Regulations 2008, the Bermuda Monetary Authority (BMA) requires regulated entities to conduct independent testing. For high-risk sectors, such as Digital Asset Businesses (DABs) and commercial banks, annual independent reviews are commonly performed to satisfy supervisory expectations.
Cayman Islands
The Cayman Islands Anti-Money Laundering Regulations require Financial Services Providers (FSPs) to maintain an independent audit function to test their AML/CFT systems. While CIMA applies a risk-based approach to schedule review frequencies, investment funds and trust licensees commonly conduct independent reviews annually as a matter of market practice.
British Virgin Islands (BVI)
Under the BVI Anti-Money Laundering Regulations and Code of Practice, the BVI Financial Services Commission (FSC) expects licensees to maintain independent testing of their compliance frameworks. Licensees frequently execute these reviews on an annual cycle to align with annual regulatory return filings.
Channel Islands (Jersey & Guernsey) & Isle of Man
The Jersey Financial Services Commission (JFSC), Guernsey Financial Services Commission (GFSC) and Isle of Man Financial Services Authority (IOMFSA) mandate that entities maintain an independent audit function. While regulatory codes incorporate a risk-based framework, financial institutions and trust/company service providers (TCSPs) in these jurisdictions typically conduct independent testing every 12 to 24 months depending on their risk assessment.
Labuan (Malaysia) & Qatar Financial Centre (QFC)
The Labuan Financial Services Authority (Labuan FSA) and QFC Regulatory Authority (QFCRA) require reporting entities to maintain an independent review function. Under Labuan FSA guidelines, entities determine review frequency based on structural business changes, shifting Key Risk Indicators (KRIs) or risk exposure. In the QFC, an annual independent review report is commonly expected for higher-risk or cross-border firms under QFCRA AML Rules.
Jurisdictions applying a risk-based review framework
In major financial centers, legislation mandates an independent review function, but leaves the operational frequency to the institution’s enterprise risk profile.
United States
Under the Bank Secrecy Act (BSA) (31 C.F.R. § 1020.210), financial institutions must provide for “independent testing for compliance to be conducted by bank personnel or by an outside party.” While federal examination manuals (FFIEC) evaluate testing frequency during examinations, the regulations do not establish a statutory 12-month requirement. Many institutions perform annual testing as standard practice, while lower-risk institutions may adopt longer intervals based on their documented risk profile.
United Kingdom
Regulation 21 of the Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017 requires relevant persons to establish an independent audit function to evaluate controls where appropriate with regard to the size and nature of the business. The Financial Conduct Authority (FCA) expects high-risk entities, payment institutions and registered crypto-asset firms to test controls periodically based on risk. While 12-to-24-month cycles are standard market practice for high-risk entities, this specific interval is not explicitly prescribed by Regulation 21.
Australia
Under Part 8.6 of the Anti-Money Laundering and Counter-Terrorism Financing Rules (AML/CTF Rules), reporting entities must undertake an independent review of Part A of their AML/CTF program. AUSTRAC requires the frequency, scope and nature of the review to be determined by the entity’s documented ML/TF risk assessment, typically spanning between 1 and 3 years.
Switzerland
Under the Swiss Anti-Money Laundering Act (AMLA) and FINMA regulations, financial intermediaries undergo regulatory reviews. Formal supervisory audits are conducted by accredited external audit firms (Prüfgesellschaften). Internally, banks and financial institutions also utilize functionally independent internal audit teams to test operational AML controls on an ongoing, risk-weighted basis.
Singapore & Hong Kong
Under Monetary Authority of Singapore (MAS) Notices (e.g., Notice 626) and Hong Kong’s Anti-Money Laundering and Counter-Terrorist Financing Ordinance (AMLO Cap. 615), institutions must maintain an independent audit function. While statutes do not mandate a universal annual audit for every entity, conducting annual independent testing is standard practice among major banks and payment service providers.
Jurisdictions with prescribed multi-year statutory cycles
Certain jurisdictions establish specific multi-year review cycles directly within their statutory text or binding supervisory frameworks:
Canada
Under section 156 of the Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations (PCMLTFA), reporting entities must conduct a Compliance Program Effectiveness Review at least every two years.
Terminology Note: FINTRAC guidelines refer to this as an “effectiveness review” rather than a formal “independent AML audit.” Depending on entity size and complexity, this review may be conducted internally or externally, provided the reviewer is objective and knowledgeable.
New Zealand
Under Section 59 of the Anti-Money Laundering and Countering Financing of Terrorism Act 2009, reporting entities must independently audit their AML/CFT risk assessment and compliance program. Under supervisory guidance issued by New Zealand regulators (the Department of Internal Affairs, DIA, acting as primary supervisor alongside the RBNZ and FMA), an independent audit must be conducted every three years, unless the supervisor formally notifies the reporting entity that a four-year timeframe applies.
Mauritius
Under the Financial Intelligence and Anti-Money Laundering Act 2002 (FIAMLA) guidelines, management companies and global business licensees must undergo independent AML reviews. These assessments are commonly undertaken every two years by regulated entities unless supervisory directions require more frequent testing.
Jurisdictions with evolving supervisory expectations
Driven by FATF mutual evaluations and regional body assessments, several markets have increased supervisory scrutiny on independent internal controls without necessarily enacting a universal annual statutory audit mandate:
India: India does not enforce a universal statutory requirement for a standalone annual independent AML audit across all reporting entities. Instead, the Reserve Bank of India (RBI) and SEBI enforce AML control testing through a combination of internal audits, concurrent audits, compliance reviews and Risk-Based Supervision (RBS) examinations.
Saudi Arabia: SAMA and the Capital Market Authority (CMA) expect periodic independent testing of financial crime controls as part of institutional governance and internal audit functions, rather than maintaining a single universal statutory mandate.
Bahrain: The Central Bank of Bahrain (CBB) Rulebook requires independent AML reviews, but the requirement for an external audit depends on the specific license category and risk profile rather than applying universally across all firms.
Oman & Japan: Following FATF evaluations, regulators have demonstrated an increasing supervisory focus on demonstrating the effectiveness of transaction monitoring, sanctions screening and other core AML controls during routine examinations.
South Africa: Following FATF gray listing remediation efforts, the Financial Intelligence Centre (FIC) and South African Reserve Bank (SARB) have significantly increased supervisory scrutiny regarding how accountable institutions demonstrate control effectiveness, requiring periodic independent testing or assurance consistent with supervisory expectations.
Annual fixed vs. Risk-based audit models
Compliance functions must balance statutory compliance with operational risk profiles:
| Feature | Annual Fixed Audit Model | Risk-Based Audit Model |
| Schedule | Fixed 12-month calendar cycle. | Variable cycle (12 to 36+ months) based on EWRA. |
| Regulatory Clarity | High; straightforward to demonstrate compliance. | Requires documented justification during supervisory exams. |
| Resource Planning | Predictable annual budget allocation. | Fluctuates depending on review cycles and risk triggers. |
| Best Suited For | High-risk sectors (Crypto/VASPs, MSBs, Offshore Funds). | Lower-risk entities, boutique advisory firms, holding companies. |
| Primary Advantage | Identifies operational gaps prior to regulatory inspection. | Focuses resources on areas of highest risk exposure. |
| Primary Limitation | Risks becoming a formulaic exercise if scope is static. | Risk of delaying testing if internal risk scores are miscalculated. |
Internal vs. External independent review
A key structural question for management is whether an independent review can be performed by an internal audit department or requires an external third-party firm.
| Model | Primary Advantage | Key Requirement |
| Internal Audit Department | Deep context on firm operations; cost-effective for large institutions. | Must have strict operational independence from the compliance team and report directly to the Board/Audit Committee. |
| External Third-Party Firm | Unbiased perspective; specialized technical expertise (e.g., algorithm testing). | Must be verified as free of conflicts of interest (cannot audit their own consulting work). |
Core Independence Rule: Neither the Money Laundering Reporting Officer (MLRO/AMLCO) nor operational compliance personnel involved in daily customer onboarding and transaction monitoring can conduct or audit their own policies and controls.
Industry sectors subject to independent review
Independent testing expectations apply across financial institutions and designated non-financial entities:
- Banking Institutions: Retail, commercial, investment and private banks.
- FinTechs & Payment Institutions: Payment gateways, e-money issuers, neo-banks, remittance providers.
- Crypto Exchanges & CASPs/VASPs: Virtual Asset Service Providers, crypto brokers, custody providers.
- Securities & Asset Management: Broker-dealers, investment funds, wealth managers.
- Insurance Companies: Life insurance and annuity underwriters.
- Trust & Company Service Providers (TCSPs): Corporate service providers, trustees, foundation managers.
- Designated Non-Financial Businesses and Professions (DNFBPs): Casinos, real estate agents, precious metals dealers, lawyers and accountants (where applicable under national law).
Common regulatory expectations
During an AML/CFT/CPF review, testing typically covers 13 core operational areas:
- Governance & Board Oversight: Assessing executive accountability, board reporting and compliance oversight.
- Enterprise-Wide Risk Assessment (EWRA): Evaluating whether product, client, geographic and channel risks are accurately measured.
- Customer Due Diligence (CDD): Sampling onboarding files to verify identity verification and beneficial ownership transparency.
- Enhanced Due Diligence (EDD): Verifying Source of Wealth (SoW) and Source of Funds (SoF) procedures for high-risk customers and PEPs.
- Customer Risk Rating (CRR): Testing whether risk-scoring models accurately categorize client risk.
- Sanctions & PEP Screening: Evaluating real-time screening engines, fuzzy-matching parameters and alert clearing logic.
- Transaction Monitoring Systems: Testing rule thresholds, scenario logic and alert remediation efficiency.
- Suspicious Transaction Reporting (STR/SAR): Reviewing internal escalation pathways and filing timelines with local Financial Intelligence Units (FIUs).
- Travel Rule Compliance: For VASPs and financial institutions, verifying originator and beneficiary data transfers.
- Record Keeping: Verifying adherence to statutory 5-to-10-year record retention mandates.
- Staff Training: Assessing whether training materials are updated annually and tailored to specific job roles.
- Control Testing Integrity: Reviewing prior audit findings, scope coverage and tracking management remediation.
- Management Reporting: Ensuring board members receive accurate, timely financial crime risk metrics.
Practical pre-audit preparation checklist
Compliance teams can use this preparation checklist prior to initiating an independent review:
| Status | Checklist Item | Action Required |
| [ ] | Documentation Alignment | Verify that policy manuals, Enterprise-Wide Risk Assessments (EWRA), and risk-scoring matrices directly reflect current local regulations and updated national risk priorities. |
| [ ] | Historical File Organization | Aggregate previous independent audit reports, supervisory examination letters, and tracking logs demonstrating management remediation of prior findings. |
| [ ] | Sample Data Extraction | Prepare clean data sets of recent onboardings (stratified across Low, Medium, and High risk), Politically Exposed Persons (PEPs), high-risk jurisdiction accounts, and off-boarded relationships. |
| [ ] | Alert & Transaction Reconciliation | Clear outstanding transaction monitoring and sanctions screening backlogs; compile sample Suspicious Transaction Reports (STRs/SARs) alongside complete narrative documentation. |
| [ ] | System & Baseline Calibration | Document screening fuzzy-matching thresholds, transaction monitoring rules engine parameters, and any significant IT or algorithm updates made since the last review. |
| [ ] | Executive & Governance Readiness | Brief the Board or Audit Committee on the review’s scope and establish interview availability for key departmental stakeholders. |
Frequently Asked Questions (FAQs)
Which countries require annual AML reviews?
Jurisdictions such as the UAE, Bermuda, Cayman Islands, BVI, Labuan and Qatar Financial Centre (QFC) frequently expect or mandate annual AML reviews across regulated sectors, either through statutory rules or supervisory practice.
Does FATF require annual AML audits?
No. FATF Recommendations 18 and 23 require an independent audit function to test compliance systems, but leave the operational frequency to national authorities under a Risk-Based Approach.
Is an external auditor mandatory?
Not universally. Most regulators permit an internal audit team to conduct testing if they are independent of daily compliance operations (MLRO/AMLCO). However, specific license categories or supervisory directives (such as FINMA prudential audits in Switzerland) may require external reviewers.
Can internal audit perform AML testing?
Yes, provided internal audit personnel possess sufficient technical AML expertise, report directly to the Board or Audit Committee and play no role in daily compliance execution or policy creation.
Are AML reviews required for crypto service providers (VASPs)?
Yes. In regulated financial centers (including the EU under MiCA/AMLA, USA, UAE under VARA/CBUAE and UK under FCA registration), VASPs must undergo periodic independent compliance testing due to their operational risk profile.
What is the difference between an AML audit and a compliance health check?
An AML audit (or independent review) is a formal assessment conducted by an independent party to report on control effectiveness to senior management and regulators. An AML health check is an informal internal review designed to identify control gaps prior to an official inspection or audit.
Conclusion & next steps
While FATF Recommendations 18 and 23 establish global standards for independent compliance testing, national implementation varies. Regulated entities operating across international borders must distinguish between statutory requirements, supervisory expectations and prevailing market practices in each operating jurisdiction.
Maintaining an objective, periodic independent review function remains a fundamental component of effective financial crime risk management and regulatory defense.
Ensure your AML compliance framework stands up to regulatory scrutiny
Preparing for an independent AML review or navigating multi-jurisdictional compliance mandates requires specialized expertise and objective insight.
At Compliance7, our team of certified financial crime specialists provides end-to-end support, including:
- Statutory & independent AML/CFT/CPF audits
- Targeted control gap testing
- Enterprise-Wide Risk Assessment (EWRA) benchmarking
- Regulatory remediation & Post-audit action plans
Get in touch with the Compliance7 team to discuss your jurisdiction-specific requirements and schedule your independent review.
Disclaimer:
This article is provided for general informational and educational purposes only and does not constitute legal, regulatory or professional advice. While reasonable efforts have been made to ensure the accuracy of the information as of the publication date, AML/CFT/CPF laws, regulations, supervisory expectations and industry practices may vary by jurisdiction, sector and licence type and may change over time. Organizations should seek independent legal or professional advice and consult the relevant competent authorities before making compliance or business decisions based on this information.



