Internal AML/CTF audits can help businesses identify compliance gaps before they become bigger problems or are uncovered during an independent evaluation.
For many businesses, one of the biggest AML/CTF compliance risks is not having an AML/CTF Program.
It is that the program exists, has been approved, staff have been trained — but over time, what is written in the program and what is actually happening in the business begin to drift apart.
That is where regular internal audits or compliance reviews can provide significant value.
AUSTRAC makes it clear that an AML/CTF Program is not simply a document that is prepared and put on the shelf. Reporting entities must comply with their program, follow their AML/CTF policies in daily operations, and monitor the effectiveness of those controls.
This is why we have introduced a quarterly AML/CTF review structure within CIRT — to help clients progressively check implementation throughout the year rather than waiting until an independent evaluation identifies the problems.
The Difference Between Having an AML/CTF Program and Implementing It
A business might have an excellent AML/CTF Program.
It might say that the business will:
- undertake Customer Due Diligence (CDD);
- identify and manage higher-risk customers;
- conduct Enhanced Customer Due Diligence (ECDD) when required;
- monitor transactions and customer behaviour;
- identify and investigate unusual activity;
- lodge Suspicious Matter Reports (SMRs) where required;
- conduct AML/CTF training;
- undertake personnel due diligence;
- maintain appropriate records; and
- report AML/CTF compliance information to senior management or the governing body.
But the important question is:
Can the business demonstrate that these things are actually happening?
AUSTRAC’s current guidance states that businesses must implement their AML/CTF policies and demonstrate how they are applied.
That makes monitoring implementation just as important as writing the program in the first place.
Why Conduct an Internal AML/CTF Audit Throughout the Year?
A quarterly internal AML/CTF audit provides an opportunity to look at a manageable part of the AML/CTF Program and ask some simple questions:
Are we doing what our program says we will do?
Are our controls actually working?
Do we have evidence to demonstrate this?
Have there been changes to our customers, services, risks or business operations?
Are there gaps that need to be corrected?
This creates a continuous improvement process rather than a last-minute compliance exercise.
For example, an internal review might identify that staff completed their initial AML/CTF training but some new employees have not yet been trained. AUSTRAC specifically recognises internal compliance reviews and audits as tools that can help identify training and knowledge gaps.
Another review might identify that CDD forms are being completed but customer risk ratings are not being consistently recorded.
A transaction-monitoring review might find that transactions are being identified but there is insufficient documentation explaining what was investigated and why an SMR was or was not considered necessary.
These are often relatively straightforward issues to fix when identified early.
Why Conduct Quarterly AML/CTF Reviews?
There is an important distinction here.
A quarterly internal AML/CTF audit is not the same as the independent evaluation required under the AML/CTF framework.
AUSTRAC requires independent evaluations at a frequency appropriate to the nature, size and complexity of the business, with a minimum frequency of at least once every three years.
Our quarterly approach is an additional management control designed to help businesses stay on top of their program between those independent evaluations.
In fact, AUSTRAC provides an example where, following adverse findings from an independent evaluation, a business decides to conduct an internal review three months later to check whether its updated policies and procedures are working effectively.
For us, that reinforces a simple principle:
Don’t wait three years to find out whether your AML/CTF Program is working.
The CIRT Quarterly Internal AML/CTF Audit Approach
This is why we have implemented a quarterly AML/CTF review structure within CIRT.
Rather than asking the Compliance Officer to undertake one enormous review at the end of the year, the process can be broken into manageable quarterly activities.
A quarterly review could examine areas such as:
- customer identification and CDD;
- higher-risk customers and ECDD;
- transaction monitoring;
- SMRs and threshold transaction reporting;
- personnel training and due diligence;
- changes to ML/TF and proliferation-financing risks;
- record-keeping;
- AUSTRAC correspondence;
- corrective actions; and
- management or board reporting.
Importantly, the review should not simply be a tick-and-flick exercise.
Where appropriate, the reviewer should sample actual records.
For example, if the program requires higher-risk customers to undergo ECDD, select several higher-risk customer files and check whether the required process actually occurred.
If the program requires particular transactions to be monitored, select a sample and check whether the monitoring occurred and whether there is evidence of the outcome.
This moves the review from:
“Do we have a procedure?”
to:
“Can we demonstrate that the procedure is working?”
Creating an AML/CTF Compliance Evidence Trail
There is another important benefit.
Every quarterly review creates evidence.
Over the course of a year, the business develops a record demonstrating that it has been actively monitoring its AML/CTF Program, identifying gaps, allocating corrective actions and following them through.
This can also improve governance.
Rather than the AML/CTF Compliance Officer simply telling the governing body that “everything is okay”, they can report:
- We completed the quarterly AML/CTF review.
- We tested these areas.
- We identified these issues.
- These corrective actions have been allocated.
- These matters have now been closed.
That is a much stronger compliance conversation.
Internal AML/CTF Audits Also Help Prepare for Independent Evaluation
Regular internal AML/CTF audits should ultimately make the independent evaluation less daunting.
The objective should never be to make sure an independent evaluator doesn’t find anything. A good evaluation may identify opportunities for improvement.
The objective is to avoid the evaluator finding basic implementation failures that the business could reasonably have identified itself months earlier.
AUSTRAC itself notes that identifying compliance and ML/TF risk-management issues early allows businesses to correct them sooner and reduce their exposure.
Internal Review vs Independent Evaluation
An internal AML/CTF audit is an ongoing management and compliance control used to monitor implementation, test controls and identify gaps.
An independent evaluation is a separate requirement under the AML/CTF framework.
An internal review does not replace the independent evaluation. Instead, regular internal reviews help businesses identify and address issues between independent evaluations.
This distinction is important because the goal of internal reviews is not simply to prepare for an external assessment. It is to help ensure that the AML/CTF Program remains effective and is actually being followed.
AML/CTF Compliance Is a Process, Not an Annual Event
AML/CTF compliance shouldn’t become something that receives attention once a year when the AUSTRAC compliance report is due, or once every few years when an independent evaluation approaches.
A better approach is:
Implement → Monitor → Review → Identify gaps → Correct → Report → Repeat.
That is the thinking behind the quarterly AML/CTF review structure we have implemented in CIRT.
It gives Compliance Officers a practical way to progressively test their AML/CTF Program, retain evidence of those reviews, identify actions and demonstrate that the organisation is actively monitoring whether its AML/CTF controls are working.
Most importantly, it helps answer one of the questions every reporting entity should be able to answer:
“We have an AML/CTF Program — but can we demonstrate that we are actually following it?”
Final Thoughts
An internal AML/CTF audit is ultimately about staying ahead of compliance risks rather than reacting to them.
Businesses change. Customers change. Services change. Risks change. Even well-designed AML/CTF controls can become less effective if they are not regularly reviewed against what is actually happening in the business.
That is why internal AML/CTF audits can play an important role between independent evaluations. They provide Compliance Officers and management with an opportunity to step back, challenge existing processes and ask whether the organisation’s AML/CTF Program still reflects its current operations and risks.
The goal is not to create more paperwork. It is to create greater confidence that the AML/CTF framework is being implemented, monitored and improved when necessary.
Don’t wait for an independent evaluation to tell you where the gaps are. Find them, address them and keep improving.
Need Support With Your AML/CTF Compliance?
If your business needs support with an internal AML/CTF audit, AML/CTF Program review or ongoing compliance monitoring, contact CHD Partners to discuss your requirements.
For further guidance, see AUSTRAC – Your AML/CTF program overview and AUSTRAC – Review and update your AML/CTF program.
