SardineCon SF/2026

Learn More
AML programs4 min de lectura

¿Qué es Independent AML audit?

SUBSCRIBE

An independent AML audit is a periodic, independent test of whether the AML program is well designed and actually works, and it is one of the BSA pillars. It is run by internal audit or a qualified outside party with no stake in the result, because a self-review by the people who run the program is not credible.

What is an independent AML audit, in plain English?

An independent AML audit is a periodic check on whether the AML program is both well designed and actually working in practice. It is one of the required BSA pillars, so covered US firms are not doing it as a courtesy; it is a mandatory component of the program.

The word that carries the weight is independent. The audit has to be run by internal audit or a qualified outside party with no stake in the program's outcome. A review by the same people who built and run the program is not credible, because they cannot objectively grade their own work, and examiners know it.

The audit tests two things: design, whether the program is set up correctly for the firm's risk, and effectiveness, whether the controls actually operate as intended. Examiners scrutinize the audit's scope, the tester's skill, and its genuine independence, so a shallow or conflicted audit is itself a finding.

How an audit runs

  1. Scope — Set what gets tested. Define coverage across the pillars and the firm's risk, avoiding a scope so narrow it misses the weak spots.
  2. Test — Check design and operation. A qualified, independent tester examines whether controls are well designed and whether they actually run.
  3. Report — Raise findings. Issues are documented with severity, becoming a remediation backlog the firm has to work down.
  4. Remediate — Fix and re-test. Findings are tracked to closure, and the next cycle checks they were genuinely fixed, not just noted.

What it looks like in practice

In practice

A firm's annual independent audit flags that its transaction monitoring rules have not been tuned since launch and are producing mostly noise. The finding is logged, everyone agrees it matters, and the report goes in the file.

The next year's audit finds the same thing, and the year after that too. Nothing was actually fixed; the finding was noted and forgotten each cycle. When examiners see the identical issue recurring across three audits, it stops being a tuning problem and becomes a governance problem: the firm has a process for finding issues and no process for resolving them. An audit that changes nothing is just paperwork.

Why repeat findings are a governance red flag

The point of an independent audit is not to generate a report; it is to drive improvement. So the right way to treat findings is as a tracked remediation backlog you actually work down, with owners, deadlines, and re-testing to confirm the fix held. A finding that is noted and then ignored delivers none of the value the pillar exists to provide.

That is why the same finding appearing cycle after cycle is a serious governance red flag. It signals that the firm can identify problems but cannot or will not fix them, which is worse than not knowing, because the firm was on notice and did nothing. Examiners scrutinize scope, tester skill, and genuine independence precisely to make sure the audit is real, and they treat recurring findings as evidence that the program's governance, not just one control, is broken.

What to watch for

  • Recurring findings. The same issue across multiple cycles is the clearest sign that findings get noted but never fixed.
  • Compromised independence. An audit run by, or reporting to, the people who own the program is not credible and is itself a finding.
  • Narrow scope. A scope drawn to avoid the risky areas produces a clean report that means nothing.
  • Underqualified tester. A reviewer without real AML expertise cannot assess whether the controls actually work.
  • No remediation tracking. Findings with no owner, deadline, or re-test are destined to reappear next cycle.

Quick questions

Who can run an independent AML audit?

Internal audit or a qualified outside party, as long as they have no stake in the program's outcome. The people who run the program cannot credibly audit their own work.

Is the audit a legal requirement?

For covered US firms, yes. Independent testing is one of the BSA pillars, so a missing or inadequate audit is a direct enforcement finding, not an optional best practice.

How often should it happen?

Periodically, with the frequency driven by the firm's risk. Many firms audit annually, but higher-risk businesses may test more often, and the cadence should be justified by the risk assessment.

What do examiners look at in the audit?

Its scope, the tester's skill, and its genuine independence. A shallow scope, an underqualified reviewer, or a conflicted arrangement all undermine the audit's credibility and become findings themselves.

Why are repeat findings such a problem?

Because they show the firm can identify issues but does not fix them. That is a governance failure: the firm was on notice and did nothing, which examiners treat as more serious than the underlying control gap.

What should happen to audit findings?

They should become a tracked remediation backlog with owners, deadlines, and re-testing to confirm the fix. An audit that changes nothing is just paperwork.

Go deeper

  • FFIEC BSA/AML Examination Manual ↗ — The manual US examiners use to assess BSA and AML programs.
  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

Qué saber junto con Independent AML audit