Since 1998

Licensed provider of company formation and corporate services

Independent AML Audit for EMIs, PIs and CASPs

An independent test of your AML/CFT policies, procedures and controls, as EU and national AML rules expect from obliged entities.Findings ranked by risk, a remediation plan and a re-test you can show your regulator.

  • Independent audit team
  • ISO 19011 audit principles
  • 500+ licensing projects
View audit scopeGet a free assessment

Free, no-obligation assessmentWe reply within 1 business day

4 to 8 weeks
Scoping to final report
10 areas
From governance to STRs
10 July 2027
AMLR applies from
ISO 19011
Audit principles
Re-test
To confirm remediation

Overview

An independent test of your AML framework

EU AML rules expect obliged entities to have their AML policies, controls and procedures tested by an independent audit function, and from 10 July 2027 the AMLR lets an external expert carry out that test. MAXCORP audits EMIs, PIs, CASPs and Canadian MSBs, testing both the design and the day-to-day effectiveness of your controls.

AML audit documents in a white folder with a magnifying glass symbol and the MAXCORP logo
  • Risk-based sample testing of CDD and EDD files, alerts, cases and STR decisions

  • Your business-wide risk assessment, policies and procedures checked against current law

  • Findings rated by severity, each with evidence references and a named owner

  • A remediation plan with owners and dates, plus a summary for your management body

  • An optional re-test that confirms remediation worked before the next inspection

  • Gaps against the AMLR rules that apply from 10 July 2027 flagged for your roadmap

Most clients commission an AML audit at a clear moment: before a licence application, around a supervisory inspection, after an incident, or as the periodic independent test their AML rules expect. We scope the audit to that moment, test a risk-based sample and report findings ranked by severity, with owners and deadlines for your management. You get evidence your regulator can review, and a clear plan to close the gaps.

Scope

What the AML audit covers

We test both the framework (how your AML programme is designed and governed) and the controls in operation (whether it works on real files, alerts and reports).

Framework

Design

Governance

Management body oversight, the Compliance Officer or MLRO role, independence and reporting lines.

Risk assessment

The business-wide risk assessment and customer risk scoring.

Policies and procedures

Completeness against current law, and readiness for the AMLR.

Training and records

Training coverage and record-keeping against retention rules.

Outsourcing and agents

Oversight of outsourced tasks, agents and distributors.

Controls in operation

Effectiveness

Customer due diligence

CDD, EDD and ongoing monitoring: PEPs, beneficial owners, high-risk countries, tested on file samples.

Sanctions screening

Lists, thresholds and tuning, and how hits are handled.

Transaction monitoring

Rules and scenarios, alert handling, case quality and backlog.

FIU reporting

STR decisions and their timeliness against national deadlines.

FIU requests

How requests for information from the FIU are answered.

Models

Audit formats: readiness, periodic audit or deep dive

Choose the format that fits your stage. Each audit is priced on a fixed scope, quoted after a short scoping call.

Before licensing

Pre-licence readiness

Fixed scopeBefore you apply or launch

A check of your AML framework and documents before the licence application or go‑live.

  • Policies and risk assessment reviewed
  • Gap list against regulator expectations
  • Remediation plan before submission
  • Useful for new EMIs, PIs and CASPs

Recurring

Periodic independent audit

Fixed scopeOne-off or recurring

The full independent test of design and effectiveness, repeated on your required cycle.

  • Framework and controls in operation
  • Sample testing of files, alerts and STRs
  • Findings ranked by risk with evidence
  • Re-test to confirm remediation

Targeted

Deep dive

Fixed scopeOne area, in depth

A focused review of one area, for example after a finding, an incident or a supervisory request.

  • E.g. transaction monitoring or sanctions
  • Root-cause analysis of the issue
  • Practical fixes and owners
  • Evidence pack for the regulator

* Pricing is indicative and subject to final confirmation. Prices exclude VAT. Prices depend on your size, business model and the number of samples, and are quoted after scoping. Audits usually start within 1 to 2 weeks once the scope is agreed.

Use cases

When to commission an AML audit

Most AML audits are triggered by a specific moment in the life of a regulated company. These are the typical situations; each one sets a different scope and depth, which we agree with you at scoping.

Periodic independent test

EU AML rules expect an independent audit function to test your AML policies, controls and procedures. From 10 July 2027 the AMLR lets an external expert carry out that test.

Before a licence application

Supervisors review the AML framework in every EMI, PI or CASP application. A readiness audit finds the gaps before you submit, when they are quickest to fix.

Around a supervisory inspection

Before an inspection, we test whether your files and records hold up. Afterwards, we check that the findings are remediated and the evidence is ready for the follow‑up.

After an incident or a finding

A missed STR, a sanctions hit or a critical bank review calls for a targeted deep dive: what went wrong, why, and which controls need to change.

New products, markets or volumes

Crypto services, new payment corridors, agents or fast growth change your risk exposure. An audit checks that the risk assessment and controls kept pace.

Bank, partner or investor review

Partner banks, payment schemes, acquirers and investors may ask for independent evidence that your AML programme works. Our audit report gives them that evidence.

Process

How an AML audit runs

A risk-based audit using interviews, walkthroughs and sample testing, following ISO 19011 principles. The timeline depends on your size and how quickly documents and access are provided.

Indicative timeline

4 to 8 weeks

  1. Week 1

    Scoping

    Scope, document request and a sampling plan agreed.

  2. Weeks 1 to 3

    Review and walkthroughs

    Policies, risk assessment and controls walked through.

  3. Weeks 2 to 5

    Testing

    Interviews and sample testing of files, alerts and STRs.

  4. Weeks 4 to 8

    Report

    Draft report, management responses and the final report.

  5. After remediation

    Re-test

    Optional re-test, typically 3 to 6 months later.

Durations are indicative and not legal deadlines. Large or complex businesses may need longer.

FAQ

AML audit: frequently asked questions

Is an independent AML audit required?

Under AMLD Art 8(4)(b) it is required where appropriate to your size and the nature of your business. From 10 July 2027, AMLR Art 9(2)(b) makes an independent audit function part of the required internal controls. In Canada, PCMLTFR s.156(3) requires an effectiveness review of the compliance programme at least every two years.

Can an external firm do the audit?

Yes. Many national laws already allow an external auditor today, and from 10 July 2027 the AMLR expressly allows an external expert to carry out the test where there is no independent audit function. Some countries require an external audit for certain licences. We confirm what applies to you during scoping.

When does the AMLR apply?

From 10 July 2027 for most obliged entities, including EMIs, PIs and CASPs.

When should we commission an AML audit?

Typically as the periodic independent test your AML rules expect, before a licence application, around a supervisory inspection, after an incident or a finding, or when new products, markets or volumes change your risk exposure.

What should we prepare for the audit?

Your AML policies and procedures, the business-wide risk assessment, recent management reports, access to your screening and case-management tools, and a contact person for interviews. We send a document request list at scoping.

What will we receive?

Findings ranked by risk with evidence references, a remediation plan with owners and dates, a summary for management, and the option of a re‑test.

Does the audit cover sanctions screening?

Yes. We test sanctions lists, thresholds and tuning, and how hits are handled, as part of the controls in operation.

Do you test STR timeliness?

Yes. As part of the FIU reporting tests, we check STR decisions and their timeliness against the national deadline that applies to you.

How long does an AML audit take?

Indicatively 4 to 8 weeks from scoping to the final report, depending on your size and how quickly documents and access are provided. This is practice, not a legal deadline.

How do you stay independent?

To keep the audit independent, MAXCORP reports to the board or audit committee and keep delivery separate from assurance. If our team runs your AML operations, we tell you and recommend another auditor where independence could be questioned.

Contact

Plan your AML audit

After a discovery meeting we send a tailored audit plan with the scope, the samples needed and an indicative timeline.

What can we help with?

We reply within 1 business day.

By submitting this form you agree to our Privacy Policy. We use your details to reply to your enquiry.

Send an enquiry

Tell us about your project. We reply with next steps and a budget.

By sending this form, you agree to our Privacy Policy.We use your details to reply to your enquiry.

Book a free call

Open in a new tab

Loading the calendar…

Cookie settings

Choose which cookies we may use. Necessary cookies are always on, because the website cannot work securely without them. Cookie Policy