An independent AML audit is an arm’s-length review that tests whether a firm’s anti-money laundering program actually works. It is one of the required pillars of a program, and it gives leadership and regulators an honest picture of what is working and what is not.
Key takeaways
- An independent AML audit tests whether an AML program actually works.
- It is a required pillar, also called independent testing.
- It must be genuinely independent, done by internal audit or an outside firm.
- It covers the whole program: controls, due diligence, monitoring, and reporting.
- Most firms run one every 12 to 18 months, based on risk.
- Its value is honest findings that leadership then acts on.
On this page
What it isWhy it is requiredWho performs itWhat it coversHow oftenThe processAudit vs examActing on findingsFAQsRead more
12 to 18 months
Common cycle for an independent AML audit
Source: FFIEC guidance
$3B
Paid by TD Bank in 2024 after control and testing gaps
Source: US Department of Justice
$800B to $2T
Laundered worldwide each year that programs aim to stop
Source: UNODC
What is an independent AML audit?
An independent AML audit is a review that checks whether a firm’s anti-money laundering program is doing its job. It is done at arm’s length, by someone not responsible for running the program, so the findings are honest.
The word independent is the key. A team cannot credibly grade its own work, so the audit brings in a separate set of eyes to test the program against the rules and against reality.
It is one of the required parts of an AML program. Read more: it is the testing pillar within the five pillars of AML.
Why an independent audit is required
The audit is required because a program can look sound on paper and still fail in practice. Independent testing is how a firm finds out which it is.
Without it, weaknesses go unseen until a regulator, or a criminal, finds them first. The audit catches gaps early, while there is still time to fix them, and it gives leadership an honest view rather than a reassuring one.
Regulators treat weak or missing testing as a serious gap. The TD Bank case in 2024, with about $3 billion in penalties, involved controls that testing should have surfaced (US Department of Justice, 2024).
Set out testing in your AML policy
Generate a tailored AML policy draft that records your controls, roles, and independent testing approach.
Who performs an independent AML audit?
The audit must be independent, but it does not have to be external. What matters is that the reviewer is separate from the program being tested.
- Internal audit. A firm’s own audit team, provided it is independent of compliance.
- An outside firm. An external auditor or consultancy brought in for the review.
- A qualified third party. A specialist with the knowledge to test an AML program.
A small firm without an internal audit function usually hires an outside party. The reviewer should have real AML knowledge, not just general audit skills.
That knowledge matters more than it sounds. An auditor who does not understand laundering can tick boxes without ever testing whether the program would catch a real scheme, which is the one thing the audit exists to do.
What an independent AML audit covers
A thorough audit looks at the whole program, not just one part. It tests each pillar and how they work together.
- Internal controls. Whether policies and procedures are sound and followed.
- Customer due diligence. Whether the firm really knows its customers.
- Transaction monitoring. Whether monitoring catches what it should.
- Reporting. Whether suspicion is escalated and reported properly.
- Training and governance. Whether staff are trained and oversight is real.
The aim is to test whether the program works in practice, by sampling real cases, not just reading the manual.
How often should it happen?
There is no single legal interval, but a common cycle is every 12 to 18 months. The right frequency depends on the firm’s size and risk.
US regulatory guidance points most banks toward independent testing every 12 to 18 months, and higher-risk firms may test more often. A firm should also run an audit after a major change, such as a new product or a serious incident.
The interval is a floor, not a ceiling. A firm that has just overhauled its monitoring, entered a new market, or had a near-miss should not wait for the calendar. The point is to test when the risk warrants it, not merely when the cycle comes due.
The audit process
An independent audit follows a clear sequence, from planning to follow-up. The steps are consistent.
- Set the scope. Agree what the audit will cover, based on risk.
- Test the program. Sample real cases and check controls against the rules.
- Identify findings. Record gaps, weaknesses, and what is working.
- Report. Give leadership and the board a clear, honest write-up.
- Follow up. Track that the findings are actually fixed.
Independent audit vs regulatory exam
An independent audit and a regulatory exam both test a program, but they are not the same thing. The difference is who runs it.
| Independent audit | Regulatory exam | |
|---|---|---|
| Run by | The firm, at arm’s length | The regulator |
| Purpose | Find and fix gaps early | Check compliance and enforce |
| Timing | On the firm’s cycle | On the regulator’s schedule |
A firm that audits itself well is far better prepared when the regulator arrives, because the gaps have already been found and fixed.
Acting on the findings
The audit only adds value if the firm acts on it. Findings that sit in a report change nothing.
- Prioritize. Rank findings by risk and fix the most serious first.
- Assign owners. Give each fix to a named person with a deadline.
- Track progress. Follow each finding through to a real resolution.
- Report upward. Keep the board informed of what was found and fixed.
Get an indicative AML risk rating
See where your money laundering risk is concentrated so an audit can focus where it matters most.
Test your screening as part of the audit
Run one search across sanctions, PEP, and adverse media data to sanity-check your screening results.
Frequently asked questions
What is an independent AML audit?
An independent AML audit is an arm’s-length review that tests whether a firm’s anti-money laundering program actually works. It is carried out by someone not responsible for running the program, so the findings are honest. It is a required pillar of an AML program, also called independent testing, and it covers the whole program.
Why is an independent AML audit required?
It is required because a program can look sound on paper and still fail in practice. Independent testing is how a firm finds out which it is. Without it, weaknesses go unseen until a regulator or a criminal finds them first. The audit catches gaps early and gives leadership an honest view rather than a reassuring one.
Who can perform an independent AML audit?
It can be performed by a firm’s own internal audit team, provided it is independent of compliance, by an outside auditor or consultancy, or by a qualified third party. What matters is that the reviewer is separate from the program being tested and has real AML knowledge, not just general audit skills. Small firms often hire an outside party.
What does an independent AML audit cover?
A thorough audit covers the whole program: internal controls and whether they are followed, customer due diligence and whether the firm really knows its customers, transaction monitoring, suspicious activity reporting, and training and governance. It tests whether the program works in practice by sampling real cases, not just reading the manual.
How often should an AML audit be done?
There is no single legal interval, but a common cycle is every 12 to 18 months. US regulatory guidance points most banks toward that range, and higher-risk firms may test more often. A firm should also run an audit after a major change, such as a new product or a serious incident, rather than waiting for the next cycle.
What is the difference between an independent audit and a regulatory exam?
An independent audit is run by the firm at arm’s length to find and fix gaps early, on its own cycle. A regulatory exam is run by the regulator to check compliance and enforce, on the regulator’s schedule. A firm that audits itself well is far better prepared when the regulator arrives, because gaps have already been found.
Does independent mean external?
Not necessarily. Independent means separate from the program being tested, not necessarily outside the firm. A firm’s own internal audit team can perform the review, as long as it is independent of the compliance function it is testing. Smaller firms without an internal audit function usually bring in an external party instead.
What happens after an independent AML audit?
After the audit, the firm should prioritize findings by risk and fix the most serious first, assign each fix to a named owner with a deadline, track progress to a real resolution, and keep the board informed. The audit only adds value if the firm acts on it, since findings that sit in a report change nothing.
Is independent testing one of the pillars of AML?
Yes. Independent testing, delivered through an independent AML audit, is one of the required pillars of a US AML program. It sits alongside internal controls, a compliance officer, training, and, since 2018, customer due diligence. Its role is to check independently that the other pillars actually work.
What makes an AML audit effective?
An effective audit produces honest findings and drives a real response. It tests the program against real cases rather than just reading policies, it does not soften problems to keep the peace, and its findings are fixed rather than filed. The value is in the fixing, not the finding, so follow-up matters as much as the review itself.
Do small firms need an independent AML audit?
Yes. Independent testing is a requirement for regulated firms of all sizes, though the scale differs. A small firm without an internal audit team usually hires an outside party to review its program. The audit can be simpler and less frequent than a large bank’s, but the principle of an honest, arm’s-length review still applies.
What is the FFIEC guidance on AML audits?
The FFIEC, which issues examination guidance for US banks, points firms toward independent testing of their AML program roughly every 12 to 18 months, with higher-risk institutions testing more often. The guidance frames independent testing as one of the pillars of a compliant program and expects the review to be genuinely independent and risk-based.
Read more: our ultimate guides, whitepapers and templates
Related guides and resources to help you act on what you just read.
Last reviewed July 12, 2026 · 10 min read · Written for compliance and risk professionals · By the WhoWiki editorial team
Key takeaway: an independent AML audit is an arm’s-length review that tests whether a firm’s anti-money laundering program actually works, and it is a required pillar.