3 June 2026 · 5 min read

Banks, acquirers, principal firms and e-money issuers increasingly require an annual independent AML audit before they will continue a relationship. Preparation determines whether that audit is a formality or a fire drill.
Phase one: gap analysis
We review your policies, risk assessment, customer files and MI against the Money Laundering Regulations and JMLSG guidance, and produce an initial list of gaps before anyone visits the office.
Phase two: onsite testing
Sample testing of customer due diligence, screening, monitoring alerts and SAR records, plus interviews with the MLRO and front-line staff, confirms whether documented controls operate in practice.
Phase three: report and action steps
You receive a rated findings report with a practical remediation plan, owners and deadlines. That plan is usually what your bank or principal actually wants to see, so it should be realistic and tracked to completion.
- Collect your risk assessment, policies and MI in one folder in advance
- Make the MLRO and an operations contact available for interviews
- Agree the sample period and file list before the visit



