top of page

How to Write a Regulatory-Compliant Anti-Money Laundering (AML) Annual Internal Audit Report? A Systematic Checklist from Compliance Consultants

An Anti-Money Laundering Internal Audit Report (AML Audit Report) that meets Hong Kong regulatory standards (such as the SFC, C&ED, or HKMA) must contain four core chapters: 1. Policy & Procedure Review, 2. Front-line CDD/STR Transaction Testing, 3. Audit Findings, and 4. Remediation Plan & Follow-up. Whether for a Licensed Corporation, a Money Service Operator (MSO), or a Trust or Company Service Provider (TCSP), drafting a high-quality AML Internal Audit Report is a mandatory statutory requirement to fulfill the Independent Audit Function. Responsible Officers (ROs) and Managers-in-Charge (MICs) must follow a systematic Financial Internal Audit Checklist to ensure the audit covers policy updates, system testing, and actual business records, ensuring a smooth pass during regulatory On-site Inspections.

I. Four Essential Chapters and Audit Focuses of an AML Internal Audit Report

According to the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615) and corresponding regulatory guidelines, a comprehensive AML Audit Report must be strictly structured as follows:

 

  • 1. Policy & Procedure Review

Evaluate whether the institution's current Anti-Money Laundering and Counter-Terrorist Financing Policy (AML/CFT Policy) and Institutional Risk Assessment (IRA) are updated in a timely manner and fully cover the latest legislative amendments and regulatory circulars (e.g., AI deepfake anti-fraud measures, offshore remote customer onboarding requirements).

 

  • 2. Front-line CDD/STR Transaction Testing

Perform sample audits on actual customer files, covering low-, medium-, and high-risk customers, as well as Politically Exposed Persons (PEPs). Focus areas:

  • Customer Due Diligence (CDD/EDD): Verify if identity documents, Source of Funds (SOF), and Source of Wealth (SOW) proof are complete.

  • Name Screening: Review daily automated screening logs against Sanctions (SAN) and PEP lists, as well as the disposal logic for False Positives.

  • Suspicious Transaction Reporting (STR): Audit transaction monitoring system alerts, internal escalation logs (MLRO Escalation), and the timeliness of submitting STRs to the Joint Financial Intelligence Unit (JFIU).

 

  • 3. Audit Findings & Risk Rating

Categorize and risk-rate identified vulnerabilities (e.g., High, Medium, Low risk). Examples include failing to conduct timely annual periodic reviews for high-risk clients, or account opening systems failing to record Liveness Detection verification logs.

 

  • 4. Remediation Plan & Management Response

Propose actionable remediation requirements for each finding, specifying responsible departments (such as Compliance, IT, or Operations), responsible persons, and clear target completion dates.

II. Regulatory Audit Standards for "Third-Party Independent Audits"

The HK Customs (for MSOs or DPMS) and the SFC (for Type 1 to 13 Licensed Corporations) enforce concrete standards during on-site inspections or routine document calls:

審查維度 Review Dimension
海關審查標準 Customs (C&ED) Audit Standards (MSO / TCSP)
證監會審查標準(持牌法團)SFC Audit Standards (Licensed Corporation - LC)

Audit Independence

Auditors must not participate in daily AML/KYC approvals. If internal segregation is impossible due to small team size, an external independent compliance consultant must be appointed.

Must maintain an independent audit trail completely separated from front-line business units and operational Compliance Teams.

Sampling Methodology

Emphasizes high-ratio or 100% sampling for large cash transactions, frequent cross-border remittances, and high-risk customers.

Requires a Risk-Based Approach, where sampling must cover all business lines, complex trust structures, and rejected account opening cases.

System Effectiveness

Checks whether Name Screening systems are regularly updated; tests keyword matching against blacklist databases.

Verifies the logic of Transaction Monitoring rules & thresholds, along with regular back-testing records.

Board & Senior Management Governance

Audit reports must be directly submitted to directors, with signed and stamped management review records retained.

Audit reports must be presented to the Board of Directors, Responsible Officers (ROs), and Managers-in-Charge   (MICs), with audit findings truthfully disclosed in the Business and Risk Management Questionnaire (BRMQ).

III. Q&A: Practical Guidance for ROs and MICs (Compliance)

Q1: Can small and medium-sized financial institutions have their internal Compliance Head double as the author of the AML Internal Audit Report?

A: In principle, this is highly discouraged and often cited as a finding by regulators. Under the "Three Lines of Defence" framework, the Compliance Head belongs to the second line of defence, responsible for formulating policies and conducting daily reviews. Internal audit operates as the third line of defence, tasked with "auditing the work of the second line." Self-review by a Compliance Head severely breaches independence principles. For small to medium financial institutions without an independent internal audit department, the best compliant practice is engaging ComplianceOne's Independent AML Audit Services to execute an external independent review.

 

Q2: How do regulators typically request and review Audit Working Papers during on-site inspections?

A: Regulatory examiners will not grant approval based solely on the conclusions of an AML Internal Audit Report. Inspectors will call for audit working papers, including:

  • Sampling List: How sample cases were selected from the total client database.

  • Testing Worksheets: Comparison logs, system screenshots, and conversation logs for every audited file.

  • Interview Records: Interview notes with Responsible Officers (ROs), front-line staff, and Managers-in-Charge (MICs).

If an audit report contains only generic statements lacking working paper support, regulators may deem the audit "Inadequate or Superficial."

 

Q3: What should management do if an AML Internal Audit Report reveals High-Risk Audit Findings?

A: When an audit uncovers significant vulnerabilities (e.g., screening systems failing long-term or widespread lack of SOF proof for high-risk clients):

  • Immediate Remediation: Management should immediately instruct relevant departments to suspend high-risk functionalities and draft corrective measures.

  • Evaluate Statutory Reporting Obligations: Assess whether the vulnerability led to actual money laundering risks or constitutes a Material Breach under relevant legislation. If a material breach occurs, the financial institution must proactively report to regulators in a timely manner according to the Code of Conduct, rather than concealing it.

Conclusion

Conclusion

Establishing a regular, high-quality internal audit system is a financial institution's strongest line of defence against regulatory enforcement and legal risks. ComplianceOne Consulting Limited (“ComplianceOne”) possesses extensive experience in executing the Financial Internal Audit Checklist, offering independent AML internal audits, working paper preparation, and remediation tracking advisory to help licensed entities build an airtight compliance governance structure.

bottom of page