The AML/CFT Independent Audit: Scope, Frequency & What Regulators Expect — CWC & ENG PLT
Articles & Resources
AMLA 7 min read·23 July 2026

The AML/CFT Independent Audit: Scope, Frequency & What Regulators Expect

Independent testing is the fifth pillar of a compliance programme — and for many Labuan institutions, a regulatory requirement. Here is what an AML/CFT independent audit covers and how to prepare.

01

What an AML/CFT independent audit is

An AML/CFT independent audit is an objective review — by internal audit or an external party independent of the functions being tested — of whether a reporting institution's AML/CFT framework is well designed and operating effectively. It is the mechanism that turns policy on paper into demonstrable compliance.

For many Labuan reporting institutions, an independent external AML/CFT audit is expressly required by LFSA, making it a regulatory obligation rather than merely good practice.

02

What the audit covers

A thorough review tests every pillar of the framework:

  • Governance — board and senior-management oversight and the compliance officer's independence and resourcing
  • The institutional risk assessment — currency, methodology and board approval
  • CDD and beneficial-ownership procedures, tested on real files
  • Sanctions screening — list management, match handling and freezing
  • Transaction monitoring and the STR/CTR escalation and decision trail
  • Record-keeping and retention against the reconstruction standard
  • Training coverage, content and attendance records
03

Design effectiveness vs operating effectiveness

1

Design effectiveness

Are the policies, procedures and controls capable, on paper, of meeting the legal requirements and mitigating the assessed risks?

2

Operating effectiveness

Do they actually work in practice? This is tested through sampling — pulling real onboarding files, screening logs, monitoring alerts and STR decisions.

Sampling is where reality showsA framework can look immaculate on paper and fail on the files. Testing real cases is how an audit distinguishes a working programme from a well-written one.
04

How often and by whom

The audit must be conducted by a party independent of the functions under review, on a frequency proportionate to the institution's risk and size — and in line with any specific regulatory requirement applicable to the licence. Higher-risk institutions warrant more frequent review. The independence requirement is fundamental: a compliance officer cannot audit their own programme.

05

How to prepare and use the findings

  1. 1
    Assemble the evidence
    Have the policy, IRA, training records, screening logs and a sample of onboarding files ready.
  2. 2
    Engage an independent reviewer
    Appoint internal audit or a qualified external firm with no involvement in the functions being tested.
  3. 3
    Test design and operation
    The reviewer assesses both design and, through sampling, operating effectiveness.
  4. 4
    Act on the report
    Convert findings into a remediation plan with owners and deadlines — and report it to the board.
  5. 5
    Close the loop
    Track remediation to completion and confirm fixes in the next review cycle.
FAQ

Frequently asked questions

Independent testing is a required pillar of a compliance programme, and for many Labuan reporting institutions an independent external AML/CFT audit is expressly required by LFSA.
A party independent of the functions being tested — internal audit or a qualified external firm. The compliance officer cannot audit their own programme.
Governance, the institutional risk assessment, CDD and beneficial ownership, sanctions screening, transaction monitoring and STR/CTR trails, record-keeping, and training — assessing both design and operating effectiveness.
On a frequency proportionate to the institution's risk and size and in line with any applicable regulatory requirement; higher-risk institutions warrant more frequent review.

In conclusion

An AML/CFT independent audit is where a compliance programme proves itself. Done properly — testing real files, not just documents — it is the cheapest way to find and fix gaps before a supervisor does.

AMLA · AML/CFT Advisory

Book an independent AML/CFT audit

As LFSA-approved auditors, we provide the independent testing pillar for Malaysian and Labuan reporting institutions.

Request a consultation