Hero Backdrop

Independent Anti-Money-Laundering (AML) Audits & Reports

Get an independent anti-money laundering audit

Are you monitoring the adequacy and effectiveness of your anti-money laundering policies and procedures by conducting a Regulation 21 independent audit?

Book your AML audit

What is a Regulation 21 independent AML audit?

A Regulation 21 independent AML audit is a key requirement under the Money Laundering Regulations 2017 (MLR). It is an objective review of your AML policies, controls, and procedures. The audit tests how effective your AML framework is in practice, identifies any gaps or weaknesses, and recommends improvements to strengthen compliance. This ensures your AML systems are not only documented but are actually working as intended. It’s about accountability, transparency, and making sure your firm stays compliant with regulatory expectations.

Requirements for an AML audit

While ‘independent’ does not necessarily mean the anti money laundering audit has to be carried out by someone external to the firm, you will need to be satisfied that you have someone suitable to carry out the AML audit within your firm who:

  • has the requisite knowledge of the requirements of the anti-money laundering regulations;
  • is a senior member of the firm who does not carry out regulated work;
  • is not involved in maintaining the anti-money laundering framework; and
  • has the necessary time and capacity to carry out the audit.

Such a person is not always easy to find! This is where our AML audit experts can help.

Our anti-money laundering audit service includes:

  • A review of your risk assessments, policies and procedures to check compliance with the most recent anti-money laundering regulations/directives and SRA guidance
  • Interviews of key staff, including your MLRO/MLCO and heads of departments carrying out regulated work
  • File reviews to confirm that policies, controls and procedures are being followed and are serving their intended purpose
  • A report detailing our findings and any recommendations which we will discuss with you

The audit will be carried out remotely, which will be less disruptive and less time consuming to the firm and only involve those relevant members of the firm for a relatively short period.

Why choose us for your AML audit?

  • Guaranteed independence
  • Legal professional privilege and confidentiality
  • Advice and recommendations from anti-money laundering compliance experts
  • Documented audit trail demonstrating compliance
  • Benchmarking to demonstrate year on year improvements

The SRA will continue to visit firms to check compliance with the anti-money laundering regulations and the adequacy and effectiveness of policies and procedures, so don’t delay! Complete the form below to book your independent AML audit.

Does an AML audit have to be done externally?

Not always — the regulation requires independence, not necessarily external involvement. The audit must be carried out independently of those responsible for implementing AML compliance day-to-day. However, many firms choose an external AML audit to ensure true objectivity and avoid any perceived conflicts of interest.

How long does an AML audit take?

That depends on your firm’s size, structure, and risk profile. For most small and medium-sized businesses, the process typically takes between one and three weeks from the initial document review to the delivery of the final report. Larger or more complex organisations may take longer.

Is the audit covered by legal professional privilege?

Generally, AML audits are not covered by legal professional privilege, as they are compliance based rather than advice given in contemplation of litigation. That said, everything shared during the audit is treated with the strictest confidentiality, and all materials are handled securely. In addition, unlike many risk and compliance consultancy services, we are a full-service law firm and are able to provide legal advice upon which firms can rely with the benefit of legal professional privilege, and which comes with the protection of professional indemnity insurance.

How often should we conduct an AML audit?

While the regulations don’t specify a set frequency, most regulators would expect an independent AML audit every 12–18 months, or more often if there have been significant changes in the firm — such as rapid growth, restructuring, or a shift in your client base or service offering.

Who needs to be involved in an AML audit?

We’ll work closely with your:

  • MLRO (Money Laundering Reporting Officer)
  • MLCO (Money Laundering Compliance Officer)
  • Heads of teams within scope of MLR
  • Representatives from your compliance, finance and HR teams (if relevant)

We may also speak to team members involved in client onboarding and conduct of matters to test understanding and day-to-day procedures.

What does your independent AML audit involve?

Our AML audit includes a detailed, independent review of your AML framework, including:

  • Policies, controls, and procedures
  • Firm-wide and client and matter risk assessments
  • Client due diligence (CDD) and ongoing monitoring
  • Staff training and competence
  • File reviews and interviews with key personnel

You’ll receive a clear, practical report setting out findings and recommendations — plus a debrief to discuss the results and next steps.

In addition, we can carry out a survey of employees/fee earners (the extent of the distribution is a matter for you), relating to AML awareness/knowledge (together with general risk and compliance areas if required) and include the results within the report. While this is not a requirement of the R21 independent AML audit, it does provide a snapshot of the level of compliance awareness and an insight into gaps in training/knowledge and areas that may be of concern.

Is your anti-money laundering audit available to firms of all sizes?

Yes. We work with law firms, accountants, corporate services firms, and other regulated entities of all sizes. The audit scope is tailored to reflect your firm’s structure, risk profile and areas of focus.

Can you carry out AML audits remotely?

Yes. The majority of our AML audits are conducted remotely, using secure online systems for document sharing and virtual meetings. Remote audits provide flexibility, convenience and less disruption to clients, without compromising the independence or quality of the review.

Do we need to prepare anything before the audit?

Yes, some preparation helps things run smoothly. Before the audit, we’ll provide a checklist of documents, which includes:

  • Your AML PCPs and firm-wide risk assessment
  • Training records
  • Client and matter files (sample selection)
  • Internal control and monitoring records

We’ll guide you through every step so you know exactly what’s needed.

How soon can the audit be carried out?

We can usually start an audit within 2–4 weeks of receiving your initial enquiry, depending on availability and your preferred timing. If you need the review urgently — for example, ahead of a regulator visit or desk-based inspection — we’ll do our best to accommodate an earlier date.

Frequently asked questions about our AML audits