An AML audit, formally independent testing, is a review of your anti-money laundering programme carried out by someone who does not run it. It checks whether your risk assessment matches your actual risk, whether your controls do what your policies say, and whether you can prove any of it. In the United States it is the fourth pillar of a BSA/AML programme. In Nigeria it sits inside the CBN's compliance expectations.
Consider what happened to Community Federal Savings Bank.
In April 2026 the OCC issued a consent order citing the usual things: alert thresholds never calibrated to the bank's risk profile, an automated triage system that auto-closed a very high percentage of alerts that should have been escalated, and controls that never caught up with the payment processing business the bank had grown since 2020.
Then it cited the audit itself. The OCC called the bank's independent testing weak, finding that the internal auditor had failed to identify weaknesses or test high-risk areas of the programme.
The audit got audited, and it failed. That is worth sitting with, because it reframes what an audit is for. It is not a box you tick before the regulator arrives. It is the thing the regulator will grade first, because a good audit should have found everything they are about to find.
What Is an AML Audit and Who Has to Have One?
An AML audit is independent testing of your compliance programme. Independent means the reviewer does not own the function being reviewed.
The FFIEC allows internal audit, outside auditors, consultants, or qualified staff not involved in the tested functions. A compliance officer cannot audit their own programme, and a first-line team cannot audit itself.
On frequency, the guidance is more flexible than most people believe. There is no mandated regulatory schedule. Testing should be commensurate with the money laundering and terrorist financing risk profile of the institution, with 12 to 18 months commonly cited, and more frequent testing where deficiencies have been found or the business has changed materially.
That distinction matters when you are defending a timetable. An eighteen-month cycle at a low-risk institution is defensible. A twelve-month cycle at an institution that just launched a payments business and acquired a portfolio is not.
What Auditors Actually Test, and What They Ask For
The FFIEC sets out what independent testing should evaluate, and the list is a useful audit-preparation checklist in its own right:
- Whether the risk assessment reflects the institution's actual risk profile
- Whether policies, procedures and processes conform to that risk profile
- Adherence to those established procedures in practice
- Compliance with recordkeeping and reporting requirements, covering the customer identification programme, customer due diligence, beneficial ownership, suspicious activity reports and currency transaction reports
- The adequacy of suspicious activity identification and reporting
- The integrity of the supporting technology systems and processes
- The quality and documentation of training
- Management's corrective action on previously identified findings
-
That last item deserves attention. Repeat findings are tested directly, which means a finding you closed with a policy update and no evidence of operation will come back, and it will come back worse. Auditors and examiners both treat a recurring issue as evidence that governance is not working, rather than as evidence that one control is not working.
The report itself has a standard too. It must contain enough information for a reviewer to conclude on the overall adequacy of the programme, ideally with an explicit statement about regulatory compliance. A report that lists observations without reaching a conclusion is an incomplete report.
The AML Audit Findings Raised Most Often
Six findings account for the bulk of what auditors write up. None is exotic, each has a specific fix, and any AML audit checklist worth using is built around avoiding them.
1. Risk Assessment That Drives Nothing
The most common finding, and the one that generates other findings.
The institution has a risk assessment. It scores products, customers and geographies. And nothing downstream changed when a rating went to high: the monitoring thresholds, the due diligence depth, the review frequency and the staffing for that area are identical to the year before.
An auditor tests this by picking one high-risk area from your assessment and asking what you do differently because of it. If the answer is a description rather than a control, the finding is written.
How to close it: build an action register that links every high residual risk to a specific decision, an owner and a date, and show the change that followed. Our guide on how to conduct an AML risk assessment covers the method that produces one.
2. Monitoring Rules Nobody Has Tuned
This is what the OCC cited at Community Federal: filtering criteria and thresholds not sufficiently calibrated for the institution's risk profile.
Rules get set at implementation, usually to vendor defaults, and then nobody owns them. The business changes. New products launch. New corridors open. The rules do not move, because switching one off feels like a risk decision nobody wants to sign, and tightening one means more alerts nobody can work.
How to close it: document a tuning cycle with an owner, and record the rationale, the testing and the approval for every threshold change. An untuned rule is defensible. An untuned rule with no evidence anyone ever looked at it is not.
3. Alert Backlogs and Cases Closed Without Reasoning
Also cited in the same order: an automated triage system auto-closing a very high percentage of alerts that should have been escalated.
The pattern is arithmetic. Alerts arrive faster than analysts can properly close them, throughput becomes the metric, and rationales degrade to "no suspicious activity identified" with nothing behind them. An auditor pulls fifty closed alerts and asks why each was closed.
How to close it: a documented rationale on every closure, a quality assurance sample reviewed by someone who did not close the cases, and reporting on the age of the oldest open case. The full workflow is in our guide to AML case management.
4. Incomplete Enhanced Due Diligence Files
The policy says enhanced due diligence applies to high-risk customers. The sample shows source of wealth missing, senior management approval undated or absent, and periodic reviews overdue.
This is usually a capacity finding dressed as a documentation finding. Thresholds were set where risk appetite wanted them rather than where the review team could deliver, and the shortfall surfaces in the files.
How to close it: measure your EDD completion rate before the auditor does, and either resource the band or move the threshold with a documented rationale. Both are defensible. Neither is defensible after the fact.
5. Training That Does Not Match the Risks You Identified
Training exists, attendance is recorded, and the content is generic. The institution rated agent networks and cross-border payments as high risk, and the training deck covers structuring and cash deposits.
Auditors test the link between the risk assessment and the training programme, and test whether front-line staff can recognise the typologies specific to their role.
How to close it: map training modules to the risks in your assessment, differentiate content by role, and keep the completion records and the materials together so the mapping is visible.
6. No Evidence of Board or Senior Management Oversight
Reports were produced. Whether anyone senior read them, questioned them or acted on them is not recorded anywhere.
Board minutes that note the compliance report was received are weaker than minutes recording a question asked and an answer given. Auditors look for evidence of challenge, not evidence of receipt.
How to close it: record what was escalated, what was asked, what was decided and by whom. Governance findings are among the cheapest to fix and the most damaging to leave open, because they suggest the programme has no owner.
How to Close an AML Audit Finding So It Stays Closed
A closed finding needs four things, and most remediation delivers only the first two.
1. The root cause, not the symptom. "Three EDD files were incomplete" is the symptom. Whether the cause was capacity, unclear procedure or an unowned queue determines the fix, and a fix aimed at the symptom guarantees the finding returns.
2. A named owner and a date. Remediation assigned to a department is remediation assigned to nobody.
3. Evidence the control now operates. This is the step most often skipped. Updating a procedure closes nothing. What closes a finding is a sample showing the procedure was followed after the change, with dates that sit after the finding.
4. Validation by someone independent. The person who fixed it should not be the person who confirms it is fixed. Given that auditors explicitly test corrective action on previous findings, a self-certified closure is a repeat finding waiting to happen.
The AML Audit Checklist to Work Through Before Fieldwork
Run this AML audit checklist before the auditor arrives rather than during fieldwork. Every line maps to something above.
- Is the risk assessment current, and can you show a control that changed because of it?
- Can you produce the tuning history for your monitoring rules, with approvals and dates?
- What is your alert closure rate, and can you show a quality sample reviewed independently?
- What proportion of high-risk customers have complete EDD files, including source of wealth and dated senior approval?
- Does your training map to the risks in your own assessment, by role?
- Do board minutes record challenge rather than receipt?
- Are all previous findings closed with evidence, validated independently?
- Can you retrieve a full decision record for any customer, any alert and any report from the last two years?
The last question is the one that decides how the audit goes. Everything else is easier to answer when the evidence retrieves in minutes.
What CBN Examiners Look For in Nigeria
Nigerian institutions work to the Money Laundering (Prevention and Prohibition) Act 2022 and the CBN AML/CFT/CPF Regulations 2022, which require an independent audit function alongside the compliance programme.
Three local emphases are worth preparing for specifically.
1. Filing timeliness against the statutory clock. Suspicious transaction reports must reach the NFIU within 24 hours of the transaction being deemed suspicious, with internal scrutiny completed inside 72 hours. An examiner can test this from your own records, so measure it before they do.
2. Domestic PEP coverage. Frameworks imported from other markets routinely under-weight domestic political exposure. An assessment that treats domestic PEPs as lower risk than foreign ones will be challenged here.
3. Automated system standards. The CBN Baseline Standards for Automated AML Solutions, issued in March 2026, set expectations for explainability, dynamic risk profiling and audit trails in AML technology. Institutions inside the compliance window should expect questions about how the system reaches a decision and what record it leaves.
And a point that catches teams out: Nigeria's exit from the FATF grey list in October 2025 lowered nothing. Supervisory expectations have tightened since, which we covered in Nigeria is off the FATF grey list.
Passing Your Next AML Audit With Youverify
A strong AML programme needs more than policies. It needs reliable data, controls that demonstrably operate, and a way to show both without three weeks of preparation.
For teams preparing for an audit, the practical question is narrow. Can we show our controls are working, and can we produce the evidence quickly?
Youverify Case Management is built to answer it. It is where a flag becomes a case: queues, SLAs, the entity graph, evidence, and a decision trail you can hand to an examiner. Every alert, who reviewed it, what they saw, what they decided and when, retrievable in the sample rather than reconstructed from six systems while fieldwork runs. Rule changes carry the same record, backtested against your own historical traffic before anything deploys, which is exactly the tuning history the OCC found missing at Community Federal.
When a case becomes a filing, Youverify Regulatory Reporting drafts STRs, CTRs and periodic returns from the case file, formatted per regulator and filed with the evidence attached. That is also the timeliness evidence an examiner will test you on, produced as a by-product of doing the work rather than assembled afterwards.
Regulator-ready before the regulator asks.
Book a free demo with our compliance experts and we will walk your last audit findings against what Youverify would have evidenced.