What to expect during an AML review

If you’re regulated for anti-money laundering (AML) purposes, you should expect a compliance review at some point.
Whether it’s carried out by a government body or your professional supervisor, the purpose is the same: to assess whether your business is meeting its AML obligations, built from the international standards FATF sets and written into your country’s own law.
That might sound daunting but it doesn’t need to be. Knowing what reviewers look for, and having the right evidence ready, makes the process far smoother.
Who carries out AML reviews
Every country that implements FATF’s standards needs to designate at least one supervisor responsible for checking that AML-regulated businesses are meeting their obligations.
FATF’s Recommendation 28 sets out that designated non-financial businesses and professions (DNFBPs) need to be subject to effective systems for monitoring and ensuring compliance. This can be by a dedicated regulator, a professional body or another competent authority.
How many bodies do this, and what they’re called, varies by country. Some have a single regulator covering every sector. Others split supervision across multiple professional bodies and government departments, coordinated by a central oversight function.
How the review process works
You’ll likely to be asked to provide a list of documents and may be invited to grant read-only access to your AML system (for AMLCC users, this takes seconds). Depending on your supervisor, the review may be:
Remote, where evidence is reviewed digitally and discussed over calls
On-site, where the reviewer visits your office to interview staff and examine files
They’ll typically:
- Request your key AML documents, including your current and historic Business Risk Assessments, AML Policies, Controls and Procedures (PCPs), training logs and sample client files.
- Interview key people, usually your Money Laundering Reporting Officer (MLRO) or Money Laundering Compliance Officer (MLCO), and sometimes front-line staff.
- Test compliance in practice, to check whether what’s written in your policies is actually followed day-to-day.
- Provide feedback or an action plan, setting out areas for improvement or follow-up.
What reviewers will look for
A review focuses on two broad areas: your AML framework and evidence that it works effectively.
Supervisors no longer just look at whether your AML documentation exists. The question now is can your business show it understands the inherent risk, acts proportionately and has reduced that risk as a result?
1. Your business framework: policies, risk assessments and controls
Reviewers will assess whether your AML documentation meets the requirements set out in FATF’s Recommendation 18, as implemented in your country’s law. They’ll look for:
- A business-wide risk assessment that’s current, detailed and tailored to your services, clients and jurisdictions
- Policies, controls and procedures (PCPs) aligned to that risk assessment
- Regularly updated and approved PCPs and business-wide risk assessments showing annual reviews or updates following regulatory change
- Defined roles and responsibilities for AML oversight
Generic or outdated documents are a red flag. As our article The 6 signs your AML PCPs are out of date notes, many inspection failures come from “copied templates” that don’t relate to the business’ actual risks.
2. Your evidence: people, records and real-world activity
Beyond the paperwork, reviewers need to see proof that your AML framework is used and works in practice. They’ll check:
- AML Training – Has every employee completed regular AML training, passed their tests and acknowledged policy updates?
- Client due diligence (CDD) – Can you evidence ongoing CDD? How are clients’ identities, beneficial ownership and source of funds verified?
- Risk assessments – Are client risk assessments completed in full and updated when circumstances change or according to the timeframe detailed in your PCPs?
- Record keeping – Can you retrieve files, internal suspicious report logs and decision-making records quickly?
If you use AMLCC, this is all visible on your dashboard.
Common findings across all regulated sectors
FATF supports its Recommendations with sector-specific guidance, built from the findings of each country’s mutual evaluations.
It also carried out a review in 2024, looking at legal professionals, accountants, TCSPs and property businesses together. It found that while half the FATF member countries scored above 80% on technical compliance, the seven members, which together represent over half of global GDP, scored below 50%.
There were three areas of particular concern: customer due diligence, internal controls and supervisors having enough power to apply a risk-based approach properly. Broken down by sector, this is shown by:
Property businesses
- In the fourth round of mutual evaluations, 78% of assessed countries were rated poor or very poor on how well the sector understood its own money laundering and terrorist financing risk.
- Agents don’t hold an ongoing relationship with a buyer the way a bank does, so building in ongoing monitoring is harder from the start.
- Suspicious activity reporting is patchy across the sector.
- Beneficial ownership checks on the entities buying and selling property are inconsistently applied.
- Supervisors are often working with limited capacity to catch any of it.
Legal professionals
- Client due diligence that doesn’t go deep enough to reflect the actual risk of a client or transaction.
- Beneficial ownership that’s identified on paper but not properly verified.
- Weak oversight of nominee arrangements, where someone holds an asset or a role on behalf of an undisclosed third party.
Accounting profession
- The role covers a wide range of services, from property transactions to asset management to business administration, each carrying its own exposure.
- FATF has documented real cases of accountants using their own systems, including shadow accounting records, to help conceal the proceeds of crime.
- Due diligence and record-keeping that hasn’t kept pace with how varied the work actually is.
Trust and company service providers
- Shell companies and trusts are a standard mechanism criminals use to hide who really owns an asset.
- Policies and procedures that haven’t been tested against that specific risk.
- Ongoing due diligence that tapers off after onboarding.
- Risk assessments that don’t reflect how the entities they’ve formed are actually being used.
How to prepare for your next review
Preparation is about visibility. You need to know where everything sits, how up to date it is and who’s responsible. Here’s how to get review-ready:
- Centralise your AML evidence: Store all policies, training logs, CDD and risk assessments in one place.
- Check your business-wide risk assessment date: FATF’s Recommendation 1 requires you to keep it current. Many supervisors expect that to mean at least annual reviews, so treat anything older than 12 months as a priority.
- Review your PCPs: Update them in line with any changes to your services or your country’s national risk assessment.
- Audit your training: Make sure every staff member’s completion is logged and up to date.
- Spot-check client files: Ensure CDD records, risk assessments and decision notes are complete and accessible.
- Document updates and approvals: Keep evidence of who reviewed and signed off each policy change.
Many businesses run a mini internal audit before an expected review. This helps identify any gaps early and creates a culture of continual readiness rather than last-minute panic.
What happens after the review
After your supervisor has completed their review, they’ll usually send a written report summarising findings. This will confirm where you’re compliant, highlight any weaknesses or breaches, and set out required improvements and timescales.
If issues are found, take them seriously. Non-compliance can lead to financial penalties and regulatory action. But if you respond promptly, document your remedial steps and demonstrate improvement, your supervisor will usually view that positively.
An AML review isn’t something to fear. It’s a chance to show that your businesses takes compliance seriously. With the right preparation, evidence and systems in place, you can make the process quick, smooth and even beneficial.
Compliance isn’t about ticking boxes. It’s about proving that your AML framework is effective and protects your business, your clients and the integrity of your profession.
What others have said
Making compliance easier








