CySEC AML · Chapter 4 · Topic 4 of 5

What does internal audit do for AML compliance?

Why an independent audit tests a firm's AML controls, how often CySEC-supervised firms must review them, and how the findings travel to the Board and to CySEC.

By the ExamPass CY editorial teamLast reviewed 5 min read

Tested inAML · Ch 4

Short answer

Internal audit gives the Board an independent check that the firm's AML policies, controls and procedures work. The Law requires an independent audit function where the firm's size and nature make it appropriate, and the supervisor can impose one. In CySEC-supervised firms internal audit assesses at least once a year whether the AML controls are appropriate, effective and adequate, and reports in writing to the Board, which decides the fixes. The Board's minutes and the audit report reach CySEC within 20 days of the meeting and by the end of April.

Internal audit at a glance

Legal basis (Article 58B)An independent audit function tests the internal policies, controls and procedures where appropriate to the firm's size and nature; the supervisor may require one
FrequencyAt least annually for CySEC-supervised firms
What is reviewedAppropriateness, effectiveness and adequacy of the AML/CFT policy, practices, measures, procedures and controls
Who auditsShould be independent of the functions they test and not combined with the compliance function, and qualified enough for their findings to be reliable
ReportWritten findings to the Board, which decides the measures to fix weaknesses
To CySECBoard minutes and the audit report within 20 days of the Board meeting and no later than four months after the year-end

Source: Law 188(I)/2007, Article 58B, as amended up to 2026; CySEC AML Directive, paragraph 6; EBA/GL/2022/05 as applied by CySEC Circular C535.

Why does a firm need an independent audit of its AML controls?

The compliance officer designs the firm's AML procedures and monitors how they are applied, so the officer cannot also be the independent check on them. An independent audit fills that gap. It tests the policies, controls and procedures against the law and against what actually happens in the business, and tells the Board where they fall short. It is one of the four building blocks of a sound AML programme.

Article 58B of the Law requires an independent audit function to test the firm's internal AML policies, controls and procedures where this is appropriate given the size and nature of the firm's business, and the supervisor keeps the right to impose one. Those carrying out the audit should be independent of the areas they review, and the EBA guidelines that CySEC applies say the audit should not be combined with the AML/CFT compliance function. They should also be qualified enough for their findings and conclusions to be relied on.

Terms used in this note

Independent audit function
A function, separate from the areas it reviews, that tests whether the firm's AML/CFT policies, controls and procedures are appropriate and effective.
Internal auditor's report
The written report of the annual AML/CFT review, addressed to the Board and later sent to CySEC with the Board's minutes.

How often is the review done, and where do the findings go?

CySEC's AML Directive requires the internal audit department of a CySEC-supervised firm to assess, at least once a year, whether the firm's AML/CFT policy, practices, measures, procedures and controls are appropriate, effective and adequate. The same applies to every type of CySEC-supervised firm, including crypto-asset service providers. A review only on request, or a single review when the firm starts, is not enough.

The internal auditor puts the findings and observations in a written report to the Board. The Board decides what must be done to correct the weaknesses and deficiencies found. The minutes of that Board decision, together with the internal auditor's report, are then submitted to CySEC within 20 days of the Board meeting and no later than four months after the end of the calendar year, which means by the end of April at the latest.

CySEC assesses these reports, together with the compliance officers' Annual Reports, every year on a risk basis, and from time to time publishes the common weaknesses it finds, most recently in 2024. For internal audit, these have included reports and Board minutes sent late, reports that left out branches and subsidiaries outside the EEA, and Board minutes that did not set specific corrective measures for every weakness, or a timetable for them.

How to think about it

Follow the chain: qualified and independent auditors, a review at least once a year, a written report to the Board, a Board decision on the fixes, then the minutes and report to CySEC by the end of April. Compare it with the compliance officer's Annual Report, which reaches CySEC a month earlier, by the end of March. If an option has internal audit reporting to the compliance officer, reviewing only on request, or the auditors checking their own work, it is wrong.

Common mistakes

  1. Having the compliance officer audit the AML controls. The audit must be independent of the function it tests; the compliance officer's own monitoring is a separate duty.

  2. Reviewing the controls only when CySEC asks. CySEC-supervised firms must have them reviewed at least annually.

  3. Sending the audit report only to the compliance officer. It goes to the Board, which decides the corrective measures; the minutes and report then go to CySEC.

  4. Mixing up the deadlines. The internal audit report and minutes reach CySEC no later than four months after the year-end; the compliance officer's Annual Report no later than three months.

Practise this topic

Test what you just read

The Chapter 4 pack has 49 exam-style questions, 5 of them on this topic. Every question has a hint before you answer and a full explanation after.

Try the free demo

Or revise the numbers first with 12 free Chapter 4 flashcards →

Last reviewed on by the ExamPass CY editorial team against the law in force on that date. Study notes help you prepare for the CySEC exams; they are not legal advice. ExamPass CY is not affiliated with CySEC.

How we write study notesReport an error