What does internal audit do for AML compliance?
Why an independent audit tests a firm's AML controls, how often CySEC-supervised firms must review them, and how the findings travel to the Board and to CySEC.
By the ExamPass CY editorial teamLast reviewed 5 min read
Topic 4 of 5 · all topics in this chapter
Short answer
Internal audit gives the Board an independent check that the firm's AML policies, controls and procedures work. The Law requires an independent audit function where the firm's size and nature make it appropriate, and the supervisor can impose one. In CySEC-supervised firms internal audit assesses at least once a year whether the AML controls are appropriate, effective and adequate, and reports in writing to the Board, which decides the fixes. The Board's minutes and the audit report reach CySEC within 20 days of the meeting and by the end of April.
Internal audit at a glance
| Point | Rule |
|---|---|
| Legal basis (Article 58B) | An independent audit function tests the internal policies, controls and procedures where appropriate to the firm's size and nature; the supervisor may require one |
| Frequency | At least annually for CySEC-supervised firms |
| What is reviewed | Appropriateness, effectiveness and adequacy of the AML/CFT policy, practices, measures, procedures and controls |
| Who audits | Should be independent of the functions they test and not combined with the compliance function, and qualified enough for their findings to be reliable |
| Report | Written findings to the Board, which decides the measures to fix weaknesses |
| To CySEC | Board minutes and the audit report within 20 days of the Board meeting and no later than four months after the year-end |
Source: Law 188(I)/2007, Article 58B, as amended up to 2026; CySEC AML Directive, paragraph 6; EBA/GL/2022/05 as applied by CySEC Circular C535.
Why does a firm need an independent audit of its AML controls?
The compliance officer designs the firm's AML procedures and monitors how they are applied, so the officer cannot also be the independent check on them. An independent audit fills that gap. It tests the policies, controls and procedures against the law and against what actually happens in the business, and tells the Board where they fall short. It is one of the four building blocks of a sound AML programme.
Article 58B of the Law requires an independent audit function to test the firm's internal AML policies, controls and procedures where this is appropriate given the size and nature of the firm's business, and the supervisor keeps the right to impose one. Those carrying out the audit should be independent of the areas they review, and the EBA guidelines that CySEC applies say the audit should not be combined with the AML/CFT compliance function. They should also be qualified enough for their findings and conclusions to be relied on.
Terms used in this note
- Independent audit function
- A function, separate from the areas it reviews, that tests whether the firm's AML/CFT policies, controls and procedures are appropriate and effective.
- Internal auditor's report
- The written report of the annual AML/CFT review, addressed to the Board and later sent to CySEC with the Board's minutes.
How often is the review done, and where do the findings go?
CySEC's AML Directive requires the internal audit department of a CySEC-supervised firm to assess, at least once a year, whether the firm's AML/CFT policy, practices, measures, procedures and controls are appropriate, effective and adequate. The same applies to every type of CySEC-supervised firm, including crypto-asset service providers. A review only on request, or a single review when the firm starts, is not enough.
The internal auditor puts the findings and observations in a written report to the Board. The Board decides what must be done to correct the weaknesses and deficiencies found. The minutes of that Board decision, together with the internal auditor's report, are then submitted to CySEC within 20 days of the Board meeting and no later than four months after the end of the calendar year, which means by the end of April at the latest.
CySEC assesses these reports, together with the compliance officers' Annual Reports, every year on a risk basis, and from time to time publishes the common weaknesses it finds, most recently in 2024. For internal audit, these have included reports and Board minutes sent late, reports that left out branches and subsidiaries outside the EEA, and Board minutes that did not set specific corrective measures for every weakness, or a timetable for them.
How to think about it
Follow the chain: qualified and independent auditors, a review at least once a year, a written report to the Board, a Board decision on the fixes, then the minutes and report to CySEC by the end of April. Compare it with the compliance officer's Annual Report, which reaches CySEC a month earlier, by the end of March. If an option has internal audit reporting to the compliance officer, reviewing only on request, or the auditors checking their own work, it is wrong.
Common mistakes
Having the compliance officer audit the AML controls. The audit must be independent of the function it tests; the compliance officer's own monitoring is a separate duty.
Reviewing the controls only when CySEC asks. CySEC-supervised firms must have them reviewed at least annually.
Sending the audit report only to the compliance officer. It goes to the Board, which decides the corrective measures; the minutes and report then go to CySEC.
Mixing up the deadlines. The internal audit report and minutes reach CySEC no later than four months after the year-end; the compliance officer's Annual Report no later than three months.
Legal references
- The Prevention and Suppression of Money Laundering and Terrorist Financing Law of 2007 (Law 188(I)/2007), consolidated Greek text on CyLaw (amendments up to Law 25(I)/2026) (opens in a new tab)
Article 58B: independent audit function
- CySEC Directive for the Prevention and Suppression of Money Laundering and Terrorist Financing, as amended (opens in a new tab)
Paragraph 6: obligations of the internal audit department
- CySEC Circular C535: EBA Guidelines on compliance management and the role of the AML/CFT compliance officer (EBA/GL/2022/05) (opens in a new tab)
- CySEC Circular C655: findings of the assessment of compliance officers' Annual Reports and internal audit reports (2024) (opens in a new tab)
Practise this topic
Test what you just read
The Chapter 4 pack has 49 exam-style questions, 5 of them on this topic. Every question has a hint before you answer and a full explanation after.
Or revise the numbers first with 12 free Chapter 4 flashcards →