Skip to main content
Category: Compliance Program Governance

Audit Function

Also known as: Internal Audit Function, Internal Audit, Audit Department
Simply put

The audit function is a part of an organization responsible for independently evaluating how well the organization's controls, risk management, and governance processes are working. In an AML context, it provides assurance to senior management and the board that compliance measures are designed and operating as intended. It reviews and assesses controls rather than performing them, helping the organization identify weaknesses and improve operations.

Formal definition

The audit function refers to an independent, objective assurance and consulting activity established to add value and improve an organization's operations by evaluating and helping to enhance the effectiveness of governance, risk management, and control processes. As articulated by the Institute of Internal Auditors (IIA), internal auditing is designed to be independent and objective; in practice a primary objective of many internal audit functions is to review, assess, and monitor internal controls, commonly assisting management in monitoring the design and proper functioning of internal control policies and procedures. Within financial crime compliance programs, the audit function typically operates as an assurance layer distinct from, and independent of, the day-to-day controls it evaluates; it is generally positioned to test the adequacy and effectiveness of an AML/CFT program rather than to execute compliance operations. The specific structure, mandate, and reporting lines of the audit function vary by organization and jurisdiction, and its status as an obligation, its scope, and any independence requirements should be confirmed against the applicable regulatory framework and professional standards.

Why it matters

Within a financial crime compliance program, the audit function provides an independent layer of assurance that controls are not only well designed on paper but are actually operating as intended. Because it evaluates rather than executes controls, it is positioned to identify weaknesses, gaps, and blind spots that those running day-to-day compliance operations may not detect on their own. This independence is central to its value: it allows senior management and the board to receive an objective assessment of whether the AML/CFT program is adequate and effective, rather than relying solely on assurances from the teams responsible for the controls themselves.

The audit function contributes to the overall governance architecture by testing the design and functioning of internal control policies and procedures. In many organizations it is understood as a distinct assurance layer, separate from and independent of the compliance and business units it reviews. This separation matters because it reduces the risk that deficiencies go unchallenged and helps drive continuous improvement in risk management, governance, and control processes. It is important to note, however, that audit work assesses and monitors controls; it does not guarantee that financial crime will be prevented, and an audit's findings do not by themselves establish wrongdoing.

The specific status of the audit function as a regulatory obligation, along with its required scope, mandate, and independence, varies by organization and jurisdiction. Whether an independent audit is mandated, how frequently it must occur, and what standards apply should be confirmed against the applicable regulatory framework and professional standards rather than assumed to be uniform across regimes.

Who it's relevant to

Boards and senior management
The audit function provides boards and senior management with independent assurance on whether governance, risk management, and control processes are designed and operating as intended. This helps them exercise oversight of the AML/CFT program based on an objective assessment rather than solely on reporting from the units responsible for the controls.
Internal auditors
Internal auditors carry out the review, assessment, and monitoring of internal controls, commonly assisting management in monitoring the design and proper functioning of control policies and procedures. Their work depends on maintaining independence and objectivity relative to the functions they evaluate.
Compliance and financial crime teams
Teams that operate AML/CFT controls are subject to review by the audit function, which tests the adequacy and effectiveness of the program. Audit findings can help these teams identify weaknesses and improve operations, while remaining distinct from the day-to-day controls the compliance teams execute.
Risk and governance professionals
Those responsible for risk management and governance processes rely on the audit function as an assurance layer that evaluates the effectiveness of those processes. Its independent perspective supports continuous improvement in how the organization manages and mitigates financial crime risk, though it does not guarantee prevention.

Inside Audit Function

Independent Testing Requirement
The audit function represents the independent testing pillar of an AML program, providing objective assurance that controls are designed and operating effectively. In many jurisdictions this independence is a regulatory expectation, such as under FinCEN rules implementing the US Bank Secrecy Act, which identify independent testing as one of the required program elements, and under equivalent obligations for obliged entities in other regimes. The independence typically means the function is separate from the operational and compliance staff who own and run the controls being tested.
Scope of Coverage
An AML audit generally assesses the adequacy of the overall program against applicable requirements, covering areas such as customer due diligence and enhanced due diligence processes, transaction monitoring, sanctions and PEP screening arrangements, suspicious activity or suspicious transaction reporting workflows, recordkeeping, training, and governance. The precise scope depends on the entity's risk profile, business lines, and the requirements applicable in its jurisdiction, so what falls within any given audit cycle may vary.
Risk-Based Approach to Testing
The audit function typically applies a risk-based approach, focusing testing intensity and frequency on the areas of highest inherent and residual risk. This means testing is calibrated to detect, assess, and help manage weaknesses rather than to guarantee that all deficiencies are identified or that financial crime is prevented. Coverage and depth are generally proportionate to the size, complexity, and risk exposure of the obliged entity.
Reporting and Escalation Lines
Findings from the audit function are generally reported to senior management and, in many governance structures, to a board or audit committee, supporting accountability and remediation tracking. The reporting line reinforces independence, as the function typically does not report to the business or compliance areas it examines. Exact governance expectations differ by regime and should be confirmed against applicable regulation and supervisory guidance.
Delivery Model (Internal or External)
The audit function may be delivered by an internal audit team, by another sufficiently independent internal party, or outsourced to a qualified external provider. What is generally required is competence and independence from the tested activities rather than a specific organizational form. Smaller obliged entities may rely more on external testing, subject to the requirements applicable in their jurisdiction.

Common questions

Answers to the questions practitioners most commonly ask about Audit Function.

Is the internal audit function the same as the compliance function?
No. These are distinct components of an AML program and should not be treated as interchangeable. The compliance function generally designs, implements, and operates the AML controls on a day-to-day basis, whereas the audit function independently tests and evaluates whether those controls are adequate and effective. In many frameworks organized around the 'three lines' model, compliance typically operates as a second-line function while independent audit sits in the third line. Conflating the two undermines the independence that gives the audit function its value.
Does a clean audit report mean an institution's AML program is fully effective and free of financial crime risk?
No. An audit provides assurance that controls have been tested against defined criteria as of a point in time or over a review period; it does not guarantee that all deficiencies have been identified or that financial crime has been prevented. The audit function is a measure to evaluate and help improve the effectiveness of controls, not a guarantee of prevention. A favourable audit outcome should be read as reasonable, not absolute, assurance, and does not establish that any transaction or customer is free of wrongdoing.
How often should the AML audit function conduct its reviews?
Frequency is generally expected to be risk-based rather than fixed by a single universal rule, and specific expectations vary by jurisdiction and by the applicable regulator or supervisory guidance. In practice, the scope and timing are typically calibrated to the institution's risk profile, the complexity of its operations, and prior findings. Exact frequency requirements or supervisory expectations should be confirmed against the applicable regulation and guidance in the relevant jurisdiction.
Can the AML audit function be outsourced to an external party?
In many jurisdictions the audit function may be performed internally, by an external provider, or through a combination, provided that independence and appropriate expertise are maintained. Where audit is outsourced, the institution generally retains responsibility for the adequacy of the arrangement and for acting on findings. Whether and how outsourcing is permitted, and any conditions attached, should be confirmed against the applicable regulatory framework and supervisory expectations.
What should the scope of an AML audit typically cover?
Scope is generally determined on a risk-based basis and commonly includes evaluation of the adequacy and effectiveness of key AML control areas, which may include customer due diligence processes, transaction monitoring, sanctions and PEP screening arrangements, suspicious activity reporting processes, governance, training, and recordkeeping. The precise coverage depends on the institution's risk profile and the obligations applicable to it, and should be aligned with the relevant regulatory requirements rather than assumed to be identical across regimes.
How should audit findings be reported and followed up?
Findings are typically reported to senior management and to the board or an equivalent oversight body, with independence from the functions being reviewed. Effective follow-up generally involves tracking identified deficiencies through to remediation and validating that corrective actions have been implemented. Reporting lines, escalation expectations, and record retention should be confirmed against the applicable regulatory framework and internal governance arrangements.

Common misconceptions

The AML audit function is the same as the compliance function and can be performed by compliance staff.
These are distinct roles. Compliance typically designs, owns, and operates the AML controls, while the audit function independently tests those controls. Having compliance test its own work would generally undermine the independence that independent testing requirements, such as those under FinCEN rules and equivalent regimes, are intended to provide.
A clean audit report proves that the institution has no money laundering or terrorist financing occurring through it.
An audit provides assurance about the design and operation of controls at a point in time and on a sample or risk-focused basis. It is a measure to detect and help manage weaknesses, not a guarantee that financial crime is absent or prevented. A favorable finding does not establish that no illicit activity has occurred.
There is a single global rule dictating exactly how often and how the AML audit must be conducted.
Requirements diverge across regimes. The FATF Recommendations set standards rather than binding law, while binding obligations arise from instruments such as the US Bank Secrecy Act and FinCEN rules, the EU AML framework, and the UK Money Laundering Regulations. Frequency, scope, and delivery expectations vary and should be confirmed against the applicable regulation.

Best practices

Preserve independence by ensuring the audit function does not report to, or test the work of, staff it is embedded within, and confirm that reporting lines reach senior management and, where applicable, a board or audit committee.
Apply a risk-based methodology that concentrates testing depth and frequency on higher-risk business lines, products, and controls, while documenting the rationale for scope decisions and any areas excluded from a given cycle.
Cover the full range of program elements over an appropriate cycle, including customer due diligence and enhanced due diligence, transaction monitoring, sanctions and PEP screening, suspicious activity or suspicious transaction reporting, recordkeeping, training, and governance.
Confirm the specific frequency, scope, and independence expectations against the requirements applicable to the entity's jurisdiction and obliged-entity category, rather than assuming a uniform global standard.
Ensure that individuals or providers performing the audit have sufficient competence and are demonstrably independent of the activities under review, whether the function is delivered internally or outsourced.
Track findings through to remediation with clear ownership and timelines, and frame results as assurance on control effectiveness rather than as confirmation that financial crime risk has been eliminated.