From September 18, 2026, CIMA-regulated financial services providers (FSPs) will face greater scrutiny of their anti-money laundering (AML), counter-terrorist financing and counter-proliferation financing frameworks. CIMA’s new AML rule introduces enhanced expectations around compliance program governance, documentation and independent testing, with expanded obligations relating to independent AML audits.
The question will no longer be simply whether an AML compliance program exists. It will be whether an organization can demonstrate, through independent review and testing, that its program is effective and operating as intended.
From Documentation to Demonstrable Effectiveness
Independent AML audits are not a new concept. CIMA’s AMLRs already require an effective, risk-based independent audit function and CIMA has repeatedly emphasized its importance through inspections and supervisory activities. However, the new AML rule elevates the role of independent assurance and makes expectations more explicit. Under the new framework, audits must assess the adequacy and effectiveness of the AML compliance program and its alignment with applicable legal and regulatory requirements. Audit frequency must reflect the nature, scale, complexity and risk profile of the business.
Audits must also be conducted by suitably qualified individuals who are independent of the controls being reviewed and free from conflicts that could impair objective judgement. In practical terms, the audit report is becoming more than an internal compliance exercise. It is regulatory evidence of whether the program works.
Why Boards Should Care
Compliance and AML frameworks can appear robust on paper while significant weaknesses exist in practice.
Customer due diligence may be inconsistently applied. Enhanced due diligence may not always be completed. Screening alerts may lack adequate documentation. Monitoring program may fail to identify material changes in customer risk. Oversight of administrators or other service providers may rely heavily on assurances rather than evidence. These are exactly the types of issues that an effective independent AML audit is designed to identify before they become regulatory findings.
For boards and senior management, an independent audit should answer three critical questions:
- Are our controls designed for the risks we face?
- Are those controls operating consistently in practice?
- Where do we need to strengthen governance, oversight or remediation?
A well-executed audit provides objective assurance and helps demonstrate a proactive approach to regulatory compliance.
What Effective Independent Assurance Looks Like
A meaningful AML audit should be tailored to the organization's specific risk profile rather than based on a generic checklist.
Typical areas of review include:
- Governance and regulatory reporting
- Enterprise-wide risk assessments
- Customer due diligence and enhanced due diligence
- Transaction monitoring
- Sanctions and adverse media screening
- Suspicious activity reporting processes
- Training and recordkeeping
- Oversight of outsourced AML functions
Importantly, effective testing goes beyond policy reviews and interviews. File sampling, process walkthroughs, control testing and data analysis provide stronger evidence of whether controls are functioning consistently across the organization.
The resulting report should provide practical, risk-based recommendations that enable management to prioritize remediation and track progress to completion.
Outsourcing Does Not Remove Accountability
This requirement is particularly relevant for investment funds and other FSPs that rely on administrators, AML officers, group functions or third-party service providers. While CIMA recognizes that certain audit work may be conducted at service-provider level, ultimate responsibility for AML compliance remains with the regulated entity. Boards should therefore consider whether the assurance they receive is sufficiently entity-specific and whether it adequately addresses the organization's risk profile and control environment.
Four Actions to Take Now
With the implementation date approaching, FSPs should:
- Review audit history and determine when the AML program was last independently assessed.
- Confirm auditor independence and document how conflicts of interest have been assessed.
- Define an appropriate scope and frequency based on the organization's risk assessment.
- Establish governance processes for reviewing findings, overseeing remediation and managing regulatory reporting requirements.
How Kroll Can Help
Kroll provides independent AML, regulatory compliance and assurance services to financial services organizations globally, including firms regulated by CIMA.
Our AML audit approach includes:
- Risk-based audit scoping
- Assessment of governance and compliance frameworks
- Control design and operating effectiveness testing
- Customer file and transaction sampling
- Review of outsourced arrangements
- Executive and regulatory reporting
- Prioritized remediation recommendations
The outcome is more than a compliance report. It is stronger board-level assurance, clearer visibility of emerging risks and a practical roadmap to strengthen the effectiveness of your AML framework. With September 18, 2026, fast approaching, now is the time to assess whether your AML program can do more than demonstrate compliance on paper.
If you require any assistance with any of the topics mentioned above or would like to learn more about how Kroll can support you, please reach out to your usual contact at Kroll or any of the contacts listed below.
Stay Ahead with Kroll
Financial Services Compliance and Regulation
In the ever-evolving financial services landscape, Kroll's award-winning team offers comprehensive regulatory and compliance services, guiding clients through registration, licensing, and compliance support to minimize risks and enhance efficiency globally.
Ireland Solutions
The regulatory environment in Ireland is dynamic and ever-changing. We support international funds, their investment managers, promoters, service providers and domestic financial institutions in navigating complex compliance and regulatory frameworks and to effectively manage financial crime risks.


