AML/CFT  ·  Audit & Compliance Review

AML Audit & Compliance Review
for Regulated Businesses

Independent AML/CFT audits and targeted compliance reviews for financial institutions, payment firms, technology-enabled businesses and other regulated organisations — testing control design, implementation, operating effectiveness and supporting evidence.

Control weaknesses, governance gaps and implementation deficiencies are translated into risk-rated findings and clear remediation priorities.

Independent
Objective third-party
review
Gap-Focused
Actionable findings,
not checklists
Evidence-Ready
Documentation built for
supervisory review
Independent review

What Is an AML Audit and Why Does It Matter?

An AML/CFT audit is an independent review of your compliance programme — assessing whether your policies, procedures, controls, customer due diligence, transaction monitoring, sanctions screening, governance and MLRO oversight are operating effectively and in line with current regulatory requirements.

AML/CFT supervisors increasingly examine whether documented controls are implemented and supported by evidence, not only whether policies exist. In the Czech Republic, relevant supervisory roles include the Financial Analytical Office and, for financial-sector entities within its remit, the Czech National Bank. At EU level, AMLA is building the common supervisory framework and will begin direct supervision of selected high-risk cross-border financial-sector obliged entities in 2028.

Periodic independent review is also a component of sound AML/CFT governance — supporting ongoing supervisory readiness, banking and investor due diligence, and internal accountability structures.

Why independent review matters

Why Independent AML Audits Matter

Regulators, banks, investors and business partners increasingly assess not only whether AML/CFT documentation exists, but whether compliance controls operate effectively in practice.

An independent AML audit helps businesses identify control weaknesses, governance gaps and documentation deficiencies before they become regulatory findings, onboarding obstacles or operational risks.

Independent review also supports regulatory readiness, licensing applications, investor due diligence and ongoing governance obligations.

When clients request an AML audit

Typical Reasons Clients Request an AML Audit.

Businesses commission independent AML reviews at different stages — proactively and in response to specific events.

Licensing application
MiCA / CASP / PSP / EMI
Bank or EMI onboarding
Banking due diligence requirement
Investor due diligence
Institutional compliance review
Regulatory review preparation
Supervisory examination readiness
Periodic independent AML review
Ongoing governance obligation
Post-finding remediation
Following regulatory findings or enforcement
Scope of review

What an AML Audit Covers.

A comprehensive AML/CFT audit covers all core components of the compliance programme — assessed against current EU AML requirements, Czech zákon č. 253/2008 Sb. and applicable FATF standards.

AML Policies & Procedures
Currency, completeness and alignment with current EU AML requirements, Czech zákon č. 253/2008 Sb. and FATF standards — including CDD, EDD, sanctions, TM, STR and governance documentation.
AML/CFT Enterprise-Wide Risk Assessment
Methodology, coverage and calibration to actual business risk — products, customers, geographies, delivery channels and whether the Enterprise-Wide Risk Assessment appropriately drives allocation of compliance resources.
Customer Due Diligence (CDD)
Onboarding procedures, verification standards, beneficial ownership identification, ongoing monitoring and risk scoring — including sample file review where appropriate.
Enhanced Due Diligence (EDD)
Application to high-risk customers, PEPs, high-risk jurisdictions and complex ownership structures — and whether EDD standards are proportionate to actual risk.
Transaction Monitoring
Calibration of monitoring rules, alert handling procedures, false positive rates, escalation governance and documentation of review decisions.
Sanctions Screening
Coverage of applicable EU, UN and other sanctions lists, screening frequency, update processes and handling of potential matches and escalation procedures.
Suspicious Activity Reporting
STR identification procedures, escalation governance, filing processes to FAÚ (or relevant authority), documentation standards and MLRO oversight of the reporting function.
MLRO Function & Governance
Role clarity, independence, oversight adequacy, management reporting, training and whether the MLRO function meets applicable regulatory expectations.
Sector-Specific Controls
Where applicable: Travel Rule compliance controls, blockchain analytics processes, wallet risk assessment procedures, crypto-specific transaction monitoring measures, sanctions controls for virtual asset transfers and digital asset AML governance frameworks.
Scope options

Types of AML/CFT Review.

From full programme audit to targeted control assessments and remediation validation — scoped to your business needs and regulatory context.

Full Programme
AML/CFT Independent Audit
  • Policies, procedures & governance review
  • Enterprise-Wide Risk Assessment methodology assessment
  • CDD & EDD process evaluation
  • Transaction monitoring effectiveness
  • Sanctions screening controls
  • STR escalation & MLRO governance
  • Gap identification & remediation report
Targeted Review
AML Control Effectiveness Review
  • Focused assessment of specific controls
  • KYC & EDD process review
  • Sanctions screening assessment
  • Customer risk scoring review
  • Onboarding controls assessment
  • Internal escalation procedures review
Transaction Monitoring
TM Testing & Review
  • Monitoring scenario coverage review
  • Alert threshold assessment
  • False positive analysis
  • Escalation workflow assessment
  • Monitoring governance documentation
  • Recommendations for enhancement
Sanctions
Sanctions Compliance Review
  • Sanctions screening programme review
  • List coverage assessment
  • False positive management review
  • Sanctions risk governance
  • Escalation & de-listing procedures
Follow-Up Review
Remediation Validation Review
  • Validation of completed remediation actions
  • Re-testing of previously deficient controls
  • Review of supporting evidence and implementation
  • Assessment of finding closure
  • Identification of residual gaps
  • Follow-up report with remaining priorities
Financial Crime
Fraud & Financial Crime Controls
  • Fraud risk assessment
  • Internal controls review
  • Payment fraud prevention
  • Account takeover risk review
  • Financial crime typology assessment
Applicable businesses

Who Needs an Independent AML Audit?

Independent AML audits are relevant for any regulated or higher-risk business — both as a proactive compliance measure and in response to specific regulatory events.

01
Licensing Applications
A pre-licensing AML review can help identify whether governance, documentation and controls are sufficiently developed for the relevant authorisation or registration process. The exact evidentiary value and required scope depend on the jurisdiction and competent authority.
02
Preparing for Supervisory Review
Where a supervisory examination, thematic review or regulatory enquiry is anticipated, an independent audit provides structured evidence of programme effectiveness and a documented remediation plan.
03
Post-Finding Remediation
Following regulatory findings, enforcement action or internal escalation, an independent review assesses whether remediation measures are adequate and the programme now meets current requirements.
04
Periodic Independent Review
Depending on the applicable legal and supervisory framework, regulated businesses may be required or expected to maintain independent testing of AML/CFT controls. The review cadence and scope should be set by the relevant requirements, size, risk profile and governance model rather than by a universal annual rule.
05
Business Model Changes
New products, new markets, M&A or corporate restructuring can materially change a business's AML/CFT risk profile. An audit following such changes validates that existing controls remain adequate.
06
New or Early-Stage Businesses
Businesses building an AML/CFT programme from the ground up benefit from an early independent review to validate that controls are proportionate, risk-based and defensible before operations scale.
Industries

Industries We Commonly Audit.

We conduct AML/CFT audits and independent compliance reviews for a wide range of regulated and higher-risk businesses, including:
Crypto-Asset Service Providers (CASPs)
Virtual Asset Service Providers (VASPs)
FinTech Companies
Payment Service Providers (PSPs)
Electronic Money Institutions (EMIs)
Investment Firms
Forex Brokers
Money Service Businesses (MSBs)
Financial Intermediaries
Other regulated businesses subject to AML/CFT obligations
Our experience includes businesses operating across both traditional financial services and digital asset sectors.
Crypto & digital asset businesses
Additional audit scope where digital-asset activity is present
Where the business has digital-asset exposure, audit scope may also include:
Travel Rule controls (TFR, Reg. (EU) 2023/1113)
Customer risk scoring methodologies
Blockchain analytics controls
Sanctions screening frameworks
Crypto-specific transaction monitoring measures
Unhosted wallet risk assessment procedures
Our process

How an AML Audit Works.

A structured, four-stage process — from scoping to written report and remediation support.

01
Scoping
We define the scope based on your business model, regulatory obligations, risk profile and any specific areas of concern — producing clear terms of reference before fieldwork begins.
02
Fieldwork & Document Review
We review your AML/CFT policies, risk assessments, CDD files, transaction monitoring outputs, sanctions records, STR documentation and MLRO governance materials against current regulatory requirements.
03
Findings & Risk-Rated Recommendations
We identify compliance gaps, weaknesses in controls and areas where documentation or practice falls short of regulatory expectations — prioritised by severity and regulatory risk.
04
Audit Report & Remediation
We deliver a structured written audit report with findings, risk ratings and recommended remediation actions. Where required, we provide ongoing support to implement recommendations.
What the audit produces
Written audit report with findings · Control gap summary with risk-based prioritisation · Remediation recommendations · Management summary for internal governance or regulatory use · Optional follow-up support for implementation
Report format
Reports are structured and documented to withstand supervisory review — suitable for internal governance, regulatory submission, banking due diligence and investor review.
Regulatory framework

AML Audit Requirements in the Czech Republic and EU.

Czech Republic
zákon č. 253/2008 Sb.
Czech obliged entities must maintain AML/CFT arrangements appropriate to their legal obligations and risk profile. The need, form and frequency of independent testing can depend on the applicable sectoral framework, governance model and supervisory expectations. The Financial Analytical Office and, for financial-sector entities within its remit, the Czech National Bank are relevant supervisors.
Supervised by FAÚ and ČNB
European Union
AMLR & AMLA
From 10 July 2027, Regulation (EU) 2024/1624 requires obliged entities to maintain internal controls and an independent audit function to test AML/CFT policies, procedures and controls; where there is no independent audit function, the testing may be carried out by an external expert, subject to the Regulation’s proportionality framework. AMLA will begin direct supervision of selected high-risk cross-border financial-sector obliged entities in 2028.
AMLD6 · AMLR 2024/1624 · AMLA (Reg. 2024/1620)
International Standards
FATF Recommendations
FATF Recommendation 18 requires financial institutions to implement independent audit functions to test the overall AML/CFT programme. For VASPs and CASPs, FATF Recommendation 15 and associated guidance set out expectations for programme testing and independent review. For cross-border businesses, we align audit scope to both EU requirements and applicable FATF standards.
FATF R.15 · FATF R.18 · FATF Guidance on Virtual Assets
Why LEX ARTA

Findings You Can Act On.

Our AML audits are conducted by professionals with hands-on MLRO, Compliance Officer and financial crime investigation experience — not generic checklists.

Practitioner perspective
Conducted by professionals with hands-on MLRO and financial crime investigation experience — findings have real operational weight, not just documentary gaps.
Findings you can act on
We prioritise findings by regulatory risk and provide specific remediation guidance — not generic observations that leave you uncertain about next steps.
Built for regulatory scrutiny
Audit reports are structured and documented to withstand supervisory review — because regulators may ask to see your independent testing, and the quality of the report matters.
EU & Czech expertise
We work across EU AML requirements, Czech zákon č. 253/2008 Sb., FATF standards and sector-specific frameworks — relevant for CASPs, VASPs, payment institutions and financial intermediaries.
Professional background

Credentials & Professional Background.

Our AML/CFT audit work is conducted by professionals with formal certifications and hands-on operational experience in AML/CFT compliance, financial crime and regulatory practice — not generic consulting backgrounds.

ACAMS
Certified Anti-Money Laundering Specialist — global standard in AML/CFT compliance
ACFE
Association of Certified Fraud Examiners — financial crime and fraud risk expertise
CySEC AML Certification
AML certification for EU investment services — Cyprus Securities & Exchange Commission
MLRO & Compliance Officer Experience
Practical operational AML/CFT experience within regulated businesses — not only advisory
Financial Crime & Investigator Background
Experience in economic crime and financial crime investigations, including evidence review and regulatory reporting
PhD-Qualified Legal Professionals
Doctoral-level legal and regulatory expertise supporting analytical depth in complex compliance matters
Pricing

Tailored to Scope.

AML/CFT audit fees are determined by the regulatory framework, business model, jurisdictions involved, complexity of the AML/CFT programme and the depth of testing required.

Fixed-fee proposal
Defined after initial scoping
A fixed-fee proposal is provided once the audit scope, relevant jurisdictions, required testing and expected deliverables have been defined.
Independence boundary. A review is not described as independent where LEX ARTA materially designed or operated the controls within the review scope and the resulting conflict cannot be appropriately managed. In that case, remediation support and independent assurance should be separately scoped or performed by different reviewers.
Common questions

AML Audit — Frequently Asked Questions.

How often should an AML audit be conducted?
+
There is no universal AML audit frequency. The required or appropriate cadence depends on applicable law, supervisory expectations, the entity’s size and risk profile, governance arrangements and material changes in the business. Additional reviews may also be commissioned before or after supervisory activity, licensing work or significant changes to the operating model.
What is the difference between an internal AML review and an independent AML audit?
+
An internal review is conducted by your own compliance team or MLRO. An independent AML audit is conducted by an external party with no involvement in the design or operation of your AML/CFT programme. Regulators generally expect periodic independent testing in addition to internal monitoring — and independent findings carry more evidentiary weight in a supervisory context.
What documentation is needed for an AML audit?
+
We typically review AML/CFT policies and procedures, the enterprise-wide risk assessment, CDD and EDD documentation, transaction monitoring records and alert logs, sanctions screening records, STR files, MLRO governance materials, training records and any previous audit or supervisory findings.
Can an AML audit help with a licensing application?
+
An independent pre-application review can help identify weaknesses in AML/CFT governance, documentation, controls and implementation before submission or supervisory follow-up. For MiCA CASP authorisation, the application itself must contain specified AML/CFT controls, policies, procedures and risk-assessment information; an independent audit is not automatically a standalone application requirement and should be scoped according to the jurisdiction and authority expectations.
What happens if the audit identifies gaps?
+
Identifying and evidencing deficiencies is a core audit outcome. Findings are prioritised by severity and supported by remediation recommendations. Any implementation support is separately scoped and subject to independence and conflict considerations so that remediation work is not presented as independent assurance.
Is the audit report suitable for regulatory review?
+
Reports are structured and documented for internal governance, regulatory review, banking due diligence and investor assessment. However, acceptance and evaluation of any report remain at the discretion of the relevant authority or institution.
AML/CFT Services

Explore AML/CFT Services.

01 · Current
AML Audit & Compliance Review
02
Enterprise-Wide Risk Assessment →
03
Outsourced MLRO & AML Support →
04
AML Policies & Procedures →
05
Travel Rule & TFR Compliance →
06
AML Training →
07
AML Regulatory Gap Analysis →
08
AML Remediation & Regulatory Readiness →
Need an AML audit or targeted compliance review?
LEX ARTA provides AML/CFT audits and targeted compliance reviews for financial institutions, payment firms and other regulated or higher-risk businesses.