Looking for a CFO? Learn more here!
All posts

Independent AML Audit Checklist for Founders

Most AML audit failures stem from missing evidence—build a clear, traceable trail from policy to files, alerts, SARs, vendors, and board records.
Independent AML Audit Checklist for Founders
Copy link

If I had to boil this down to one point, it’s this: most AML audit findings come from missing proof, not missing intent. If I can’t trace a policy to a customer file, then to an alert, then to a SAR log, then to board records, I should expect trouble.

Here’s the short version of what I need before fieldwork starts:

  • Current AML documents: board-approved policy, procedures, version history, and risk assessment
  • Governance records: board minutes, committee materials, issue logs, and prior finding trackers
  • Customer file proof: CDD/KYC records, risk ratings, screening results, and review dates
  • Case support: alert files, analyst notes, dispositions, review timing, and case indexes
  • SAR records: filed SARs, no-SAR decisions, filing dates, and 5-year record retention
  • Staff records: role-based training logs, missed-course follow-up, and refresher dates
  • Vendor files: due diligence, contracts, SLAs, audit rights, and review notes
  • Audit room setup: one request owner, one document index, and a folder structure that cuts search time

A few numbers matter here. SAR timing is usually 30 days, or 60 days if no suspect is known. Board minutes should usually cover at least the last 12 to 24 months. And I should do my last internal check about 1 to 2 weeks before fieldwork.

The goal is simple: make every AML decision easy to follow, easy to date, and easy to prove.

That’s what this checklist is about.

AML Audit Readiness: Full Traceability Chain for Founders

AML Audit Readiness: Full Traceability Chain for Founders

Part 1 : How to create AML/CFT Compliance Program/Framework | elements of AML/CFT compliance program

Checklist 1: Core AML Documents and Risk Assessment

Auditors usually start by following the logic of your business model through three things: your risk assessment, your policies, and your governance records. If those pieces don’t line up, or if the latest version is hard to find, that tends to get attention fast.

A simple setup helps a lot. Keep one central repository with three folders:

  • Current approved documents
  • Historical versions and redlines
  • Supporting evidence

That gives auditors a clean path to see what’s active now, what changed over time, and who signed off on it - without hunting through email chains or half-forgotten shared drives.

Board-Approved AML Policy, Procedures, and Version History

Your board-approved AML/BSA policy should spell out the scope of the program, the obligations it is meant to meet, escalation thresholds, recordkeeping rules, ownership, and approval roles. It should also point to the main parts of your program, including CIP, SAR/CTR reporting, CDD, transaction monitoring, alert review, investigation, escalation, and filing decisions.

Auditors also look for a version history or change log. That record should show the document number, effective date, approval date, summary of changes, approving body, and the business reason behind each update. Update the policy every year and after material changes, such as a new product, customer segment, channel, or geography. FFIEC Appendix H asks for the most recent board-approved BSA/AML compliance program, with the approval date captured in board minutes.[5]

Think of this policy as the starting point for the risk assessment below. If the policy says one thing and the assessment shows another, auditors will spot the gap.

Risk Assessment and Control Ownership

A current risk assessment is one of the first things auditors ask for. It should cover customer, product, transaction, channel, and geographic risk across the full business - not just one team or business unit.[3][4]

Keep it tied to how the business actually works. That might mean showing differences between SMB and consumer customers, card payments and wires, self-serve onboarding and direct sales, or domestic and cross-border activity.

The assessment should document:

  • Inherent risk
  • Controls
  • Residual risk
  • Final rating rationale
  • What triggers an update after business changes[4]

You also need to show who owns each control, who reviews it, who approves escalations, and who closes remediation. In a small company, one person may wear more than one hat. That happens. Still, auditors expect compensating controls and, where possible, some separation between preparation, review, and approval. A role matrix or RACI chart makes that easy to show.

Those ownership lines shouldn’t live only in someone’s head. They should show up clearly in board and committee records.

Governance Records That Support the Paper Trail

Governance records are what turn policy into proof. Keep committee charters, board or risk committee minutes, control summaries, prior audit reports, issue logs, and remediation trackers that show open items were tracked through closure.

For prior findings, list the basics in one place: severity, root cause, owner, target date, interim mitigation, testing evidence, and closure date.

Auditors care less about a spotless record than most teams expect. What they want to see is that issues were found on time, assigned to someone, worked through, and closed with evidence.

Checklist 2: Customer Files, Alerts, and SAR Records

After reviewing policies and governance records, auditors usually move straight into sampling. They pull actual customer files, alert cases, and SAR decisions to see if your written process lines up with day-to-day work.

This is often where things fall apart. A policy may look fine on paper, but file-level testing shows whether the team is following it.

A smart move before fieldwork: pull the same kind of sample auditors are likely to review. That gives you time to spot gaps in the files before someone else does.

CDD and KYC File Completeness

For individual customers, sampled files should include:

  • Full legal name
  • Date of birth
  • Residential address
  • Taxpayer identification number
  • Government-issued photo ID
  • Notes showing how the ID and customer information were verified

For entity customers, files should also include the legal name, formation documents, EIN, business address, a description of business activities, and ownership and control details for beneficial owners and control persons, including anyone who owns at least 25% of the equity, as required under FinCEN's CDD Rule.[6]

Each file should also show the customer's risk rating, the reason for that rating, sanctions and PEP screening results, and proof of periodic review. For higher-risk customers, there should be a separate EDD section or folder with source-of-funds and source-of-wealth documents, adverse media review notes, and compliance or senior management sign-off with the date.

Before fieldwork starts, pull a sample across low-, medium-, and high-risk customers and check each file against your written CDD program. Even one missing field can turn into a finding.

Alert Reviews and Case Documentation

Auditors will pull alert cases and try to rebuild the full decision trail. If the file doesn't tell a clear story, that's a problem.

Each case file should include the rule or trigger name and ID, a summary of the transactions involved, and analyst notes that explain what was reviewed and why the activity was or was not unusual.

The disposition, reviewer, and closure date need to match your stated review timeline. The disposition should be clear: Closed – no SAR, SAR filed, or Escalated to enhanced monitoring. Just as important, the reason for that decision should tie back to the thresholds in your policy.

Use one file naming format across all cases, such as CASE-2026-001045_CUST-000987_ALERT-R102, and keep an index with key fields like:

  • Case ID
  • Customer ID
  • Alert rule
  • Alert date
  • Closure date
  • Disposition
  • Analyst name

Before the audit begins, run a data quality check on that index for missing fields or format mismatches. It's a small step, but it can save a lot of back-and-forth during fieldwork.

SAR Log, No-SAR Decisions, and Filing Timeliness

After reviewing alerts, auditors test whether SAR decisions were logged, timed, and retained the right way.

Your central SAR register should include both filed SARs and no-SAR decisions. It should capture the customer ID, customer name, account number(s), alert origin, the date of initial detection or the initial determination that the activity appeared suspicious, the filing decision, the actual SAR filing date, and, when available, a submission confirmation number from the BSA E-Filing System.[7]

Timeliness is measured against the 30-day filing clock, or 60 days when no suspect is identified.[8][9][10] A calculated elapsed-days field in the register makes this easy to show.

No-SAR decisions need the same level of care as filed SARs. Every cleared case should have a written memo that explains what made the activity look suspicious at first, what the reviewer checked, and why the activity did not meet the filing threshold in the end. That decision should be approved based on policy, entered into the SAR register, and documented at the time of review.[5]

SAR supporting records must be kept for 5 years from the filing date and must be available to FinCEN or supervisory agencies if requested.[7]

Checklist 3: Training, Vendors, and Board Minutes

After file-level testing, auditors shift to the controls behind the work: training, vendors, and board oversight. The point is simple. They want to see whether the AML program works day to day, not just on paper.

Training Records by Role and Date

Track who completed training, when they took it, what role they held at the time, and which modules they finished. A solid training register should include employee name, department, role, hire date, required modules, completion dates, assessment scores, and the next refresher due date.

Role-based training is a big deal. Different teams face different risks, so the content should match the job.

  • Front-line staff should get training on CDD/KYC, red flags, CIP, and escalation
  • Monitoring teams should get training on SAR decisions and documentation
  • Managers and executives should get AML oversight training each year and within 30 to 60 days of moving into a new role [5]

Missed training should be logged, not brushed aside. Before the audit, run a gap report from your LMS or even a tracking spreadsheet. For each gap, record the employee name, missing module, date found, remediation step, and completion date. Keep the remediation record and the close date together.

Once staff training is in order, auditors usually turn to outsourced controls tied to the same workflow.

Vendor Due Diligence and Outsourced Control Oversight

Outsourcing does not move AML liability to the vendor. You still own it. That means each critical vendor should have a due diligence file, along with contracts that spell out control ownership, escalation paths, and audit rights [12].

If a vendor handles onboarding, monitoring, or screening, its controls need to line up with the same customer files and cases auditors already sampled. That connection matters.

For each AML-critical vendor, organize the due diligence file around these six areas:

Due Diligence Area Evidence to Have Ready
Company profile and ownership Company registration documents, ownership chart, background checks on key principals
Licensing and regulatory status Copies of licenses, compliance attestations, enforcement disclosures
Security controls SOC 2 or similar audit report, security policies, penetration test summary, data encryption standards
AML/sanctions capabilities Product descriptions, coverage lists for OFAC screening, match logic documentation, sample output reports
SLAs and incident handling Contracts with SLAs, uptime targets, incident timelines, and escalation paths
Performance history and KPIs Vendor review reports, false positive ratios, records of material incidents and resolutions

Contracts should also state who owns SAR decision-making, how suspicious activity moves through escalation, and how fast review and response must happen. Ongoing oversight should include scheduled vendor performance reviews, often quarterly or semi-annually, with scorecards and meeting minutes kept on file [13][14]. Auditors will check for that ongoing review.

Finally, auditors look at whether leadership saw the risk, discussed it, and did something about it.

Board and Committee Minutes

Board minutes show whether leadership understood AML risk and took action. Good minutes do more than note that a topic came up. They should show decisions, assigned owners, and follow-up steps [2].

Pull board and committee minutes for at least the last 12 to 24 months. Those records should show repeated discussion of:

  • changes to the AML risk assessment
  • alert and SAR trends
  • internal audit findings
  • staffing or system decisions that affect AML
  • remediation status for prior issues [11]

Board packs matter too. If they include AML dashboards with SAR volumes, alert backlogs, and training completion rates, auditors can trace the analysis behind the discussion.

A separate board action tracker helps tie it all together. It should log AML-related decisions from the minutes, assigned owners, and completion dates. Attach the board pack and the action tracker behind each discussion.

Final Pre-Audit Checklist and Next Steps

Once the main checklists are done, the last step is traceability. About 1 to 2 weeks before fieldwork starts, do a short internal review across every area auditors are likely to test. The point here is simple: make sure every policy, file, and decision is easy to follow from start to finish. Each document should have a clear owner, a known location, and a recent review date so no one is scrambling to rebuild records at the last minute.

How to Organize the Audit Room and Evidence List

A topic-based folder structure is usually the easiest way to set up the evidence repository. Create folders by area, such as 01 Policies & Risk Assessment, 02 Customer Files, 03 Alerts & Cases, 04 SAR Logs, 05 Training, 06 Vendors, 07 Governance & Board, and 08 Prior Findings & Remediation. Inside each folder, add a short document index so auditors can move through the evidence without guesswork. That index should list the document name, owner, and last review date. If records sit across more than one system, note the system of record for each item so the audit team doesn't get mixed versions of the same file. [16][21][23]

For customer files, the tracker should include:

  • Customer ID
  • Risk rating
  • Required documents
  • Missing items
  • Review date
  • Reviewer

For alert cases, track:

  • Alert ID
  • Trigger
  • Review date
  • Analyst
  • Disposition
  • SAR/no-SAR outcome

After the folders are set up, test the process. Pull a sample of files and make sure each one can be found fast and matched back to its tracker. [15][22]

How Founders Can Reduce Disruption Before Fieldwork Starts

Assign one internal audit coordinator before fieldwork begins. That person should handle document requests, keep a single request log with due dates, and route questions to the right team members. When no one owns that process, the same request can hit two teams, or worse, auditors can receive different versions of the same record.

Before auditors arrive, spot-check a few recent customer files, alert cases, SAR entries, and training records for traceability and missing approvals. If you find a gap, fix the control itself, not just the individual file. A patched record may look fine on the surface, but auditors usually follow the trail far enough to see whether the issue is isolated or part of a bigger pattern. If records are spread across multiple systems, Phoenix Strategy Group can help centralize them and create a cleaner evidence trail.

Weak documentation is behind many negative findings, especially when controls are in place but can't be shown clearly in workpapers, logs, or governance records. The gaps that show up most often include outdated policies, incomplete CDD/KYC files, thin alert narratives, SAR logs that don't line up with case files, missing training dates, stale vendor reviews, and board minutes that fail to show AML oversight. [1][17][18][19][20]

One last check goes a long way: trace a few records through the full audit path used across this checklist - policy → file → case → log → board record - and confirm each step connects from source to tracker to decision. If a record can't be traced from source to decision within minutes, there's a good chance auditors will flag it.

FAQs

What triggers an independent AML audit?

An independent AML audit usually comes into play when your business hits a key operational or regulatory milestone.

That often includes moments like:

  • preparing for regulatory exams
  • expanding into new markets
  • introducing automated compliance systems
  • scaling transaction monitoring
  • building long-term compliance frameworks

If you don’t have an internal audit team, it makes sense to bring in an external firm for independent reviews once or twice a year.

How many files should I test before fieldwork?

There’s no fixed industry-standard number. Your sampling strategy should be risk-based, with more frequent testing for high-risk activities and customer segments.

Sample files across risk categories to check that systems are working and customer profiles stay current. For the highest-risk files, use human judgment alongside automated monitoring, and document your sampling method and test plan.

What are the most common AML audit findings?

Common AML audit findings usually point to the same trouble spots: risk assessment, customer due diligence (CDD), and transaction monitoring.

Auditors also often flag:

  • weak independent audit functions
  • poor vendor oversight
  • record-keeping issues
  • poor data quality
  • missed Suspicious Activity Report (SAR) deadlines
  • uneven risk-based procedures for higher-risk clients
  • unclear escalation roles that slow responses to flagged activity or control failures

This tends to look less like one big failure and more like small cracks across the program. A team may have monitoring in place, for example, but weak data quality can blunt its value. Or escalation steps may exist on paper, yet unclear ownership delays action when alerts or control issues show up.

Related Blog Posts

Founder to Freedom Weekly
Zero guru BS. Real founders, real exits, real strategies - delivered weekly.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Our blog

Founders' Playbook: Build, Scale, Exit

We've built and sold companies (and made plenty of mistakes along the way). Here's everything we wish we knew from day one.
Consumer Goods Exit Planning: Strategic vs PE Buyers
3 min read

Consumer Goods Exit Planning: Strategic vs PE Buyers

Compare strategic vs private equity exits for consumer brands: cash at close, valuation, rollover equity, earnouts, and founder roles.
Read post
Cash Flow Forecasting for Seasonal Demand
3 min read

Cash Flow Forecasting for Seasonal Demand

Map receipts and payments, use 13-week and 12-month forecasts, and run monthly reviews to avoid seasonal cash shortfalls.
Read post
Independent AML Audit Checklist for Founders
3 min read

Independent AML Audit Checklist for Founders

Most AML audit failures stem from missing evidence—build a clear, traceable trail from policy to files, alerts, SARs, vendors, and board records.
Read post
Post-Quantum HSM Roadmap for Finance Data
3 min read

Post-Quantum HSM Roadmap for Finance Data

Map HSMs, rank long-lived finance data, and align vendors for a hybrid post-quantum migration before 2035.
Read post

Get the systems and clarity to build something bigger - your legacy, your way, with the freedom to enjoy it.