
AML & Financial Crime
AML/CFT Independent Review
Independent AML/CFT review support for firms that need evidence-ready controls, clear findings and remediation that management can act on.
Overview
BlackCores & Partners helps firms review whether AML policies, controls, procedures and file evidence are operating in practice. Each engagement is tailored around the firm's risk profile, client base, services, governance model and internal documentation. The work produces board-ready reporting and a practical remediation tracker.
What we can review
- Firm-wide AML risk assessment
- Client and matter risk assessments
- AML policies, controls and procedures
- Customer due diligence (CDD) evidence
- Enhanced due diligence (EDD) evidence
- Beneficial ownership and control records
- Source of funds and source of wealth evidence
- Sanctions, PEP and adverse-media workflow evidence
- Ongoing monitoring triggers and periodic review
- Escalation records and approval notes
- MLRO/MLCO administrative records
- Training logs and compliance registers
- Record keeping and audit trail quality
Circumstances that prompt this work
Most engagements begin from one of the following positions rather than from a general review cycle.
- 01An external AML audit or supervisory visit has been scheduled.
- 02A new MLRO or compliance lead has inherited controls they did not design.
- 03A bank or professional indemnity insurer has asked for evidence of independent review.
- 04File reviews keep surfacing the same CDD gaps and the cause has not been isolated.
- 05The firm-wide risk assessment has not been refreshed against current services or client base.
Deliverables
What you receive
- 01
Scoping note
Agreed scope, timeline and document request
- 02
Evidence request list
Structured list of policies, files and records
- 03
File sample review
CDD/EDD evidence quality assessment
- 04
Gap analysis
Gaps mapped against agreed review criteria, client policies, applicable guidance identified in scope and evidence requirements
- 05
RAG-rated findings
Prioritised findings with owner assignment
- 06
Management summary
Board-ready summary of key findings
- 07
Remediation tracker
Action tracker with owners and deadlines
- 08
Follow-up review option
Closure evidence and progress review
How a typical engagement runs
Stages are confirmed in writing before work begins and adjusted to the scope agreed.
- 01
Scope
Written scope covering services, file population, review criteria and reporting format.
- 02
Request
Structured document request for policies, registers, risk assessments and the agreed file sample.
- 03
Review
Policy and control review alongside file-level testing of CDD, EDD and monitoring evidence.
- 04
Report
RAG-rated findings, management summary and remediation tracker with named owners.
- 05
Follow-up
Optional closure review confirming which actions are evidenced as complete.
What stays on file afterwards
The point of the engagement is the record it leaves behind, so a later reviewer can follow the same trail.
- Written scope and document request retained on file
- File-level review notes with evidence references
- Gap analysis mapped against agreed review criteria
- Board-ready management summary
- Remediation tracker with owners, deadlines and closure evidence
Who it supports
- 01Law firms preparing for SRA or external review
- 02Accountancy firms with MLRO oversight
- 03Trust and company service providers (TCSPs)
- 04Property professionals with AML obligations
- 05Compliance teams seeking evidence-led review
- 06Senior management preparing for external scrutiny
Engagement safeguards
BlackCores & Partners may undertake an AML/CFT Audit, AML/CFT Independent Review or AML/CFT Control Review where the written scope, purpose, independence and evidence requirements support that form of engagement. The work is not a statutory financial audit, legal opinion or guarantee of any regulatory outcome.
The engagement letter determines the final basis and report title. An AML/CFT Audit Report is a defined-scope report concerning AML/CFT policies, controls, procedures and supporting evidence. It is not a statutory financial audit, legal opinion, regulatory certification or guarantee of compliance or acceptance.
What we do not do
- We do not provide legal advice.
- We do not make regulatory filings unless separately agreed and appropriate.
- We do not act as the client's MLRO, MLCO or nominated officer through website engagement.
- We do not guarantee regulator, bank, insurer or counterparty acceptance.
- We do not provide investment or financial advice.
Frequently asked questions
What is included in an AML/CFT review?
A representative scope may include the firm-wide risk assessment, AML/CFT policies and procedures, selected CDD and EDD files, beneficial-ownership evidence, source-of-funds and source-of-wealth records, sanctions, PEP and adverse-media workflows, transaction monitoring, escalation and reporting, training records and governance oversight. The precise population and depth are agreed in writing and depend on the risk profile.
When is the deliverable called an AML/CFT Audit Report?
This title is used only where the written engagement establishes an independent AML/CFT audit, appropriate independence has been assessed, and the defined audit scope has been completed. Where those conditions are not met, the deliverable is titled differently to reflect the actual basis of the work. It is not a statutory financial audit, legal opinion or regulatory certification.
When is the deliverable called an AML/CFT Control Review Report?
This title applies to a control-design, operating-evidence or remediation-focused engagement that is not constituted as an independent audit function. It examines how specified AML/CFT controls are designed, operated and evidenced, and records observations and actions, without presenting itself as an independent audit opinion.
How is independence considered?
Independence considers conflicts of interest, any prior involvement, relationships with the firm, and whether management retains responsibility for the controls under examination. BlackCores & Partners does not audit controls it has designed or owns, and assesses whether it can reach an evidence-based conclusion objectively before accepting an audit-basis engagement.
How long does an AML/CFT review take?
There is no universal duration. Timing depends on the risk profile, the file population, the agreed scope, the quality and availability of evidence and stakeholder access. An anticipated timetable is confirmed after initial scoping and may be revised if the evidence population or mandate changes materially.
Can the report support an external AML audit or supervisory review?
It may provide management with an organised evidence record, documented findings and a clearer basis for external scrutiny. It does not bind an external reviewer or guarantee acceptance; a regulator, supervisor or counterparty makes its own assessment and reaches its own conclusions.
Confidential scoping
Ready to request an aml review?
Contact us to discuss scope, document requirements and deliverables. All engagements are confirmed in writing before work begins.