Key answer
An AML/CFT independent review and a statutory financial statement audit answer different questions. The AML review assesses whether the TCSP’s AML/CFT systems are appropriately designed and operating effectively. A statutory audit provides an opinion on financial statements under the applicable financial reporting and auditing framework. One does not replace the other, even when an accounting firm performs both engagements. Management should commission, scope and read each report for the distinct risk and assurance question it answers.
Side-by-side comparison
| Dimension | AML/CFT independent review | Statutory audit |
|---|---|---|
| Primary purpose | Assess AML/CFT control design and effectiveness | Express an opinion on financial statements |
| Main criteria | AMLO, Companies Registry guidance and approved internal AML/CFT procedures | Applicable financial reporting framework, company law and auditing standards |
| Typical evidence | Risk assessments, policies, CDD files, screening, monitoring, STR arrangements, training and governance records | Accounting records, balances, transactions, confirmations, estimates and financial disclosures |
| Core output | Review report with scope, findings, risk and remediation actions | Independent auditor’s report on the financial statements |
| Sampling focus | Risk-based customer and control populations | Financial statement assertions and risk of material misstatement |
| Responsible management | Senior management, compliance officer, MLRO and control owners | Directors and those charged with governance for the financial statements |
Why a statutory audit does not cover the AML review
A financial statement auditor may consider laws, regulations and fraud risk to the extent relevant to the financial statement audit, but that does not mean the auditor has tested the TCSP’s customer onboarding, beneficial-owner verification, PEP procedures, ongoing monitoring, internal suspicion escalation or staff knowledge against the Companies Registry AML/CFT Guideline.
Likewise, the fact that financial records were audited does not establish that the AML/CFT policy is current or that customer files contain the required evidence. The scope, criteria and intended users are different. Any overlap—such as transaction records or governance minutes—does not merge the engagements.
Why an AML review is not a financial audit
An AML reviewer may examine payment flows, transactions or financial information to understand customer activity and unusual patterns. That work does not express an opinion on the completeness, accuracy or fair presentation of the TCSP’s financial statements. The AML review report should avoid language that could be mistaken for a statutory audit opinion.
Similarly, terms such as “material” or “sample” may be used in both contexts but with different meanings. An AML control weakness can be significant because of regulatory or ML/TF risk even if it has no material effect on the financial statements.
Can the same firm perform both engagements?
Potentially, but capability in one field should not be assumed from the other. The AML reviewer needs relevant knowledge of the AMLO, Companies Registry guidance, TCSP services, risk-based CDD, beneficial ownership, PEP and sanctions controls, suspicious transaction reporting and operational testing.
Independence and conflicts should be evaluated for the AML engagement itself. If the provider designed the AML policy, operates outsourced compliance controls or made the decisions now being reviewed, safeguards and scope need careful consideration. The Companies Registry Guideline emphasises a direct line to senior management and sufficient expertise and resources, not a particular professional label alone.
What each engagement should say about its limitations
Neither engagement provides absolute assurance or a guarantee that misconduct cannot occur. An AML independent review uses an agreed period, scope and evidence; sampling means not every customer file is tested. A statutory audit is also subject to materiality, sampling and the inherent limitations of audit.
The AML report should identify excluded services, unavailable records, restricted access and the period tested. It should not promise regulatory approval. The statutory audit report has its own prescribed form and responsibilities. Management should read each report for the question it was designed to answer.
When management needs both
A TCSP that is subject to statutory financial statement audit may also need an AML/CFT independent audit function because the two assurance needs coexist. A regulatory inspection, licensing process, material business change or previous AML finding may increase the urgency of AML work without changing the statutory audit timetable.
Management should maintain separate engagement letters, scopes, evidence requests and reports. Coordination can reduce duplicate requests, but confidential AML and suspicion information should only be shared on an authorised need-to-know basis.
- Define the objective and criteria of each engagement separately.
- Confirm the competence and independence relevant to each scope.
- Map overlapping evidence without merging conclusions or access rights.
Continue with the AML review overview, review timing guidance, the report anatomy and the document checklist.
Frequently asked questions
Does an audited set of accounts prove AML compliance?
Must an AML reviewer be a statutory auditor?
Can the two engagements share customer information?
Primary sources
Regulatory references were checked on 28 July 2026. Always consult the current official text for a live matter.