Audit and assurance distinctions

AML Independent Review vs Statutory Audit: What Is the Difference?

Compare a Hong Kong TCSP AML independent review with a financial statement audit: purpose, criteria, evidence, report, reviewer and limitations.

Key answer

An AML/CFT independent review and a statutory financial statement audit answer different questions. The AML review assesses whether the TCSP’s AML/CFT systems are appropriately designed and operating effectively. A statutory audit provides an opinion on financial statements under the applicable financial reporting and auditing framework. One does not replace the other, even when an accounting firm performs both engagements. Management should commission, scope and read each report for the distinct risk and assurance question it answers.

Side-by-side comparison

DimensionAML/CFT independent reviewStatutory audit
Primary purposeAssess AML/CFT control design and effectivenessExpress an opinion on financial statements
Main criteriaAMLO, Companies Registry guidance and approved internal AML/CFT proceduresApplicable financial reporting framework, company law and auditing standards
Typical evidenceRisk assessments, policies, CDD files, screening, monitoring, STR arrangements, training and governance recordsAccounting records, balances, transactions, confirmations, estimates and financial disclosures
Core outputReview report with scope, findings, risk and remediation actionsIndependent auditor’s report on the financial statements
Sampling focusRisk-based customer and control populationsFinancial statement assertions and risk of material misstatement
Responsible managementSenior management, compliance officer, MLRO and control ownersDirectors and those charged with governance for the financial statements

Why a statutory audit does not cover the AML review

A financial statement auditor may consider laws, regulations and fraud risk to the extent relevant to the financial statement audit, but that does not mean the auditor has tested the TCSP’s customer onboarding, beneficial-owner verification, PEP procedures, ongoing monitoring, internal suspicion escalation or staff knowledge against the Companies Registry AML/CFT Guideline.

Likewise, the fact that financial records were audited does not establish that the AML/CFT policy is current or that customer files contain the required evidence. The scope, criteria and intended users are different. Any overlap—such as transaction records or governance minutes—does not merge the engagements.

Why an AML review is not a financial audit

An AML reviewer may examine payment flows, transactions or financial information to understand customer activity and unusual patterns. That work does not express an opinion on the completeness, accuracy or fair presentation of the TCSP’s financial statements. The AML review report should avoid language that could be mistaken for a statutory audit opinion.

Similarly, terms such as “material” or “sample” may be used in both contexts but with different meanings. An AML control weakness can be significant because of regulatory or ML/TF risk even if it has no material effect on the financial statements.

Can the same firm perform both engagements?

Potentially, but capability in one field should not be assumed from the other. The AML reviewer needs relevant knowledge of the AMLO, Companies Registry guidance, TCSP services, risk-based CDD, beneficial ownership, PEP and sanctions controls, suspicious transaction reporting and operational testing.

Independence and conflicts should be evaluated for the AML engagement itself. If the provider designed the AML policy, operates outsourced compliance controls or made the decisions now being reviewed, safeguards and scope need careful consideration. The Companies Registry Guideline emphasises a direct line to senior management and sufficient expertise and resources, not a particular professional label alone.

What each engagement should say about its limitations

Neither engagement provides absolute assurance or a guarantee that misconduct cannot occur. An AML independent review uses an agreed period, scope and evidence; sampling means not every customer file is tested. A statutory audit is also subject to materiality, sampling and the inherent limitations of audit.

The AML report should identify excluded services, unavailable records, restricted access and the period tested. It should not promise regulatory approval. The statutory audit report has its own prescribed form and responsibilities. Management should read each report for the question it was designed to answer.

When management needs both

A TCSP that is subject to statutory financial statement audit may also need an AML/CFT independent audit function because the two assurance needs coexist. A regulatory inspection, licensing process, material business change or previous AML finding may increase the urgency of AML work without changing the statutory audit timetable.

Management should maintain separate engagement letters, scopes, evidence requests and reports. Coordination can reduce duplicate requests, but confidential AML and suspicion information should only be shared on an authorised need-to-know basis.

  • Define the objective and criteria of each engagement separately.
  • Confirm the competence and independence relevant to each scope.
  • Map overlapping evidence without merging conclusions or access rights.

Continue with the AML review overview, review timing guidance, the report anatomy and the document checklist.

Frequently asked questions

Does an audited set of accounts prove AML compliance?
No. The financial statement audit has different criteria and procedures. It does not by itself demonstrate that the TCSP’s AML/CFT systems are appropriately designed and operating effectively.
Must an AML reviewer be a statutory auditor?
The Companies Registry Guideline focuses on independence, direct communication to senior management, sufficient expertise and resources. The provider should be selected for the competence and independence needed for the actual AML review scope.
Can the two engagements share customer information?
Only where the sharing is authorised, necessary and appropriately protected. AML records, especially internal suspicion and STR information, require careful confidentiality and tipping-off controls.

Primary sources

Regulatory references were checked on 28 July 2026. Always consult the current official text for a live matter.

  1. Companies Registry — Guideline on AML/CFT for TCSP Licensees (March 2025)
  2. Hong Kong e-Legislation — Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615)
  3. Companies Registry — TCSP AML/CFT overview
  4. FATF — Guidance for a Risk-Based Approach for Trust and Company Service Providers
Scope note: This guide provides general information for Hong Kong TCSP licensees. It is not legal advice and does not determine the treatment of any particular customer or guarantee a regulatory outcome.