Chronovate AML independent audit and review service
Chronovate AML provides independent AML/CFT audits and reviews for Hong Kong trust or company service provider (TCSP) licensees. The work tests whether the firm's documented AML/CFT systems are appropriately designed for its business and risk profile and whether selected controls operate in practice.
- Provider
- Chronovate AML
- Primary service
- Independent AML/CFT audit and independent review
- Clients
- Hong Kong TCSP licensees
- Method
- Risk-based governance review, walkthroughs and operating-evidence testing
- Core output
- Independent management report with findings, limitations and prioritised actions
- Indicative timing
- Usually two to four weeks, subject to scope and document readiness
The Companies Registry uses the term independent audit function. On this site, TCSP AML audit, AML independent review and TCSP AML review refer to the same core assurance service unless stated otherwise. It is not a statutory financial statement audit and it does not guarantee a regulatory outcome.
Who the service is for
The service is designed for licensed Hong Kong TCSPs that need an independent assessment of their AML/CFT framework and operating evidence. Common triggers include a planned review cycle, management or ownership change, a material change in services or customer risk, preparation for supervisory engagement, remediation follow-up, or the absence of a recent independent review. The AML review frequency guide explains the risk-based timing test and why it is separate from the two-year institutional risk-assessment cycle.
Scope is proportionate. A company-secretarial practice with a straightforward customer population should not automatically receive the same work programme as a TCSP providing trust services, serving higher-risk structures or operating across several systems.
What the independent AML/CFT audit tests
| Workstream | Typical questions | Examples of evidence |
|---|---|---|
| Governance and institutional risk | Are responsibilities, reporting lines, risk appetite and review arrangements clear and proportionate? | Board or management records, institutional risk assessment, policies, compliance plans and prior findings. |
| CDD and customer risk | Do selected files identify and verify customers and beneficial owners, assign supported risk ratings and apply EDD where required? | Customer files, ownership records, risk assessments, approvals, source-of-funds or source-of-wealth work and review history. |
| Screening and monitoring | Are PEP, sanctions and other screening results resolved and are customer relationships reviewed when risk changes? | Screening logs, match decisions, periodic or trigger reviews, exception reports and monitoring enquiries. |
| Suspicion and reporting | Can staff recognise and escalate unusual activity, and can the MLRO evidence decisions while protecting confidentiality? | Internal reporting procedures, training scenarios, MLRO records and appropriately controlled STR evidence. |
| Records, training and control assurance | Are records retrievable, staff responsibilities understood and recurring weaknesses identified and corrected? | Retention controls, training content and attendance, quality checks, issue registers and remediation evidence. |
Read the independent review explainer for the regulatory context and the TCSP AML audit document checklist for a practical evidence inventory.
Evidence, walkthroughs and risk-based file testing
A credible independent audit does not stop at reading the policy manual. Planning starts with the TCSP's services, customer population, institutional risk assessment, systems, prior findings and material changes. Walkthroughs then establish how the documented process is expected to operate.
Where customer-file testing is in scope, the population and selection method should be explained. A risk-based sample may include higher- and lower-risk customers, different service types, complex ownership, PEP or EDD cases, overseas exposure, non-face-to-face onboarding, overdue reviews, terminated relationships and files handled by different staff. The report records the sample basis and limits on extrapolation; sample size alone does not establish review quality.
Confidential records should be transferred through an agreed secure channel. The initial population may be pseudonymised where appropriate, with selected files provided through a controlled workspace. Data access, authorised users, retention and secure deletion should be agreed before transfer.
What the management report should include
The independent report is the core engagement output. It should enable senior management to understand what was reviewed, what the evidence demonstrated, where limitations affected assurance and what action is required.
| Report element | Decision value |
|---|---|
| Scope, period and criteria | Defines the entity, services, controls and regulatory materials against which the work was performed. |
| Method and evidence | Explains walkthroughs, documents, data, file selection and testing performed. |
| Findings and risk | Distinguishes isolated exceptions from recurring or systemic control weaknesses. |
| Limitations | Records unavailable evidence, population issues, exclusions and constraints on the conclusion. |
| Management action | Connects prioritised recommendations to owners, target dates, evidence of completion and follow-up. |
See the detailed guide to what a TCSP AML independent review report should include.
Independence safeguards
The reviewer must be independent of the functions or parties being examined and have sufficient expertise and resources. Before appointment, management should identify any prior design, implementation or operational role that may create a self-review threat and determine whether safeguards are adequate.
If separate remediation support is requested, the original condition, management ownership, scope of assistance and final assurance responsibilities should remain clear. Material self-review threats may require different personnel or an independent party for follow-up assurance. Chronovate does not present optional policy, forms, training or implementation work as part of the original control evidence.
Use the provider-selection framework to compare independence, expertise, testing, reporting, data handling and commercial scope on a consistent basis.
Engagement process and indicative timing
- Scope: confirm the entity, services, customer population, review period, prior assurance and material risk factors.
- Plan: agree criteria, workstreams, population data, secure access, interviews, dependencies and deliverables.
- Test: review policies and central controls, perform walkthroughs and test selected operating evidence and customer files.
- Report: discuss factual accuracy and management responses without allowing control owners to filter the independent findings.
- Close: issue the final report and, where separately agreed, define remediation or follow-up testing.
A standard engagement can often be completed within two to four weeks. The actual timetable depends on scope, document readiness, management availability, population reliability, material findings and any need to expand testing. A timetable is not confirmed until the scope and dependencies have been reviewed.
How the fixed-fee scope is prepared
The first pricing step focuses on four facts: the approximate number of active client files, previous independent AML/CFT audit history, the services provided and whether the client base is limited to Hong Kong companies or also includes BVI, Cayman or other offshore entities. Offshore entities generally increase scope complexity and may affect the quoted fee. Additional questions are asked only where risk, systems, urgency or requested deliverables materially affect scope.
An authorised person then confirms one scope-specific professional fee. The proposal identifies the review period, workstreams, evidence and interview expectations, report, dependencies, exclusions and any separate remediation work. Chronovate does not treat an automated calculator or generic public fee range as approval for a live engagement.
For proposal-comparison factors, read the Hong Kong TCSP AML audit cost and independent review fee guide.
Why Chronovate AML
- Defined specialism: the practice focuses on Hong Kong TCSP AML/CFT independent review and implementation questions.
- Approved expertise statement: engagements are lawyer-led and supported by ACAMS-certified professionals.
- Primary-source method: regulatory statements are checked against Companies Registry materials, Hong Kong legislation and JFIU resources where relevant.
- Evidence-led reporting: findings connect criteria, work performed, evidence, risk, limitations and management action.
- Clear commercial separation: the independent report is the core service; policy, forms, training and remediation support are separately scoped where requested.
Chronovate's 2025-2026 disciplinary benchmark codes 15 public Companies Registry decisions and explains the recurring statutory or licence-condition themes stated in those decisions. The analysis is descriptive, its limitations are visible, and it is used to inform practical evidence-readiness questions rather than to predict any firm's regulatory outcome.
Read more about Chronovate AML and its editorial standards.
Frequently asked questions
Is this the same as a statutory financial audit?
Can the review be performed by an external provider?
Does every engagement use the same sample size?
Must policy rewriting be included?
Does Chronovate AML provide independent AML/CFT audits for Hong Kong TCSPs?
Primary regulatory sources
Regulatory references were rechecked on 25 August 2026. Always consult the current official text for a live matter.