Single Blog

  • Home
  • A Guide to Independent Compliance Testing
A Guide to Independent Compliance Testing

A Guide to Independent Compliance Testing

September 12, 2026

A compliance framework can look complete on paper and still fail at the point of onboarding, monitoring or escalation. The difference is usually not the policy itself, but whether people follow it consistently, systems support the intended control and management can evidence oversight. This guide to independent compliance testing explains how regulated firms can obtain a clear, defensible view of how their AML and wider compliance controls operate in practice.

Why independent compliance testing matters

Independent testing provides assurance that a firm’s compliance arrangements are not merely designed well but are working as intended. It examines evidence rather than relying on management statements: client files, screening records, risk assessments, monitoring alerts, training logs, governance minutes and remediation records.

For an MLRO, compliance officer or board member, this distinction matters. A policy may require enhanced due diligence for higher-risk clients, yet file testing may show that source of wealth evidence is inconsistent, approvals are undocumented or periodic reviews are overdue. These are not minor administrative gaps. They can affect the firm’s ability to demonstrate a risk-based approach to a regulator, auditor, banking partner or counterparty.

Testing conducted with sufficient independence also reduces the risk of confirmation bias. The team responsible for operating a control may reasonably believe it is effective because it works in most cases. An independent reviewer is better placed to challenge assumptions, test exceptions and assess whether the control remains appropriate as the business, customer base and regulatory environment change.

What independent testing should assess

The scope should reflect the firm’s risk profile rather than follow a generic checklist. A payment institution with high transaction volumes, for example, may require detailed testing of transaction monitoring scenarios and alert handling. A corporate service provider may need deeper scrutiny of beneficial ownership verification, complex structures and source of funds decisions. For Malta FIAU subject persons, the review should also consider the practical application of applicable implementing procedures and guidance.

At a minimum, testing should consider the relationship between the business risk assessment, written policies, operational procedures and records retained. These components must align. If the business risk assessment identifies high-risk geographies, products or delivery channels, the client risk methodology and onboarding controls should visibly respond to those risks.

A meaningful review commonly tests four connected areas:

  • governance and oversight, including committee reporting, MLRO authority, escalation routes and management information;
  • client due diligence controls, including identification, verification, beneficial ownership, PEP and sanctions screening, and enhanced due diligence;
  • ongoing monitoring, including periodic review triggers, transaction monitoring, alert investigation and suspicious activity reporting governance; and
  • control sustainability, including training, record keeping, issue management, change management and assurance reporting.

The objective is not to prove that every file is perfect. It is to determine whether the control environment can identify, prevent, escalate and remediate risk reliably.

Start with a risk-based testing plan

An effective review begins before the first file is selected. The tester should understand the firm’s regulatory perimeter, services, customer segments, jurisdictions, distribution channels, systems and recent changes. A new onboarding platform, rapid growth in a higher-risk market or recurring audit findings may justify additional testing even where the formal annual plan appears unchanged.

The testing plan should state what will be reviewed, the period covered, the sample rationale, evidence required and criteria against which findings will be assessed. Clear criteria prevent vague conclusions such as “process needs improvement”. Instead, a finding should identify the relevant obligation or internal standard, the evidence reviewed, the control failure, the risk created and the action required.

Sample selection deserves particular care. Random sampling can provide a useful baseline, but it should not be the only method. Risk-led selection often produces more useful assurance by targeting higher-risk customers, manual overrides, unusual transactions, expired documentation, closed alerts, recent staff joiners or cases handled during a system change.

The appropriate sample size depends on population size, risk, control maturity and the consequences of failure. A small firm may permit a broader review of its entire high-risk customer population. A larger organisation may need stratified samples across business lines and risk ratings. Testing is strongest when the rationale is transparent and repeatable.

Test the full control journey, not isolated documents

A common weakness in compliance reviews is treating documents as proof of effective control. A completed risk assessment form is not enough if the inputs were inaccurate, the risk rating does not follow the methodology or the stated mitigating measures were never applied.

Testing should trace the client journey from initial contact through to approval, monitoring and review. Consider a client assessed as high risk because of ownership complexity and geographic exposure. The reviewer should establish whether the firm identified all beneficial owners, performed appropriate screening, obtained proportionate source of wealth and source of funds information, secured senior management approval where required, set an appropriate review frequency and monitored activity against the expected profile.

This approach also reveals hand-off failures. Sales or operations may collect information, compliance may approve the relationship and an operations team may later handle periodic review. Each team may perform its own task adequately, while important information is lost between stages. Independent testing should therefore assess ownership, workflows, evidence trails and escalation points across the process.

Design effectiveness and operating effectiveness

A well-structured testing report distinguishes between design and operating effectiveness. A design issue exists where the control is absent, unclear, poorly targeted or incapable of addressing the stated risk. For example, a sanctions procedure that does not define escalation or disposition requirements may leave staff without a reliable response to potential matches.

An operating effectiveness issue arises where a suitable control exists but has not been performed consistently or evidenced properly. An analyst may have followed the correct escalation process but failed to retain the approval record. The remediation for this may involve training, supervision or system workflow changes rather than rewriting the policy.

This distinction helps management direct resources appropriately. It also prevents firms from responding to every finding with more policy wording when the real issue is capacity, ownership, data quality or management oversight.

Assess whether management information drives action

Boards and senior management cannot oversee what they cannot see. Independent testing should evaluate whether compliance reporting gives decision-makers a clear view of risk, control performance, breaches, overdue reviews, suspicious activity trends, training completion and remediation progress.

Volume alone is not useful. A report showing hundreds of alerts closed each month provides limited assurance without information on ageing, quality assurance outcomes, repeat typologies, escalations and backlogs. Equally, a low number of suspicious activity reports may be entirely reasonable for one business model and concerning for another. Context is essential.

The strongest management information links operational data to ownership and action. If periodic reviews are overdue, the report should identify the affected risk segments, the underlying cause, accountable owners, target dates and any interim controls. That gives the board evidence of active governance rather than passive reporting.

Reporting findings with clarity and proportionality

The value of independent compliance testing is realised through the report. It should be candid enough to support remediation, yet precise enough to avoid overstating risk. Findings should be graded using a defined methodology that considers regulatory impact, financial crime exposure, population affected, duration, likelihood and whether compensating controls exist.

Each finding should set out the condition observed, the expected standard, the cause where known, the associated risk and a practical recommendation. Management responses should not simply accept the finding. They should identify an accountable owner, realistic completion date, required resources and how closure will be validated.

Recommendations must fit the organisation. A sophisticated automated monitoring solution may be appropriate for a high-volume payments business but disproportionate for a smaller regulated intermediary. Conversely, a manual control is not automatically inadequate if it is timely, independently reviewed and supported by clear evidence. The question is whether the chosen control is proportionate to the risk and sustainable at the firm’s current scale.

Make remediation part of the assurance cycle

A report is not the endpoint. High-quality assurance includes follow-up testing to confirm that agreed actions have been implemented and are operating effectively. Closing an action because a procedure has been updated is rarely sufficient. The firm should test whether relevant staff understand the change, systems reflect it and new cases show consistent application.

Remediation should also feed back into the risk assessment and compliance plan. Repeated onboarding exceptions may indicate a need to revise client acceptance criteria, enhance first-line training or reassess staffing levels. Recurrent screening issues may point to poor data capture rather than a weakness in the screening tool itself.

Complipal approaches independent testing as a practical management tool: one that identifies control weaknesses early, prioritises proportionate action and gives leadership a clearer basis for decisions. The aim is not a checkbox exercise, but a compliance programme that can withstand scrutiny while supporting responsible growth.

When the next audit, regulatory review or serious client-risk decision arrives, confidence will not come from the existence of a policy. It will come from being able to show, with evidence, that the organisation knows where its controls stand and acts decisively when they need to improve.