Single Blog

  • Home
  • Common AML Findings in Internal Audits Explained
Common AML Findings in Internal Audits Explained

Common AML Findings in Internal Audits Explained

August 7, 2026

An internal audit rarely identifies a single isolated AML failure. More often, common AML findings in internal audits reveal a gap between the written framework and the way decisions are made, documented and challenged in practice. A policy may be current, staff may have completed training, and client files may appear complete at first glance. Yet the underlying control environment can still be difficult to defend when a regulator asks why a client was accepted, how risk was assessed, or whether suspicious activity was escalated promptly.

For MLROs, compliance leaders and boards, the value of internal audit is not limited to identifying deficiencies. It is an opportunity to test whether the AML programme produces consistent, evidence-based outcomes under real operational pressure.

Why recurring AML findings matter

Many findings arise because controls have been designed around completing a process rather than managing risk. A completed checklist is not necessarily evidence of effective customer due diligence. Equally, a transaction-monitoring alert that was closed does not demonstrate that the rationale was proportionate, independently reviewable and supported by the available information.

Regulators assess substance as well as documentation. They expect firms to understand their exposure, apply enhanced measures where risk requires them, retain a clear audit trail and demonstrate effective oversight. This is particularly relevant for firms operating in Malta and other highly regulated markets, where the quality of governance and decision-making is often as significant as the existence of policies.

The most useful audit reports therefore distinguish between an administrative omission and a systemic weakness. A missing document on one low-risk file may call for remediation at file level. Repeated weak risk rationales across client categories may indicate a deeper issue in methodology, training, quality assurance or management oversight.

Common AML findings in internal audits

Customer risk assessments that do not support the rating

A frequent finding is a customer risk assessment that reaches a low, medium or high-risk outcome without showing how the relevant factors influenced that result. This can happen where scoring tools are overly mechanical, where free-text explanations are generic, or where staff override automated scores without documented approval.

A defensible assessment should reflect the customer, their ownership and control structure, geography, products or services used, delivery channel, anticipated activity and any relevant adverse information. The purpose is not to produce a high score whenever a risk factor appears. It is to show why the overall assessment is reasonable and what controls are required as a result.

The trade-off is practical. Highly detailed assessments can slow onboarding and create unnecessary operational burden. Overly brief assessments create inconsistency and leave the firm unable to explain its judgement. A well-designed risk-based approach uses structured data for consistency while requiring concise, meaningful rationale for higher-risk relationships, exceptions and overrides.

Incomplete or stale CDD and beneficial ownership evidence

Internal auditors often find that identification and verification records are technically present but incomplete, expired or inconsistent with other information held by the business. For corporate clients, beneficial ownership is a particularly sensitive area. Ownership charts may not identify all natural persons who ultimately own or control the entity, or the evidence may not explain how control has been established where ownership is complex.

The issue is not always a failure to collect documents. It may be a failure to assess whether the documents are reliable, independent and sufficient for the risks involved. A registry extract, for example, may be useful evidence but may not resolve questions raised by a layered structure, nominee arrangement, foreign jurisdiction or conflicting information.

Remediation should go beyond a file-clean-up exercise. Firms need clear standards for acceptable evidence, escalation routes for complex structures, and defined triggers for refreshing information. Periodic review schedules should be risk-sensitive, but event-driven review matters just as much. Changes in ownership, unusual activity, adverse media or a new high-risk connection should prompt reassessment before the next scheduled review.

Weak source of wealth and source of funds enquiries

Source of wealth and source of funds are regularly confused. Source of wealth concerns how a customer accumulated their overall wealth; source of funds concerns the origin of the money involved in a particular relationship or transaction. Audit findings commonly show that firms record a broad statement, such as “business income” or “investments”, without gathering proportionate evidence or testing whether the explanation aligns with the known profile.

This weakness is most acute for politically exposed persons, high-net-worth clients, customers connected to higher-risk jurisdictions and relationships involving significant or unusual transactions. The required depth of enquiry depends on the risk. There is no value in demanding excessive evidence from every customer, but there is clear regulatory exposure where a firm accepts a vague explanation despite material risk indicators.

A good control requires staff to record the explanation, the evidence considered, any inconsistencies identified and the reason the evidence was judged sufficient. It should also make clear when senior management approval and enhanced due diligence are required.

Screening controls with poor alert disposition

Sanctions, PEP and adverse media screening can create a false sense of security when firms focus on completing the search rather than resolving the result. Common findings include undocumented false-positive decisions, incomplete screening of beneficial owners and connected parties, or no evidence that rescreening occurs after onboarding.

Alert disposition should be clear enough for an independent reviewer to understand who was screened, what potential match was identified, what information was compared, and why the alert was closed or escalated. A note stating “not a match” is seldom sufficient for a higher-risk alert.

Firms should also test whether screening parameters reflect their business model. Poorly calibrated tools can generate excessive noise, encouraging hurried closures. Settings that are too narrow may fail to identify relevant exposure. Periodic testing should therefore assess both efficiency and detection quality, not merely whether the system is operational.

Transaction monitoring that is not tailored to risk

Transaction-monitoring programmes are often found to be generic, outdated or disconnected from the customer risk assessment. Thresholds may have been set when the business was smaller, when products were different, or without regard to expected activity. In some cases, monitoring is largely manual but there is no documented quality review of decisions.

Effective monitoring begins with a credible expected activity profile. If the firm does not understand the anticipated purpose, volume, counterparties and geographical exposure of a relationship, it cannot identify meaningful deviation later. This is especially relevant for payment businesses, gaming operators, fintechs and corporate service providers, where behaviour can vary significantly between legitimate clients.

Audit testing should examine more than alert volumes. It should consider whether scenarios detect relevant risks, whether alerts are investigated within suitable timeframes, whether the investigator considers linked activity, and whether outcomes feed back into the client risk rating. A monitoring system can be technically functional while the surrounding process remains ineffective.

Inconsistent suspicious activity reporting and escalation

Another material finding is uncertainty over when staff should escalate a suspicion, who makes the decision to submit a report, and how that decision is documented. Some firms retain investigation notes but do not record the MLRO’s assessment. Others document decisions to report but provide little evidence for decisions not to report.

A sound process protects confidentiality, provides escalation routes outside line management, and preserves an adequate record of the facts, analysis and decision. Staff should understand that suspicion does not require proof. At the same time, not every unusual event warrants an external report. The decision must be based on an informed assessment, free from commercial pressure and supported by a clear rationale.

Governance, training and independent oversight gaps

AML controls do not operate in isolation. Audits frequently identify unclear ownership between first-line operations, compliance, the MLRO and senior management. This can lead to overdue reviews, unresolved remediation actions and inconsistent treatment of exceptions.

Training can also be weak where completion rates are treated as the key measure of effectiveness. Training should be role-specific and tested against real decisions staff are expected to make. Front-line onboarding teams, for example, need practical guidance on ownership structures and escalation indicators, while senior management needs a clear understanding of approval responsibilities and risk appetite.

Boards and senior management should receive management information that allows them to challenge performance: overdue high-risk reviews, ageing alerts, quality-assurance results, rejected or exited relationships, suspicious activity trends and remediation status. Reporting that only confirms policy completion provides limited assurance.

Turning findings into defensible improvement

The strongest remediation plans identify the root cause, accountable owner, required evidence, target date and method of validation. Rewriting a procedure may be necessary, but it will not resolve a finding caused by unclear systems, insufficient resourcing or inconsistent supervisory challenge.

Prioritisation should reflect regulatory and financial-crime risk. Deficiencies involving sanctions exposure, high-risk customers, overdue enhanced due diligence or suspicious activity escalation normally require immediate containment as well as longer-term correction. Lower-risk documentation gaps may be remediated through a controlled review programme, provided the rationale is recorded and progress is monitored.

Independent retesting is essential. Management confirmation that an action is complete is not the same as evidence that the control works. A targeted sample can establish whether the revised process is being followed consistently, whether staff understand it, and whether the resulting audit trail would withstand scrutiny.

A well-run AML internal audit should leave the organisation with more than a list of exceptions. It should provide a clearer view of where judgement is weak, where controls need to evolve and where leadership must apply stronger challenge. That is how compliance becomes a source of operational confidence rather than a last-minute response to regulatory pressure.