Skip to content

All topicsAML/CFT compliance

An AML inspection checklist is useful only if the records tell the same story

Policies, customer files and training records should connect. Use this annotated checklist to understand what each record demonstrates and where gaps appear.

قائمة فحص مكافحة غسل الأموال: هل تحكي سجلات الشركة قصة متسقة؟اقرأ هذا الموجز بالعربية
A compliance officer's desk with an AML policy file, customer due diligence folders and a training attendance register laid out for inspection.

A company can have a signed AML policy, a folder of identity documents and a training certificate for every employee, yet struggle to explain one customer decision. The documents exist; the connection between them does not.

That is why preparing for an AML inspection is more than assembling a large file. A useful review follows the work: what risk was identified, which control applied, who used it, what decision followed and where that decision was recorded.

The checklist below is a practical review aid, not an official inspection form or a guarantee of a particular inspection outcome.

From policy to one real customer file

Consider a hypothetical company customer. Its trade licence and the representative’s passport are present. The policy says the business identifies beneficial owners, but the file contains no evidence of who ultimately owns or controls the company.

The missing item is not simply another attachment. It is a missing part of the reasoning behind accepting the relationship. Adding the policy again cannot resolve it.

Cabinet Resolution 134 of 2025 addresses risk assessment, due diligence, internal controls, reporting and records. A practical internal review should examine how these obligations connect in the business, while also taking account of its supervisor’s specific requests.

An annotated checklist for the review

Area

Records to examine

What the review should establish

Business risks

Current risk assessment and its supporting rationale

The assessment describes the actual services, customers and locations

Governance

Approved procedures, responsibilities and compliance arrangements

Someone owns each control and has authority to act

Customer due diligence

Identification, beneficial-owner information and risk decisions

The file supports the decision, not just the customer’s name

Screening

Search records, possible-match reviews and decisions

An alert can be followed through to a reasoned outcome

Escalation and reporting

Restricted internal records and relevant submissions

Concerns reach authorised people and are handled confidentially

Staff capability

Role-based training records and relevant assessments

Staff have learned the procedures they are expected to apply

Monitoring and remediation

Review findings, action owners and closure evidence

Identified weaknesses lead to verified changes

Record retrieval

Indexed files and controlled access

Required information can be produced without exposing unrelated records

Not every record belongs in one unrestricted folder. Suspicion-related information, identity documents and ordinary attendance data can require different access arrangements. “Ready for inspection” should not mean “available to everyone.”

Sampling reveals more than counting documents

Counting completed forms is easy. Examining a small selection of varied cases is often more revealing: a straightforward customer, a complex ownership structure and a relationship that required additional review.

For each case, follow the sequence. Was the information available when the decision was made? Does the explanation fit the facts? If a gap was identified, was it resolved or escalated? A later correction is important, but it should not be presented as if it existed earlier.

This is an internal review method, not a statement that a supervisor will use those exact samples or accept a particular sample size.

What should happen when the review finds a gap?

An honest finding is a useful starting point. “Beneficial-owner verification missing in file X” is more actionable than “improve compliance.” It identifies the affected record and allows the company to decide whether immediate restrictions, further checks or wider review are needed.

A corrective-action record should identify the issue, responsible person, intended action and evidence of completion. Closing it because an email was sent is different from closing it because the missing check was performed and reviewed.

Backdating a document to make a file appear complete undermines the history the review is meant to clarify. A dated correction preserves both the original weakness and the response.

Preparation should improve the work itself

The Ministry’s AML supervision information provides the official starting point for entities within its remit. Any actual inspection notice and instructions should guide the response, including scope, delivery channel and deadlines.

Between inspections, the same connected view remains valuable. A well-maintained training register, for example, helps explain whether the person operating a control had learned the relevant procedure. The strongest preparation is a system the business can use on an ordinary working day.

Questions we are asked

Short answers on the points readers raise most about this topic.

Does a desk-based inspection require less reliable evidence than a site visit?
No. The delivery method may differ, but submitted records still need to be accurate, relevant and traceable. Follow the authority’s request rather than assuming remote review is only a paperwork exercise.
Does fixing a gap before inspection erase the earlier failure?
No. A correction is evidence of remediation, not proof that the control always operated correctly. Preserve dates and the sequence of events, and seek appropriate advice where the issue may require notification or further action.

Related articles

All topics

Train your people, and keep records an inspector can read.

Register your companyBrowse the course catalogue