All topicsAML/CFT compliance
An AML inspection checklist is useful only if the records tell the same story
Policies, customer files and training records should connect. Use this annotated checklist to understand what each record demonstrates and where gaps appear.

A company can have a signed AML policy, a folder of identity documents and a training certificate for every employee, yet struggle to explain one customer decision. The documents exist; the connection between them does not.
That is why preparing for an AML inspection is more than assembling a large file. A useful review follows the work: what risk was identified, which control applied, who used it, what decision followed and where that decision was recorded.
The checklist below is a practical review aid, not an official inspection form or a guarantee of a particular inspection outcome.
From policy to one real customer file
Consider a hypothetical company customer. Its trade licence and the representative’s passport are present. The policy says the business identifies beneficial owners, but the file contains no evidence of who ultimately owns or controls the company.
The missing item is not simply another attachment. It is a missing part of the reasoning behind accepting the relationship. Adding the policy again cannot resolve it.
Cabinet Resolution 134 of 2025 addresses risk assessment, due diligence, internal controls, reporting and records. A practical internal review should examine how these obligations connect in the business, while also taking account of its supervisor’s specific requests.
An annotated checklist for the review
Area | Records to examine | What the review should establish |
|---|---|---|
Business risks | Current risk assessment and its supporting rationale | The assessment describes the actual services, customers and locations |
Governance | Approved procedures, responsibilities and compliance arrangements | Someone owns each control and has authority to act |
Customer due diligence | Identification, beneficial-owner information and risk decisions | The file supports the decision, not just the customer’s name |
Screening | Search records, possible-match reviews and decisions | An alert can be followed through to a reasoned outcome |
Escalation and reporting | Restricted internal records and relevant submissions | Concerns reach authorised people and are handled confidentially |
Staff capability | Role-based training records and relevant assessments | Staff have learned the procedures they are expected to apply |
Monitoring and remediation | Review findings, action owners and closure evidence | Identified weaknesses lead to verified changes |
Record retrieval | Indexed files and controlled access | Required information can be produced without exposing unrelated records |
Not every record belongs in one unrestricted folder. Suspicion-related information, identity documents and ordinary attendance data can require different access arrangements. “Ready for inspection” should not mean “available to everyone.”
Sampling reveals more than counting documents
Counting completed forms is easy. Examining a small selection of varied cases is often more revealing: a straightforward customer, a complex ownership structure and a relationship that required additional review.
For each case, follow the sequence. Was the information available when the decision was made? Does the explanation fit the facts? If a gap was identified, was it resolved or escalated? A later correction is important, but it should not be presented as if it existed earlier.
This is an internal review method, not a statement that a supervisor will use those exact samples or accept a particular sample size.
What should happen when the review finds a gap?
An honest finding is a useful starting point. “Beneficial-owner verification missing in file X” is more actionable than “improve compliance.” It identifies the affected record and allows the company to decide whether immediate restrictions, further checks or wider review are needed.
A corrective-action record should identify the issue, responsible person, intended action and evidence of completion. Closing it because an email was sent is different from closing it because the missing check was performed and reviewed.
Backdating a document to make a file appear complete undermines the history the review is meant to clarify. A dated correction preserves both the original weakness and the response.
Preparation should improve the work itself
The Ministry’s AML supervision information provides the official starting point for entities within its remit. Any actual inspection notice and instructions should guide the response, including scope, delivery channel and deadlines.
Between inspections, the same connected view remains valuable. A well-maintained training register, for example, helps explain whether the person operating a control had learned the relevant procedure. The strongest preparation is a system the business can use on an ordinary working day.
Questions we are asked
Short answers on the points readers raise most about this topic.
- Does a desk-based inspection require less reliable evidence than a site visit?
- No. The delivery method may differ, but submitted records still need to be accurate, relevant and traceable. Follow the authority’s request rather than assuming remote review is only a paperwork exercise.
- Does fixing a gap before inspection erase the earlier failure?
- No. A correction is evidence of remediation, not proof that the control always operated correctly. Preserve dates and the sequence of events, and seek appropriate advice where the issue may require notification or further action.
Related articles
Train your people, and keep records an inspector can read.
