AML Health Check Before a Regulatory Visit: 7 Domains Explained
A seven-domain method for surfacing the weaknesses regulators commonly test for, before they arrive, and documenting them so the findings drive remediation.
A regulatory visit is not the time to discover weaknesses in your AML programme. An internal health check, conducted rigorously and honestly, is how you find them first.
The seven core domains a robust AML health check will usually cover, and the specific questions to ask within each.
AML Expert
Get tailored guidance on your compliance obligations, SAR filing, or AML program review.
- What an AML health check is and what it is not
- The seven core domains of an AML health check
- Why most internal reviews miss what regulators find
- How to prioritise and document health check findings
- How frequently an AML health check should be conducted
Jurisdictions: Global guidance; local legal and regulatory requirements must be verified.
Sectors / audience: MLROs, CCOs, Compliance Officers
Last Updated: 8 July 2026 | Last reviewed: 5 July 2026 | Reviewed by: Monika Shah, Partner, CAMS
In short: An AML health check is an independent, evidence-based review of whether a firm's AML/CFT programme is designed, governed, and operating effectively in line with applicable regulatory expectations. It tests governance, business risk assessment, policies, customer due diligence, transaction monitoring, suspicious activity reporting, and training, and produces a prioritised remediation plan.
This article provides general guidance for practitioners and is not legal advice. AML/CFT obligations, independent testing requirements, examination powers, privilege rules, reporting duties, tipping-off restrictions, record retention rules, and remediation expectations vary by jurisdiction, regulator, sector, and firm risk profile. Firms should verify local requirements and seek legal advice when findings may indicate a breach, a disclosure obligation, a privilege issue, or an enforcement risk.
- An AML health check is a structured review of the AML/CFT programme's design and operational effectiveness.
- The seven core domains are governance, business risk assessment, policies, customer due diligence, transaction monitoring, SAR/STR, and training.
- A health check should produce prioritised findings with named owners, target dates, evidence requirements, and validation.
- Local legal obligations must be checked before relying on any global framework.
Regulatory visits arrive with varying degrees of notice. Some jurisdictions provide several weeks of warning. Others provide considerably less. In either case, the compliance teams that fare best under examination are not those that prepare hardest in the final weeks before the visit. They are those who have been conducting honest, rigorous internal reviews of their AML programme regularly throughout the year.
An AML health check is a structured internal assessment of the compliance programme against the regulatory standard applicable to the firm. When conducted properly, it identifies weaknesses before the regulator does, creates an opportunity to remediate them, and produces documentation demonstrating the firm's commitment to continuous improvement. When conducted poorly, it produces a document that records known weaknesses without addressing them, which, in some respects, is worse than conducting no review at all.
This article sets out how to conduct an AML health check that genuinely protects the firm: what to assess, how to assess it honestly, and how to use the findings constructively. It draws on my experience conducting health checks and examination-preparation reviews across financial institutions, fintechs, virtual asset service providers (VASPs), and designated non-financial businesses and professions (DNFBPs) in the UAE, the UK, Singapore, India, Hong Kong, and Australia.
Who This Article Is For
This is practitioner guidance for MLROs, compliance officers, and heads of compliance at financial institutions, fintechs, VASPs, and DNFBPs who are preparing for a regulatory visit or strengthening their AML/CFT programme. It is not legal advice, a jurisdiction-specific compliance manual, or a substitute for any independent audit, testing, or evaluation required by local law.
What an AML Health Check Is and What It Is Not
An AML health check is an independent, evidence-based assessment of the firm's AML programme against the applicable regulatory standard. The word independent is important. A health check conducted by the compliance team reviewing its own work is useful but limited. The most valuable health checks are conducted by someone who is not operationally responsible for the programme being reviewed, whether that is an internal audit function with genuine independence from compliance, an external adviser, or a combination of both (see FATF Recommendation 18 on internal controls and the independent audit function).
A health check is not a regulatory mock examination, though the two are related. A mock examination simulates the experience of a regulatory visit. A health check is a deeper, more methodical assessment that may take longer, cover more ground, and produce a more detailed output than a mock examination would. The health check informs the mock examination, not the other way around.
A health check is also not a gap analysis against a regulatory checklist, though that is a component of it. The most significant weaknesses in AML programmes are rarely the ones that a checklist would identify. They are the ones that emerge from testing whether documented processes are actually followed in practice, whether controls are functioning as designed, and whether the organisation's compliance culture supports the programme on paper.
The firms that do best in regulatory examinations are the ones that have been honest with themselves about their weaknesses long before the examiner arrives. That honesty requires a health check process that is genuinely independent, genuinely rigorous, and genuinely willing to identify uncomfortable findings. A health check that produces only minor observations is almost certainly not being conducted with sufficient depth or independence.
Pathik Shah | Founder, NIYEAHMA Consultants LLP
Health Check, Internal Audit, and Mock Examination Compared
| Review type | Purpose | Independence | Output |
|---|---|---|---|
| AML health check | Identify programme weaknesses and drive remediation | Preferably independent from day-to-day compliance | Findings and remediation plan |
| Internal audit / independent testing | Provide assurance against legal, regulatory, risk, and policy standards | Formally independent | Audit or testing report to governance |
| Mock examination | Simulate examiner review and interviews | Internal or external | Readiness observations and exam-prep actions |
The Seven Core Domains of an AML Health Check
The seven domains below provide a practical core framework for an AML health check. They are not exhaustive, and firms should expand them to reflect their sector, risk profile, products, jurisdictions, regulator expectations, sanctions and proliferation-financing (PF) exposure, outsourcing model, and local legal obligations. This framework is a practical review structure, not a legal standard. It does not replace any jurisdiction-specific independent audit, independent testing, independent evaluation, board reporting, breach notification, SAR/STR, record retention, or regulator access requirement.
1. Governance and Oversight
The governance domain assesses whether the firm's AML programme has appropriate engagement from senior management and the board, clear accountability, and effective oversight mechanisms. The questions to ask include: Does the board receive regular, meaningful reporting on AML matters? Does senior management understand its personal accountability for AML compliance? Is the Money Laundering Reporting Officer (MLRO) sufficiently senior, sufficiently resourced, and sufficiently independent to discharge their responsibilities effectively?
Governance weaknesses are among the most serious findings a regulator can make, because they indicate that the programme lacks the organisational support needed to function effectively. A technically well-designed programme that lacks genuine governance engagement is a programme waiting to fail. In the UK, for example, the FCA expects senior management to understand the firm's financial crime risks and ensure that appropriate mitigation is in place.
2. Business Risk Assessment
The business risk assessment (BRA) domain assesses whether the firm's enterprise-wide risk assessment is current, accurate, and genuinely reflective of the firm's risk profile. The questions to ask include: when was the BRA last reviewed? Does it reflect the current customer base, product set, and geographic footprint? Does evidence rather than assumption support the risk ratings? Does the BRA connect visibly to the rest of the compliance programme?
In regulatory reviews and independent testing exercises, an outdated or poorly evidenced BRA is a recurring weakness. The health check should test whether material changes in products, customers, geographies, delivery channels, and operating model have occurred since the last BRA review, and whether those changes have been reflected in the risk assessment.
3. Policies and Procedures
The policies domain assesses whether the firm's AML policies and procedures are current, complete, and accurately reflect both the regulatory standard and the firm's actual practice. The questions to ask include: when were the policies last reviewed? Do they reflect current regulatory requirements in all applicable jurisdictions? Is there a gap between what the policies say and what the compliance team actually does?
The gap between documented policy and actual practice is one of the most fertile sources of regulatory findings. The health check should test this gap directly by comparing documented procedures with observed practice, rather than simply reviewing the policy documents themselves.
4. Customer Due Diligence and Onboarding
The customer due diligence (CDD) domain assesses the quality and consistency of the firm's customer onboarding and due diligence processes. The questions to ask include: Is the customer risk rating methodology being applied consistently? Are enhanced due diligence (EDD) triggers being identified and acted upon correctly? Is the documentation collected during onboarding sufficient to support the assigned risk rating? Are there gaps or inconsistencies in the customer file population?
File testing is an essential component of the CDD review. Reading the policy is not sufficient. The health check should include a review of a sample of customer files across risk categories to assess whether the documented process is being followed in practice and whether the quality of the CDD output is adequate.
5. Transaction Monitoring
The transaction monitoring (TM) domain assesses whether the firm's TM programme is calibrated correctly, functioning effectively, and producing alerts that are reviewed with appropriate rigour. The questions to ask include: Are the TM rules calibrated to the risk profile identified in the BRA? Is the alert closure process documented and consistently followed? What proportion of alerts result in escalation, and what does that ratio suggest about calibration quality? Is the TM system being tested and tuned regularly?
Transaction monitoring is one of the areas most frequently highlighted in regulatory examinations, and the quality failures are often systemic rather than isolated. The health check should assess not just whether a TM system exists, but whether it functions as a genuine control rather than as a volume generator of low-quality alerts.
6. Suspicious Activity Reporting
The suspicious activity and transaction reporting (SAR/STR) domain assesses whether the firm's internal suspicion identification and reporting process is functioning effectively and whether the quality of external filings meets the expected standard. The questions to ask include: Is the internal suspicion report process clearly documented and understood by front-line staff? Are escalation timelines being met? Is the quality of SAR/STR narratives adequate? Is the decision not to file being documented with the same rigour as the decision to file?
A review of a sample of SAR/STR filings and declined cases from the review period is an essential component of this domain. The health check should assess both the quality of the SAR/STR documents themselves and the integrity of the process that produced them.
7. Training and Awareness
The training domain assesses whether the firm's AML training programme is up to date, relevant, and effective. The questions to ask include: Is training delivered at the frequency required by applicable law, regulations, policies, and risk profile, and is it delivered periodically for all relevant staff? Is the content tailored to the firm's specific risk profile and the roles of the individuals being trained? Is completion being tracked and followed up? Is there evidence that the training is changing behaviour rather than simply recording attendance?
Training quality is an area where the gap between policy and reality is often significant. A firm that records 100% training completion but cannot demonstrate that the training content is fit for purpose, or that completion is meaningful rather than nominal, has not discharged its training obligation effectively.
Beyond the Seven Domains: Cross-Cutting Areas
The seven domains are the spine of a health check, but several areas cut across all of them and deserve explicit attention. Depending on the firm's risk profile and jurisdiction, a thorough review will also test:
- Sanctions and proliferation-financing controls: customer and transaction screening, list management and updates, false-positive handling, escalation, and sanctions and PF governance and ownership.
- Screening governance: politically exposed person (PEP), sanctions, and adverse-media configuration, data quality, matching logic, and alert-closure quality assurance.
- Beneficial ownership and control: identification and verification of ownership and control, treatment of complex structures, trusts and nominees, and refresh triggers.
- Recordkeeping and audit trail: whether records are complete, retrievable, retained for the required period, and able to evidence the decisions made.
- Outsourcing and third-party reliance: oversight of KYC utilities, monitoring and screening vendors, managed-service providers, and reliance arrangements.
- Issue management and validation: who validates remediation, what evidence is required for closure, whether internal audit retests, and how overdue items are escalated.
- Sampling methodology: how customer files, alerts, SAR/STR decisions, training records, and governance management information (MI) are selected and tested.
- Management information quality: whether board and committee MI is timely, accurate, risk-based, and useful for decisions.
When I conduct a health check, I always spend time with front-line staff as well as the compliance team. The compliance team can tell me what the programme is designed to do. The front-line staff tell me what it actually does. When those two accounts are significantly different, I know where the real work is. A health check that only reviews documents and speaks only to the compliance function is missing the most important evidence.
Pathik Shah | Founder, NIYEAHMA Consultants LLP
Document Checklist by Domain
| Domain | Key documents and evidence to have ready |
|---|---|
| Governance and oversight | Board and committee terms of reference, AML governance and MI reporting packs, minutes evidencing AML discussion, MLRO appointment and job description, delegation and accountability records. |
| Business risk assessment | Current enterprise-wide risk assessment, rating methodology and rationale, evidence of periodic review, records linking the BRA to the control framework. |
| Policies and procedures | AML/CFT policy, procedures and manuals, version history and review dates, jurisdiction-specific addenda, approval records. |
| Customer due diligence and onboarding | CDD and EDD procedures, risk-rating methodology, a sample of customer files across risk tiers, EDD trigger and escalation records, PEP and sanctions screening evidence. |
| Transaction monitoring | TM rules and calibration rationale, alert investigation and closure records, escalation and SAR linkage, system tuning and testing evidence. |
| Suspicious activity reporting | Internal suspicion reporting procedure, a sample of SAR/STR filings and narratives, declined-case records, escalation timelines, MLRO decision logs. |
| Training and awareness | Training plan and materials, completion and attendance records, role-based content, assessment results, evidence of effectiveness. |
Why Most Internal Reviews Miss What Regulators Find
Internal reviews conducted by the compliance team tend to identify weaknesses already known to the team and gaps made visible by the existing documentation. They tend not to find the weaknesses that are invisible from within the function: the gaps between documented process and actual practice, the controls that are technically in place but not functioning effectively, and the cultural or behavioural issues that undermine the programme at the front line.
Regulators find these weaknesses because they approach the review from the outside, with no prior knowledge of the firm's self-assessment, and because their examination methodology is designed to test practice rather than documentation. They interview front-line staff. They sample files independently. They test whether the TM system is producing alerts that are being reviewed with genuine analytical rigour. They review the governance record to assess whether senior management engagement is substantive or merely ceremonial.
Closing this gap requires either genuine independence in the internal review, which means a reviewer who is not operationally responsible for the programme and who is willing to report findings upwards without self-censorship, or external input from an adviser who brings the external perspective that the internal team cannot provide. Many firms benefit from a combination of both: an internal review that covers the breadth of the programme, supplemented by targeted external review in the domains where independence is most important.
How to Prioritise and Document Health Check Findings
A health check that produces a long list of findings without a clear prioritisation framework is of limited practical value. The compliance team needs to know which findings require immediate attention, which can be addressed over a longer timeframe, and which represent best-practice enhancements rather than compliance gaps.
A simple three-tier prioritisation is effective in most cases. Critical findings are those that may indicate a current breach or a material control failure that creates significant risk exposure; these require immediate attention and notification to senior management, and a legal conclusion on whether a breach has occurred may require advice from counsel. Significant findings are material weaknesses in the programme that may not require an immediate crisis response but do require governed remediation on a defined timeline. That timeline should be risk-based, which may mean immediate action or a 30-, 60-, or 90-day window, depending on severity and local regulatory expectations. Observations are enhancements to current practice that would improve programme quality but where the current position is broadly compliant: these can be addressed over a longer period and integrated into the programme improvement cycle.
Sample Remediation Tracker
| Finding | Severity | Owner | Target date | Evidence of completion | Validation | Status |
|---|---|---|---|---|---|---|
| TM rules not calibrated to BRA high-risk typologies | Critical | Head of Compliance | Immediate / 30 days | Updated rule set and tuning report | Internal audit retest | Open |
| BRA not refreshed after new product launch | Significant | MLRO | 60 days | Approved refreshed BRA | Compliance sign-off | In progress |
| Adverse-media alerts closed without rationale | Observation | Screening lead | 90 days | Updated closure notes and QA sample | Compliance QA | In progress |
The documentation of health check findings should be treated with care. A written record of known compliance weaknesses can create supervisory, disclosure, privilege, and governance implications if it is not paired with timely remediation. This does not mean that findings should be suppressed or softened; it means that the health check documentation should always be accompanied by a remediation action plan that demonstrates what is being done to address the identified findings. A firm that identifies weaknesses and can evidence timely, governed remediation is generally better placed to explain its position than a firm that has not identified or acted on those weaknesses.
Health check reports can contain sensitive findings, legal analysis, management deliberations, and evidence of known gaps. Before commissioning or circulating a review, the firm should consider the implications of privilege, confidentiality, retention, disclosure, and regulator access under local law. Privilege should not be assumed merely because an external adviser is involved; where the protection of legal advice matters, the engagement should be structured with that in mind, and legal advice should be sought on how the report will be treated.
I have seen health check reports used very effectively in regulatory examinations, where the firm has been able to demonstrate to the examiner that they identified a weakness before the examination, put a remediation plan in place, and can show the progress made against that plan. That is a very different conversation from one where the examiner identifies the weakness themselves. The health check is only valuable if it is honest and if the findings are acted upon. It is potentially damaging if it is honest but the findings are filed away.
Pathik Shah | Founder, NIYEAHMA Consultants LLP
How Frequently Should an AML Health Check Be Conducted
The frequency of the health check should be calibrated to the firm's risk profile and the rate of change in its business and regulatory environment. As a practical governance baseline, many firms choose an annual full-scope health check. Still, the appropriate frequency should be calibrated to the firm's risk profile, legal obligations, business change, prior findings, and regulatory environment. Firms operating in higher-risk sectors, firms that have undergone significant business changes, and firms operating in rapidly evolving regulatory environments should consider a more frequent review cycle, with targeted assessments of specific domains between full-scope reviews. In some jurisdictions, the maximum interval between independent reviews is prescribed by law, so any annual practice should be checked against the local requirement.
Beyond the scheduled cycle, certain events should trigger an unscheduled health check or targeted review. These include a material change in the business model or product set, entry into a new market or jurisdiction, a significant change in the customer profile, the appointment of a new MLRO, a regulatory enquiry or examination, and any internal incident that suggests a control failure in the AML programme.
The health check should also be distinguished from the ongoing monitoring activities that form part of the programme's day-to-day operation. File reviews, TM alert quality assessments, and training completion tracking are continuous activities. The health check is a periodic, structured assessment that steps back from day-to-day operations and evaluates the programme as a whole against the applicable regulatory standard.
Preparing for the Regulatory Visit After the Health Check
The health check informs the preparation for the regulatory visit but does not replace it. Once the health check findings have been prioritised and remediation is underway, the preparation for the regulatory visit should focus on three areas.
The first is ensuring that the remediation evidenced by the health check is properly documented and can be presented clearly to the examiner. A structured, evidence-based approach to programme improvement is generally easier to explain to a regulator. However, the regulator's response will depend on the facts, the legal framework, and the seriousness of any findings. The health check and the remediation action plan that flows from it are central to that demonstration.
The second is preparing the compliance team and relevant business staff for examination interviews. Regulatory examiners interview frontline staff, business managers, and compliance officers. The preparation should ensure that all staff who may be interviewed understand the firm's AML programme, their role within it, and how to describe both accurately and clearly.
The third is reviewing the documentation that the regulator is likely to request and ensuring that it is complete, current, and accessible. Most regulators provide guidance on the documents they expect to review at examination. Working through that list systematically before the visit and addressing any gaps is a straightforward but important preparation step.
Jurisdiction-Specific Points to Verify
Health checks are conducted in accordance with local law. Before relying on any of the guidance above, verify the following in each jurisdiction where the firm operates.
| Area | What to verify locally |
|---|---|
| Legal privilege | Whether, and on what basis, privilege attaches to health check reports and legal analysis, and how it can be lost through circulation or waiver. |
| Regulator powers of access | The regulator's powers to compel production of internal reviews, working papers, and remediation records. |
| SAR/STR disclosure and tipping-off | Local reporting obligations, timelines, and tipping-off restrictions that constrain how findings are described and shared. |
| Breach notification | Whether identified breaches must be self-reported, within what period, and to which authority. |
| Independent audit and testing | Whether law or regulation mandates an independent audit or independent testing function, and its required scope and frequency. |
| Record retention | Minimum retention periods for AML records, review reports, and remediation evidence. |
Sources and Further Reading
The following materials informed the general principles in this article. They set out internationally recognised expectations for AML/CFT internal controls and independent testing. None prescribes the specific seven-domain health check structure described above, and firms should always work from the standards that apply in their own jurisdiction.
- FATF, The FATF Recommendations, Recommendation 18 and its Interpretive Note, on internal AML/CFT programmes, compliance management, training, and an independent audit function.
- Basel Committee on Banking Supervision, Sound management of risks related to money laundering and financing of terrorism.
- FFIEC BSA/AML Examination Manual, on independent testing of the BSA/AML compliance programme.
- AUSTRAC, guidance on AML/CTF programmes and independent evaluation.
- Wolfsberg Group, guidance on effective AML/CFT programmes and assurance.
Frequently Asked Questions
Everything you need to know about AML health checks and how AML Guild supports your business.
An AML health check is an independent, evidence-based review of whether a firm's AML/CFT programme is designed and operating effectively against the regulatory standard that applies to it. It tests governance, business risk assessment, policies, customer due diligence, transaction monitoring, suspicious activity and transaction reporting, and training, and it produces prioritised findings and a remediation plan.
Not exactly. Independent testing and independent audit are often mandated by law or regulation and follow a formal methodology, reporting to governance. A health check is a broader, practitioner-led review that can inform those functions but does not replace any independent audit, independent testing, or independent evaluation that a firm is legally required to perform.
A health check is most useful when the reviewer is independent of the programme being assessed. That can be an internal audit function with genuine independence from compliance, an external adviser, or a combination of both. The compliance team can run a self-review, but a reviewer with no operational responsibility for the programme is more likely to surface uncomfortable findings.
An internal audit is a formal, governance-mandated review conducted by a function that is independent of the business and compliance. It typically follows a defined audit methodology and produces findings that are reported to the audit committee or board. An AML health check is a more flexible, compliance-focused assessment that may be conducted by internal audit, by the compliance function with external support, or by external advisers. The health check is designed to identify programme weaknesses and inform remediation. The internal audit is designed to provide independent assurance to governance. Both are valuable, and they are complementary rather than substitutes. Importantly, a health check does not replace any independent audit or independent testing that law or regulation requires the firm to perform (see the FFIEC BSA/AML Examination Manual on independent testing).
Critical and significant findings should be escalated to senior management and, where they indicate material programme weaknesses, to the board or relevant board committee. The governance record of that escalation is itself important: it demonstrates that the firm has a functioning governance structure that receives and acts on compliance intelligence (AUSTRAC's independent-evaluation guidance, for example, requires the evaluator's written report to be provided to the governing body and a responsible senior manager). Observations that represent best-practice enhancements rather than compliance gaps may be managed at a lower level, but the decision about what to escalate should be made deliberately and documented.
Yes, and this is one of its primary uses. A health check conducted in advance of a known or anticipated regulatory examination allows the firm to identify and address weaknesses before the examiner arrives, prepare the remediation documentation that demonstrates programme improvement, and ensure that the compliance team and relevant staff are well prepared for examination interviews. The earlier in the examination preparation process the health check is conducted, the more time is available to act on its findings.
The remediation action plan should include a clear description of each finding, the priority tier assigned to it, the specific action required to address it, the owner responsible for that action, the target completion date, and the evidence that will demonstrate completion. The plan should be reviewed regularly against the target dates and updated to reflect progress. Where remediation is delayed, the reason for the delay and the revised timeline should be documented. The plan should be signed off by the MLRO and, for critical findings, by senior management.
Where a health check finding suggests that a regulatory breach may have occurred, the MLRO should assess the nature and materiality of the potential breach and seek legal advice where appropriate. Many regulatory frameworks include provisions for voluntary disclosure of identified breaches, and some regulators may take timely voluntary disclosure, cooperation, and credible remediation into account, though the effect depends on the jurisdiction, regulator, facts, and legal framework. The decision about whether and how to disclose should be made with legal advice and should be documented carefully.
Commission an AML Health Check with Pathik Shah
Pathik conducts AML health checks and examination preparation reviews for financial institutions, fintechs, VASPs, and DNFBPs across the UAE, UK, Singapore, India, Hong Kong, and Australia. Engagements are scoped to the firm's risk profile and regulatory context.