The Difference Between a Health Check and a Regulatory Examination: Why Confusing Them Costs You

Pathik Shah Pathik Shah 14 min read AML Insights
Article Summary

How to tell an AML health check apart from a regulatory examination, and why treating the two as the same thing exposes your firm to avoidable regulatory risk.

A practitioner guide for compliance officers on the distinction between an AML health check and a regulatory examination, covering privilege, scope, purpose, and how to use both tools correctly in the compliance assurance framework. Written by Pathik Shah for AML Guild. 

AML Expert
Talk to an expert

AML Expert

Get tailored guidance on your compliance obligations, SAR filing, or AML program review.

Reach Out Now

Authored by

Pathik Shah

Founder, NIYEAHMA Consultants LLP

CAMS | FCA | CISA | CS | DISA (ICAI) | FAFP (ICAI)

28 years in AML/CFT advisory across UAE, UK, Singapore, India, Hong Kong, Australia and the GCC

Expert Panel

Dipali Vora — AML/CFT Practitioner | Associate Member, ICSI

Jyoti Maheshwari — AML/CFT Practitioner | Published in ACAMS Today & AMLverse

What This Article Covers
  • What a health check is
  • What a regulatory examination is
  • The privilege dimension
  • Using both tools correctly
  • Health check vs regulatory examination: key differences (comparison table)
  • When to conduct an AML health check
  • How to prepare for a regulatory examination
  • What not to do when preparing
  • Governing the examination process
  • Common mistakes firms make
  • Treating findings and remediation plans
  • Documents regulators commonly request
  • Frequently asked questions

What a Health Check Is

A health check is a voluntary internal or external review, commissioned by the institution at its discretion, to assess the design and operational effectiveness of its AML/CFT programme and identify areas for improvement. It may be run by an internal team or, more often, by an external expert engaged to bring an outside perspective and sector-specific depth. Where an external expert conducts it, the health check is typically carried out under terms of engagement that preserve the confidentiality of the findings, allowing the institution and the expert to discuss the programme frankly without the exercise itself automatically becoming a formal supervisory finding.

The scope of a health check is defined jointly by the institution and the expert, based on the specific areas of concern or the breadth of assessment the institution requires. A full-scope health check assesses the entire programme across all its dimensions: risk assessment, CDD, monitoring, reporting, governance, and training. A focused health check may address a specific concern, such as the quality of the STR process or the effectiveness of the monitoring programme for a specific product line.

What a Regulatory Examination Is

A regulatory examination is a formal supervisory process conducted by the relevant regulatory authority under its statutory powers. The examination may be announced in advance or may be conducted with limited or no notice. The examiner has the power to require the production of documents and information, to conduct interviews with the compliance team and staff, and to make findings that may result in formal regulatory requirements, penalties, or other supervisory actions.

The compliance consequence of a regulatory examination makes it a fundamentally different experience from a health check, regardless of the quality of the compliance programme being examined. The compliance officer overseeing a regulatory examination is conducting a formal supervisory process with legal and regulatory implications, not a consulting engagement with an advisory output.

Health Check vs Regulatory Examination: Key Differences

The two exercises differ across every dimension that matters in practice: who runs them, why, with what notice, and with what consequence. The table below sets out the contrast at a glance.

Dimension AML Health Check Regulatory Examination
Who conducts it An internal team or, more often, an external expert engaged by the institution The regulatory authority or examiners appointed by it
Nature Voluntary; commissioned at the institution's discretion Mandatory; initiated by the regulator under statutory powers
Notice Planned with the institution in advance May be announced or carried out with limited or no notice
Purpose To assess design and operating effectiveness and identify improvements To verify compliance and make formal supervisory findings
Confidentiality Retained by the institution for its own assurance; may attract privilege if structured through counsel, though a regulator may request the report Findings form part of the supervisory record
Output An advisory report with recommendations and a remediation plan Formal findings, requirements, penalties or other supervisory action
If weaknesses are found Addressed internally through a self-directed remediation plan May result in enforcement, directions, sanctions or mandated remediation

The Privilege Dimension

The confidentiality of a health check may be strengthened by engaging the external expert through legal counsel, so that the review may be conducted under legal professional privilege. When privilege applies, the findings report and the communications between the expert and the institution may be protected from disclosure, depending on the jurisdiction, the role of legal counsel, the purpose of the review, and whether privilege has been properly preserved. Where it applies and is properly preserved, that protection may allow the health check to explore the most sensitive programme dimensions, including areas where the programme may not currently meet the regulatory standard, with greater candour. However, privilege and disclosure risk should still be assessed under local law.

The privilege position is the part clients most often get wrong. Engaging the expert through legal counsel can protect a frank health check report, but it varies by jurisdiction, so I tell people to take specific local advice before commissioning the review rather than assuming the protection travels across borders.

Jyoti Maheshwari | CAMS, ACA, AML/CFT Practitioner, AML Guild

The compliance officer should take specific legal advice on the privilege protection available for health check reports in the relevant jurisdiction before commissioning a health check. The privilege position varies by jurisdiction, and the protection that applies in one market may not apply in another. An unprivileged health check report that identifies significant programme weaknesses may be disclosable to a regulator, which makes prompt, well-evidenced remediation the institution's best protection.

Using Both Tools Correctly

The well-governed compliance assurance framework uses both the health check and the examination process, each for its appropriate purpose. The health check should be conducted at regular intervals, ideally annually, as a genuine programme assessment tool rather than only as examination preparation. The examination preparation process should draw on the health check findings and the remediation work they have driven, but should be a distinct exercise from the health check itself.

A health check squeezed into the ninety days before an examination is just examination prep wearing a different label. I recommend running it annually as a genuine improvement tool, so that by the time a regulator does arrive, the programme has actually been strengthened rather than rehearsed.

Dipali Vora | CAMS, ACA, AML/CFT Practitioner, AML Guild

The compliance officer who uses the health check to identify and address genuine programme weaknesses and then approaches the regulatory examination with a programme that has been genuinely improved is using both tools correctly. The one who conducts a health check only in the 90 days before an examination and uses it primarily for examination preparation is using the health check as a subset of the examination preparation process rather than as an independent programme improvement tool.

When Should a Firm Conduct an AML Health Check?

An AML compliance health check should be a scheduled part of the compliance assurance framework rather than a reaction to an impending regulatory visit. As a baseline, most regulated firms benefit from a full-scope AML health check once a year, supported by focused reviews triggered by specific events: a material change in the business or its risk profile, entry into a new product line or jurisdiction, a merger or acquisition, the appointment of a new MLRO, a significant remediation programme, or early signals that a supervisory examination may be approaching.

A health check is not mandatory in most regimes, but conducting one at sensible intervals is a recognised marker of a mature programme and gives the board genuine assurance rather than a last-minute rehearsal. A voluntary health check should not be confused with any legally required independent audit, independent testing, or periodic review obligation imposed by the applicable regulator; where such an obligation exists, the health check supplements it rather than replaces it. For a practical walkthrough, see how to conduct an AML health check before your next regulatory visit.

How to Prepare for a Regulatory Examination

Preparing for a regulatory examination, sometimes called a regulatory inspection or supervisory examination, is a distinct exercise from a health check. However, it should draw on the health check findings and the remediation work they have driven. Preparation begins with assembling the core documentation a regulator will expect, rehearsing how the compliance team will present the programme, and confirming that issues identified in earlier reviews have been closed or have a credible plan in train.

Practical preparation covers reviewing the enterprise-wide risk assessment and confirming it is current; checking that customer due diligence and enhanced due diligence files are complete and retrievable; testing that transaction monitoring and the STR process can be evidenced end-to-end; and ensuring governance records show active board and senior management oversight. The aim is not to stage-manage the examination but to demonstrate, calmly and with evidence, that the programme works as described. For a fuller treatment, see our guide to managing a regulatory examination.

What Not to Do When Preparing for an Examination

The line between thorough preparation and misconduct matters. Do not back-date policies or procedures, overwrite or recreate historical records, coach staff to give scripted answers, conceal known issues, or describe remediation as complete unless the evidence supports it. Presenting the programme honestly, including what is still being fixed, is safer than dressing it up for the visit. If a material issue comes to light before or during an examination, take legal and regulatory advice on whether notification or self-disclosure is required rather than staying silent by default.

Governing the Examination Process

Treat the examination itself as a governed process. Nominate a single examination coordinator as the regulator's point of contact, maintain a request tracker so nothing is missed, keep copies of everything submitted, record every deadline, and route sensitive or unexpected requests to legal counsel before responding. Keep the board and senior management informed of material findings as they emerge, so that oversight is visible and remediation decisions are taken at the right level.

Common Mistakes Firms Make

The most common mistake is confusing the two exercises and treating a health check as nothing more than preparation for an examination, which strips it of its value as an independent improvement tool. Others include commissioning a health check only in the ninety days before an expected visit, failing to act on the findings once they are received, allowing an unprivileged report that documents serious weaknesses to sit on file without a remediation plan, treating the internal audit function and an external health check as interchangeable, and assuming that privilege obtained in one jurisdiction travels automatically to another. Each of these turns a useful assurance exercise into a source of avoidable regulatory exposure.

How to Treat Health Check Findings and Remediation Plans

Health check findings should be treated as the start of a remediation cycle, not as a report to be filed. Each finding should be assigned an owner, a severity rating and a target date, and tracked through to closure with evidence. A credible regulatory remediation plan distinguishes between issues that can be fixed quickly and those that require systemic change, sequences the work by risk, and is visible to the board. Where findings are significant, the institution should take a considered view, with legal advice, on how the report is held and who has access to it, since an unaddressed finding is far more damaging in an examination than one that has been identified and is being actively resolved.

Documents Regulators Commonly Request

The precise list of requests varies by regulator and sector, but an AML/CFT examination will typically call for some combination of the following. Having these current and retrievable is itself a sign of a well-run programme.

Commonly requested documents
  • The enterprise-wide AML/CFT risk assessment and its supporting methodology.
  • AML/CFT policies, procedures and controls, with version history.
  • Customer due diligence and enhanced due diligence files for a sample of clients.
  • KYC and beneficial ownership records behind that sample.
  • Transaction monitoring rules, alerts, and the rationale for alert disposition.
  • Suspicious transaction or activity reports and the underlying decision records, where disclosure to the relevant competent authority is lawfully permitted or required.
  • Sanctions and PEP screening configuration and results.
  • Training records and the training programme.
  • Governance materials, including board and committee minutes evidencing oversight.
  • Prior internal audit reports, AML/CFT independent review and AML audit reports, and remediation tracking.

Got questions

Frequently Asked Questions

Everything you need to know about health checks, examinations, and how AML Guild supports your business.

In most regimes, a health check is not a legal requirement; it is a voluntary exercise the institution chooses to commission. That said, many supervisors expect or encourage regulated firms to subject their programmes to periodic independent review, and an AML/CFT independent review is often the practical way to evidence that expectation. Running a health check at sensible intervals is treated as a marker of a mature compliance programme even where no rule compels it.

Not quite. The terms overlap and are sometimes used interchangeably. Still, a formal AML audit, particularly the third-line-of-defence internal audit, is a structured assurance activity within the governance framework, with defined independence and reporting lines. A health check is usually a more flexible, advisory review, often conducted by an external expert to bring sector-specific depth and an outside perspective. The two are complementary rather than substitutes.

As a baseline, a full-scope AML compliance health check once a year suits most regulated firms, supplemented by focused reviews when the risk profile changes: a new product, a new jurisdiction, an acquisition, a change of MLRO, or a major remediation. The right cadence is risk-based rather than fixed, so a higher-risk business may need to review more often.

A health check can usefully inform preparation for a regulatory inspection, but it should not exist only for that purpose. A review squeezed into the weeks before an expected visit is examination preparation wearing a different label. The better practice is to run the health check on its own annual cycle, so that by the time a regulator arrives, the programme has genuinely been strengthened rather than rehearsed.

A regulator can ask, and whether disclosure can be compelled depends on the report's privileged status and the regulator's specific powers in the relevant jurisdiction. A genuinely privileged document may be protected from compelled disclosure in many circumstances, but privilege can be waived or may not apply, and the position varies between jurisdictions. A report not conducted under privilege is more likely to be disclosable. Take specific legal advice on the disclosure risk before commissioning a health check and before responding to any disclosure request.

The internal audit function, as the third line of defence, has a specific, independent assurance role, reflected in supervisory guidance such as the FFIEC examination manual on independent testing (one example of how supervisors frame these expectations) within the institution's governance framework. The health check conducted by an external expert is a separate assessment that provides an outside perspective on the programme, typically with greater depth of sector-specific expertise than the internal audit function. The two are complementary rather than substitutes: internal audit provides ongoing independent assurance from within the governance framework, while the external health check provides a market-referenced perspective from outside it.

Sources and Further Reading
  • FATF, The FATF Recommendations — the global AML/CFT standards, including the expectation of an independent audit function.
  • FATF, Methodology for Assessing Compliance and Effectiveness — how national AML/CFT/CPF systems are assessed for technical compliance and effectiveness through mutual evaluations; useful background, not a firm-level examination manual.
  • FFIEC, BSA/AML Examination Manual: Independent Testing — a worked example of how supervisors frame examinations and independent review.
  • The Wolfsberg Group, Principles for Auditing a Financial Crime Programme for Effectiveness — industry guidance on the three lines of defence and effectiveness.

External sources are provided for general reference and reflect their position at the time of writing; they are not a substitute for jurisdiction-specific legal advice.

Related Articles
  • What Regulators Are Really Looking For in an AML Examination (series hub)
  • How to Read a Mutual Evaluation Report for Your Own Programme
  • When the MLRO Says No, and the CEO Says Yes: Managing the Disagreement Professionally
  • How to Read a FATF Mutual Evaluation Report
Work with this expert
Pathik Shah
Pathik Shah Founder, NIYEAHMA Consultants LLP

Work With Pathik Shah Through AML Guild

Pathik Shah and the AML Guild network provide on-demand, CAMS-certified AML/CFT support for regulated businesses, from building and remediating compliance programmes to preparing for regulatory examination and selecting the right technology.