Guide
Running an AML and KYC forensic audit
A forensic AML/KYC audit is not a routine control check. It reconstructs what actually happened across onboarding, monitoring, and reporting, then measures that reality against the standard your program claims to meet. The trigger is usually specific: a regulator finding, a suspected internal failure, a spike in suspicious activity reports, or a change of control that puts prior conduct under scrutiny. The goal is defensible evidence, not reassurance.
What the audit reconstructs
The work starts with the customer file. An auditor rebuilds identity verification, beneficial ownership, source-of-funds documentation, and the risk rating assigned at onboarding, then checks whether that rating was refreshed as behaviour changed. From there it moves to transaction monitoring: were alerts generated, triaged, and dispositioned on time, and did closed alerts have written rationale that a third party could follow. Gaps here are where most programs fail, because a control that runs but leaves no record is indistinguishable from a control that never ran.
Evidence that survives scrutiny
Forensic means the findings hold up when challenged. That requires a clear chain from policy to procedure to the individual decision, with dates, owners, and the underlying data preserved. Sampling should be risk-weighted rather than random, concentrating on high-risk customers, politically exposed persons, and correspondent relationships. Every exception needs a documented disposition: remediated, escalated, or accepted with a named approver. The output is a control-by-control map showing what was tested, what was found, and what remains open, so remediation can be tracked to closure instead of restarting each cycle.
Owning the framework
Most teams rebuild this scaffolding under pressure, which is the worst time to design it. The AML/KYC forensic audit program is available as an owned, single-file, regulator-mapped dashboard from The Protocol Collective. You pay once and keep it, it is updated for life, and it is built from public frameworks. It gives you the control map, the sampling logic, and the evidence structure in one place, so an audit becomes a matter of populating a known framework rather than inventing one while the clock runs.
Explore The Protocol Collective
General information about compliance and program structure, not regulatory, legal, tax or financial advice, and no promise of any examination or audit outcome. Built from public frameworks.