Purpose

Coordinate independent AML/CTF/CPF testing and track findings to closure.

Scope

This procedure applies to annual independent testing and additional reviews triggered by material business changes, regulatory findings, incidents, major policy updates or technology changes.

Steps

#ActionDetailsEvidence
1Schedule independent testingSchedule independent AML/CTF/CPF testing at least annually and after material business/service change, regulatory finding, major policy update or technology upgrade. Additional reviews may be triggered by material changes in business/services, regulatory inspection findings, or major policy updates or technology upgradesIndependent review report
2Appoint independent reviewerAppoint internal audit personnel with no day-to-day compliance involvement or a qualified independent external auditor or AML consultant. Testing team must have no day-to-day involvement in compliance operations and must report findings directly to senior management or the BoardIndependence and competence confirmation
3Confirm reporting accessConfirm direct reporting access to senior management or the Board and document reviewer competence and independenceIndependence and competence confirmation
4Define risk-based scopeDefine risk-based scope, methodology, review period, sample basis, limitations and evidence request. Testing must assess whether policies, procedures, controls and risk-management framework are effective and comply with applicable requirements (NOIS, NORUT, CBCS Provisions & Guidelines, sanctions obligations, internal manuals). Must be risk-based, proportionate to size and business model, and include sample testing where relevantScope, methodology, sample and limitations record
5Cover minimum review scopeScope includes, at minimum: AML/CTF/CPF manual(s), procedures and control framework including sanctions screening; most recent risk assessment including EWRA/SARA methodology, annual performance, trigger-based updates and enterprise/client-level alignment; customer file review (KYC/CDD, EDD, beneficial ownership, authorized representatives, source of funds/wealth, client acceptance decisions and approval requirements by risk category); interviews with onboarding, transactions, monitoring, escalation/reporting personnel and supervisors; sample testing of unusual transactions and alerts (on/beyond thresholds, internal escalation, investigation quality, decision rationale, reporting compliance); review of freezing/unfreezing/blocking/restriction/refusal/release decisions including sanctions-related restrictive measures; review of corrective actions from previous testing/review findings/regulatory feedback/material control issues; Know Your Employee/employee screening policy and implementation evidence; transaction monitoring and escalation processes (on-ramp/off-ramp, alert scenarios, thresholds, calibration, investigation, documentation); sanctions-list monitoring (coverage, refresh, alert handling, false-positive closure rationale, unresolved-alert stop controls, freezing, reporting/notification); FIU Curaçao UTR decisioning and reporting controls (timeliness, completeness, rationale, confidentiality, anti-tipping-off); wallet screening, wallet ownership verification, blockchain analytics and transaction tracing including high-risk wallet exposure; VASP counterparty due diligence and KYV controls; record retention, audit trails and retrievability; AML/CTF/CPF training coverage, role-based content, completion records and remediation; AML/CTF/CPF technology and systems controls (onboarding, screening, transaction monitoring, case handling, reporting, access rights, audit logs, tool calibration, list refresh, change management, vendor oversight)Scope, methodology, sample and limitations record
6Include interviewsInclude interviews with personnel and supervisors involved in onboarding, transactions, monitoring, escalation and reportingInterview and working-paper evidence
7Sample transactions and casesSample transactions on and beyond thresholds, alert decisions, freezes and releases, false-positive closures, UTR cases, CDD/EDD files and prior remediationSample list
8Document review findingsReviewer must document scope, methodology, sample basis, limitations, findings, ratings, recommendations, management responses and remediation actionsIndependent review report
9Report findings to leadershipReport findings to Compliance, senior management and the BoardBoard or management reporting
10Track remediation actionsAssign each remediation action an owner, target date and status, and track to completion. Give high-priority issues a documented remediation plan with clear owners and deadlinesRemediation tracker
11Verify closure independentlyVerify closure evidence independently and retain the report, working papers, responses and closure recordClosure evidence
12Feed lessons into frameworkFeed lessons into policies, SARA, training, monitoring, technology and control designEffectiveness review and improvement record

Evidence

  • independent review report
  • sample list
  • management response
  • remediation tracker
  • closure evidence
  • Board or management reporting
  • independence and competence confirmation
  • scope, methodology, sample and limitations record
  • interview and working-paper evidence

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved AML/CTF/CPF Compliance Manual version 2.2

History

  • 2026-07-26: Expanded independence, minimum annual frequency, mandatory review scope, sampling, reporting and closure verification after a full manual rescreen.
  • 2026-07-26: Created from the approved AML/CTF/CPF Compliance Manual version 2.2.