Purpose
Coordinate independent AML/CTF/CPF testing and track findings to closure.
Scope
This procedure applies to annual independent testing and additional reviews triggered by material business changes, regulatory findings, incidents, major policy updates or technology changes.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Schedule independent testing | Schedule independent AML/CTF/CPF testing at least annually and after material business/service change, regulatory finding, major policy update or technology upgrade. Additional reviews may be triggered by material changes in business/services, regulatory inspection findings, or major policy updates or technology upgrades | Independent review report |
| 2 | Appoint independent reviewer | Appoint internal audit personnel with no day-to-day compliance involvement or a qualified independent external auditor or AML consultant. Testing team must have no day-to-day involvement in compliance operations and must report findings directly to senior management or the Board | Independence and competence confirmation |
| 3 | Confirm reporting access | Confirm direct reporting access to senior management or the Board and document reviewer competence and independence | Independence and competence confirmation |
| 4 | Define risk-based scope | Define risk-based scope, methodology, review period, sample basis, limitations and evidence request. Testing must assess whether policies, procedures, controls and risk-management framework are effective and comply with applicable requirements (NOIS, NORUT, CBCS Provisions & Guidelines, sanctions obligations, internal manuals). Must be risk-based, proportionate to size and business model, and include sample testing where relevant | Scope, methodology, sample and limitations record |
| 5 | Cover minimum review scope | Scope includes, at minimum: AML/CTF/CPF manual(s), procedures and control framework including sanctions screening; most recent risk assessment including EWRA/SARA methodology, annual performance, trigger-based updates and enterprise/client-level alignment; customer file review (KYC/CDD, EDD, beneficial ownership, authorized representatives, source of funds/wealth, client acceptance decisions and approval requirements by risk category); interviews with onboarding, transactions, monitoring, escalation/reporting personnel and supervisors; sample testing of unusual transactions and alerts (on/beyond thresholds, internal escalation, investigation quality, decision rationale, reporting compliance); review of freezing/unfreezing/blocking/restriction/refusal/release decisions including sanctions-related restrictive measures; review of corrective actions from previous testing/review findings/regulatory feedback/material control issues; Know Your Employee/employee screening policy and implementation evidence; transaction monitoring and escalation processes (on-ramp/off-ramp, alert scenarios, thresholds, calibration, investigation, documentation); sanctions-list monitoring (coverage, refresh, alert handling, false-positive closure rationale, unresolved-alert stop controls, freezing, reporting/notification); FIU Curaçao UTR decisioning and reporting controls (timeliness, completeness, rationale, confidentiality, anti-tipping-off); wallet screening, wallet ownership verification, blockchain analytics and transaction tracing including high-risk wallet exposure; VASP counterparty due diligence and KYV controls; record retention, audit trails and retrievability; AML/CTF/CPF training coverage, role-based content, completion records and remediation; AML/CTF/CPF technology and systems controls (onboarding, screening, transaction monitoring, case handling, reporting, access rights, audit logs, tool calibration, list refresh, change management, vendor oversight) | Scope, methodology, sample and limitations record |
| 6 | Include interviews | Include interviews with personnel and supervisors involved in onboarding, transactions, monitoring, escalation and reporting | Interview and working-paper evidence |
| 7 | Sample transactions and cases | Sample transactions on and beyond thresholds, alert decisions, freezes and releases, false-positive closures, UTR cases, CDD/EDD files and prior remediation | Sample list |
| 8 | Document review findings | Reviewer must document scope, methodology, sample basis, limitations, findings, ratings, recommendations, management responses and remediation actions | Independent review report |
| 9 | Report findings to leadership | Report findings to Compliance, senior management and the Board | Board or management reporting |
| 10 | Track remediation actions | Assign each remediation action an owner, target date and status, and track to completion. Give high-priority issues a documented remediation plan with clear owners and deadlines | Remediation tracker |
| 11 | Verify closure independently | Verify closure evidence independently and retain the report, working papers, responses and closure record | Closure evidence |
| 12 | Feed lessons into framework | Feed lessons into policies, SARA, training, monitoring, technology and control design | Effectiveness review and improvement record |
Evidence
- independent review report
- sample list
- management response
- remediation tracker
- closure evidence
- Board or management reporting
- independence and competence confirmation
- scope, methodology, sample and limitations record
- interview and working-paper evidence
Relationships
- Policy: POL-AML-001 AML CTF CPF Compliance Manual
- Process: PRC-FCI-001 Financial Crime and Integrity
- Controls: CTRL-AML-009 Ensure AML Independent Review Findings Are Tracked
- Second-line testing: PROC-ICA-004 Perform Second Line Control Testing
- Manual coverage: sections 1.2 and 10.1-10.6.
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved AML/CTF/CPF Compliance Manual version 2.2
History
- 2026-07-26: Expanded independence, minimum annual frequency, mandatory review scope, sampling, reporting and closure verification after a full manual rescreen.
- 2026-07-26: Created from the approved AML/CTF/CPF Compliance Manual version 2.2.