Risk Horizon
Live

Intelligence generated by AI from public regulatory sources. Not investment or regulatory advice. Verify before relying on any output.

Governance
Annualv1Updated 27 Jul 2026

Annual Audit Committee Pack — Financial Crime, AML & Regulatory Compliance Assurance

This annual Audit Committee cadence pack provides the deep-dive assurance review over the financial crime, anti-money laundering (AML), and regulatory compliance control environment. It is designed to satisfy the Audit Committee's non-executive oversight responsibilities under the UK Corporate Governance Code, PRA SS5/16 (Corporate Governance), and the SMCR expectations placed on the Chair of Audit. The annual review consolidates outputs from Internal Audit, the MLRO, Compliance, and external audit, testing the design and operating effectiveness of key controls across sanctions screening, transaction monitoring, customer due diligence, and regulatory reporting. Particular attention is given to typology shifts flagged by FinCEN and other FIUs, and to the adequacy of the three-lines-of-defence model. The pack also frames the Committee's opinion for inclusion in the Annual Report and Accounts, supports the going concern and viability statement, and informs the Board's declaration on the effectiveness of internal controls. Regulators increasingly expect Audit Committees to demonstrate substantive challenge rather than passive receipt of assurance reports.

CommitteeAudit Committee

8

Required Materials

6

Key Questions

1

Related Themes

Required Materials(8)
  • Annual MLRO Report
  • Internal Audit Universe & Annual Plan
  • External Auditor Year-End Report and Management Letter
  • Financial Crime Control Effectiveness Assessment
  • Compliance Monitoring Plan Outcomes Report
  • Regulatory Correspondence Log
  • Whistleblowing Annual Report
  • Sanctions & PEP Screening KRI Dashboard
Key Questions(6)
  • Is the financial crime control framework demonstrably effective against the current typology landscape, including state-actor and sanctions evasion risks?
  • Do we have sufficient independent assurance over the design and operating effectiveness of AML controls to sign the Annual Report attestation?
  • How has management responded to overdue Internal Audit findings, and are any indicative of systemic control weakness?
  • Is the whistleblowing channel demonstrably trusted, and how have material concerns been investigated and closed?
  • Does the Compliance function have sufficient stature, resource, and independence to challenge the first line?
  • Are emerging regulatory expectations (e.g. FinCEN advisories) reflected in updated policies, training, and monitoring rules within an acceptable lag?
Related Themes(1)