AML/CFT Independent Audit Report

Independent Assessment (Audit) of AML/CFT Controls and Processes with a Remediation Plan. A comprehensive "diagnostics" of the company's internal systems to identify existing deficiencies and non-compliance with regulatory requirements, followed by a clear roadmap for their remediation.

I. Independent Assessment Phase (AML Audit & Assessment)

  1. Regulatory and Document Compliance Analysis (Gap Analysis)

    • Internal Framework Review: Comparing existing policies, instructions, and procedures against applicable legislation, regulatory requirements (National Bank of Georgia, FMS), and FATF standards.

    • Risk Assessment Methodology Review: Verifying the validity and adequacy of the Business-Wide and Customer Risk Assessment Frameworks.

  2. Testing Operational Effectiveness

    • Sample Testing of CDD/EDD Processes: Reviewing actual customer files to assess the accuracy of KYC data collection, UBO identification, and PEP/sanctions screening.

    • Transaction Monitoring System Testing: Evaluating the effectiveness of rules and alert indicators, and analyzing false positive versus real match cases.

    • Suspicious Transaction Reporting (STR/SAR): Assessing the timeliness and quality of identifying suspicious transactions/behavior, internal escalation, and reporting to the Financial Monitoring Service (FMS).

  3. Technological and Organizational Infrastructure

    • AML/KYC Software Assessment: Evaluating the functionality and integration quality of automated tools in use.

    • Team Competence and Resources: Assessing the knowledge, distribution of functions, and decision-making independence of the Compliance Officer and operational staff.

II. Remediation Plan (Corrective Action Plan / CAP) Based on the assessment, a Corrective Action Plan (CAP) is developed, which includes:

  • Risk Prioritization: Categorizing findings by risk level — Critical, High, Medium, and Low.

  • Action Items: Detailed instructions on required changes:

    • Updating/redrafting internal documentation;

    • Adjusting transaction monitoring limits and scenarios;

    • Remediation of historical customer files.

  • Responsibility & Timeline: Defining clear deadlines and responsible roles for each task.