Skip to main content

Call us today +971 - 56411 3575 or +971 - 58914 9282 | Email: info@vertexcompliance.com

AML Agreed-Upon Procedures

Complete your AML AUP with clear findings and stay ready for reporting deadlines.

Request an AUP Engagement

    About AML Agreed-Upon Procedures

    An Agreed-Upon Procedures engagement, or AUP, is different from a traditional audit. Instead of giving an overall audit opinion, specific procedures are agreed before the engagement begins. These procedures are then carried out, and the factual findings are reported.
    Vertex Compliance provides AML AUP services for businesses that need specific checks on their AML/CFT compliance function. For exchange houses, the annual AUP looks at key areas of the AML/CFT framework and how required processes are being followed.
    The work can include your AML framework, risk assessments, KYC processes, transaction monitoring, sanctions screening, AML training, suspicious transaction records, compliance reports, and other areas agreed as part of the scope.
    At the end of the engagement, you receive a clear record of the procedures completed and the findings identified. This gives the Board, management, and other relevant parties the information they need to understand the results and decide what action is required.

    AML Agreed-Upon Procedures

    What Our AML Agreed-Upon Procedures Cover

    Depending on the scope, the engagement can cover the following areas of your AML/CFT compliance function.

    1. AML Framework and Risk Controls

    We look at the main documents and controls that form the basis of your AML/CFT programme. This section can cover the compliance framework, AML/CFT policies and procedures, and your ML/FT/PF risk assessments. The agreed checks may also cover the appointment and responsibilities of the Compliance Officer, internal audit reports, and the semi-annual reports prepared by the MLRO or Compliance Officer. Continuous professional development arrangements can also form part of the work. Each procedure is carried out against the agreed requirement. The result is then recorded as a factual finding, giving management a clear view of what the audit focuses on: the specific procedures agreed upon by the relevant parties and reports the findings from those checks. This process is conducted without expanding the engagement to include a broader audit opinion.

    2. Customer and Transaction Controls

    Much of AML compliance is done through customer due diligence and transactional controls in the course of the day-to-day business. Therefore, the AUP may include KYC processes, customer information, transaction analysis and the management of specific business relationships. Depending on the agreed scope, we may also review transaction monitoring systems, sanctions screening, typology assessments, PEP and HIO checks and the gathering of required customer information or declarations. Where relevant, procedures may cover relationships with DNFBPs and dealers in precious metals and stones. The purpose is to carry out the specific checks already agreed for the engagement and clearly record the outcome of each one.

    3. Training, Records and Reporting

    AML controls also depend on how people, records, and reporting processes. The management of people, records, and reporting processes across the business also influences AML controls. across the business. The procedures can cover employee recruitment checks, AML training programmes, conflict-of-interest arrangements, suspicious transaction logs, and record-retention practices. We may also include committee meeting minutes and other supporting records as part of the agreed work. For exchange houses, the scope can also include remittance data uploads and other records linked to the AML/CFT compliance function. We document the result of each procedure so the final report provides the relevant parties a clear account of the checks completed and the findings identified.

    Our Approach

    Our AML Agreed-Upon Procedures approach focuses on specific compliance areas agreed upon before the engagement begins.

    1
    Agree on the Scope

    We start by defining the objective of the engagement and the procedures needed. The relevant parties should agree on the scope before the work starts. We also verify the records, reports, systems and other information that will be needed to perform those procedures. This keeps the engagement focused and clarifies the AUP’s coverage. It also helps keep the engagement focused and clarifies what the AUP covers specifically and what it does not.

    2
    Carry Out the Checks

    When the scope is agreed on, our team executes the defined AML/CFT procedures. This may include policies, compliance records, customer information, risk assessments, system outputs, reports, training records or other material associated with the agreed checks. The work is performed according to the agreed procedures. An AUP is never extended to a general audit or a wider assessment unless a separate scope has been agreed.

    3
    Record the Findings

    We document what was found while carrying out each agreed procedure. If a review identifies an exception, missing record, inconsistency, or another point that needs attention, it is recorded as part of the factual findings. The aim is to provide the people using the report a clear account of the work performed and its results, without adding an audit opinion that falls outside the purpose of an AUP engagement.

    4
    Complete the Report

    Once the procedures have been completed, the findings will be compiled in the AUP report. The report sets out the procedures performed and the factual results from those checks. Where the engagement is being completed for a regulatory requirement, we also work around the applicable reporting timeline. This gives management and the board the information needed to review the findings and take the appropriate next steps.

    Who Is AML AUP For?

    Exchange Houses
    CBUAE-Regulated Businesses
    Financial Institutions
    Businesses With Specific AML Checks

    Ideal for UAE-regulated businesses that need specific AML/CFT controls independently tested and the factual findings clearly reported.

    Why Choose Our AML AUP Service?

    AML AUP Expertise

    Vertex Compliance has hands-on experience in AML Agreed-Upon Procedures and UAE regulatory requirements. We keep each engagement focused on the agreed scope, required checks and factual reporting needed to produce a clear and reliable AUP.

    Clear AUP Scope

    You know what will be checked before the engagement begins. We work with you to set out the procedures, information required, key steps, and expected timeline, reducing confusion once the AUP is already underway.

    Practical, Clear Findings

    Our reports focus on what the agreed procedures actually found. The results are set out clearly so the Board, management, and other intended users can understand the findings without having to work through unnecessary or overly technical language.

    On-Time AUP Support

    Regulatory AUP work often comes with firm reporting dates. We plan the engagement around the required timeline, keep the process moving, and work with your team to obtain the information needed to complete the agreed procedures on time.

    Meet the Experts

    Sarah Khan
    Vasantha Madan Mohan

    Managing Director

    Sarah Khan
    Sridhar Rajam

    Associate Partner

    Sarah Khan
    Arjun Mohan

    Director – Sales & Marketing

    Frequently Asked Questions

    AML Agreed-Upon Procedures are specific checks that are agreed upon before the engagement starts. The practitioner performs those procedures and reports the factual findings. Unlike a traditional audit, an AUP engagement does not provide an overall audit opinion.
    An AML audit normally looks more broadly at the compliance framework and may provide an overall conclusion or opinion depending on the engagement. An AUP is narrower. It focuses on the exact procedures agreed by the relevant parties and reports what was found from those checks.
    The scope can include AML/CFT policies, ML/FT/PF risk assessments, KYC, transaction analysis, transaction monitoring, sanctions screening, PEP and HIO checks, training, suspicious transaction records, record retention, compliance reports, and other areas agreed upon for the engagement.
    Under the applicable CBUAE requirements for exchange businesses, external auditors must perform agreed-upon procedures on the AML/CFT compliance function annually. The exact regulatory requirements that apply to your business may vary. Please confirm the exact regulatory requirements applicable to your business when setting the engagement scope.
    The report outlines the agreed-upon procedures performed and the factual findings derived from those procedures. The report does not provide an overall audit opinion. The intended users can consider the findings and decide what action The intended users can review the findings and determine the necessary actions.
    The timeline depends on the number of procedures involved, the size of the business, the information available, and the reporting deadline. We agree on the main steps and expected timeline at the start so both teams know what needs to happen and when.