How to perform your Quarterly Effectiveness Review
The review is deliberately hands-on. Automated checks confirm a field was filled in; only a person can judge whether what's in that field is adequate.
AML/CTF compliance requires you to review that your processes are working in practice, not just that they exist on paper. This quarterly review is how you do that, and the records it produces are evidence for your independent evaluation.
1. Search for last quarters Entities and Transactions
Filter the client list to the quarter and note the total count. Do the same for transactions. These are the records you're checking against.
Keep your filters and sort order consistent throughout, so your review covers the last quarter.
2. Review every high-risk client and transaction
Filter by risk rating: High and Very High. Review all of them, this group is too important to sample.
For each, satisfy yourself that:
- EDD has been carried out, and that the measures taken were proportionate to the risk
- Source of funds and source of wealth are supported by evidence, not just a stated explanation
- Any required approval is recorded
- The next review date hasn't passed
3. Sample your standard-risk records
Review 10% of the quarter's records, or 25, whichever is larger — clients and transactions separately.
Choose them at random. With your list sorted, pick your row numbers first and then work to those records, rather than reviewing whichever files come to hand. Selecting the convenient ones tells you about your best work, not your typical work.
For each, confirm:
- Every individual on the file is verified
- Verification was completed before the service was provided
- Identity documents were current at the time of verification
- Beneficial owners on entity files are verified, not just recorded
- Where source of funds or wealth was required, it's evidenced
- Ask whether the rating assigned still reflects the risk correctly
This is the most valuable step in the review. A client rated too low never appears in a high-risk filter, so nothing will flag the EDD that wasn't required due to the risk rating. Only your judgement catches it.
5. Clear any outstanding tasks
Review all of these, rather than a sample:
- Clients whose review date has passed or have had their verification abandoned
- Verifications that need refreshing - this is required if you are stilling dealing with clients two years after their original verification
- Review any outstanding PEP, adverse media or sanctions matches from the quarter
6. Check your staff training
Open the staff training dashboard and confirm every person who needs AML/CTF training has completed it and isn't overdue.
Then check your exemptions still stand. An exemption granted on the basis of someone's role stops being valid the moment that role changes, and nothing will tell you it has so confirm the reason you granted it is still true, and remove it if it isn't.
Also check the list itself is current. Staff who've joined since your last review should appear; those who've left shouldn't still have access.
7. Remediate what you find
For clients: reverify, or request the missing information from the individual or entity. Note on each record that the gap was identified during your quarterly review, so the file history is clear.
For training: assign the outstanding training with a completion date, and revoke any exemption that no longer applies.
Where client information can't be obtained, escalate to your compliance officer. They'll decide whether the relationship continues and whether a suspicious matter report is required. Record that decision and the reasoning behind it.
8. Complete the review
Record what you reviewed — the counts in each category, the issues you found, what you remediated, and anything escalated. This record is your evidence that the review took place and what it told you about your program.