
The compliance officer's annual report is not a filing. Under ICPAC's Directive it goes to your own board, it should be used to formulate an action plan where needed, and an inspector may ask for both. Which is why the report is read next to the thing it changed.
The paragraph is 3.2.1(j), inside the list of what the Compliance Officer as a minimum should do. The CO is also responsible to prepare an annual Compliance Officer's Report for the purpose of informing the Board of Directors of the firm regarding the level of compliance of the firm, records of any internal monitoring activity and any weaknesses identified, and any enhancements needed for the firm's compliance program. The report should be used to formulate an action plan where needed and both the report and the action plan should be readily available for inspection during the on-site monitoring visits or following a request by ICPAC.
Plainly: one report a year, written to inform the board about how compliant the firm is, what its internal monitoring recorded and what came out weak, and what the compliance programme needs by way of improvement. Where it needs one, it becomes a plan. Both then sit ready for the Institute. And read the verbs. Preparing the report is a responsibility. Using it to formulate an action plan is a should, and only where needed.
The filing is the paragraph above it. At 3.2.1(i) the CO must also prepare and submit to the Institute the Annual AML/CFT Questionnaire in accordance with ICPAC's Members Handbook and guidelines updated from time to time. Must, submit, to the Institute. Nothing in 3.2.1(j) sends the report anywhere. Its stated purpose is informing the Board of Directors of the firm, and ICPAC reaches it by inspection during the on-site monitoring visits or following a request. Two annual documents, two different verbs, and only one of them travels on its own. One flag on that paragraph: the Directive's table of amendments records, against 4 March 2024, a deletion of paragraph 3.2.1(i), yet the current text still prints an item (i), and that printed text is what is quoted here. The log does not say what went.
There is a second report in the Directive, and it is not this one. Paragraph 2.1.4 says that where appropriate and proportional to the size and nature of their activities, an independent internal audit service covering the AML/CFT system of the firm should be established for verification of the adequacy, effectiveness, appropriateness and proportionality of internal policies, controls and procedures, that the work of the internal audit service should take the form of a written report, and that the board or equivalent managing body should be able to demonstrate that it has given proper consideration to the report and then take appropriate action to remedy any AML/CFT deficiencies highlighted.
In plainer words: a firm big enough to need one should have an internal audit of its AML system, that audit writes its own report, and the board has to be able to show it considered that report and acted. Different document, different author, and a condition on the front of it.
Put the two side by side and the asymmetry is on the face of the text. For the internal audit report the Directive says the board should be able to demonstrate proper consideration and then act. For the compliance officer's report it says the report should be used to formulate an action plan where needed, and says nothing about demonstrating that the board considered it at all. The Directive does not explain the difference and this card is not going to resolve it. What it leaves is this: the action plan is the only downstream trace the paragraph names.
Who the report goes to is a defined term, and the definition is wider than a company boardroom. The Directive's Board of Directors is the board, committee and/or body of an entity with the power to set the strategy, objectives, and general direction of that entity and oversees and monitors management decision-making, including a person who effectively directs the business activities of that entity. Elsewhere the Directive knows that some firms have no board: 2.1.5 asks firms to designate a member of the Board of Directors or senior partners, provided there is a Board. What a firm without one does with the report, 3.2.1(j) does not say. The definition, which ends on a single person, is as close as the text comes.
Three things the paragraph does not ask for, because they get assumed. It does not ask for statistics on internal suspicious reports, or the reasons some were not passed to MOKAS: that documentation duty is real but it is written at 9.3.5, about the enquiries made into each report, and not as content of the annual report. Nothing in the paragraph keeps such figures out either; records of any internal monitoring activity is broad. It simply does not ask for them. It does not ask the report to quantify resources; its words are any enhancements needed. It does not ask for board minutes, and the Directive does not use the word anywhere.
Two things this card is not saying. The duty is located in ICPAC's Directive, which is binding and obligatory as to its adoption by the persons to whom it is addressed, and the section it sits in opens by saying that the role of the Compliance Officer is not defined in the Law. So nothing here says the statute requires an annual report. And if another supervisor licenses you, you are reading the wrong document. The Directive itself notes that other supervisory authorities prepare their own directives. This card has read only ICPAC's; whether yours asks for an annual report, from whom, to whom and by when is in your own supervisor's document.
So open last year's report and look for the plan. If there is one, check that the report names the weakness it answers. If there is not, the words are where needed, and the report is the only place a reader can be shown that nothing was.
An inspector who asks for the report asks for the action plan in the same breath. A report with nothing beside it is either a clean year or a year nobody acted on, and the paragraph does not tell them which. Only the report can.
Not legal advice. Verify against the primary source before acting.
FIRMCY screens names against all of the lists above — plus a worldwide PEP database and adverse media — with fuzzy matching and an audit-ready report for every check. New organisations get 100 free credits, no card required.
Start screening free Free PEP & sanctions check FATF high-risk countries Weekly AML briefing Live on Telegram ↗