Paragraph 30 of the Anti-Money Laundering and Countering the Financing of Terrorism Code 2019 requires four things of every relevant person, and none of them is a file review. Your firm must have "robust and recorded arrangements" for managing the risks identified by its business risk assessment; the operational performance of those arrangements must be "suitably monitored"; "prompt action" must be taken to remedy any deficiencies; and a report must go to senior management at least annually, covering four specified subjects. Para 30(3) puts a suitable person at management level in charge of those functions, and para 30(4) sets three conditions the firm must give them: seniority or sufficient experience and authority, direct access to the officers of the firm, and sufficient time and resources. Most firms do the arrangements properly and thin out everything after them.
What paragraph 30 actually requires
Part 8 of the Code, headed "Compliance and Record Keeping", has been in operation since 1 June 2019. Para 30(1) reads:
A relevant person must establish, record, maintain and operate appropriate procedures and controls for monitoring and testing compliance with the AML/CFT legislation, so as to ensure that — (a) the relevant person has robust and recorded arrangements for managing the risks identified by the business risk assessment carried out in accordance with paragraph 5; (b) the operational performance of those arrangements is suitably monitored; and (c) prompt action is taken to remedy any deficiencies in arrangements.
Limb (a) asks not whether you have arrangements but whether they manage the risks your own BRA identified, which random file sampling will not tell you. The April 2026 AML/CFT Handbook makes the same link at §6.1, describing para 30 as testing that "processes and procedures (and the operation of these processes and procedures) comply with the AML/CFT/CPF legislation" — design and operation both. On scale it asks only for testing "commensurate with the nature and scale of the relevant person", and requires the procedures to be "approved by the senior management of the relevant person". The report is at least annual; the Code sets no testing interval.

The annual report, and what it has to say
Para 30(2) requires a report to senior management, at least annually, describing four things.
| Code para 30(2) requirement | What it means | What a thin version looks like |
|---|---|---|
| (a) AML/CFT environment and legislative developments | Where the firm sits; what changed in law | Background copied forward; "no developments to report" |
| (b) Progress on internal developments in policies and controls | What you meant to change, what landed, what is open | The policy suite restated, with no before-and-after |
| (c) Compliance activities undertaken in the period | Reviews, systems changes, remediation, training delivered | Activities listed with no outcome attached |
| (d) Results of any testing under sub-paragraph (1) | What was tested, what it found, what followed | "Testing was completed satisfactorily", with no findings |
The Handbook sets the standard: beyond awareness of the risks, the report must let senior management "understand how effective the relevant person's AML/CFT/CPF framework is in mitigating these risks". Effectiveness cannot be shown if row (d) is empty. The Supplemental Information Document lists "examples of what could be included" — a prompt, not a template. Row (c) is where firms understate themselves: the AML/CFT staff training you delivered belongs there, along with what it changed.
If a director could not explain the framework's effectiveness from your last report, fix that.
Who the "suitable person" is
Para 30(3) requires "a suitable person at management level that is responsible for the functions specified in this paragraph". The Handbook at §6.1 expects "the Head of Compliance of the firm (Controlled function R13)" in regulated firms, and "the compliance officer (where appointed)" in registered ones. Its footnotes define both: regulated firms are licensed under the Financial Services Act 2008 or the Insurance Act 2008; registered firms under the Designated Businesses (Registration and Oversight) Act 2015. This is not the MLRO's job — para 23 is where the MLRO sits, dealing with disclosures, as our guide to what the MLRO is appointed to do explains.
Para 30(4) sets the effectiveness test: the suitable person must "be sufficiently senior in the organisation of the relevant person or have sufficient experience and authority", "have a right of direct access to the officers of the relevant person", and "have sufficient time and resources to properly discharge the responsibilities of the position". Those are conditions the firm creates, not attributes the appointee arrives with: access is granted and protected by the board, time allocated by a managing director taking other work away.

Independence is the point, and the Code is honest about it
The Handbook is candid at §6.1: "The Authority notes that smaller registered firms may not have a dedicated compliance or AML/CFT/CPF resource to be this suitable person, in such cases it is useful to be pragmatic while trying to ensure the monitoring/testing is independent from the person who designed the procedures or undertook the task, though it is recognised this may not always be possible."
Where a firm genuinely cannot separate the roles, the Authority accepts it; harder to defend is the firm that never tried.
One point deserves precision, because it is often over-claimed. The Code requires monitoring and testing, with a pragmatic expectation of independence where a firm can manage it; it does not impose a mandatory external independent AML audit on every Isle of Man firm. The independent-audit shortcoming below is a jurisdiction-level finding about the Island's framework under FATF Recommendation 23, not a duty on each relevant person.
Independence changes the quality of the answer: testing whether a control works differs from confirming a policy exists, the distinction that separates a document review from what an IT security audit actually examines. A procedure can be word-perfect and ignored at the counter all year. If you would like yours tested by someone who did not design it, we do that.
Why this is the area MONEYVAL is most likely to press
The Island's sixth-round MONEYVAL on-site runs from 28 September to 9 October 2026, and our overview of what the mutual evaluation involves covers the process. At the fourth and final enhanced follow-up report, adopted in November 2022, MONEYVAL found the Island had addressed most of the technical compliance deficiencies from its 2016 evaluation, with 39 of the 40 FATF Recommendations compliant or largely compliant. The Authority's private-sector briefing states the exception: "However, Recommendation 23 remained partially compliant due to shortcomings in requirements for independent audit functions and group wide AML/CFT programmes for certain DNFBPs. This point remains to be addressed."
One Recommendation outstanding, and it is the one about independent audit. The team's interview topics include "Governance and Oversight AML/CFT/PF Controls" and "Supervisory Interaction & Past Findings", and two published sample questions land on para 30: "What remedial actions and sanctions are taken by [firms] when AML/CFT obligations are breached?" and "Do [firms] have adequate resources to implement AML/CFT policies and controls relative to their size, complexity, business activities and risk profile?" The first is para 30(1)(c) in interview form; the second is para 30(4)(c).

Common mistakes we see
The most common is monitoring that is really file review: files checked for missing documents while nothing tests whether the controls around them operate. Then the report with no results, where 30(2)(a) to (c) run to pages and 30(2)(d) is one sentence, because testing was never scoped. Then the self-marked programme, where whoever wrote the procedures tests them though an independent option existed. And remediation without a trail, where deficiencies are fixed informally and nothing records it.
We scope the testing, run it independently, and draft the report so it survives outside scrutiny.
Frequently asked questions
Do we need an external independent AML audit?
Not as a matter of Code compliance. Para 30 requires monitoring and testing under a suitable person at management level, and the Handbook asks only that firms be pragmatic "while trying to ensure the monitoring/testing is independent from the person who designed the procedures". Recommendation 23 concerns the Island's framework, not every relevant person.
Can our MLRO carry out the monitoring and testing?
The Code separates them: the MLRO sits at para 23 and deals with disclosures, while the para 30 suitable person tests the framework — the Head of Compliance (Controlled function R13) in regulated firms, the compliance officer in registered ones. Combining them leaves the framework tested by the person running it.
We are too small to separate the roles. What should we do?
Say so in writing, then get as close as you can. The Handbook recognises that smaller registered firms may have no dedicated compliance resource. Record the constraint, the mitigations, who else reviewed the work and what is left unmitigated.
What counts as "testing" as opposed to "monitoring"?
Monitoring is the ongoing oversight of operational performance required by 30(1)(b): management information, exception reporting, oversight of how arrangements run. Testing is the discrete exercise whose results 30(2)(d) requires you to report — a scope, a sample, a pass or fail against the procedure as written, and findings that go somewhere.
A monitoring programme that has never produced a finding is not evidence that your controls work; it is evidence that nobody has tested them.
