The Isle of Man's sixth-round MONEYVAL mutual evaluation goes on-site from 28 September to 9 October 2026. Two questions matter to an MLRO: whether your firm will be in the room, and what will be asked once you are. The assessment team chooses the firms itself and expects to meet around 30 of them in person. The Isle of Man Financial Services Authority said those firms would be notified "likely to be during July/August", while noting that some additional firms may be selected during the on-site period. What happens in those meetings is not an inspection. Assessors interview, in sessions that can run to an hour, against seven published focus areas and two core issues: how well you understand your risks, and how well you apply your obligations. Everything below comes from the Authority's MONEYVAL Preparation briefing pack and its AML Focus newsletter of May 2026.

Will your firm be selected?
Selection "rests solely with the MONEYVAL Assessment Team, and confirmation is typically provided shortly before the on-site visit". Those 30 or so firms represent "a cross-section of the most economically significant and risk-relevant parts of the Island's financial and non-financial services landscape", and the exercise "is expected to be broad and illustrative rather than focused on any individual firm".
Notification was expected in July or August, though some firms may still be picked once the on-site is under way.
What actually happens in the room
The briefing pack is unambiguous: "Assessors do not enter businesses or conduct inspections. Instead, they meet with private sector representatives through interviews and roundtables." Some are one-to-one, often one or two assessors plus a secretariat member; others are joint sessions. Each could run as long as an hour, and "the agenda is likely to be fiercely kept, especially earlier in the process".
The FATF Methodology the Authority quotes sets the depth: "Assessors are not expected to conduct an in-depth review of the operations of financial institutions, DNFBPs and VASPs, but should consider, on the basis of evidence and interviews with supervisors, FIUs and other competent authorities, as well as the private sector, whether financial institutions, DNFBPs and VASPs have adequately assessed and understood their exposure to money laundering and terrorist financing risks; whether their policies, procedures and internal controls adequately address and mitigate these risks; and whether regulatory requirements (including STR reporting) are properly implemented."
Copies of documents may be requested; anything provided stays confidential and never appears in the Evaluation Report.
The seven areas assessors focus on
The seven topics link into Recommendations 3, 5, 6, 10, 11 and 20, the gateway recommendations to the follow-up process. Core issue 3.3 / 4.3 asks: "How well do [firms] understand the level and the nature of their ML/TF risks? This includes demonstrating understanding of the evolution of ML/TF risks over time." Core issue 3.4 / 4.4 covers how obligations are applied. The Authority publishes the topics and the core issues; the pairing below, and the evidence column, are our reading rather than its own allocation.
| Focus area | Maps to | Evidence to have ready |
|---|---|---|
| Understanding of AML/CFT/PF Risk Exposure | Core issue 3.3 / 4.3 | Your risk view, its reasoning, and how it has changed |
| Governance and Oversight AML/CFT/PF Controls | 3.4 / 4.4 (d): internal controls, procedures and audit requirements including at group level | Board approval, named ownership, resources matched to your risk profile |
| Customer Due Diligence, including Enhanced and Simplified Measures | 3.4 / 4.4 (a): CDD and record-keeping, including beneficial ownership information and ongoing monitoring; (b): enhanced or specific measures for PEPs, correspondent banking, new technologies, payment and value transfer rules and virtual asset transfer rules, and high-risk countries identified by the FATF | Where simplified measures apply and why, plus an answer to "To what extent is business refused when CDD is incomplete and what are the outcomes from this?" |
| Use of New Technologies | 3.4 / 4.4 (b) | Your technology risk position, and why you decline what you decline |
| Record Retention | 3.4 / 4.4 (a) | What is held, where, and how fast it can be produced |
| Supervisory Interaction & Past Findings | Immediate Outcomes 3 and 4, tested as one effectiveness chain | Past findings, what you did, when each closed and what closed it |
| Suspicious Activity Reporting | 3.4 / 4.4 (c): reporting obligations and practical measures to prevent tipping off | Reporting in practice, from escalation to submission |
Limb (e) covers legal or regulatory requirements impeding implementation.
What "sixth round" means in practice
The sixth-round methodology is more targeted than the fifth, concentrating on higher risk, recent legislative reform, and areas where standards have evolved. The shift firms feel is evidential: it "places greater emphasis on structured, data driven evidence. This represents a shift away from broader narrative submissions towards more precise, measurable inputs."
Most noticeable for industry are amendments to Immediate Outcomes 3 and 4 "to test financial institutions and VASPs/DNFBPs (respectively) and supervisors as a single effectiveness chain", fuller integration of proliferation financing, increased interest in the application of simplified CDD, and FATF amendments to Recommendation 24 and its interpretive note. Ashley Whyte, Head of AML/CFT Supervision at the Authority: "The sixth-round evaluation raises the bar by requiring countries to demonstrate that risk understanding drives development of the AML/CFT/CFP framework, supervisory priorities, and operational activity."
The Island came through enhanced follow-up and the FATF International Cooperation Review Group process, after its December 2016 report, without being grey listed, and by November 2022, 39 of the 40 FATF Recommendations were compliant or largely compliant. Recommendation 23 was not, on independent audit functions and group-wide AML/CFT programmes for certain DNFBPs: "This point remains to be addressed."

The one preparation task that matters
The Authority does not hedge. "The most essential task an industry member can do to prepare is read and digest the suite of National Risk Assessments ('the NRA's'), consider how they impact their business utilising their existing Business Risk Assessment, Customer Risk Assessment and Technology Risk Assessment processes and associated procedures and controls." That work should be complete by 1 September 2026, with updates as soon as practicable. The 2026 National Risk Assessment holds the Island's money laundering risk at Medium High, and every firm must update its Business Risk Assessment to document it has been considered, then check whether the Customer Risk Assessment and the Technology Risk Assessment move with it.
Firms skip the assessments without their own sector's name on them. "Consideration of all the NRAs is important, as they may impact your sector regardless of the title." A bank with TCSP clients should read the TCSP and Legal Persons and Arrangements assessments; an estate agent that has chosen not to accept virtual assets should still read the VA/VASP assessment "to be able to explain why you aren't accepting VAs"; a TCSP or accountant servicing online gambling operators should read the Gambling assessment. Risk reaches you through your customers, not the cover page.
The Authority also asks: "If there are substantial changes to a business following this process it is important to be able to talk to them, describing why as a business you've changed. In some ways this is an important story to tell as it demonstrates the evolution of risk over time." Come "prepared with a number of real-life examples that demonstrate how the core issues are addressed" — a different exercise from rehearsing your procedures or the April 2026 AML/CFT Handbook.
In our experience, saying those examples out loud, against the seven areas, is worth an afternoon.
What happens after the on-site
Nothing comes back: "Following the MONEYVAL interview, you will not receive any feedback." What you say informs the team's understanding of the Island, and everything stays confidential while the report is drafted.
| Stage | When |
|---|---|
| Remaining sectoral and national risk assessments completed | March 2026 |
| Effectiveness questionnaire submitted to MONEYVAL | June 2026 |
| On-site programme finalised and selected firms notified | Summer 2026 |
| On-site mutual evaluation | 28 September to 9 October 2026 |
| First draft report (confidential) | December 2026 |
| MONEYVAL Plenary adopts the report | May 2027 |
| Report published, around six weeks after adoption | 2027 |
Comments go back in January and February 2027, a face-to-face meeting follows in March, and publication comes around six weeks after the May 2027 Plenary.

Common mistakes we see
The first is preparing for the wrong event: a file-review pack for an inspection that will not happen. The second is reading only the assessment with your own sector's name on it. The third is a current risk rating with no history behind it, when core issue 3.3 / 4.3 asks about the evolution of risk over time. The fourth is answering in narrative where the sixth round wants measurable inputs. The fifth is assuming you will not be selected.
Frequently asked questions
How will we know whether our firm has been selected?
Selection rests solely with the MONEYVAL Assessment Team, confirmed shortly before the visit. Firms were notified "likely to be during July/August", though some may still be selected during the on-site period.
Will assessors visit our offices and review our files?
No. They do not enter businesses or conduct inspections. Documents may be requested in the meeting; anything provided stays confidential and never appears in the Evaluation Report.
We do not accept virtual assets. Must we still read the VA/VASP risk assessment?
Yes. The Authority's own example is an estate agent that has chosen not to accept them and must still be able "to explain why you aren't accepting VAs".
Will we be told how the meeting went?
No. You will not receive any feedback, and confidentiality holds until the report is adopted at the May 2027 Plenary.
If you want your risk assessments and your examples stress-tested before the on-site, there is time.
An hour with an assessor rewards the firm that can describe what it actually did, and when, over the firm that can only describe what its policy says.
