AML Threats for the Accounting Profession Part 1 of 2

AML Threats for the Accounting Profession Part 1 of 2

The Department of Justice recently published Ireland’s 2026 AML National Risk Assessment in advance of a FATF inspection expected in 2028. The last such assessment was carried out in 2019.

Noteworthy is the fact that the AML risk of the accountancy sector has changed from ‘Medium-High’ to ‘Significant’ as follows:

Risk Rating

Key to the chart:

ML = Money Laundering

TF = Terrorist Financing

PF = Proliferation financing

AML Threats for the Accounting Profession

The document explains that accountants are exposed to significant ML and TF risks due to the sector’s accessibility, diversity, and the breadth of services offered.

Criminals may exploit accountants not only to lend legitimacy to illicit transactions, but also to enhance the overall credibility and respectability of illegitimate business activities. The involvement of a qualified and professional accountant can create a veneer of legitimacy that helps obscure the true nature of criminal enterprises.

This can occur through services such as bookkeeping, payroll, tax advice, and the use of accountant’s certificates to support falsified documentation, making illicit operations appear compliant and trustworthy to third parties. The risk is elevated in cases involving cash-intensive businesses, where criminal proceeds can be more easily co-mingled with legitimate income.

When delivered effectively and in line with the ML regulations, accountants play a vital role in safeguarding against economic crime, however, weak or poorly implemented AML controls can be targeted by criminals. In rare but serious instances, there is also a risk of infiltration by criminal organisations, or corruption of staff within legitimate firms. Accountants that provide TCSP services face additional exposure, while those offering audit services play a key role in identifying and preventing economic crime.

There has been no evidence to suggest that Accountants are being exploited for PF purposes, and the sector’s exposure is therefore assessed as low. Nonetheless, continued vigilance is essential, particularly where services intersect with high-risk jurisdictions or involve complex corporate structures.

All the templates on our website have had a refresh as of June 2026 and the letters of engagement have had a new paragraph added for the potential use of artificial intelligence and machine learning on client assignments along with auto enrolment for payroll assignments. There is a bulk discount (five templates for the price of four) for purchases of five or more templates when purchased in a single transaction.

If you need an up-to-date engagement letter, there is a search bar near the bottom of our home page (www.jmcc.ie) to quickly look up the item you need. More details see here.

For those of you still in the process of ISQM 1 implementation, please see our ISQM TOOLKIT or if you prefer to chat through the different audit risks and potential appropriate responses presented by this new standard, please call or e-mail John McCarthy FCA or e-mail him at john@jmcc.ie.

We typically tailor our training and brainstorming sessions to suit each firm’s unique requirements.

Publications:

AML Threats for the Accounting Profession Part 2 of 2

AML Threats for the Accounting Profession Part 2 of 2

In our last blog we wrote about the fact that the Department of Justice has recently published Ireland’s 2026 AML National Risk Assessment in advance of a FATF inspection expected in 2028. The last such assessment was carried out in 2019.

This week we look at another extract from the document focusing on the accountancy sector.

Vulnerabilities

While accountancy services, when delivered in line with legal obligations, can serve as a strong defence against economic crime, weaknesses in execution, whether accidental, negligent, or complicit, can inadvertently facilitate criminal activity. Financial distress and intimidation may be factors in cases of complicity, and once a client relationship is established, practitioners may find it difficult to disengage, even when concerns arise.

This can be compounded by:

  • a reluctance to challenge long-standing clients or
  • by a lack of formal disengagement procedures within smaller firms.

 

Some individuals in Ireland operate outside the regulated sector, using the title ‘accountant’ or ‘financial advisor’ without formal qualifications or oversight. These unregulated providers may unknowingly facilitate illicit activity due to limited awareness of AML/CFT obligations and risk indicators. In addition, Accountants engaged in the misuse of accounting services for illicit purposes often avoid interaction with supervisory authorities and remain disconnected from the regulated sector, further increasing the risk of misuse.

In contrast, regulated Accountants knowingly involved in illicit activity may be well-versed in regulatory requirements and ensure Client Due Diligence (CDD) records and related documentation are maintained to a high standard to create a façade of compliance. While such records may be falsified, their presence can complicate detection efforts and obscure the true nature of the activity.

The report highlights the risk of compartmentalizing services where the fragmentation of services can pose a risk. Criminals may engage different Accountants for distinct functions, such as tax advisory, payroll processing, and bookkeeping, thereby limiting each provider’s visibility of the client’s overall financial activity. This compartmentalization can prevent any single firm from developing a comprehensive understanding of the client’s operations, making it more difficult to identify suspicious patterns or inconsistencies. Smaller Accountants may only be engaged for specific tasks and lack access to broader financial records, impairing their ability to assess risk effectively.

Consequences of these vulnerabilities

Accountants act as gatekeepers to the financial services sector. A substantive ML, TF or PF incident in the sector would have a significant impact on the financial sector and result in reputational damage to Ireland’s financial services sector. As such, the consequence has been rated as significant.

Control Weaknesses

While most Irish Accountants demonstrate good compliance with AML regulations and CDD processes, control weaknesses persist in the form of gaps in awareness, oversight, or inconsistent application of procedures. These lapses are often linked to limited resourcing, particularly in smaller firms, where AML/CFT responsibilities may not be adequately supported by dedicated personnel or systems.

Between 2020 and 2024, the total volume of STRs submitted by Accountants remained consistently low, with submissions ranging from 9 to 33 reports annually.

While this may be indicative of the sector’s strong AML/CFT expertise, it may also be an indication of lower levels of understanding of ML red flags, given the heightened threat in the sector. Supervisory inspections by Designated Accountancy Bodies have not raised concerns about under-reporting, suggesting current volumes may be proportionate to risk; however, the persistently low figures may indicate a potential weakness in detection or escalation processes and should be adequately considered during supervisory activities

All the templates on our website have had a refresh as of June 2026 and the letters of engagement have had a new paragraph added for the potential use of artificial intelligence and machine learning on client assignments along with auto enrolment for payroll assignments. There is a bulk discount (five templates for the price of four) for purchases of five or more templates when purchased in a single transaction.

If you need an up-to-date engagement letter, there is a search bar near the bottom of our home page (www.jmcc.ie) to quickly look up the item you need. More details see here.

For those of you still in the process of ISQM 1 implementation, please see our ISQM TOOLKIT or if you prefer to chat through the different audit risks and potential appropriate responses presented by this new standard, please call or e-mail John McCarthy FCA or e-mail him at john@jmcc.ie.

We typically tailor our training and brainstorming sessions to suit each firm’s unique requirements.

Publications:

100% Artificial Intelligence Law Firm

100% Artificial Intelligence Law Firm

The move away from using human beings in professional services has already started.

In May 2025 the UK Legal sector regulator, the Solicitors Regulatory Authority approved Garfield Law, as the first fully AI-driven law firm, to operate without human lawyers.

Garfield offers businesses and individuals cost-effective legal services, such as debt collection, at substantially lower rates—starting at just £2 for initial actions.

The firm was Co-founded by former litigator Philip Young and quantum physicist Daniel Long. Garfield initially concentrates on small claims debt collection and aims to recover billions in unpaid debts and streamline court processes using AI.

Pursuing claims in the UK under £10,000 is typically seen as too costly or time-consuming. The English small claims Court process is perceived as confusing and intimidating, especially for sole traders and smaller businesses.

See our ISQM TOOLKIT at this link. We can tailor ISQM training and brainstorming sessions to suit your firm’s unique requirements.  Please contact John McCarthy FCA by email at john@jmcc.ie.

For AML training and compliance please send a mail to john@jmcc.ie.

For audit cold file reviews and tailored training sessions explaining more about various topics like AML, Audit, FRS 102, please send a mail to john@jmcc.ie.

For more on engagement and representation letter templates and a variety of CPD webinars on money laundering and other accounting/audit related topics, please go to our website for:

ISQM TOOLKIT, or if you prefer to chat through the different audit risks and potential appropriate responses presented by this new standard. We typically tailor ISQM training and brainstorming sessions to suit your firm’s unique requirements.  Please contact John McCarthy FCA by email at john@jmcc.ie.

Artificial Intelligence In Audit

Artificial Intelligence In Audit

The Financial Reporting Council issued a Thematic Review Report in June 2025 which provides useful guidance on the use of artificial intelligence in audit procedures, including illustrative examples and documentation expectations for firms utilizing AI tools in their audits.

Use of AI in Audit Procedures

The Financial Reporting Council have come up with a new acronym call ‘ATTs’ or Automated Tools and Techniques to describe the use of AI tools in audit. Specifically, these would be ‘Technology used to perform risk assessment procedures and/or obtain audit evidence’. Some of this is not new as firms have already been using ATTs for data analytics used to audit journal entries and revenue.

The ultimate aim of the Report is to support the use of ATTs by audit firms to improve audit quality.

The Report refers to the need to ensure that ATTs are subject to a certification process that complies with the requirements of the ISQM (Ireland) 1 so that quality objectives are established to ensure such tools and techniques are appropriately obtained or developed, implemented, maintained and used to enable the performance of quality audit engagements.

The Financial Reporting Council reviewed the certification process in the Top 6 firms in the UK namely BDO, Deloitte, EY, Forvis Mazars, KPMG and PwC and the report is based on these findings. One unidentified firm had a KPI which reported against usage targets for certain key ATTs, to encourage their use by audit teams.

Responsible AI deployment according to the Report helps to improve trust in financial reporting by for example helping identify potentially fraudulent journals.

Use of AI in Audit Procedures

The report is accompanied by an illustrative example and documentation guidance which covers the testing of journals for suspected fraudulent entries in a listed retail business.

Fraud procedures often consist of filtering the population of journals by applying rules-based criteria which may indicate higher risk, for example, journals posted at certain times or with certain values. This tool allows the identification of more subtle patterns that may be indicators of risk, enhancing the quality of the procedure.

More information is available in Technical Alert 04 2025 Quality Management Top tips available on the Institute’s website. A template ISQM Toolkit (to assist with the ISQM implementation) is available to purchase for €250 +VAT.

  1. RI CPD – Each Responsible Individual’s (RI) CPD is reviewed in line with the IAASA CPD Guidelines on the regulation, monitoring and enforcement of continuing education for statutory auditors. More details are available at final-cpd-guidelines-020221.pdf (iaasa.ie).

RIs are required to:

  • Plan CPD annually by reflecting on the knowledge, skills and values required to fulfil their responsibilities;
  • Identify learning and development needs;
  • Complete sufficient, relevant, and appropriate CPD annually to meet the learning and development needs and to demonstrate achievement of learning outcomes in the Institute IES 8, Table A template document;
  • Evaluate the effectiveness of the CPD activities regularly and revise the approach as necessary;
  • Maintain appropriate written CPD records, including supporting documentation to evidence CPD planning, completion, and evaluation; and
  • Submit an annual declaration confirming compliance with CPD

More information is available at the CPD hub on the Institute’s website CPD for Responsible Individuals – ..rteredaccountants.ie (charteredaccountants.ie)

  1. Evidence of challenge and scepticism – Audit files must demonstrate that the

auditor has evaluated whether the accounting estimates and related disclosures are reasonable (see ISA540). Auditors should watch out for indicators of possible management bias.

  1. Central Bank Regulated Entities– Under the Companies Act 2014 (Schedule 5)

Republic of Ireland entities cannot avail of the small company exemption and cannot file abridged financial statements with the CRO.

Auditors are reminded that financial statements for such entities cannot be prepared under FRS 102 Section 1A, and full financial statements must be filed with CRO. Neither can such entities avail of the Provisions Available for Audits of Small Entities (PAASE).

  1. Risk assessment (ISA 315) – the risk assessment on file must be tailored to the specific client’s circumstances and generic risks that are prepopulated with not be regarded as convincing.
  1. Fraud considerations (ISA 240) – fraud considerations should be evidenced on the file, including the likelihood of management override of controls and risks connected to related parties. In our own file reviews John McCarthy Consulting Ltd. Has seen comments like ‘there has never been a fraud’, according to the Directors. Such comments are not regarded as displaying sufficient scepticism by the auditors.
  1. Audit of construction contracts, including long term contracts and work in Audit files need to show that the audit firm has a good understanding of the entity being audited, the risk assessment is appropriate and responses to assessed risks are adequate. The requirements of ISA 540 on accounting estimates and judgements will be relevant. The audit file will also need to contain adequate evidence of challenge of management assumptions.

8.      Assembly of the final audit file – ISA 230 requires the auditor to complete the administrative process of assembling the final audit file on a timely basis, typically within 60 days after the date the auditor’s report is signed. New audit procedures or forming new conclusions cannot be documented once the audit report is signed.

9.      Statutory Duty Confirmation (SDC) – under Section 27B of the Central Bank Act 1997, auditors are obliged to make a written report (‘SDC’) to the Central Bank of Ireland (CBI), stating whether or not circumstances have arisen that require the auditor to report a matter to the CBI.

The ‘SDC’ must be submitted to the CBI within one month of the date of the auditor’s report. The ‘SDC’ should cover the period commencing on the date of issue of the previous declaration to the date of signing the current declaration. The format for these reports is set out in Appendix 2 of Technical Release 02 2025 – Reporting under The Central Bank and Financial Services Authority of Ireland Act 2004 which is available on the Institute’s website.

  1. Group Audits (ISA 600) – Where group accounts are not prepared, firms are expected to clearly document the basis for the non-consolidation.

Group Audit documentation should clearly demonstrate how the component auditor’s work was directed, supervised, and reviewed. Firms are reminded that component performance materiality should be set at an amount lower than group performance materiality.

See our ISQM TOOLKIT at this link. We can tailor ISQM training and brainstorming sessions to suit your firm’s unique requirements.  Please contact John McCarthy FCA by email at john@jmcc.ie.

For AML training and compliance please send a mail to john@jmcc.ie.

For audit cold file reviews and tailored training sessions explaining more about various topics like AML, Audit, FRS 102, please send a mail to john@jmcc.ie.

For more on engagement and representation letter templates and a variety of CPD webinars on money laundering and other accounting/audit related topics, please go to our website for:

ISQM TOOLKIT, or if you prefer to chat through the different audit risks and potential appropriate responses presented by this new standard. We typically tailor ISQM training and brainstorming sessions to suit your firm’s unique requirements.  Please contact John McCarthy FCA by email at john@jmcc.ie.

Common Issues on Audit Monitoring Visits

Common Issues on Audit Monitoring Visits

The Quality Review Section (QRS) of the Institute recently published the most common issues that arise on its monitoring visits.

These issues are quite serious as similar issues have been re-occurring for many years,

1.      ISQM – Firms are required to have a documented ISQM system of quality management (SoQM) in place, including a risk assessment with quality risks identified in the firm’s risk assessment clearly linked to the achievement of a quality objective.

There must be a documented annual evaluation of the SoQM which concludes one of 3 outcomes with these grades:

  1. SoQM provides reasonable assurance that the objectives of the SoQM are being achieved;
  2. Except for matters that have a severe but not pervasive effect, the SoQM provides reasonable assurance that the objectives of the SoQM are being achieved; or
  3. The SoQM does not provide the firm with reasonable assurance that the objectives of the SoQM are being achieved.

Evidence that an annual evaluation has been performed, and the results of the annual evaluation will be assessed for consistency with the visit findings.

More information is available in Technical Alert 04 2025 Quality Management Top tips available on the Institute’s website. A template ISQM Toolkit (to assist with the ISQM implementation) is available to purchase for €250 +VAT.

  1. RI CPD – Each Responsible Individual’s (RI) CPD is reviewed in line with the IAASA CPD Guidelines on the regulation, monitoring and enforcement of continuing education for statutory auditors. More details are available at final-cpd-guidelines-020221.pdf (iaasa.ie).

RIs are required to:

  • Plan CPD annually by reflecting on the knowledge, skills and values required to fulfil their responsibilities;
  • Identify learning and development needs;
  • Complete sufficient, relevant, and appropriate CPD annually to meet the learning and development needs and to demonstrate achievement of learning outcomes in the Institute IES 8, Table A template document;
  • Evaluate the effectiveness of the CPD activities regularly and revise the approach as necessary;
  • Maintain appropriate written CPD records, including supporting documentation to evidence CPD planning, completion, and evaluation; and
  • Submit an annual declaration confirming compliance with CPD

More information is available at the CPD hub on the Institute’s website CPD for Responsible Individuals – ..rteredaccountants.ie (charteredaccountants.ie)

  1. Evidence of challenge and scepticism – Audit files must demonstrate that the

auditor has evaluated whether the accounting estimates and related disclosures are reasonable (see ISA540). Auditors should watch out for indicators of possible management bias.

  1. Central Bank Regulated Entities– Under the Companies Act 2014 (Schedule 5)

Republic of Ireland entities cannot avail of the small company exemption and cannot file abridged financial statements with the CRO.

Auditors are reminded that financial statements for such entities cannot be prepared under FRS 102 Section 1A, and full financial statements must be filed with CRO. Neither can such entities avail of the Provisions Available for Audits of Small Entities (PAASE).

  1. Risk assessment (ISA 315) – the risk assessment on file must be tailored to the specific client’s circumstances and generic risks that are prepopulated with not be regarded as convincing.
  1. Fraud considerations (ISA 240) – fraud considerations should be evidenced on the file, including the likelihood of management override of controls and risks connected to related parties. In our own file reviews John McCarthy Consulting Ltd. Has seen comments like ‘there has never been a fraud’, according to the Directors. Such comments are not regarded as displaying sufficient scepticism by the auditors.
  1. Audit of construction contracts, including long term contracts and work in Audit files need to show that the audit firm has a good understanding of the entity being audited, the risk assessment is appropriate and responses to assessed risks are adequate. The requirements of ISA 540 on accounting estimates and judgements will be relevant. The audit file will also need to contain adequate evidence of challenge of management assumptions.

8.      Assembly of the final audit file – ISA 230 requires the auditor to complete the administrative process of assembling the final audit file on a timely basis, typically within 60 days after the date the auditor’s report is signed. New audit procedures or forming new conclusions cannot be documented once the audit report is signed.

9.      Statutory Duty Confirmation (SDC) – under Section 27B of the Central Bank Act 1997, auditors are obliged to make a written report (‘SDC’) to the Central Bank of Ireland (CBI), stating whether or not circumstances have arisen that require the auditor to report a matter to the CBI.

The ‘SDC’ must be submitted to the CBI within one month of the date of the auditor’s report. The ‘SDC’ should cover the period commencing on the date of issue of the previous declaration to the date of signing the current declaration. The format for these reports is set out in Appendix 2 of Technical Release 02 2025 – Reporting under The Central Bank and Financial Services Authority of Ireland Act 2004 which is available on the Institute’s website.

  1. Group Audits (ISA 600) – Where group accounts are not prepared, firms are expected to clearly document the basis for the non-consolidation.

Group Audit documentation should clearly demonstrate how the component auditor’s work was directed, supervised, and reviewed. Firms are reminded that component performance materiality should be set at an amount lower than group performance materiality.

See our ISQM TOOLKIT at this link. We can tailor ISQM training and brainstorming sessions to suit your firm’s unique requirements.  Please contact John McCarthy FCA by email at john@jmcc.ie.

For AML training and compliance please send a mail to john@jmcc.ie.

For audit cold file reviews and tailored training sessions explaining more about various topics like AML, Audit, FRS 102, please send a mail to john@jmcc.ie.

For more on engagement and representation letter templates and a variety of CPD webinars on money laundering and other accounting/audit related topics, please go to our website for:

ISQM TOOLKIT, or if you prefer to chat through the different audit risks and potential appropriate responses presented by this new standard. We typically tailor ISQM training and brainstorming sessions to suit your firm’s unique requirements.  Please contact John McCarthy FCA by email at john@jmcc.ie.