Skip to content
complianceofficer

AML compliance software with KYC, sanctions screening and transaction monitoring

AML compliance software is what a US financial institution uses to run the anti-money laundering program the Bank Secrecy Act already requires of it: verifying who the customer is, screening names against sanctions lists, watching transactions for the patterns that matter, filing the reports on the statutory clock, and holding the policy, training and testing record an examiner will ask to see.

Complianceofficer covers the program layer and the part almost no financial crime tool covers: the rulebook itself. When FinCEN, OFAC or your functional regulator publishes something that touches your program, you get the change, the plain language reading and the specific policy it lands on, with the primary source attached.

Every regulatory citation on this page was checked against the eCFR and the Federal Register API on 11 August 2026. Where a rule is still proposed rather than final, this page says so.

Run the scan against your own BSA obligations

Choose your sector and size. The scan returns the obligation register that applies to an institution like yours, the regulatory movement of the last 12 months behind each line, and the source document for every claim. No signup, nothing stored.

§ Live · Compliance scan

No signup. Nothing you pick is stored.

Frameworks you answer to

Sample register · fintech, US · what a scan returns

  • § 01 Written AML program with a named officer
  • § 02 KYC and customer due diligence
  • § 03 Sanctions screening lists Changed
  • § 04 PCI DSS v4.0 validation
§ 51 Four products, one label

Four different products get sold as AML compliance software

This is where AML procurement goes wrong, and it goes wrong early. A BSA officer asking for AML software, a fintech founder asking for AML software and a bank's technology committee asking for AML software are frequently describing four different systems. They are bought from different vendors, priced on different units, and replacing one does nothing for the gap in another. Work out which of these you are missing before you take a single demo.

Product The question it answers Priced on Regulatory anchor
KYC and onboarding Is this customer who they claim to be, and how risky are they? Verifications performed CIP under 31 CFR 1020.220, CDD under 1020.210(a)(2)(v)
Sanctions and watchlist screening Is this name on a list we are forbidden to deal with? Names screened OFAC sanctions programs, 31 CFR chapter V
Transaction monitoring Does this activity look like something we must report? Transaction volume SAR duty under 31 CFR 1020.320
AML program management Can we evidence a compliant program to an examiner? Seats or institution size The five minimum contents of 31 CFR 1020.210(a)(2)

Complianceofficer sits in the fourth row and adds a fifth job to it: watching the rules that govern the other three. Our AML transaction monitoring page covers the detection layer specifically, and the anti money laundering program guide walks the program itself end to end.

§ 52 What the rule says

The five things the regulation actually requires, in its own order

Search for AML program requirements and you will find the same list of five pillars on every page, usually ordered internal controls, compliance officer, training, independent testing, customer due diligence. That ordering is industry convention. It is not what 31 CFR 1020.210(a)(2) says, and the word pillar appears nowhere in the regulation. Here is the actual list, in the actual sequence, with what a software layer can and cannot do for each.

Cite What the regulation requires What software can carry
(a)(2)(i) A system of internal controls to assure ongoing compliance Policy library, control mapping, attestations, exception tracking
(a)(2)(ii) Independent testing, by bank personnel or an outside party Test plans, sampling records, findings and remediation trail. The independence itself is organizational, not technical
(a)(2)(iii) Designation of an individual or individuals responsible for coordinating and monitoring day to day compliance Nothing. This names a person. Software supports the officer, it cannot be the officer
(a)(2)(iv) Training for appropriate personnel Assignment by role, completion records, refresh on rule change
(a)(2)(v) Risk based procedures for ongoing customer due diligence, including customer risk profiles and beneficial ownership of legal entity customers Risk scoring, refresh cadence, beneficial ownership capture under 31 CFR 1010.230

Two things most summaries drop entirely. First, paragraph (a)(1) separately requires compliance with 31 CFR 1010.610 and 1010.620, the correspondent and private banking due diligence rules, so the program obligation does not stop at the five contents. Second, a bank without a federal functional regulator, which includes private banks, non federally insured credit unions and certain trust companies, falls under paragraph (b) instead, where the program must be written, approved by the board or an equivalent governing body, and made available to FinCEN on request. That board approval requirement is not in paragraph (a).

§ 53 Filing clocks

The reporting deadlines, and the two that are widely published wrong

Any tool you buy has to enforce these dates, because a late filing is a finding regardless of how good the underlying detection was. Two of the numbers below are stated incorrectly on a large share of the pages that come up for these queries, so they are worth checking against the regulation itself rather than a summary.

Report Trigger Deadline Cite
SAR Suspicious transaction involving or aggregating at least $5,000 30 calendar days from initial detection, extendable to 60 only where no suspect has been identified 31 CFR 1020.320
CTR Transaction in currency of more than $10,000 15 days following the day the transaction occurred 31 CFR 1010.311 and 1010.306(a)(1)
SAR records Copy of the SAR plus supporting documentation Retain five years from the date of filing 31 CFR 1020.320(d)
CTR records Copy of each report filed Retain five years from the date of the report 31 CFR 1010.306(a)(2)

§ 53.1 · Correction

The SAR clock starts at detection, not at the transaction

1020.320(b)(3) reads "no later than 30 calendar days after the date of initial detection by the bank of facts that may constitute a basis for filing a SAR." An activity from four months ago that your analyst surfaced on Monday is due 30 days from Monday. Tools that anchor the due date to the transaction date will show you a breach that is not real, or worse, hide one that is.

§ 53.2 · Correction

A CTR needs more than $10,000, not $10,000 or more

1010.311 requires a report of a transaction in currency "of more than $10,000." A deposit of exactly $10,000.00 does not meet it. The distinction is small until you are defending a threshold configuration in an exam, or explaining why a structuring pattern parked at the round number was never reported as a CTR but should have raised a SAR.

§ 54 Who is covered

Does my company need AML compliance software?

If your institution is a defined financial institution under the Bank Secrecy Act, the program obligation is statutory and the only open question is how you tool it. Banks, credit unions, money services businesses, broker dealers, casinos, mortgage lenders and originators, and dealers in precious metals, stones or jewels all carry it today. The interesting cases are the ones that moved.

Investment advisers: the date moved to 2028

FinCEN's IA AML rule, published 4 September 2024 at 89 FR 72156, brought registered investment advisers and exempt reporting advisers into scope from 1 January 2026. That is no longer the date. A final rule published 2 January 2026 delayed the effective date by two years, to 1 January 2028. A large number of adviser facing pages still publish the 2026 date and are quietly out of date.

Fintechs and sponsor bank programs

A fintech operating through a sponsor bank usually has no direct BSA program duty of its own, but inherits an operational one through the bank partnership agreement, and the bank's examiners will look straight through to your controls. In practice that means you build to the same standard without the statutory hook, which makes the evidence trail more important rather than less.

The program rule that is still proposed

FinCEN's AML/CFT program rule, which would add an explicit risk assessment process and a duty to consider government priorities, was published as a proposal on 10 April 2026 and comments closed 9 June 2026. Checked against the Federal Register API on 11 August 2026, no final rule has issued. 31 CFR 1020.210 as written above remains the operative text. Treat anything describing the proposal as current law with suspicion.

§ 55 How to evaluate

What to ask an AML software vendor before you sign

Financial crime demos are unusually good at showing you alerts and unusually quiet about the parts that decide whether the deal works. These are the questions that separate the tools, drawn from where AML programs actually get written up.

Can you tune a rule without the vendor?

Risk based means your thresholds have to move as your customer base moves. If every change is a support ticket with a two week turnaround, your program is not risk based in any way you can defend, and your false positive rate is somebody else's roadmap.

What does an alert look like six months later?

Examiners read closed alerts, not open ones. Ask to see a disposition record from half a year ago: the rule version that fired, the data it saw, who cleared it and the reason given. If the rule has since changed and the record does not show which version applied, you cannot reconstruct the decision.

Who updates the sanctions lists, and how fast?

OFAC designations take effect on publication, not on your next refresh cycle. Get the refresh interval in writing, and ask what happens to customers already onboarded when a new designation lands. Retroactive rescreening is the control most programs discover they were missing during an exam.

What happens when the regulation changes?

Almost every financial crime platform monitors your customers. Very few monitor FinCEN, OFAC and your functional regulator and tell you which of your policies a published change lands on. That gap is the reason programs drift between exams, and it is the specific job this product exists to do.

Does it hold the training and testing record?

Two of the five minimum contents are training and independent testing, and both are documentation obligations. A detection engine with no home for those records leaves you running the program in a spreadsheet next to it, which is where version control goes to die.

Can you export everything?

Five year retention under 1020.320(d) and 1010.306(a)(2) outlives most vendor relationships. Confirm you can extract filings, supporting documentation and alert history in a readable format, and confirm it before you need it rather than during a migration.

§ 56 Cost

How much does AML compliance software cost?

Almost nobody in financial crime publishes a rate card, and the reason is structural rather than evasive: AML pricing tracks customers and transaction volume, so two institutions with identical headcount can be an order of magnitude apart. Anyone quoting you a single figure for the category is guessing.

For orientation, recorded buyer data on adjacent compliance platforms puts median annual contracts at roughly $20,000 for Vanta across 169 purchases and about $24,601 for Drata across 127, with enterprise GRC suites near a $45,900 median. Dedicated financial crime suites from the large incumbents commonly sit above that band once transaction volume is in the pricing. Our full breakdown, with sample sizes and ranges rather than a single number, is on the compliance software pricing page, and Complianceofficer's own planned tiers are published on the pricing page rather than quoted.

The number that usually decides the business case is not license cost. It is analyst time against false positives, and the cost of a program written up at exam. Institutions running mature transaction monitoring routinely clear the large majority of alerts as false, and each one carries a documented disposition. That is the line worth modelling before you compare quotes, and it is the same arithmetic behind the loaded cost of a compliance officer.

§ 57 Questions

Frequently asked questions

What is the difference between AML and KYC software?

KYC software answers who the customer is: identity verification, beneficial ownership, sanctions and PEP screening, and the risk rating that comes out of it. AML software is the wider program that consumes that answer, watches behavior over time and reports what looks wrong. Under 31 CFR 1020.210 ongoing customer due diligence is one of five minimum program contents, so KYC is an input to AML rather than a synonym for it.

How does AML software work?

It ingests customer and transaction data, applies rules and models to flag activity that matches known typologies, routes the flag to an analyst as a case, and records the disposition. Where the case supports a filing, it assembles the SAR narrative and tracks the 30 day clock. Around that loop sits the program record: policies, training completion, testing results and the risk assessment.

What are the five pillars of an AML program?

The regulation never uses the word pillar. 31 CFR 1020.210(a)(2) lists internal controls, independent testing, designation of a responsible individual, training, and risk based ongoing customer due diligence. The fifth was added by the 2016 customer due diligence rule, which is why older material describes four. Note that independent testing is second in the regulation, not fourth.

Can AI do AML compliance?

It can do most of the work and none of the accountability. 31 CFR 1020.210(a)(2)(iii) requires designation of an individual responsible for coordinating and monitoring day to day compliance, and enforcement runs against that person and the institution. Use AI for the reading, matching and drafting volume, and keep a named officer approving. We cover the boundary in detail on whether AI can replace a compliance officer.

When must a SAR be filed?

No later than 30 calendar days after the date of initial detection of facts that may form a basis for filing. Where no suspect has been identified by that date, filing may be delayed a further 30 days, capped at 60 calendar days from initial detection. Violations needing immediate attention, such as an ongoing laundering scheme, additionally require an immediate telephone notification to law enforcement.

Is AML software required by law?

No. The program is required; the software is not. 31 CFR 1020.210 specifies contents and outcomes, not tooling, and a very small institution can in principle run a compliant program manually. What software changes is whether you can evidence it at volume and reconstruct decisions years later, which is the part manual programs reliably fail at exam.

§ 58 Next

Where this fits with the rest of your program

AML rarely sits alone. Most institutions carrying a BSA program also carry consumer compliance, information security and vendor obligations on the same calendar, which is why the register matters more than any single module. If you are building the wider picture, the bank compliance software page covers the institution level view, and regulatory change management covers the discipline of catching a rule change before your next exam does. For the detection layer specifically, see AML transaction monitoring.

§ 99 · Final entry

Get on the early-access list

Leave your work email, confirm the 6-digit code, and we will email you when your spot opens. Nothing is charged before launch.