Skip to content
complianceofficer

Blog · 9 Jul 2026 · 10 min read

Anti money laundering program: what it requires and how to run one

§ Live · Compliance scan

No signup. Nothing you pick is stored.

Frameworks you answer to

Sample register · fintech, US · what a scan returns

  • § 01 Written AML program with a named officer
  • § 02 KYC and customer due diligence
  • § 03 Sanctions screening lists Changed
  • § 04 PCI DSS v4.0 validation

An anti money laundering program is the written, board-approved system a financial business runs to detect, prevent and report financial crime. In the United States the obligation comes from the Bank Secrecy Act and FinCEN's implementing rules, and examiners test it against five specific pillars. This guide walks through each pillar, what regulators actually look for, and how teams keep the program current while the rules move.

Who must have one

Banks and credit unions, obviously, but the net is far wider: money services businesses and money transmitters (most fintechs holding or moving customer funds), broker-dealers, mutual funds, casinos, insurers for covered products, and, under FinCEN's expanding rulemaking, investment advisers. If your product touches the movement of money, assume the BSA reaches you and confirm with counsel rather than the reverse.

The five pillars, one by one

1. Internal policies, procedures and controls

The written program itself: how you identify customers, which products carry which risks, when transactions escalate, who decides. Examiners read for specificity; a program describing a generic bank fails for a crypto exchange. It must match the business you actually run and be approved, in writing, by the board.

2. A designated compliance officer

A named person with authority, resources and independence, the BSA officer. Regulators expect the role to have teeth: direct board access, headcount appropriate to volume, and no reporting line that subordinates compliance to sales.

3. Ongoing training

Documented, role-specific, repeated. Support staff who can be socially engineered into moving a payment need different training than the analysts reading alerts. Records of who was trained on what, and when, are exam evidence.

4. Independent testing

An audit of the program by someone who does not run it, internal audit or an external firm, on a cycle appropriate to risk. The finding list matters less than what happened to it: examiners track whether last cycle's findings were remediated.

5. Customer due diligence and beneficial ownership

The CDD rule: risk-rate customers, identify the humans behind legal-entity customers, and keep the picture current. Onboarding KYC is the visible half; the ongoing half, refreshing risk ratings when behavior changes, is where programs most often drift.

Anti money laundering monitoring in practice

Transaction monitoring turns the written program into daily operations: rules and models score transactions, analysts investigate alerts, and suspicious activity reports go to FinCEN within 30 days of detection. Sanctions screening runs in parallel against OFAC's lists, which change far more often than any framework. The operational trap is treating monitoring as a solved, installed system: thresholds tuned for last year's volume quietly stop fitting, and the backlog becomes the exam finding. Our AML transaction monitoring page covers how the monitoring duty and the rulebook watching fit together.

The part that changes under you

AML is the fastest-moving register most compliance teams hold. In the last two years alone: FinCEN and the banking agencies proposed a substantial rewrite of AML program rules toward effectiveness and risk-based design, beneficial ownership reporting was introduced and then repeatedly revised, and sanctions lists changed weekly. A program written to the 2023 rulebook and reviewed annually is stale by design. Whatever tooling you use, the requirement underneath is the same: someone, or something, reads FinCEN, OFAC and your examiner's manual continuously and re-opens the program documents when they move. That is the job Complianceofficer is being built to do; the compliance scan will show you the last 12 months of AML movement for your sector right now, with sources.

General regulatory information, not legal advice. Written by the team at ComplianceOfficer building Complianceofficer; verify anything consequential with qualified counsel.

§ 99 · Final entry

Get on the early-access list

Leave your work email, confirm the 6-digit code, and we will email you when your spot opens. Nothing is charged before launch.