Blog · 9 Jul 2026 · 10 min read
Anti money laundering program: what it requires and how to run one
§ Live · Compliance scan
No signup. Nothing you pick is stored.
Sample register · fintech, US · what a scan returns
- § 01 Written AML program with a named officer
- § 02 KYC and customer due diligence
- § 03 Sanctions screening lists Changed
- § 04 PCI DSS v4.0 validation
An anti money laundering program is the written, board-approved system a financial business runs to detect, prevent and report financial crime. In the United States the obligation comes from the Bank Secrecy Act and FinCEN's implementing rules, and examiners test it against five specific pillars. This guide walks through each pillar, what regulators actually look for, and how teams keep the program current while the rules move.
Who must have one
Banks and credit unions, obviously, but the net is far wider: money services businesses and money transmitters (most fintechs holding or moving customer funds), broker-dealers, mutual funds, casinos, insurers for covered products, and, under FinCEN's expanding rulemaking, investment advisers. If your product touches the movement of money, assume the BSA reaches you and confirm with counsel rather than the reverse.
The five pillars, one by one
1. Internal policies, procedures and controls
The written program itself: how you identify customers, which products carry which risks, when transactions escalate, who decides. Examiners read for specificity; a program describing a generic bank fails for a crypto exchange. It must match the business you actually run and be approved, in writing, by the board.
2. A designated compliance officer
A named person with authority, resources and independence, the BSA officer. Regulators expect the role to have teeth: direct board access, headcount appropriate to volume, and no reporting line that subordinates compliance to sales.
3. Ongoing training
Documented, role-specific, repeated. Support staff who can be socially engineered into moving a payment need different training than the analysts reading alerts. Records of who was trained on what, and when, are exam evidence.
4. Independent testing
An audit of the program by someone who does not run it, internal audit or an external firm, on a cycle appropriate to risk. The finding list matters less than what happened to it: examiners track whether last cycle's findings were remediated.
5. Customer due diligence and beneficial ownership
The CDD rule: risk-rate customers, identify the humans behind legal-entity customers, and keep the picture current. Onboarding KYC is the visible half; the ongoing half, refreshing risk ratings when behavior changes, is where programs most often drift.
Anti money laundering monitoring in practice
Transaction monitoring turns the written program into daily operations: rules and models score transactions, analysts investigate alerts, and suspicious activity reports go to FinCEN within 30 days of detection. Sanctions screening runs in parallel against OFAC's lists, which change far more often than any framework. The operational trap is treating monitoring as a solved, installed system: thresholds tuned for last year's volume quietly stop fitting, and the backlog becomes the exam finding. Our AML transaction monitoring page covers how the monitoring duty and the rulebook watching fit together.
The part that changes under you
AML is the fastest-moving register most compliance teams hold. In the last two years alone: FinCEN and the banking agencies proposed a substantial rewrite of AML program rules toward effectiveness and risk-based design, beneficial ownership reporting was introduced and then repeatedly revised, and sanctions lists changed weekly. A program written to the 2023 rulebook and reviewed annually is stale by design. Whatever tooling you use, the requirement underneath is the same: someone, or something, reads FinCEN, OFAC and your examiner's manual continuously and re-opens the program documents when they move. That is the job Complianceofficer is being built to do; the compliance scan will show you the last 12 months of AML movement for your sector right now, with sources.
General regulatory information, not legal advice. Written by the team at ComplianceOfficer building Complianceofficer; verify anything consequential with qualified counsel.