AML

AML Compliance: What Banks Must Build and Prove

Sahil Kataria, Founder and CEO of FluxForce Published: Last updated:

AML compliance is the set of controls a bank runs to detect and report money laundering: customer due diligence, transaction monitoring, sanctions screening, and SAR filing. Examiners now grade programs on outcomes, not policy documents. A weak program shows up as fines, consent orders, and lost banking charters.

Key takeaways

  • AML compliance rests on five pillars: risk assessment, internal controls, an independent test, a trained BSA officer, and customer due diligence (the "fifth pillar" added by the 2016 CDD Rule).
  • FinCEN issued over $1.3 billion in AML-related penalties in 2024 alone, spread across banks, money services businesses, and crypto exchanges.
  • Transaction monitoring systems typically generate 90-95% false positive alerts, according to a widely cited LexisNexis Risk Solutions study, which is the single biggest driver of AML operating cost.
  • The OCC's most common AML consent order finding is not "no controls," it's "controls exist on paper but aren't actually followed."
  • FinCEN's 2024 SAR statistics show over 4 million SARs filed annually in the US, up from roughly 2 million a decade ago.
  • FATF's 40 Recommendations remain the baseline every national AML regime maps to, including the US Bank Secrecy Act and the EU's AMLD6.
  • A program that passes an exam on paper and fails in practice is the most common finding in enforcement actions since 2022.

What AML Compliance Means in Practice

AML compliance is the operational work a financial institution does to stop its accounts from being used to move illicit money, and to report it when they are. It's not a policy binder. It's a working system: customer screening at onboarding, ongoing transaction monitoring, sanctions checks, and a pipeline that turns suspicious activity into a filed Suspicious Activity Report (SAR).

In the US, the legal foundation is the Bank Secrecy Act (BSA), amended by the USA PATRIOT Act and the 2016 Customer Due Diligence (CDD) Rule. Examiners (the Federal Reserve, OCC, FDIC, or state regulators depending on charter) test against FinCEN's regulations and the interagency BSA/AML Examination Manual.

Ownership sits with a designated BSA Officer, usually reporting into the Chief Compliance Officer or directly to the board. But AML compliance touches more than compliance staff. Frontline bankers do the initial customer due diligence. Operations teams clear the alert queue. Legal reviews SAR narratives before filing. A program with strong policy and a compliance team of one is not a program examiners will pass.

The scope covers five statutory pillars, plus a sixth many banks add voluntarily:

  1. A written risk assessment tied to actual customer and product risk
  2. Internal controls (policies, procedures, systems)
  3. Independent testing, usually annual, by internal audit or a third party
  4. A designated BSA compliance officer with real authority
  5. Ongoing training for relevant staff
  6. Customer due diligence, including beneficial ownership identification (added 2016)

Programs that treat this as a checklist rather than a working control environment are exactly what examiners are trained to find.

Why AML Compliance Matters Now

Enforcement has gotten more expensive and more personal. FinCEN's 2024 enforcement actions totaled well over $1.3 billion, and that figure sits alongside parallel OCC and Federal Reserve penalties against the same institutions for the same underlying failures (FinCEN enforcement actions). TD Bank's 2024 settlement, over $3 billion combined across FinCEN, OCC, and DOJ, is the largest AML penalty in US banking history and came with an asset cap, an unusual and severe structural remedy.

Individual accountability is now standard practice, not an outlier. Since 2021, the OCC and Federal Reserve have both issued personal fines and industry bars against compliance officers and executives, and now target the individuals responsible as well as the institutions employing them. That changes the risk calculus for a BSA officer signing an independent test attestation.

The volume problem is also getting worse before it gets better. FinCEN's own SAR statistics show more than 4 million SARs filed annually in the US, roughly double the volume from a decade ago (FinCEN SAR Stats). Investigator headcount hasn't doubled to match. That gap is why AML regulatory compliance has become as much a staffing and throughput problem as a policy problem.

FATF, the global standard-setter, updated its Recommendation 1 guidance on a risk-based approach in 2023, pushing member states toward outcome-based supervision rather than rules-checking (FATF Recommendations). US examiners have followed that shift: the question in an exam is increasingly "did this control actually catch anything," not "does this policy exist."

How AML Compliance Programs Work

The mechanics run in a loop, not a straight line. A customer opens an account, gets risk-rated, and every transaction after that gets scored against rules and models tuned to that risk profile.

Onboarding and CDD. Know Your Customer (KYC) checks identity, and the 2016 CDD Rule requires identifying beneficial owners holding 25%+ of a legal entity customer. This is where risk scoring starts: geography, industry, product type, and expected activity all feed an initial risk tier.

Ongoing transaction monitoring. Rules-based scenarios flag structuring, rapid movement of funds, high-risk-corridor wires, and activity that doesn't match the customer's stated profile. Scenario tuning is a constant task: too tight and you miss real activity, too loose and investigators drown.

Sanctions and watchlist screening. Every transaction and every counterparty gets checked against OFAC's SDN list and equivalent lists (UN, EU, UK OFSI) in real time or near-real time.

Case management and SAR filing. Alerts that survive initial triage become cases. Investigators build a narrative, and if the activity is suspicious, file a SAR within 30 days of initial detection (extendable to 60 with no suspect identified).

Program Stage What It Catches Typical Failure Point
CDD / onboarding High-risk customers, shell companies Stale risk ratings never refreshed
Transaction monitoring Structuring, layering, unusual patterns Untested scenario thresholds
Sanctions screening Prohibited parties, embargoed jurisdictions Fuzzy-match tuning too loose or too tight
Case investigation Confirmed suspicious activity Backlogs past the 30-day SAR clock

AML compliance software exists to run this loop at the volume modern payment rails demand: real-time rails like FedNow don't leave room for batch-overnight screening.

Where AML Compliance Programs Fail

Almost none of the enforcement actions of the last five years cite "no AML program." They cite a program that exists but doesn't work as documented.

Stale risk assessments. A risk assessment written in 2021 and never updated for a 2024 product launch (say, embedded finance or a new correspondent banking relationship) is functionally worthless. The OCC has flagged this specifically in multiple 2023-2024 consent orders.

Alert backlogs. When the investigation queue backs up past the 30-day SAR filing clock, that's a finding regardless of whether the underlying detection worked. TD Bank's consent order cited alert backlogs stretching into months.

Scenario tuning nobody revisits. Rules get built at go-live and never retuned as customer behavior shifts. A LexisNexis Risk Solutions survey found the median bank reviews monitoring thresholds less than once a year, even as fraud typologies change monthly.

Independent testing that isn't independent. Internal audit reviewing a program it helped design, using checklists the compliance team wrote, isn't the independent test the BSA/AML Examination Manual expects.

Training that's a video, not a skill. Annual click-through training satisfies the letter of pillar five. It doesn't produce a teller who recognizes structuring in real time.

Third-party and correspondent banking blind spots. Money service businesses, fintech partners operating through a bank's charter, and correspondent relationships are consistently where the weakest controls sit, because the risk is one step removed from the bank's own customer base.

What Good AML Compliance Looks Like

A program examiners pass has three things a weak one doesn't: evidence, thresholds, and a paper trail that matches what actually happened.

Risk-based resourcing. Investigator headcount and technology spend track the institution's actual risk profile, not last year's budget. A correspondent bank clearing cross-border wires for high-risk jurisdictions needs a different staffing ratio than a single-state community bank.

Defined, tracked metrics. Alert-to-SAR conversion rate, average case age, time-to-SAR-filing, and false-positive rate are tracked monthly and reported to the board rather than staying confined to the compliance committee. A program that can't produce these numbers on request is a program that hasn't been measuring itself.

Documented threshold rationale. Every monitoring scenario threshold has a written reason it's set where it is, tied to actual alert-to-SAR yield data, and a review date. "We set it there in 2019" is not a rationale an examiner accepts in 2026.

A real independent test. Third-party or genuinely walled-off internal audit, testing against a sample of actual alerts and actual SAR narratives, not a policy-document review.

Evidence retained for every decision, including closed alerts. Regulators increasingly want to see why an alert was closed as a false positive, a question separate from why a SAR was filed. An AML risk assessment template built around FFIEC's risk categories is a reasonable starting structure, but the working document has to be a living one, not something pulled off a shelf once a year.

Programs at this level also tend to have already read through AML risk assessment: a step-by-step guide and treat the BSA/AML compliance checklist as a floor, not a finish line. Identity verification at onboarding matters just as much as monitoring after the fact; see KYC and identity verification automation for how the two connect.

How AI and Automation Change AML Compliance

Automation already does the boring, high-volume work: scoring transactions, matching names against sanctions lists, and pulling KYC documents into a case file. What it should not do is decide, on its own, that a customer is a money launderer and file the report. That decision needs a human name attached to it, because a suspicious activity report is a legal document, not a data export.

Here's what's actually safe to automate today:

  • Alert triage and prioritization. Machine learning models can rank thousands of daily alerts by risk, so investigators start with the ten that matter instead of working through a queue in ticket order.
  • Evidence assembly. Pulling transaction history, KYC records, adverse media hits, and prior SAR filings into one case file used to take an analyst 30-45 minutes. An agent can do it in under a minute, and it can pull the same fields every time.
  • Sanctions and PEP screening. Automated fuzzy-matching against OFAC, EU, and UN lists is faster and more consistent than manual checks, provided someone tunes the match thresholds so it doesn't drown investigators in false positives.
  • Regulatory report drafting. An agent can produce a first-draft SAR narrative from the case evidence, formatted to FinCEN's expectations, in minutes instead of the 1-2 hours a manual draft takes.

Here's what still needs a human signature:

  • The SAR filing decision itself. FinCEN's SAR guidance requires a financial institution to determine that activity is suspicious, not a vendor's model. Someone with investigative authority reviews the evidence and signs off before the filing goes out.
  • Escalation to law enforcement referrals. Any case that might involve an active criminal investigation gets a compliance officer's judgment call, not an automated threshold.
  • Novel typologies. Models are trained on patterns they've seen. When a new laundering technique shows up (and they do, regularly, as FATF's typology reports document), a human analyst is the one who first recognizes it doesn't fit the existing rules.
  • Regulatory relationship management. Explaining your program's design to an examiner is a conversation, not an API call.

The honest framing: automation compresses the investigation timeline and removes repetitive work, but it does not remove liability. Bank Secrecy Act enforcement actions name compliance officers and boards, not software vendors. A good implementation makes that liability easier to defend, not because the human involvement disappears, but because every automated action leaves a clean evidence trail. If you want the deeper mechanics of how explainability works in a transaction monitoring model, our piece on XAI in AML compliance covers why "the model said so" isn't good enough for a regulator, and what a defensible explanation actually looks like.

One more thing worth saying plainly: automation adds a new failure mode. A model that's 95% accurate is still wrong 1 in 20 times, and if nobody reviews the misses, you've traded a slow process for a fast one that quietly ships errors. The fix isn't avoiding automation. It's building the review step into the workflow instead of treating it as optional.

How to Evaluate a Solution

Most AML software vendors demo well and disappoint six months in. The gap is usually in three places: how the system handles your specific data quality, how well it explains its own decisions, and how much manual cleanup your team does after go-live.

Ask these questions before you sign anything:

  1. Can it show its work? If an investigator can't explain why an alert fired, in language a regulator understands, that alert is a liability, not a tool. Ask for a live walkthrough of an actual explanation output, not a marketing slide.
  2. What's the false positive rate on your data, not theirs? Vendors quote benchmark numbers from clean reference datasets. Ask for a pilot against your actual transaction history before committing.
  3. Does it integrate with your existing core banking and case management systems? A tool that requires you to rebuild your data pipeline is a multi-year project disguised as a purchase.
  4. Who owns the audit trail? If the vendor's cloud logs are the only record of a decision, and your contract ends, do you keep access to that history? Regulators expect you to produce records going back years.
  5. How does it handle model drift? Laundering patterns change. Ask how often the model retrains, who reviews the retrained version before deployment, and how they detect performance decay between reviews.
  6. What happens when it's wrong? Every vendor's model misses things. Ask for their false negative rate methodology and how they've handled a missed typology after the fact.
Evaluation Area Weak Answer Strong Answer
Explainability "Our model is proprietary" Shows the specific transaction features that triggered each alert
False positive rate A single benchmark number Offered a pilot on your live data before purchase
Integration "We'll build custom connectors" (undefined timeline) Named integrations with your existing core systems, live references
Audit trail ownership Data lives only in vendor's system You retain exportable, independently verifiable records
Model updates Black-box retraining on their schedule Documented retraining cadence with human review before deployment
Regulatory reporting Manual export, you format the SAR Drafts formatted to FinCEN's current narrative structure, human-reviewed before filing

If a vendor can't answer question 1 with a concrete example, that's disqualifying. Compliance programs get examined, and "the vendor's algorithm decided" is not an answer that survives an exam. For a closer look at how automated regulatory reporting should actually work in practice, from draft to filing, see our breakdown of agentic AI for regulatory reporting.

Regulatory and Standards References

AML compliance in the US sits on a specific legal foundation, and it's worth knowing the actual sources rather than a paraphrase of them:

  • The Bank Secrecy Act (BSA), 31 U.S.C. 5311 et seq., is the original statute requiring financial institutions to assist government agencies in detecting money laundering. FinCEN's BSA resource page has the current text and amendments.
  • The USA PATRIOT Act, particularly Section 314, expanded BSA requirements and created the information-sharing framework between institutions and law enforcement. FinCEN's Section 314 guidance covers the current implementation.
  • FinCEN's SAR filing requirements, 31 CFR 1020.320 for banks, set the specific thresholds and timelines: a SAR is due within 30 days of detecting suspicious activity involving $5,000 or more (or $25,000 if no suspect is identified). FinCEN's SAR guidance has the complete filing instructions.
  • FATF Recommendations, the 40 standards the Financial Action Task Force sets for global AML/CFT frameworks, shape how most countries structure their national requirements. The current FATF Recommendations are the reference most regulators cite when assessing program adequacy.
  • The FFIEC BSA/AML Examination Manual is what US bank examiners actually use to assess your program. It's public, and reading it before an exam tells you exactly what the examiner will check. Available through the FFIEC's official manual page.
  • OFAC sanctions regulations, 31 CFR Chapter V, govern sanctions screening obligations separate from AML monitoring, though most programs run them together operationally. OFAC's sanctions programs list stays current with active designations.

If you operate outside the US, check your local regulator's equivalent framework. The EU's AMLD6 (Sixth Anti-Money Laundering Directive), the UK's Proceeds of Crime Act, and Singapore's MAS Notice 626 all set materially different thresholds and reporting windows. A program built only around US requirements will miss obligations elsewhere.

Next Steps

This guide covered what AML compliance means in practice and where automation actually helps. Two follow-up reads go deeper on the mechanics: how explainability works in AI transaction monitoring if you're evaluating a monitoring vendor, and how agentic AI handles regulatory reporting if SAR drafting time is your bottleneck.

If you're building a business case for your board, start with your current false positive rate and average investigation time. Those two numbers make the cost of doing nothing concrete.

See how FluxForce automates aml compliance

FluxForce AI agents run the checks described in this guide in real time, keep every decision explainable, and hand your examiners audit-ready evidence.

← All guides