Financial institutions must maintain a written anti-money-laundering programme reasonably designed to achieve compliance with the Bank Secrecy Act.
The pillars. A system of internal controls; independent testing; a designated compliance officer with authority and resources; and ongoing training for appropriate personnel. Rulemaking added a fifth: risk-based procedures for ongoing customer due diligence, including understanding the nature and purpose of relationships and monitoring for suspicious activity.
Risk assessment first. Everything else is judged against a documented assessment of products, customers, geographies and delivery channels. A programme calibrated to a risk profile the institution does not actually have is the most common finding.
Independent testing need not be by an outside firm, but must be by someone outside the compliance function’s reporting line, with the scope and frequency matched to risk.
Board oversight. Approval of the programme, and reporting sufficient for the board to exercise judgment rather than receive assurance.
Where enforcement concentrates. Alert backlogs, unresolved investigations, suppressed alerts, model tuning done to reduce volume rather than to improve detection, and failure to remediate prior findings. The last of these is treated far more seriously than the original defect.