What an anti-money-laundering program has to contain
Four pillars, then a fifth, and examiners who test whether the program is real.
Esshaki Legal Media TeamCurrent as of May 2022
Financial institutions must maintain a written anti-money-laundering program
reasonably designed to achieve compliance with the Bank Secrecy Act.
The pillars. A system of internal controls; independent testing; a
designated compliance officer with authority and resources; and ongoing training
for appropriate personnel. Rulemaking added a fifth: risk-based procedures for
ongoing customer due diligence, including understanding the nature and purpose
of relationships and monitoring for suspicious activity.
Risk assessment first. Everything else is judged against a documented
assessment of products, customers, geographies and delivery channels. A
program calibrated to a risk profile the institution does not actually have is
the most common finding.
Independent testing need not be by an outside firm, but must be by someone
outside the compliance function’s reporting line, with the scope and frequency
matched to risk.
Board oversight. Approval of the program, and reporting sufficient for the
board to exercise judgment rather than receive assurance.
Where enforcement concentrates. Alert backlogs, unresolved investigations,
suppressed alerts, model tuning done to reduce volume rather than to improve
detection, and failure to remediate prior findings. The last of these is treated
far more seriously than the original defect.