A business can have a well-written AML policy and still fail a review of it. The review asks whether people did what the policy says, one client at a time.
That proof tends to live in pieces: the ID check in one inbox, the approval in a chat thread, the reason in a reviewer’s notes. Showing how one client was cleared then means searching all three places for one decision.
The rules behind these programs are also changing in the US and the EU. A US proposal would judge a program’s design and its use in practice as separate questions.
The 5 Parts of an AML Compliance Program
Lists of the five pillars of AML often show six, seven or eight parts, because each guide counts them differently. Behind every list is the same idea. Anti-money laundering compliance is the written program a business keeps, and follows, to spot and report money laundering and terrorist financing.
The USA PATRIOT Act of 2001 made that program a legal duty for each US financial institution. Under the Bank Secrecy Act, the program has four minimum parts. FinCEN’s 2016 customer due diligence rule added a fifth for banks, broker-dealers, mutual funds and commodity brokers.
FinCEN’s April 2026 proposal would count four, because it places ongoing customer checks under internal controls.
A Written AML Policy With Internal Controls
A rule that lives only in someone’s head cannot be tested, and two people will apply it two ways. So the AML policy has to be written down. FINRA requires broker-dealers to have it approved in writing by a member of senior management.
FinCEN’s program rules generally require a written program that FinCEN can ask to see. Its procedures must be reasonably designed to detect suspicious activity and get it reported.
A bank must file a suspicious activity report (SAR) within 30 calendar days of first detecting the facts. With no suspect identified, it may take 30 more days to find one. Cash over $10,000 in one business day, in one transaction or several by one person, needs a currency transaction report (CTR).
The policy should also rest on a business-wide risk assessment. FinCEN’s proposal would require one covering products, services, distribution channels, customers and geographic locations.
A Named AML Compliance Officer
Who answers when a regulator calls about the program? The law requires a designated compliance officer. US bank rules describe the job as coordinating and monitoring day-to-day compliance.
Under the April proposal, the officer would have to be based in the US and reachable by FinCEN and federal regulators. Staff abroad could still carry out some AML tasks.
From July 2027, the EU AML Regulation splits the role in two, though a small firm may give both jobs to one person. A member of the management body, the compliance manager, answers for compliance overall. A compliance officer runs the day-to-day work, deals with the authorities and reports suspicious transactions to the financial intelligence unit (FIU).
Ongoing Training for the People Who Need It
The law asks for an ongoing employee training program. What each person needs depends on the job.
Staff who collect passports and company registry extracts need to spot a document that is out of date or altered. Reviewers who clear possible sanctions matches need to know when a match is real. Managers who sign off higher-risk clients need to know what to ask before they approve.
The EU AML Regulation, which applies from July 2027, also asks for documented training suited to each role. Keep the date, the attendees and the topics of every session.
Independent Testing of the Program
The law also requires an independent audit function. A bank can use an outside party, or its own staff not involved in the reporting they test.
For broker-dealers, FINRA bars the AML compliance officer, anyone doing the work being tested and anyone reporting to either.
FINRA also sets the schedule: once every calendar year. A firm that does not execute customer transactions, hold customer accounts or introduce customer accounts can test every two years.
A tester can pull a sample of client files and ask who approved each one, when and on what evidence. Clustdoc logs every upload, approval, rejection and signature in a time-stamped audit trail.
Ongoing Checks on Every Customer
The fifth part builds on the identity check a firm makes when a client joins. Under a separate rule, a bank’s customer identification program must let it form a reasonable belief that it knows each customer’s true identity.
The firm also needs to know what each client will use the account or service for. The rules call this the nature and purpose of the relationship.
After that, ongoing monitoring has two jobs. It spots and reports suspicious transactions, and it keeps customer information current on a risk basis. For a company client, that information includes its beneficial owners.
At onboarding, the KYC process runs an ID check, sanctions and PEP screening, then a risk rating with a reason.
Records an Examiner or Auditor Will Ask to See
Partway through a test, the questions move from the policy to the client files. Each part of the program leaves a record that shows it was followed.
|
Part |
What the rule asks |
Records to have ready |
|---|---|---|
|
Policy and controls |
Written, approved, available on request |
Signed approval, current version, SAR and CTR copies |
|
Compliance officer |
A named person for day-to-day compliance |
Appointment record and contact details |
|
Training |
Ongoing and suited to each role |
Session dates, attendees and topics |
|
Independent testing |
Done by people outside the AML function |
Test report, findings and each fix |
|
Ongoing customer checks |
Purpose of each relationship and ongoing monitoring |
ID result, risk rating and reason, beneficial owners, screening result |
US rules generally require Bank Secrecy Act records to be kept for five years, including each SAR and its evidence.
Most of the last row is built at onboarding. Our KYC onboarding software verifies government-issued IDs and business registration documents, then runs the review steps in one process. You can customize its checklist, and automated reminders ask the client for anything still missing.
AML Regulations Now Changing in the US and EU
Neither change adds a new part to the program. The US proposal changes how the parts are grouped and judged, and the EU moves them into one regulation.
United States: FinCEN’s April 2026 Program Proposal
FinCEN proposed a new program rule on 7 April 2026, replacing an earlier proposal from 3 July 2024. It partly reflects the AML Act of 2020. That Act says a program should be risk-based, with more attention and resources on higher-risk customers and activities.
The new text regroups the program into four core pillars. FinCEN says moving ongoing customer checks under internal controls is not meant to change what they require.
The text also separates two questions: was the program designed properly (“establishment”), and is it carried out in practice (“maintenance”)?
Comments closed on 9 June 2026. No final rule had been published by 1 October 2026.
European Union: The AML Regulation From July 2027
From 10 July 2027, an EU firm’s core AML duties come from one regulation, Regulation (EU) 2024/1624. It applies directly in every member state. Until then, each member state’s own law under Directive (EU) 2015/849 sets these duties.
Internal policies, procedures and controls must be recorded in writing, with the policies approved by the management body. Testing comes from an independent audit function or, failing that, an outside expert.
The business-wide risk assessment must be documented, kept up to date and shown to supervisors on request. Supervisors can waive an individual written assessment where a sector’s risks are clear and understood. They cannot do so for banks, other financial institutions, or crowdfunding service providers and intermediaries.
For an EU firm, the table still applies, but SARs and CTRs are US forms. Suspicions go to the national FIU, and the business-wide assessment belongs in the first row.
Who Has to Meet AML Requirements
A non-bank mortgage lender needs an AML program in the US, and so does a casino. FinCEN’s program rules cover:
- Banks, savings associations and credit unions
- Broker-dealers, mutual funds, futures commission merchants and introducing brokers
- Money services businesses, such as money transmitters and check cashers
- Casinos and card clubs
- Insurance companies issuing non-group permanent life policies or annuities, or other products with cash value or investment features
- Dealers in precious metals, stones or jewels
- Non-bank residential mortgage lenders and originators, card system operators and housing government sponsored enterprises
FinCEN has delayed its program rule for registered investment advisers and exempt reporting advisers to 1 January 2028.
The EU list goes beyond finance. Auditors, external accountants, tax advisers and trust or company service providers must comply. So must banks and other financial institutions, including crypto-asset service providers.
Notaries and lawyers count when they take part in deals such as buying property or setting up a company. So do estate agents acting as intermediaries in property deals.
Confirm your own coverage with a compliance officer or lawyer. This is general information, not legal advice.
KYC and AML: How the Two Fit Together
KYC and AML compliance are often named together, but one sits inside the other. KYC, short for know your customer, covers the identity checks under internal controls and the customer checks in the fifth part. AML is the whole program around it, including reporting, training and testing.
Banks, job ads and software listings often write the pair as one term, KYC/AML, which blurs the line. A complete KYC file does not show that the rest of the program works.
With a business client, KYB verification extends the checks to the company itself and its beneficial owners.
Before your next independent test, book a demo call and we will pull up a sample client’s ID check, risk rating and approval in Clustdoc.
Frequently Asked Questions
What are the 5 pillars of AML compliance?
The five pillars are internal policies and controls, a compliance officer, ongoing employee training, independent testing and ongoing customer due diligence. The first four come from the Bank Secrecy Act.
FinCEN added the fifth for banks, broker-dealers, mutual funds and commodity brokers in its 2016 customer due diligence rule. Compliance was required from 11 May 2018.
Who is required to have an AML program?
In the US, AML requirements apply to banks, credit unions, broker-dealers, money services businesses and casinos. They also cover insurers issuing permanent life policies and annuities, and other businesses such as dealers in precious metals, stones or jewels.
In the EU, the list also includes accountants, tax advisers, estate agents, and lawyers and notaries in certain transactions.
What is AML in banking?
For a bank, AML means running the program the Bank Secrecy Act requires. The bank identifies each customer, monitors accounts, and reports suspicious activity and cash transactions of more than $10,000. It also names a compliance officer, trains staff and has the program tested independently.
What is AML compliance?
AML compliance means keeping, and following, a written program to spot and report money laundering and terrorist financing. In the US, the law says a program should be risk-based, with more attention on higher-risk customers and activities. Under FinCEN’s 2026 proposal, a program would have to be both well designed and carried out in practice.
What are AML guidelines?
AML guidelines are the rules and guidance a program is built on. In the US, that means FinCEN’s regulations in 31 CFR Chapter X and the FFIEC BSA/AML Examination Manual.
In the EU, the AML Regulation takes over from July 2027. It says EU rules should keep taking particular account of the FATF Recommendations. These are the international AML standards set by the Financial Action Task Force.


