SardineCon SF/2026

Learn More
AML programs4 min de lectura

¿Qué es Internal controls?

SUBSCRIBE

Internal controls are the policies, procedures, and system controls that turn AML duties into daily action, covering customer checks, monitoring, screening, thresholds, escalation, and reporting workflows. They are the connective tissue between what policy intends and what actually happens, and control gaps are exactly where risk turns real.

What are internal controls, in plain English?

Internal controls are the machinery that turns AML policy into daily action. They are the concrete policies, procedures, and system settings that make the program actually run: how customers get checked, how transactions get monitored, how names get screened, where thresholds sit, how escalation flows, and how reports get filed.

Think of them as the connective tissue between intent and reality. A policy can say the firm will monitor for structuring, but a control is the specific rule, owner, and workflow that makes that monitoring happen every day. Without the control, the policy is just a statement of good intentions.

That is why control gaps are exactly where risk turns real. A launderer does not walk through the policy; they walk through the place where a control was supposed to run and did not. Undocumented or untested controls fail both examinations and real-world detection, because if you cannot show a control operating, you should assume it is not.

What the controls cover

Control area

What it does in daily practice

Customer checks

The onboarding and due-diligence steps that decide who gets in and at what risk rating.

Monitoring

The rules and reviews that watch transactions for suspicious patterns over time.

Screening

The sanctions, PEP, and watchlist checks run against customers and payments.

Thresholds

The dollar and behavior limits that trigger reports or reviews.

Escalation and reporting

The workflows that move a concern to a decision and, where needed, to a filing.

What it looks like in practice

In practice

A firm's policy manual lists a control requiring dormant accounts that suddenly reactivate with high-value transfers to be reviewed. On paper it is a solid control. In reality no system generates the alert, no analyst is assigned to it, and there is no evidence it has ever run.

A reactivated account moves large sums for weeks and nobody looks, because the control existed only in the document. When the pattern finally surfaces through another route, the post-mortem is blunt: the control had no owner, no tuning, and no proof of operation, so a launderer walked straight through the gap the paper control was meant to close.

Why a control nobody owns is a gap

The failure mode with internal controls is almost never a control that is missing from the manual; it is a control that exists on paper but has no clear owner, no tuning, and no evidence it ever runs. A control nobody owns is a control nobody runs, and that is precisely the gap a launderer walks through.

This is why documentation and testing are not bureaucratic extras but the substance of the control. Undocumented or untested controls fail both examinations and real-world detection for the same reason: there is no proof they operate. The operating rule is simple and unforgiving. If you cannot show a control running, with an owner, a workflow, and evidence, assume it is not running and treat it as an open gap, not a green check.

What to watch for

  • Ownerless controls. A control with no named owner is a control nobody runs; it is a gap, not a safeguard.
  • No evidence of operation. If you cannot show a control actually ran, examiners and criminals both treat it as absent.
  • Untuned rules. Monitoring thresholds that were never adjusted after launch drift into noise or blindness.
  • Paper-only procedures. Steps documented in the manual with no corresponding system or workflow are aspiration, not control.
  • Broken escalation. A control that flags an issue but has no path to a decision leaves the risk sitting unactioned.

Quick questions

What exactly counts as an internal control?

The policies, procedures, and system settings that operationalize AML duties: customer checks, monitoring, screening, thresholds, escalation, and reporting workflows. They are the specific mechanisms that make policy happen day to day.

How are internal controls different from policy?

Policy states intent; controls make it real. A policy might say the firm monitors for structuring, but the control is the actual rule, owner, and workflow that runs that monitoring. Without the control, the policy does nothing.

Why do undocumented controls fail?

Because there is no proof they operate. Undocumented or untested controls fail both examinations and real-world detection, since neither an examiner nor a launderer is stopped by a control that cannot be shown to run.

What is the most common control gap?

A control that exists on paper but has no owner, no tuning, and no evidence it ever runs. A control nobody owns is a control nobody runs, and that is the gap risk exploits.

Are internal controls a BSA pillar?

Yes. A system of internal controls is one of the required pillars of a BSA/AML program, assessed on its own by examiners alongside the officer, training, testing, and due-diligence pillars.

How do you prove a control works?

Show it operating: a named owner, a documented workflow, tuning history, and records of it running and producing outputs. If you cannot produce that evidence, assume the control is not effective.

Go deeper

  • FFIEC BSA/AML Examination Manual ↗ — The manual US examiners use to assess BSA and AML programs.
  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

Qué saber junto con Internal controls