SardineCon SF/2026

Learn More
AML programs4 分で読めます

AML compliance programとは?

SUBSCRIBE

An AML compliance program is the full set of controls a firm runs to catch and stop financial crime. It is the whole machine regulators judge you on, from risk assessment and customer checks to monitoring, screening, reporting, training, and independent testing, not any single piece.

What is an AML compliance program, in plain English?

An AML compliance program is the whole system a firm uses to detect and prevent money laundering and related financial crime. It is not one control but a connected set: the risk assessment that sizes the threat, the customer due diligence that checks who you deal with, the transaction monitoring that watches behavior, the screening against sanctions and watchlists, the suspicious activity reporting, the training, and the independent testing that checks it all works.

Think of it as the machine regulators grade you on. Examiners do not just want a binder of policies; they want evidence that each part operates and that the parts fit together. A program is judged as a whole, so a strong monitoring system paired with weak customer checks is still a weak program.

The central test examiners apply is whether it works day to day, not just on paper. Gaps between the written manual and real practice are one of the most common findings, and anything the program forgets to cover becomes a blind spot that later surfaces as a missed report or a costly lookback.

The pillars of the program

Pillar

What it does

Risk assessment

Sizes money laundering and terrorist financing risk across customers, products, regions, and channels.

Policies and controls

Written standards, plus customer due diligence and screening that put risk appetite into practice.

Transaction monitoring

Watches activity for patterns that do not fit expected behavior and generates alerts.

Reporting

Files suspicious activity reports and other regulatory reports on time and with quality.

Training and testing

Keeps staff sharp and uses independent testing to prove the program actually works.

Who is involved?

Who

Their role

The board and senior management

Own the program, set risk appetite, and are accountable for whether it works.

The compliance officer or MLRO

Runs the program day to day, owns reporting, and answers to regulators.

First-line staff

Onboarding, operations, and monitoring teams who execute the controls in practice.

Independent testing and examiners

Audit and regulators who test whether the program operates as written.

What it looks like in practice

In practice

A growing fintech launches a new crypto-linked product but does not update its risk assessment or monitoring rules to cover it. On paper the program looks complete, with policies, onboarding checks, and a monitoring system all in place.

An examiner asks how the new product is monitored and finds the answer is that it is not. The gap between the written program and the live business becomes a formal finding, followed by a lookback across months of unreviewed activity. Nothing in the binder was wrong; the program simply forgot to cover the new product, and that blind spot became the failure.

Why it matters to operators

The program is the thing you are ultimately accountable for. Regulators do not grade individual alerts; they grade whether the whole system detects and reports financial crime. Weaknesses anywhere, a stale risk assessment, thin training, unmonitored products, roll up into program failure, with fines, enforcement, and reputational damage attached.

The practical lesson is to keep the program's scope honest and current. Examiners test the gap between the manual and real practice, so the dangerous state is a program that reads well but has quietly fallen behind the business. Every new product, market, or channel needs to be pulled into the program deliberately, because anything it forgets to cover is exactly where the missed report or costly lookback shows up.

What to watch for

  • Manual versus practice gaps. Controls described in the policy that do not match how the work is actually done.
  • Uncovered products. New products, markets, or channels launched before the program is updated to cover them.
  • Weak links. A strong control undermined by a weak one, such as good monitoring paired with thin customer checks.
  • No independent proof. Little or no independent testing to show the program works, not just that it exists.
  • Stale scope. A program that has not kept pace with business growth, leaving quiet blind spots.

Quick questions

What are the main pillars of an AML program?

Commonly a risk assessment, internal policies and controls, a designated compliance officer, ongoing training, and independent testing, with customer due diligence, transaction monitoring, screening, and reporting running through them. Regimes describe the pillars slightly differently but the substance is similar.

How is the program different from the AML policy?

The policy is the top-level document stating duties and standards; the program is the whole operating system that carries them out. The policy is one part of the program, not the program itself.

Why do examiners focus on day-to-day operation?

Because a program that looks complete on paper can still fail in practice. Examiners test whether controls actually run, so gaps between the written manual and real work are among the most common findings.

What happens when the program has a blind spot?

Uncovered activity goes unmonitored, which typically surfaces later as a missed suspicious activity report and a lookback across the affected period. Lookbacks are expensive and often accompany enforcement action.

Who is accountable for the program?

The board and senior management own it, and a designated compliance officer or MLRO runs it. Accountability sits at the top, which is why governance and risk appetite are treated as part of the program.

How often should it be reviewed?

Continuously in effect, and formally whenever the business changes: new products, markets, or channels, plus periodic independent testing. Waiting years between reviews is how scope goes stale and blind spots form.

Go deeper

  • FFIEC BSA/AML Examination Manual ↗ — The manual US examiners use to assess BSA and AML programs.
  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

AML compliance programと併せて知っておきたい用語