Between $800 billion and $2 trillion moves through the global financial system illegally every year, roughly 2%–5% of global GDP, according to UNODC. The vast majority of those illicit flows go undetected and unseized. Regulators and enforcement agencies are increasingly focused on closing that gap.
An anti-money laundering (AML) compliance program is the formal framework financial institutions use to detect and prevent money laundering activity.
What that framework looks like depends heavily on institution type, size, and the jurisdictions it operates in. A community bank in Ohio faces different exposure than a global fintech processing cross-border remittances in 40 markets. Regulators expect programs to reflect that reality. One-size-fits-all approaches are a common reason programs fail under examination.
The AML requirements governing these programs have grown more demanding and more fragmented. A program that looks good on paper but falls apart under operational scrutiny isn't a program that works. Regulators know the difference.
That gap is exactly what this guide addresses. You'll find a breakdown of the five FinCEN pillars, what a risk-based program actually looks like in practice, where most programs quietly fail, and how identity verification and watchlist screening hold the whole framework together.
重要ポイント
- An AML compliance program is a legally required framework for detecting and reporting money laundering, grounded in the Bank Secrecy Act in the U.S. and FATF's 40 Recommendations globally.
- FinCEN's five pillars form the structural baseline for U.S. programs: compliance officer designation, internal policies and controls, employee training, independent testing, and customer due diligence (CDD).
- Strong identity verification at onboarding is what makes every other control in the program reliable.
- AML compliance is ongoing. Transaction monitoring, watchlist screening, and periodic risk reassessment are continuous obligations, not one-time events.
- FinCEN's April 2026 proposed rule is moving away from procedural checklists toward a single standard: Does the program actually work?
What Is an AML Compliance Program?
An AML compliance program is a set of policies and systems designed to prevent a financial institution from being used to launder money or finance terrorism. In the U.S., those requirements are set by the Bank Secrecy Act (BSA), administered by FinCEN. Internationally, most national regulators build their frameworks around the Financial Action Task Force's (FATF) 40 Recommendations.
Banks and credit unions were the original covered institutions, but broker-dealers, money services businesses (MSBs), and insurance companies have since come under the same requirements. More recently, FinCEN also extended formal AML program requirements to investment advisers (effective 2028) and, through the GENIUS Act's implementing rules, to payment stablecoin issuers.
In parallel, the EU's new Anti-Money Laundering Authority (AMLA), began actively drafting the technical standards and guidelines that will eventually execute the rules of the AMLR (Anti-Money Laundering Regulation.) The AMLR is a unified framework that replaces fragmented national laws, ensuring a consistent implementation of customer due diligence (CDD). This regulation will strongly integrate digital identity frameworks like Digital Wallet and eIDAS 2.0 to standardize remote identification assurance.
Having a program and running one that actually works are two different things, and regulators know how to spot the gap. Policies that don't reflect how the institution operates, or monitoring systems that generate more signals than noise, are exactly what reviews often surface. FinCEN's 2026 proposed rule makes that expectation a formal standard: The program should stop financial crime in practice.
Know Your Customer (KYC) sits inside that standard as the customer-facing layer, covering the processes institutions use to verify who they're dealing with before any broader anti-laundering controls can take effect.
AML Compliance Program Requirements
U.S. AML compliance is built around five pillars established by the BSA and expanded by FinCEN in 2016 when customer due diligence (CDD) was added as a formal requirement. These pillars remain the operational baseline today, though FinCEN's 2026 proposed rule would restructure them into four by folding CDD into internal policies and shifting the evaluation standard from procedural compliance to demonstrated effectiveness.
1. A Designated Compliance Officer
Every covered institution must name a specific individual accountable for the AML program, typically referred to as the BSA officer. That person needs real organizational standing to enforce policies across business lines, with direct access to senior leadership and the authority to act on it.
Core responsibilities include managing internal audits, updating policies when the institution's risk profile or product mix changes, overseeing staff training, and serving as the primary regulatory contact.
Professional certification such as Certified Anti-Money Laundering Specialist (CAMS) or Certified Regulatory Compliance Manager (CRCM) is standard and increasingly expected by examiners.
2. Internal Policies, Procedures, and Controls
Written policies have to match how the institution actually operates. Generic templates drawn from regulatory guidance, without tailoring to the institution's customer base and delivery channels, are a recurring finding in enforcement actions.
The Securities and Exchange Commission (SEC) has charged firms in enforcement actions for relying on general AML policies not tailored to the specific business.
Controls need to cover how the institution monitors customer activity and how it fulfills its reporting obligations, including Suspicious Activity Report (SAR) and Currency Transaction Report (CTR) filings.
Equally important is the review cycle. When an institution expands into a new product line or customer segment, the AML controls governing that activity must keep pace. A program designed for last year's business is already behind.
3. Ongoing Employee Training
Training needs to reach everyone from front-line staff to senior leadership, with content calibrated to each group's actual exposure: red flag recognition for customer-facing roles, risk posture, and reporting obligations for those at the top. Regulators look for documented evidence that training occurred – not just confirmation that a program exists.
The content also has to evolve. Deepfake-assisted account opening and fraud-as-a-service networks have changed what financial crime looks like at the point of customer interaction. Training programs that haven't kept pace with these developments are leaving staff unprepared for what they're now actually encountering.
4. Independent Testing and Auditing
Independent audits must be conducted by someone with no involvement in running the AML function, either an internal audit team with appropriate separation or a qualified external party. The scope should cover whether policies are being followed in practice and whether transaction monitoring is generating alerts worth investigating.
Auditors should also review SAR and CTR filings directly to confirm they are submitted on time and that the supporting documentation holds up under scrutiny.
Audit frequency varies. Primary regulators such as the OCC for national banks and the FDIC and Federal Reserve for state-chartered institutions set examination schedules based on institution size and risk profile. Additional testing is expected whenever there is a material change to the program.
Audit findings addressed on paper without operational follow-through draw heightened examiner scrutiny.
5. Customer Due Diligence (CDD)
Customer due diligence (CDD) is the process through which institutions verify customer identities, assess the nature of those relationships, and monitor accounts over time. When a business opens an account, CDD also requires identifying the real individuals who own or control it – not just the legal entity on the paperwork.
If the identity data collected at onboarding is unreliable, every downstream risk decision rests on a compromised foundation.
What Goes Into a Risk-Based AML Program
Both FATF and FinCEN require programs to be calibrated to actual risk rather than minimum requirements. A fintech operating in high-risk remittance corridors and a regional bank serving a predominantly retail customer base face different exposure, and their programs should look different as a result.
A program starts with a business-wide risk assessment covering customers, geographies, products and services, delivery channels, and transaction types. From that assessment, institutions assign one of three due diligence tiers to each customer relationship:
- Simplified CDD for lower-risk customers with transparent fund sources and no connection to high-risk jurisdictions
- Standard CDD for the general customer population
- Enhanced due diligence (EDD) for higher-risk profiles, including politically exposed persons (PEPs), customers from FATF grey-list jurisdictions (22 countries as of 2026), cash-intensive businesses, and complex or opaque ownership structures
The tier assigned also drives how transaction monitoring thresholds are configured. The cost of miscalibration runs in both directions. Under-calibrated programs miss real risk. Over-calibrated systems generate so many alerts that analysts spend most of their time clearing noise rather than investigating substantive threats, leaving genuine suspicious activity at risk of being missed.
Ongoing Monitoring and Watchlist Screening
Upon verifying a customer at onboarding, institutions are required to monitor transactions continuously and screen against sanctions and watchlists, reassessing risk as circumstances change. For compliance teams, this ongoing work is where the heaviest costs accumulate and where gaps are easiest to miss.
Transaction monitoring is designed to flag activity that looks out of place, given what the institution knows about a customer. Modern systems analyze behavioral patterns and contextual signals to surface cases that warrant investigation.
The quality of those alerts depends heavily on how well monitoring rules are calibrated to the institution's actual customer base and risk profile. This is why the risk assessment underpinning the program matters as much as the technology running it.
Watchlist screening runs in parallel to transaction monitoring and covers several distinct data sources: the OFAC Specially Designated Nationals (SDN) list, UN Security Council sanctions, the EU consolidated list, and jurisdiction-specific databases. Effective screening requires fuzzy matching and transliteration handling, so that a name spelled inconsistently across documents doesn't result in a clean pass.
Adverse media screening supplements these sanctions databases, surfacing negative information that hasn't yet resulted in a formal designation.
When monitoring produces evidence of suspicious activity, institutions have a legal obligation to act. Under FinCEN's rules, a Suspicious Activity Report (SAR) must be filed within 30 days of initial detection for transactions of $5,000 or more where the institution suspects the funds are illegal, the transaction is structured to evade BSA requirements, or there is no apparent lawful purpose. If no suspect has been identified, the filing window extends to 60 days.
Separately, a Currency Transaction Report (CTR) is required for any cash transaction or aggregated cash transactions exceeding $10,000 in a single business day, with a 15-day filing deadline.
Entrust's AML screening and monitoring solutions are built to support continuous watchlist screening across global sanctions data sources, designed to keep pace with list updates without creating unmanageable alert volumes.
Common AML Compliance Program Failures (and How to Avoid Them)
Meeting the requirements on paper is one thing. Keeping them operational is where most programs run into trouble.
- Stale risk assessments: A program calibrated to last year's customer base and product mix will mis-rate current risk. Every time a new product launches or a new customer segment is added, the risk assessment needs to be revisited, not left until the next annual review cycle.
- Identity gaps at onboarding: CDD is only as good as the identity verification underpinning it. Identity verification confirms that a person is who they claim to be, typically by checking official documents and biometric signals. Building CDD on identity data that was never properly verified creates exposure that transaction monitoring alone cannot compensate for.
- Siloed data: Compliance teams that can't connect transaction behavior to identity records and account history are limited in their ability to recognize layering patterns or build coherent SAR narratives. The underlying issue is often a monitoring system that can't contextualize what it's seeing.
- Inadequate beneficial ownership verification: A persistent weakness identified by FATF in its 2024 U.S. mutual evaluation follow-up, which noted remaining deficiencies in timely access to beneficial ownership information.
In February 2026, FinCEN issued exceptive relief, allowing covered institutions to limit re-verification of beneficial owners to initial account opening and subsequent risk-based triggers. The underlying obligation to know who controls a legal entity remains unchanged.
Most of these failures share a common origin: weak identity data quality at the front end of the customer relationship.
Building an AML Compliance Program That Holds Up
The five pillars mentioned above work as a system. Each pillar depends on the others functioning as designed. Treating the pillars as a checklist rather than an interdependent framework is precisely the gap that regulators are now testing for.
Getting the interdependencies right is only part of the challenge. Regulatory expectations will continue to evolve. FinCEN's April 2026 proposed rule shifts the evaluation standard from procedural compliance to demonstrated effectiveness, and EU AMLA's supervisory mandate centralizes AML oversight across Member States under a single authority. Both raise the bar in ways that a program built once and left unchanged will struggle to meet.
Reliable identity data at onboarding and continuous screening afterward underpin the rest of the AML program. Without them, customer risk ratings and SAR decisions become harder to defend.
That's where Entrust’s identity verification solutions come in. Automated identity verification makes AML compliance scalable, confirming who your customers are at onboarding and keeping that data accurate as relationships evolve. Entrust's AML solutions are built on that same foundation, giving compliance teams the confidence to act on what their program surfaces. Explore Entrust's identity verification and AML solutions to see how they work in practice.
よくある質問
What is an AML compliance program?
An AML compliance program is a formal set of policies and procedures that financial institutions use to detect and prevent money laundering. In the U.S., it's required under the Bank Secrecy Act and enforced by FinCEN. Globally, FATF's 40 Recommendations set the overarching standard most national frameworks reflect.
What are the key components of an AML program?
FinCEN's five-pillar framework covers: a designated compliance officer, internal policies and controls, ongoing employee training, independent testing and auditing, and customer due diligence. Each pillar depends on the others. Weakness in one creates exposure across the program.
How does AML compliance relate to KYC?
KYC (Know Your Customer) is a control set that sits within a broader AML program. KYC processes, centered on identity verification and ongoing customer due diligence, are how institutions fulfill the customer-facing requirements of AML compliance.
How can automation improve AML compliance?
Automation reduces false positive rates in transaction monitoring and streamlines SAR and CTR workflows. The measurable gain is analyst time redirected from alert triage toward meaningful investigation, though automated systems require regular calibration and documented audit trails to satisfy examiner review.
What are the latest AML trends for 2026?
FinCEN's April 2026 proposed rule is the most significant regulatory development, shifting evaluation toward program effectiveness rather than procedural compliance. The EU's AMLA began centralized supervision in January 2026.
Ready to Strengthen Your Program's Identity Foundation?
Download Entrust's Compliance Manager's Guide to KYC for a practical look at selecting and implementing identity verification technology that meets AML requirements across markets.
Learn how Entrust anti-money laundering solutions automate screening, monitoring, and identity verification to reduce risk and maintain compliance.