You can have a written AML policy, a customer identification checklist, and a training deck on file, and still be exposed if the program doesn't match how the firm takes clients, moves money, escalates concerns, and proves decisions. That gap is where exam problems start, especially for advisors, broker-dealers, and compliance officers who inherited a binder that looked complete until someone asked for the risk assessment, the testing file, or the rationale behind a closed alert.
The hard truth is that regulators do not treat an anti-money laundering compliance program as a static document. They look for a defensible operating system, one that shows leadership involvement, risk-based controls, documented judgment, and a record that can survive an SEC, FINRA, or state review. The firms that get this right do not just “have AML.” They can show what the program was designed to do, who owned it, how it was monitored, and why each decision made sense at the time.
Why Most AML Programs Fail Before the Regulator Walks In
The most common failure starts in a conference room, not on an examiner's workpaper. A firm principal pulls out the AML policy, points to the training log, and assumes the file is ready. Then the examiner asks for the enterprise risk assessment, the monitoring rationale, and the evidence that the program was tuned to the business, and the room goes quiet.
That scene is familiar because many firms build AML as a document library instead of a working control system. The result is a policy that describes what should happen, while the day-to-day workflow happens somewhere else, in emails, spreadsheets, or a vendor portal nobody has reviewed in months. The program looks complete until someone asks how it was calibrated for the firm's clients, products, and jurisdictions.
A useful starting point is to treat the program as a record of judgment, not a checklist. The review lens is similar across regulators, even when the labels differ, because they want to see that the firm understood its risks, assigned responsibility, and kept the controls aligned to real activity. A practical overview of software support for that kind of workflow is the CEFCore compliance software overview, which is helpful because it frames AML tools as part of evidence capture, not just alert generation.
Practical rule: If you can't explain why a control exists, who reviews it, and where the evidence lives, the control will not help you much in an exam.
The deeper problem is that weak programs often begin with no real risk assessment. A firm can't calibrate monitoring, onboarding, or escalation if nobody has scored the customer base, the delivery channels, or the product mix. That's why an AML binder can look polished and still fail on first review.
Mapping Risk Before You Write a Single Policy
The best programs start with the business, not with form language. An enterprise-wide risk assessment should score customers, products and services, delivery channels, and jurisdictions, then translate those scores into controls that are proportionate to the risk profile. If the business model changes, the score should change with it.
A useful way to think about it is simple. A representative RIA with mostly domestic, fee-based, natural-person clients will not need the same monitoring profile as a representative introducing broker-dealer that touches legal entities, higher turnover, and broader third-party activity. The framework is the same, but the intensity of review is not. That is what makes the assessment defensible.
The key is to document both inherent risk and residual risk. Inherent risk is what the business would look like without controls. Residual risk is what remains after onboarding checks, screening, monitoring, and escalation are in place. Examiners care a great deal about the bridge between those two states, because that bridge tells them whether the controls are doing work.

A few scoring mistakes come up again and again. Firms double-count the same risk factor in two categories, treat a “low-risk” designation as if it means zero risk, or ignore concentration risk because no single client looked troubling in isolation. The better practice is to write down the weighting logic, identify the reviewer, and keep the rationale with the risk file so the firm can defend the outcome later.
The governance point matters too. Written supervisory procedures only help if they reflect how the firm supervises the business, which is why it's worth keeping the AML assessment aligned with the firm's broader supervisory framework, including the structure discussed in written supervisory procedures definition. When the AML assessment and the supervisory procedures tell different stories, examiners notice fast.
A risk assessment that sits in a folder and never changes is not a risk assessment. It's a compliance artifact.
Customer Due Diligence and OFAC Screening That Actually Hold Up
Customer due diligence is where the program meets the client file. Under the U.S. framework, the AML program has to be written and include policies, suspicious activity detection, a compliance officer, training, and independent review, and the customer side now includes beneficial ownership identification for covered legal entity customers under the CFTC summary of the BSA rules. That means onboarding is not just a data collection exercise, it is the first control point in the file.
The exam question is usually not whether the firm has forms. It is whether the firm can show that it understood who the customer is, why the relationship is being opened, and what follow-up is needed if the risk profile changes. That is where ongoing CDD matters, because a clean account on day one can become a very different account after a funding pattern changes, a related entity appears, or the activity no longer matches the original profile.
CDD and EDD Triggers at a Glance
| Risk Tier | Common Triggers | Required Action |
|---|---|---|
| Lower risk | Simple ownership, familiar source of funds, ordinary transaction patterns | Standard CIP and ongoing review |
| Moderate risk | Some entity complexity, occasional unusual activity, cross-border touchpoints | Enhanced review of source of funds and ownership |
| Higher risk | PEP status, high-risk jurisdictions, complex ownership, atypical funding sources | Enhanced due diligence, senior review, and tighter monitoring |
The most effective firms make EDD triggers explicit. A politically exposed person, a customer linked to a higher-risk jurisdiction, a layered ownership structure, or an unusual funding source should prompt a documented review, not a casual note in the onboarding system. If the firm decides not to apply EDD, the file should say why.
OFAC screening needs the same discipline. List management, rescreening, and true-hit escalation should be built into the workflow, not handled ad hoc by one analyst who knows where the spreadsheet lives. The practical issue is not whether screening exists, it's whether the firm can show that it screened the right parties at the right time and escalated real matches promptly.
Adverse media is another place where firms overreach. A bad search result is not the same as a confirmed compliance event, and firms need a workflow that uses public information carefully without drifting into unsupported consumer-reporting style decisions. The better approach is to document the source, the relevance, and the reason the information changed the risk rating, or didn't.
FINRA's rule on customer identification makes the point that firms should know the customer, not just collect a name, and its broader AML guidance reinforces the need for risk-based CIP and ongoing CDD. That is why the internal reference on FINRA Rule 2090 belongs in the same conversation as onboarding review. The front door and the recordkeeping have to match.
Transaction Monitoring, Alerts, and the SAR Decision
Once the account is open, the program has to watch what happens next. That sounds obvious, but many firms still run monitoring like a passive vendor feed, where alerts arrive without a clear owner, a clear rule rationale, or a consistent case memo. Regulators do not like uncertainty there, because the decision to escalate, close, or file needs to be reconstructable months later.
Monitoring should be calibrated to the business. Small and mid-size firms often do better with a narrow set of well-tuned scenarios than with a noisy system that produces endless false positives. If the threshold settings are too tight, analysts drown in alerts. If they're too loose, real issues slide through because nobody trusts the queue.
Document the analyst's judgment, not just the alert outcome. A closed alert with no reasoning is a weak record, even if the conclusion was correct.
A practical case management workflow usually has three stages. First, the alert fires. Second, the analyst checks context, including expected activity, prior activity, related accounts, and source-of-funds consistency. Third, the case is escalated, closed, or referred for SAR review. The file should show who reviewed it, what they saw, and why the decision was made.
The distinction between a SAR and a CTR matters too. A CTR is a reporting regime for reportable cash activity, while a SAR is about suspicious conduct. Firms sometimes blur those categories and either under-report suspicion or over-file because they treat every oddity as a reportable event. The better practice is to separate the cash logic from the suspicion logic and document the basis for each.
The best monitoring programs are also honest about continuing activity reviews. A customer may generate a pattern that is repetitive but not suspicious, or suspicious but not yet reportable. That middle zone is where human review matters most, because the analyst needs to decide whether the pattern is explainable, escalating, or closed with no further action.
For firms that need a practical fraud-control lens, the discussion in preventing business fraud is useful because it overlaps with the same discipline regulators expect in AML. Good monitoring is not about catching everything. It is about showing that the firm used a consistent, risk-based process and reached a defensible outcome.

Governance, Training, and Independent Testing
Regulators usually find governance failures long before they find technical failures. The AML officer may be named in the policy, but the question is whether that person has authority, resources, and a direct reporting line that lets issues rise quickly. If senior management only sees AML when a problem hits the file, the control environment is already weak.
That is why the board or senior management approval piece matters. Under FINRA's framework, the AML program must be approved in writing by senior management, reasonably designed to detect and report suspicious activity, include a risk-based CIP and ongoing CDD process, provide training, and undergo independent testing. Those are not separate chores, they are the structure that gives the program credibility.
What each audience needs
- Front line staff: Practical scenario training on how to spot unusual behavior, collect accurate onboarding data, and escalate issues early.
- Advisors and registered persons: Client-specific examples, especially around entity complexity, funding mismatches, and suspicious red flags in transfers or account changes.
- Supervisors: Training on review standards, documentation quality, and when to push a matter to the AML officer instead of closing it locally.
- Board or senior committee: A concise report format focused on trends, open issues, testing findings, and remediation progress.
Training that is too generic usually fails the first time an examiner asks a rep what happens when a true match appears or why a client file was classified as moderate risk. Training that is too technical can also miss the mark if it doesn't connect to daily workflow. The content has to fit the person who is being trained.
Independent testing is the part firms love to postpone and regulators love to ask about. Best practice is to schedule it based on risk, document the scope, and make sure the tester is separate from the people who run the program day to day. A good test does not just identify gaps, it measures whether remediation happened and whether the fix stuck.
The corporate governance perspective in what is corporate governance is relevant because AML works best when leadership treats it as part of enterprise governance, not a compliance silo. A program with clean governance and weak evidence still looks weak. A program with strong evidence and active oversight usually survives a closer look.
Avoiding Over-Compliance and Unintended De-Risking
The hardest AML judgment is not when to add more controls. It's when controls start excluding legitimate clients. FATF has warned that overly cautious AML/CFT controls can become disproportionate and push legitimate customers out of the formal financial system, with the burden falling heavily on underserved communities. That risk is real in lower-income, rural, and politically fragile markets, where access can disappear because a firm chose convenience over calibration.
De-risking often starts with good intentions. A firm sees a high-risk indicator, decides the file is too hard, and exits the relationship instead of refining the review. That can create regulatory and reputational problems of its own, because the firm hasn't reduced risk so much as moved the risk decision into a blunt exclusion policy.
The stronger approach is to calibrate, not abandon. A customer with a legitimate reason for cross-border activity, for example, may need more documentation and more frequent review, not automatic rejection. A business with a complex ownership structure may need better source-of-funds verification, not a default “no.”
Risk-based does not mean risk-averse. It means the firm can explain why it imposed a tighter control, and why that control was proportionate to the actual risk.
Documentation matters here because the examiner may ask why a high-risk indicator didn't trigger EDD, or why a particular client remained onboarded. If the file shows the risk score, the factors considered, and the reasons for the final decision, the firm has a defensible answer. If the file only shows the outcome, the decision looks arbitrary.
There's also a practical inclusion point. Brookings has argued that newer fintech capabilities can reduce compliance costs and improve financial inclusion, which reinforces a broader lesson for traditional firms, too. Better data, cleaner escalation, and smarter workflows can reduce false positives without turning the program into a rubber stamp.
Your 90-Day AML Program Roadmap and Next Steps
A rebuild does not need to be perfect on day one. It needs to be credible, documented, and moving in the right direction. The first 30 days should focus on the risk assessment, the policy gap review, and the ownership of the AML file, because everything else depends on those decisions.
The next 30 days should address onboarding, CDD, screening, and monitoring. That means checking whether beneficial ownership collection works in practice, whether OFAC escalation is documented, and whether alert review logic matches the actual client base. The third 30 days should close the loop with governance materials, staff training, and an independent testing plan.

A workable 90-day checklist looks like this:
- Days 1 to 30: Refresh the enterprise risk assessment, identify control owners, and inventory the current policy, training, and testing files.
- Days 31 to 60: Fix CDD gaps, tighten screening escalation, and review how alerts are documented and closed.
- Days 61 to 90: Finalize governance reporting, deliver role-based training, and schedule independent testing with a clean remediation tracker.
If the program has already been questioned in an exam, preservation comes first. Keep the file intact, avoid informal edits to the record, and make sure counsel is looped in before the firm answers regulators on issues that could later become a formal finding. That matters even more for CFP-designated advisors, who may face parallel scrutiny when the AML issue overlaps with broader conduct questions.
If your firm needs to rebuild an AML program, defend one after an SEC or FINRA exam, or pressure-test how the file would look under CFP Board scrutiny, Kons Law can help you map the gaps and organize the remediation. If you want to discuss your business law matter, contact Kons Law at (860) 920-5181. You can also visit Kons Law to connect with counsel on AML remediation, regulatory response, and related securities compliance issues.
