…
In October 2024, FinCEN assessed a record $1.3 billion civil money penalty against TD Bank for Bank Secrecy Act violations. It was the largest penalty FinCEN had assessed against a depository institution.
That distinction is everything. AML compliance means building controls that actually detect, prevent, and report financial crime: controls strong enough to hold up when a regulator examines them.
AML compliance is the set of policies, procedures, and internal controls organizations use to detect, prevent, and report money laundering and related financial crimes. In the United States, it is governed primarily by the Bank Secrecy Act (BSA) and enforced by the Financial Crimes Enforcement Network (FinCEN), with additional oversight from regulators including FINRA, the OCC, and the FDIC.
This guide covers the regulatory framework, the five pillars of a working program, how to identify red flags, and what’s changing heading into 2028, written for General Counsels, Compliance Officers, and Legal Directors who carry this risk.
Why AML compliance failures are so costly
According to the United Nations Office on Drugs and Crime (UNODC), between $800 billion and $2 trillion is laundered globally each year, roughly 2–5% of global GDP. The financial system is the mechanism. Regulators know it, and enforcement reflects that reality.
U.S. enforcement has intensified steadily over the past decade. The 2024 TD Bank case set a new benchmark: beyond the record-breaking fine, the bank was subject to a growth restriction on its U.S. retail business, a consequence with far longer commercial reach than the penalty itself.
Reputational damage typically outlasts the financial penalty. An AML enforcement action is public, permanent, and signals to counterparties, investors, and future regulators that internal controls weren’t taken seriously.
Which organizations must comply with AML laws?
The Bank Secrecy Act defines “financial institutions” broadly, and the definition has expanded with every major regulatory cycle. AML compliance obligations currently apply to:
- Banks, credit unions, and savings associations
- Broker-dealers and investment companies
- Money services businesses (MSBs): money transmitters, currency exchangers, check cashers
- Casinos and card clubs
- Insurance companies
- Mutual funds
- Dealers in precious metals, stones, or jewels
- Real estate professionals (under FinCEN’s active rulemaking)
- Law firms and accountants (sector-specific obligations vary by transaction type and jurisdiction)
Investment advisers: FinCEN issued a final rule in 2024 requiring certain SEC-registered investment advisers and exempt reporting advisers to establish AML/CFT programs and file SARs. The original effective date of January 1, 2026 was subsequently postponed to January 1, 2028. If your firm manages external capital, the extended timeline provides more runway, but program design should start well ahead of that deadline.
The three stages of money laundering
Understanding how money laundering works is the foundation of detecting it.
How money laundering moves through the financial system
Money laundering follows three stages, and effective controls need to reach each one.
Placement
Placement is where illicit cash enters the financial system. Cash deposits, shell company contributions, and co-mingling with legitimate business revenue are typical entry points. This stage carries the highest exposure for the launderer and the highest detection value for your monitoring systems.
Layering
Layering involves moving funds across accounts, jurisdictions, and asset classes to obscure their origin. Wire transfers, cryptocurrency conversions, and trade-based manipulation are standard methods at this stage. The goal is distance from source.
Integration
Integration is where the laundered funds re-enter the economy as apparently legitimate assets: real estate, luxury goods, or business investments. By this point, tracing the origin is extremely difficult.
A monitoring system calibrated only for suspicious cash deposits will miss layering and integration patterns, which are often more revealing. Controls need to reach all three stages.
The 5 pillars of an effective AML compliance program
FinCEN’s 2016 Customer Due Diligence (CDD) rule added explicit risk-based CDD requirements to the existing AML program requirements. These requirements are commonly described as the fifth pillar, although FinCEN’s regulation does not use that label.
1. Designation of a compliance officer
Your AML program must have a named, senior individual responsible for day-to-day oversight. This person needs genuine authority: the kind that holds under pressure. Regulators look for evidence that the compliance officer can escalate concerns, access senior management, and drive program changes without being overridden by revenue considerations.
2. Internal policies, procedures, and controls
Written policies must translate regulatory requirements into operational procedures specific enough that a new employee could actually follow them. That means documented workflows for customer onboarding, transaction monitoring thresholds, escalation paths, and recordkeeping timelines.
What satisfies examiners is operational specificity: defined thresholds, system controls, and documented escalation steps. Policy language that promises “identifying suspicious activity” without those specifics won’t hold up under scrutiny.
3. Ongoing employee training
Personnel whose duties require knowledge of BSA/AML obligations need role-appropriate AML training. A front-line teller’s curriculum looks different from a relationship manager’s. Both are examined.
Training records, completion rates, and competency assessments are standard requests during regulatory examinations. Keep them organized and accessible.
4. Independent testing (audit)
Your AML program must be tested regularly by someone outside the compliance function (typically an internal audit team or a qualified third party). The audit should assess whether controls are designed correctly and whether they’re actually working as intended.
“Independent” is taken literally. A review conducted by the same team that manages the program doesn’t satisfy this requirement. Neither does a review that only examines documentation without testing operational controls.
5. Customer due diligence (CDD) and beneficial ownership
This is the most operationally intensive pillar. It covers four requirements that build on each other:
- Customer Identification Program (CIP): Collect and verify the identifying information required by the applicable CIP, including name, date of birth for individuals, address, and identification number. Verification may use documentary or non-documentary methods.
- Customer Due Diligence (CDD): Understand the nature and purpose of each customer relationship and assign it a risk profile.
- Enhanced Due Diligence (EDD): Apply additional scrutiny to higher-risk customers, including Politically Exposed Persons (PEPs), customers in high-risk jurisdictions, and entities with complex ownership structures.
- Beneficial ownership: Since 2018, covered financial institutions have generally had to verify beneficial owners. The Corporate Transparency Act (CTA) separately governs BOI reporting and currently exempts U.S.-created entities and U.S. persons.
Key AML requirements in the United States
The U.S. AML framework layers federal statute, FinCEN rulemaking, and sector-specific regulatory requirements. Here’s the core of what applies to most regulated entities.
| Regulation / Requirement | What it requires |
|---|---|
| Bank Secrecy Act (BSA) | Foundation of U.S. AML law; requires records and reports to assist law enforcement |
| FinCEN regulations | Implements BSA; governs SAR/CTR filing, CDD rules, and program requirements |
| FINRA Rule 3310 | Requires FINRA member firms to maintain a written AML program approved by senior management |
| Suspicious Activity Reports (SARs) | Filed for transactions over $5,000 involving suspected illegal activity; must be filed within 30 days of detection |
| Currency Transaction Reports (CTRs) | Required for cash transactions over $10,000; filed with FinCEN within 15 days |
| FBAR | Required for U.S. persons with foreign financial accounts exceeding $10,000 in aggregate |
| Corporate Transparency Act (CTA) | Requires most U.S. companies to report beneficial ownership information directly to FinCEN |
| Investment Adviser AML Rule (2028) | Effective January 1, 2028 (postponed from 2026): SEC-registered RIAs must establish AML/CFT programs and file SARs |
For a broader look at how AML sits within an organization’s governance, risk, and compliance architecture, see DiliTrust’s GRC framework guide.
Don’t let entity gaps become compliance gaps.
Managing beneficial ownership records and entity filing deadlines across multiple jurisdictions is where AML programs most often break down in practice. DiliTrust Legal Entity Management centralizes your entity structures, mandates, and compliance deadlines in one place, so nothing falls through the gaps when a regulator asks.
AML red flags: what triggers a suspicious activity report?
A SAR is both a legal obligation and an intelligence tool. FinCEN shares SAR data with federal, state, and local law enforcement agencies, and patterns in that data help identify criminal networks and systemic financial abuse.
A covered financial institution must file a SAR when a transaction meets the applicable BSA criteria and thresholds, including when the institution knows, suspects, or has reason to suspect that the transaction involves illegal activity, is designed to evade BSA requirements, or has no apparent lawful purpose.
Common red flags that trigger SAR analysis include:
- A customer structures deposits to stay below the $10,000 CTR threshold (structuring itself is a federal crime under 31 U.S.C. § 5324)
- Significant, unexplained changes in transaction patterns or account activity
- Wire transfers to or from high-risk jurisdictions with no clear business rationale
- A customer refuses to provide identification or is evasive about the source of funds
- Shell company structures with no apparent economic purpose or business activity
- Third-party payments where the payer has no identifiable connection to the account
- Cryptocurrency transactions designed to obscure wallet ownership through chain-hopping or mixing services
The 30-day SAR filing window generally starts when the reporting institution initially detects facts that may constitute a basis for filing. If no suspect is identified, an additional 30 days may be available, subject to the applicable rules. The standard is reasonable suspicion, not certainty.
How to build an AML compliance program: a step-by-step approach
Whether you’re building from scratch or auditing a program that may have gaps, this eight-step structure covers the essential elements.
- Conduct a risk assessment: Map your customer base, products, services, and geographies against known money laundering typologies. Your program’s depth should reflect your actual risk exposure, not a template imported from an institution with a different profile.
- Appoint and resource your compliance officer: Give this person real authority, clear reporting lines to senior leadership or the board, and a budget proportionate to your risk profile. A compliance officer without resources or access is a liability, not a safeguard.
- Document your policies and procedures: Write at an operational level and test them against real scenarios before finalizing. If a procedure can’t be followed by a new hire on day one, it needs revision.
- Build your CIP and CDD framework: Define the documentation you’ll collect at onboarding, your risk tiering methodology, and the precise conditions under which EDD applies. Vague triggers leave decisions to individual judgment, and individual judgment creates inconsistency.
- Implement transaction monitoring: Establish automated alerts and human review workflows. Document your escalation path clearly, from initial alert through SAR decision. Every step needs to be traceable.
- Train your team: Run role-specific training at onboarding and at least annually thereafter. Keep records of completion, assessment scores, and training materials used.
- Schedule independent testing: Commission independent testing at a frequency based on your institution’s risk profile. Track findings and remediation timelines as formal action items with assigned owners and deadlines.
- Establish a board reporting cadence: Your board or audit committee should receive regular updates on AML program status, key metrics, and significant findings. Regulators examine board engagement as part of their assessment of program governance. A board that receives no AML reporting is a program gap in itself.
AML compliance trends in 2025–2026
Three developments are reshaping AML compliance operations right now.
AI-powered transaction monitoring
Rules-based systems generate high false-positive rates, which can create substantial false-positive volumes, creating analyst workload that pulls attention away from genuine alerts. Machine learning models are increasingly being used to improve alert quality and surface genuinely suspicious patterns faster. According to Gartner’s Hype Cycle for Legal Risk, Compliance and Audit Technologies, 2025, compliance monitoring solutions that draw on data and analytics are rated as high-benefit and are approaching early mainstream adoption. The principal constraint is data quality: the model reflects the data it’s trained on, no more.
Cryptocurrency and digital assets
Certain businesses that transmit or exchange convertible virtual currency are treated as money services businesses and are subject to applicable BSA obligations. The Travel Rule, which requires financial institutions to transmit specified originator and beneficiary information with covered transmittals of funds, also applies to certain virtual-currency transfers. If your organization conducts activities involving digital assets, assess whether those activities create BSA, AML, or sanctions obligations and address them in the relevant control framework.
The investment adviser rule
Registered investment advisers have operated without mandatory AML program requirements for years. FinCEN’s 2024 final rule changes that, requiring certain SEC-registered investment advisers and exempt reporting advisers to establish written AML/CFT programs and file SARs. The original effective date of January 1, 2026 was pushed to January 1, 2028, but the obligation itself is settled. For compliance officers at RIAs, that runway should go toward program design, not delay.
The governance infrastructure behind AML compliance
An AML program is only as strong as the governance structure supporting it. Controls break down when oversight is fragmented: entity data in one system, contractual obligations in another, board reporting assembled manually from exports that are out of date before they reach the committee.
For General Counsels managing AML obligations across multiple entities or jurisdictions, the core challenge is visibility. You need to know which entities are in scope, who holds beneficial ownership, when filings are due, and whether controls are operating as designed across the full organization, not just the business unit that was last audited.
That kind of cross-entity visibility requires more than a compliance checklist. It requires a governed data environment where legal entity structures, mandates, and obligations are tracked centrally and consistently. The DiliTrust Suite gives legal and compliance teams that foundation: entity structures and mandate data centralized in Legal Entity Management, contractual obligations and deadlines tracked in Contract Management, and governance reporting that generates audit-ready outputs for boards and regulators. Backed by ISO 27001 and SOC 2 certified infrastructure, it provides the legal operations layer that makes a broader compliance framework defensible and auditable.
Most AML program gaps don’t start with a missing policy. They start with a governance infrastructure, entity visibility, obligation tracking, board engagement, that was never fully built. Closing that gap is where durable compliance programs begin.
If you’re also managing enterprise-wide risk methodology alongside AML obligations, the ISO 31000 risk management framework offers a practical reference for building an integrated approach.
Frequently asked questions
What is the difference between AML and KYC?
KYC (Know Your Customer) is a component of AML compliance. It refers specifically to the processes organizations use to verify customer identities, understand their financial behavior, and assess their risk profile. AML is the broader legal and regulatory framework; KYC is one of its core operational tools.
What is the difference between AML and OFAC compliance?
AML compliance focuses on detecting and preventing money laundering through transaction monitoring, SAR filing, and customer due diligence. OFAC (Office of Foreign Assets Control) compliance covers sanctions: ensuring your organization doesn’t transact with designated individuals, entities, or countries. Both are federal legal obligations, but they operate through separate regulatory frameworks and require distinct control structures.
What are the penalties for AML non-compliance?
Civil penalties under the BSA vary by violation and are adjusted periodically for inflation. For example, the maximum civil penalty for a willful SAR or CTR reporting violation is generally the greater of the transaction amount, subject to a statutory cap, or $69,733 per violation under FinCEN’s 2025 inflation-adjusted schedule.
Does the Corporate Transparency Act affect my AML program?
Under FinCEN’s current rule, entities created in the United States and U.S. persons are exempt from BOI reporting. Certain foreign entities registered to do business in the United States may still have reporting obligations. The CDD rule remains a separate requirement for covered financial institutions to identify and verify beneficial owners of legal entity customers.
What is BSA/AML compliance?
BSA/AML is shorthand for the combined obligations under the Bank Secrecy Act and related anti-money laundering regulations. The terms are used together because the BSA is the primary U.S. statutory framework for AML requirements, and most FinCEN rules derive directly from it.
What is the AML compliance process?
At its core, the AML compliance process involves four recurring activities: identifying and verifying customers (KYC/CDD), monitoring transactions for suspicious activity, filing required reports with FinCEN (SARs, CTRs), and maintaining records that support regulatory examination. That cycle runs continuously, governed by your written program and tested periodically by an independent reviewer.
Build the governance foundation your AML program depends on.
AML compliance doesn’t fail at the policy level. It fails when the underlying governance infrastructure, entity visibility, obligation tracking, board reporting, isn’t there to support it. If your team is managing those obligations manually or across disconnected systems, that’s the gap worth closing first. DiliTrust gives legal and compliance teams the centralized foundation to make it work.



