Your AML program isn't theoretical. It's a set of operational controls that either work or don't. This checklist gives you a clear done/not-done state for each requirement, with specific references where applicable. If you can't confirm "done" for an item, you've identified your next remediation priority.
What This Checklist Covers
This checklist focuses on the operational components of a risk-based AML compliance program required under the Bank Secrecy Act and subsequent regulatory frameworks. It addresses customer identification, transaction monitoring, suspicious activity detection, and governance controls. Each item maps to a verifiable control state, not an aspirational goal.
Use this to audit your current program or build a new one. The checklist assumes you operate under U.S. BSA requirements, but the control principles apply across jurisdictions including EU Anti-Money Laundering Directives.
Prerequisites
Before starting this checklist, confirm you have:
- Access to your institution's written AML policy document (not just slides or training materials)
- Your current risk assessment methodology and last assessment results
- A list of all customer-facing products and channels (including third-party integrations)
- Your SAR filing records from the past 12 months
If you don't have these four items documented and accessible, that's your starting point.
Compliance Checklist
Governance and Policy
1. Written AML policy approved by senior management within the past 12 months
Your AML policy must be a formal document, not an email or presentation. It should identify your designated AML Compliance Officer by name and title, outline your risk-based approach, and reference specific regulatory obligations under the Bank Secrecy Act.
Good looks like: A board-approved policy document dated within the current year, with version control and a documented review schedule.
2. Designated AML Compliance Officer with documented authority and direct reporting line
The USA PATRIOT Act requires designation of a specific individual responsible for AML compliance. This person must have sufficient authority to implement controls and access to senior management.
Good looks like: An organizational chart showing the Compliance Officer reporting to the CEO or board, with a formal appointment letter specifying responsibilities and authority.
3. Annual independent AML audit completed by qualified third party
Your program requires regular testing by someone who doesn't perform the day-to-day compliance work. This can be an external auditor or an internal audit team that's independent from the compliance function.
Good looks like: An audit report from the past 12 months that tested specific controls, identified gaps, and documented management's remediation plan.
Customer Due Diligence and KYC
4. Customer Identification Program (CIP) procedures that verify identity for all new accounts
You must verify customer identity using documentary or non-documentary methods before account opening. The 6AMLD extends criminal liability to legal persons, making entity verification equally critical.
Good looks like: Written procedures specifying what documents you accept (passport, driver's license, etc.), how you verify them, and what you do when verification fails. Your system should log verification method and result for every customer.
5. Customer Due Diligence (CDD) risk scoring applied at onboarding and updated periodically
Risk-based AML requires differentiating between low-risk and high-risk customers. Your CDD process should assign a risk score based on customer type, geography, product usage, and transaction patterns.
Good looks like: A documented risk scoring matrix with defined criteria and thresholds. Every customer record includes a risk rating, last review date, and next review date. High-risk customers have enhanced due diligence documentation.
6. Politically Exposed Person (PEP) screening integrated into onboarding and ongoing monitoring
The 6AMLD identifies 22 predicate offenses requiring enhanced scrutiny. PEP screening helps identify customers who may pose elevated risk for corruption-related money laundering.
Good looks like: Automated screening against recognized PEP databases at account opening and periodic rescreening (at least annually for existing customers). Documented procedures for enhanced due diligence when PEP matches occur.
7. Beneficial ownership information collected for legal entity customers
You need to know who ultimately owns and controls the entities you serve. This requirement became more explicit under the Corporate Transparency Act.
Good looks like: A certification form signed by entity customers identifying beneficial owners with 25% or greater ownership, plus documentation verifying those individuals' identities.
Transaction Monitoring and Reporting
8. Automated transaction monitoring system with documented scenarios and thresholds
Manual review doesn't scale. You need a system that flags unusual patterns based on customer risk profile and transaction history.
Good looks like: A monitoring platform running defined scenarios (velocity, structuring, cross-border patterns, etc.) with documented threshold settings. You can produce a report showing what scenarios ran, how many alerts they generated, and disposition of those alerts.
9. Documented investigation procedures for transaction monitoring alerts
Generating alerts means nothing if you don't investigate them consistently. Your procedures should specify who investigates, what documentation they review, and how they decide whether to file a Suspicious Activity Report (SAR).
Good looks like: A written investigation protocol with decision trees. Each alert has a documented disposition (cleared, escalated, or filed) with investigator notes explaining the rationale.
10. Suspicious Activity Reports (SARs) filed within regulatory timeframes
You have 30 days from initial detection to file a SAR (60 days if you need to identify the subject). Late filing is a compliance failure.
Good looks like: A tracking log showing alert date, investigation completion date, SAR filing date, and BSA E-Filing acknowledgment number. No filings exceed the 30-day window without documented justification for the 60-day extension.
11. Currency Transaction Reports (CTRs) filed for transactions exceeding $10,000
This is the oldest BSA requirement and the easiest to verify. Every cash transaction over $10,000 requires a CTR.
Good looks like: System-generated CTR filing for every qualifying transaction, with aggregation logic that catches multiple related transactions. You can reconcile your CTR filing log against your transaction database and find zero gaps.
Watchlist Screening and Sanctions Compliance
12. OFAC sanctions screening integrated into payment processing
The Office of Foreign Assets Control administers sanctions programs that prohibit transactions with designated individuals, entities, and countries. Screening must occur before you complete a transaction, not after.
Good looks like: Real-time screening against the OFAC Specially Designated Nationals (SDN) list integrated into your payment flow. Matches block the transaction and generate an alert for compliance review. You can demonstrate that no prohibited transactions were processed.
13. Watchlist screening covers customers, beneficiaries, and counterparties
Sanctions screening can't stop at your direct customer. You need to screen the entire payment chain.
Good looks like: Screening logic that checks customer, beneficiary, intermediary banks, and any other parties identified in payment messages. Your screening configuration captures name variations and partial matches.
Training and Culture
14. Annual AML training completed by all employees with customer contact or transaction processing responsibilities
The Bank Secrecy Act requires ongoing training. Generic compliance training doesn't satisfy this requirement; it must be AML-specific.
Good looks like: Training records showing completion dates, topics covered, and test scores (if applicable). Training content addresses your institution's specific risks and includes real scenarios from your operations. New hires complete training within 30 days.
15. Escalation procedures tested and documented
Your procedures mean nothing if staff don't follow them when they encounter suspicious activity. Testing confirms your controls work under operational conditions.
Good looks like: Documented testing results from the past year showing that staff correctly identified red flags, escalated concerns through proper channels, and documented their actions. Testing should include both announced and unannounced scenarios.
Common Mistakes
Treating risk assessment as a one-time project. Your risk profile changes as you add products, enter new markets, or change your customer mix. Annual reassessment is the minimum; quarterly is better for fast-growing institutions.
Filing SARs without investigating first. Defensive filing creates noise and doesn't satisfy your obligation. Every SAR should be supported by a documented investigation showing why you concluded the activity was suspicious.
Relying on vendor default settings. Your transaction monitoring vendor's out-of-the-box scenarios weren't calibrated for your institution. You must tune thresholds based on your customer base and risk appetite, then document that tuning decision.
Separating AML from fraud monitoring. Fraud patterns often overlap with money laundering typologies. Siloed teams miss connections between account takeover, structuring, and money mule activity.
Next Steps
If you identified gaps in this checklist, prioritize them by regulatory risk and operational impact. Items 1, 2, 10, and 12 carry the highest penalty risk; fix those first. Items 8 and 9 have the highest operational impact; improving them reduces your alert backlog and makes your entire program more effective.
Document your remediation plan with specific deadlines and assign ownership. A gap you've identified and scheduled for remediation is better than one you haven't acknowledged. Your next audit will ask what you did after you found the problem.
Your AML program isn't static. Schedule your next full checklist review for 90 days from now, and use that cadence to catch drift before it becomes non-compliance.



