Your AML policy might be a dusty PDF from 2019 or a Word doc from a past employee. Either way, it's not protecting your institution from enforcement actions or guiding your team effectively.
AML fines have surged by 50%, and regulators are scrutinizing documentation more than ever. When Goldman Sachs paid $2.9 billion for its role in the 1MDB scandal, gaps in policy enforcement and documentation were key issues. Your policy documentation isn't just for compliance; it's your first line of defense when examiners arrive.
This guide walks you through building a maintainable AML policy documentation system in 30 days.
What You Need Before Starting
Authority and Access
Get written approval from your Chief Compliance Officer to update and publish AML policies. Ensure you have edit access to your institution's policy management system, like SharePoint or Confluence.
Current State Inventory
Collect all AML-related documents: policies, procedures, guides, training materials, and audit reports from the past three years. List each document in a spreadsheet with its last update date and owner.
Regulatory Baseline
Download the current FFIEC BSA/AML Examination Manual and your primary regulator's latest AML guidance. If you operate internationally, get the relevant FATF-Style Regional Body standards for your jurisdictions.
Stakeholder List
Identify who needs to review and approve policy changes: Legal, Internal Audit, Operations, IT, and business line managers. Confirm their availability for a 30-day sprint.
Step-by-Step Implementation
Days 1-5: Risk Assessment Documentation
Start with your risk assessment. Your policy must document how you identify, measure, and mitigate money laundering risk across customer types, products, services, and geographic exposure.
Create a risk assessment template covering:
- Customer risk factors (industry, transaction patterns, geographic location, Politically Exposed Person status)
- Product/service risk factors (cash intensity, cross-border capability, anonymity features)
- Geographic risk factors (FATF high-risk jurisdictions, sanctions lists)
- Risk scoring methodology (how you weight and combine factors)
Document your risk rating scale. Define each tier with specific criteria, not vague language.
Write the risk assessment procedure as a step-by-step workflow. Specify actions like: "Review customer industry code against high-risk industry list (Appendix A). If match found, assign minimum Medium risk. Proceed to geographic review."
Days 6-12: Customer Due Diligence Procedures
Your Customer Identification Program and Customer Due Diligence procedures must specify exactly what you collect, verify, and document for each risk tier.
For each customer risk tier, document:
- Required identification documents
- Verification methods (database checks, document authentication)
- Beneficial ownership requirements (Corporate Transparency Act thresholds)
- Enhanced Due Diligence triggers and procedures
- Watchlist Screening requirements (which lists, how often)
Create decision trees for common scenarios. Example: "If customer is a non-US legal entity AND conducts wire transfers > $50,000/month, apply Enhanced Due Diligence per Section 4.2."
Days 13-18: Transaction Monitoring and SAR Filing
Document your transaction monitoring approach with specificity. Specify scenarios like:
"Transaction monitoring system (TMS) applies the following scenarios:
- Structuring: Multiple transactions below $10,000 within 24 hours totaling > $10,000
- Rapid movement: Funds in/out within 48 hours, > $25,000
- Geographic risk: Transactions to/from high-risk jurisdictions per Appendix B"
For each scenario, document the threshold, lookback period, and alert scoring logic.
Your Suspicious Activity Report procedure must specify:
- Alert investigation timeline (most institutions use 30 days from alert generation)
- Investigation documentation requirements
- SAR decision authority (who can approve filing or clearing an alert)
- SAR filing deadline (FinCEN requires filing within 30 days of initial detection)
- Record retention for alerts cleared without filing (typically 5 years)
Days 19-23: Independent Testing Requirements
Document your independent testing program with audit scope, frequency, and methodology. The FFIEC BSA/AML Examination Manual recommends testing every 12-18 months, with more frequent testing for high-risk areas.
Your policy should specify:
- Testing frequency by risk area
- Tester independence requirements (third-party or qualified internal audit)
- Minimum sample sizes for transaction testing
- Required testing outputs (written report, management response, remediation tracking)
Create an audit testing checklist covering:
- Risk assessment accuracy and completeness
- Customer due diligence file review (sample 25-50 accounts per risk tier)
- Transaction monitoring scenario effectiveness
- SAR quality review (timeliness, narrative completeness, supporting documentation)
- Training completion and effectiveness
- Recordkeeping compliance
Days 24-28: Training and Recordkeeping
Document training requirements by role:
- All employees: Annual AML awareness (money laundering typologies, reporting obligations)
- Customer-facing staff: Customer due diligence procedures, red flag identification
- BSA/AML staff: Regulatory requirements, investigation techniques, SAR preparation
- New hires: AML training within 30 days of hire
Specify recordkeeping requirements:
- Customer due diligence files: 5 years after account closure
- Transaction records: 5 years from transaction date
- SARs and supporting documentation: 5 years from filing date
- Training records: 5 years from training date
Days 29-30: Review and Approval
Route your draft policy package through your stakeholder list. Legal reviews for regulatory accuracy. Internal Audit reviews for testability. Operations reviews for feasibility.
Consolidate feedback in a comment matrix. For each comment, document: accepted, rejected (with rationale), or deferred to next review cycle.
Get final sign-off from your CCO and Board (or Board committee). Most institutions require Board approval for AML policy changes.
Validation: How to Verify It Works
Procedure Walk-Through
Select three customer accounts of different risk tiers. Have a BSA analyst who wasn't involved in writing the policy follow your documented procedures step-by-step. Note every point where they need to ask a question or make an assumption. Those are gaps.
Regulatory Cross-Check
Compare your policy against the FFIEC BSA/AML Examination Manual table of contents. Every major examination area should map to a policy section. If examiners ask "What's your policy on [X]?" you should be able to cite a section number.
Audit Readiness Test
Give your independent auditor (or internal audit team) your policy package. Ask them to design a test plan. If they identify untestable requirements or missing procedures, revise before publication.
Maintenance: Ongoing Tasks
Quarterly Review Triggers
Set calendar reminders to review your policy when:
- New AML regulations or guidance are published
- Your institution launches new products or enters new markets
- Independent testing identifies control gaps
- You receive regulatory feedback or examination findings
Annual Full Review
Schedule a complete policy review every 12 months. Compare your documented procedures against actual practice. Shadow your team for a week and note where they deviate from policy. Those deviations are either policy defects (fix the policy) or training gaps (fix the behavior).
Version Control
Maintain a policy revision log showing what changed, why, who approved it, and when it became effective. When examiners ask "What was your policy in Q2 2023?" you need to produce the version that was in effect then.
Change Communication
When you update policy, don't just republish the document. Send a change summary to affected staff highlighting what's new, what's different, and what they need to do differently starting when. Follow up with targeted training on material changes.
Your AML policy documentation will never be perfect. But if you can hand it to a new analyst and they can execute your program without asking 50 questions, you're in defensible shape.



