You've likely heard about the Federal Reserve's evidence-based AML proposal and thought it was "interesting but not urgent." That's a mistake. The shift from checkbox compliance to evidence-based risk management isn't just a regulatory change. It's a fundamental shift in how you'll justify your program's design, staff your teams, and defend your decisions to examiners.
Misconceptions about what "evidence-based" actually means are already causing resistance. Let's address them directly.
Myth 1: Evidence-Based Means Lower Standards
The Reality: Evidence-based compliance raises the bar by requiring you to prove your controls work, not just that they exist.
Under traditional AML frameworks, you could satisfy examiners by showing you had policies, trained staff, and ran transaction monitoring. The Federal Reserve's proposal changes this: you need evidence that your specific controls actually reduce money laundering risk in your specific environment.
This doesn't mean relaxed requirements. It means you'll need to measure alert quality, track investigation outcomes, and demonstrate that your $500K transaction monitoring system catches suspicious activity better than a $200K alternative would. You're trading procedural compliance for performance accountability.
For your team, this means building measurement into everything. When you tune monitoring rules, document the before-and-after false positive rates. When you enhance customer due diligence for a segment, track how many SARs result. You're not just doing the work, you're proving the work matters.
Myth 2: You Can't Start Until the Rules Are Final
The Reality: Waiting for final regulations means you'll be scrambling when they arrive.
Your current program already generates data you're not using. You have alert disposition records, SAR filing patterns, investigation timelines, and quality assurance findings. Evidence-based compliance means turning that operational exhaust into strategic insight.
Start now by asking: which of our controls have we never actually validated? Consider a team that spent two years requiring enhanced due diligence for all cash-intensive businesses but never analyzed whether that segment actually produced more SARs than baseline. That's a control with assumed value but no proven value.
Build the habit of evidence collection before it's mandated. When you implement a new screening rule, establish metrics first: What's the expected hit rate? What's acceptable precision? How will we know if it's working? Document your hypotheses and test them. By the time evidence-based requirements become formal, you'll have a library of proven controls and a process for evaluating new ones.
Myth 3: Evidence-Based Compliance Is Just More Documentation
The Reality: It's about decisions, not paperwork.
The goal isn't to generate reports proving you followed procedures. It's to use evidence to make better resource allocation decisions and defend them to examiners.
Here's the distinction: traditional compliance asks "did you review high-risk customers annually?" Evidence-based compliance asks "did annual reviews of high-risk customers produce actionable intelligence, and if not, would quarterly automated monitoring plus biennial deep-dive reviews work better?"
You're not documenting that you did the thing. You're documenting why the thing was the right choice given your risk profile and the available evidence.
This actually means less busywork if you do it right. When you can show that monthly sanctions screening of dormant accounts has never produced a hit in four years, you have evidence to justify moving that segment to quarterly screening and redeploying those hours to higher-yield activities. The documentation supports the decision; it doesn't replace thinking with process.
Myth 4: Small Institutions Can't Compete on Evidence
The Reality: Evidence-based frameworks favor focused programs over comprehensive-but-shallow ones.
Large institutions have analytics teams and data warehouses. You don't. But evidence-based compliance doesn't require sophisticated infrastructure. It requires honest measurement of what you actually do.
A community bank that monitors 2,000 business accounts can manually track whether its customer risk ratings correlate with SAR filings. You don't need machine learning to notice that your "high risk" segment and your "medium risk" segment produce SARs at identical rates, suggesting your risk model needs recalibration.
The advantage you have: shorter feedback loops. When you adjust a control, you can measure the impact in weeks, not quarters. When an examiner asks why you allocated resources a certain way, you can walk them through specific cases because you know your customer base.
Evidence-based compliance rewards programs that know themselves well. Scale is less important than clarity.
Myth 5: This Replaces Risk-Based Compliance
The Reality: Evidence-based compliance is how you validate that your risk-based approach actually works.
Risk-based compliance has been the standard for years, but most programs never closed the loop. You identified higher-risk customers, applied enhanced controls, and... then what? Did those controls reduce risk? Did they catch more suspicious activity? Or did you just create more work?
Evidence-based frameworks force you to answer those questions. You still start with risk assessment, inherent risk, customer risk, product risk. But now you need evidence that your control intensity actually corresponds to risk outcomes.
Consider transaction monitoring. You've probably set lower thresholds for high-risk customers, assuming they need closer scrutiny. Evidence-based compliance asks: do high-risk customer alerts convert to SARs at higher rates than low-risk alerts? If not, you're generating noise, not managing risk. The evidence tells you whether your risk-based theory matches reality.
This is the feedback mechanism risk-based compliance always needed but rarely got.
What to Do Instead
Stop thinking about evidence-based compliance as a regulatory burden and start treating it as a management tool.
Build measurement into your next control change. Pick one area, customer risk rating, transaction monitoring, or periodic review, and establish metrics before you implement changes. Track outcomes for 90 days. Did the change work? You now have evidence.
Audit your assumptions. List three controls your program treats as essential. For each one, write down what evidence would prove it's working. If you can't identify that evidence, you've found your starting point.
Document your decisions, not just your actions. When you allocate staff, adjust thresholds, or change review frequencies, write a two-paragraph rationale explaining what evidence informed the choice. Examiners under evidence-based regimes will ask "why this approach?" not just "did you do it?"
The Federal Reserve's proposal isn't about doing more compliance. It's about doing compliance that demonstrably works. The teams that figure this out early won't just satisfy regulators, they'll run better programs.



