Skip to main content
Fintech Bank Charter AML ChecklistAML and KYC
6 min readFor Fintech Risk and Compliance Teams

Fintech Bank Charter AML Checklist

The OCC's denial of Wise's national trust bank charter application, due to deficiencies in its BSA/AML/CFT programs, highlights a critical point: your fintech's compliance infrastructure will face the same scrutiny as a traditional bank's. This checklist outlines the essential AML/CFT program elements regulators expect before you submit a charter application.

If you're aiming for a bank charter, this isn't just about checking boxes. It's about demonstrating operational maturity that withstands examiner review.

Prerequisites

Before you start this checklist, confirm:

  • You have executive sponsorship for a multi-year compliance buildout. Charter applications take at least 12-18 months, and the OCC expects an established program, not just a plan.
  • You have allocated budget for experienced AML leadership. Hire from banks; don't promote your strongest engineer into a compliance role.
  • You understand the difference between MSB compliance and bank-level BSA/AML obligations. The regulatory bar is significantly higher with a charter.

AML/CFT Program Checklist

Leadership and Governance

1. Appoint a BSA/AML Officer with bank-level experience

Done when: You've hired someone who has served as a BSA Officer or Senior AML Manager at a regulated depository institution for at least three years. They report directly to your CEO or board-level risk committee.

Good looks like: Your BSA Officer can walk an examiner through a risk assessment methodology without referencing vendor templates. They've filed SARs, managed examinations, and built transaction monitoring rules at scale.

2. Establish a board-level AML oversight committee

Done when: Your board has designated a committee (or full board) that receives quarterly AML program updates, reviews high-risk customer decisions, and approves policy changes. Minutes document these reviews.

Good looks like: Board members ask specific questions about alert backlogs, model performance, and staffing gaps. They don't just accept management summaries.

Risk Assessment

3. Complete a comprehensive BSA/AML risk assessment

Done when: You've documented inherent risk across products, customers, geographies, and delivery channels. You've identified specific controls for each risk area and assigned risk ratings (high/medium/low) with supporting rationale.

Good looks like: Your risk assessment addresses cross-border payment flows, correspondent banking relationships, and high-risk customer segments with specific control mappings. It's not a generic template from a consultant.

4. Document customer risk segmentation methodology

Done when: You can explain how you assign risk scores to customers based on transaction patterns, geography, business type, and other factors. Your methodology is reproducible and auditable.

Good looks like: An examiner can pull ten customer files and independently verify that risk ratings align with your documented criteria.

Customer Due Diligence

5. Implement enhanced due diligence procedures for high-risk customers

Done when: You've defined what triggers enhanced due diligence (EDD), documented specific information requirements for EDD customers, and established refresh intervals. You maintain source documentation for all EDD findings.

Good looks like: For a customer flagged as high-risk due to international wire volume, you have documented beneficial ownership, source of funds verification, and transaction purpose justification on file, not just a checkbox in your system.

6. Establish ongoing customer monitoring with defined triggers

Done when: You've built or configured transaction monitoring scenarios that generate alerts for unusual activity relative to expected customer behavior. You document investigation outcomes and maintain a defensible alert disposition process.

Good looks like: Your monitoring scenarios cover structuring, rapid movement of funds, and geographic anomalies. You can demonstrate that you've tuned scenarios based on false positive rates and missed typologies.

Suspicious Activity Reporting

7. Build a SAR decision-making framework with clear escalation paths

Done when: You've documented who reviews alerts, who makes SAR filing decisions, and what evidence supports each decision. You maintain a complete audit trail from alert generation through SAR filing or closure.

Good looks like: Your investigators use a standardized narrative template that addresses the five essential elements (who, what, when, where, why suspicious). You have a secondary review process before filing.

8. Establish SAR filing timelines and tracking

Done when: You've implemented controls to ensure SARs are filed within 30 days of initial detection (or 60 days if no subject identified). You track all open investigations and escalate aging items.

Good looks like: You maintain a SAR filing log that includes detection date, filing date, and investigator notes. Your compliance officer reviews this log monthly.

Sanctions Screening

9. Implement real-time sanctions screening across all payment flows

Done when: You screen all parties (originators, beneficiaries, intermediaries) against OFAC SDN, EU, and UN sanctions lists before processing transactions. You've documented your screening tool configuration and match thresholds.

Good looks like: You can demonstrate that screening occurs before settlement, not in batch overnight. You maintain records of all screening hits and disposition decisions.

10. Establish a sanctions hit review and escalation process

Done when: You've documented how you evaluate potential matches, what information you collect to clear false positives, and when you block or reject transactions. You maintain records of all sanctions-related holds.

Good looks like: Your sanctions analyst can explain why a 95% name match on "Muhammad Ali" was cleared as a false positive, with supporting documentation in the customer file.

Training and Testing

11. Deliver role-specific AML training annually

Done when: All employees receive annual BSA/AML training appropriate to their role. Customer-facing staff receive transaction monitoring and red flag training. Compliance staff receive regulatory update training.

Good looks like: Your training includes case studies from actual alerts or investigations (sanitized). You test comprehension and track completion rates.

12. Conduct independent AML program testing

Done when: You've engaged a qualified third party (or internal audit, if independent) to test your AML program annually. Testing covers all program elements and results in a written report with findings.

Good looks like: Your testing report identifies specific control gaps, not just "enhance documentation", and management responds with corrective action plans and completion dates.

Common Mistakes

Hiring compliance generalists instead of AML specialists. Wise's denial specifically cited the failure to select management with sufficient AML/CFT experience. Your VP of Compliance who came from a SaaS company won't satisfy this requirement.

Treating transaction monitoring as a vendor problem. Buying a monitoring tool doesn't create a monitoring program. You need analysts who understand your customer base and can tune scenarios to your risk profile.

Documenting policies without operational evidence. Examiners will ask to see work product: investigation files, SAR narratives, risk assessment updates, board minutes. Well-written policies don't compensate for weak execution.

Underestimating the talent competition. Banks are competing for the same experienced AML officers you need. If you're offering equity instead of market-rate compensation, you'll struggle to attract candidates who can satisfy regulatory expectations.

Assuming your MSB compliance program scales to bank requirements. The OCC noted that Wise had a record of failing to comply with MSB requirements, and MSB standards are lower than bank standards. If you're struggling with state money transmitter compliance, you're not ready for a bank charter application.

Next Steps

If you've completed this checklist, you have the foundation for a charter application. But completion isn't the same as maturity. The OCC expects to see:

  • At least 12 months of operational history under your current AML program with documented board oversight
  • Evidence of continuous improvement based on testing findings and regulatory feedback
  • Adequate staffing relative to transaction volume and customer risk profile

Before you submit, consider: Wise had been operating for years and still faced a denial. The company had already paid $2.5 million to the CFPB for illegal remittance practices and faced a $4.2 million consent order from state regulators for compliance program deficiencies. Those enforcement actions didn't control the OCC's decision, but they informed it.

Your application will be evaluated on the same standard. If you have open consent orders, pending examinations, or unresolved audit findings, address them before you apply.

You Might Also Like