Your AML compliance program passed last year's audit, but the methods criminals used last quarter didn't exist when you wrote those procedures. This checklist addresses that gap.
What This Checklist Covers
This checklist helps you build an AML compliance program that adapts to emerging threats, not just documented requirements. You'll find actionable items across customer due diligence, monitoring infrastructure, reporting mechanisms, and program governance. Each item includes what "done" looks like and common failure modes.
This isn't a first-time setup guide. It's a diagnostic tool for teams moving from static compliance to continuous adaptation.
Prerequisites
Before you start, ensure you have:
- Documented risk assessment methodology: Your institution's current risk profile, updated within the past 12 months, with identified high-risk customer segments and jurisdictions.
- Technology baseline: Existing transaction monitoring system with configurable rules and alert workflows.
- Reporting authority: Designated compliance officer with authority to file Suspicious Activity Reports (SARs) and direct access to executive leadership.
- Regulatory framework map: List of applicable regulations (Bank Secrecy Act, USA PATRIOT Act, relevant state laws) with assigned owners for each requirement.
Checklist Items
Customer Due Diligence and Risk Classification
1. Customer risk scoring reflects current threat intelligence
Review your risk scoring model against the past six months of SAR filings and enforcement actions in your sector. Adjust weights for factors that appear in actual money laundering cases.
Done: Your scoring model includes at least three risk factors updated in the past six months based on observed typologies. High-risk scores trigger Enhanced Due Diligence (EDD) automatically.
2. Enhanced Due Diligence procedures specify information sources
EDD shouldn't just mean "collect more documents." Define which additional sources you'll check for Politically Exposed Persons (PEPs), beneficial ownership structures, and source of funds verification.
Done: Your EDD procedure lists specific databases (OFAC, state UCC filings, corporate registries) and includes decision trees for when to escalate beyond standard checks.
3. Beneficial ownership data is verified, not just collected
Collecting a beneficial ownership form doesn't satisfy the requirement if you don't verify the information. Define your verification standard for entities with complex ownership.
Done: For entities with ownership through trusts or holding companies, you've documented the verification method (public records check, third-party data provider, or customer attestation with supporting evidence).
Transaction Monitoring and Watchlist Screening
4. Monitoring rules are tuned to your actual transaction patterns
Default vendor rules generate noise. Calibrate thresholds based on your customer base's legitimate activity, not generic industry averages.
Done: You've analyzed false positive rates by rule type in the past quarter and adjusted at least two threshold values. Your alert review time has decreased or remained stable despite transaction volume growth.
5. Watchlist screening runs against consolidated customer data
Screening only account opening data misses aliases, updated addresses, and related parties added after onboarding.
Done: Your screening process runs against current customer records (including beneficial owners and authorized signers) at least weekly, and you've documented how you handle partial name matches.
6. Alert disposition includes typology classification
When you clear an alert, record why it's legitimate and which money laundering typology it resembled. This data drives rule tuning and training scenarios.
Done: Your alert management system includes a required typology field (Structuring, Trade-Based Money Laundering, etc.) and a free-text business justification for every cleared alert.
Suspicious Activity Reporting
7. SAR decision criteria are documented and consistent
"Suspicious" can't be subjective. Define the threshold for filing based on specific indicators, not investigator judgment alone.
Done: You maintain a decision matrix that maps combinations of risk factors (customer type, transaction pattern, due diligence gaps) to file/no-file outcomes. Investigators reference this matrix in case notes.
8. SAR narratives describe the suspicious pattern, not just transactions
A list of transactions doesn't explain why they're suspicious. Your narrative should connect the activity to a money laundering typology.
Done: Every SAR includes a section that names the suspected typology and explains how the customer's behavior fits that pattern, using specific transaction examples as evidence.
Technology and Automation
9. Your monitoring system ingests external risk signals
Transaction patterns alone miss context. Feed your system data about sanctions updates, negative news, and regulatory alerts.
Done: You've configured automated feeds for at least two external data sources (OFAC updates, adverse media screening, or industry alert services) that trigger customer reviews without manual intervention.
10. Rule changes are version-controlled and tested
Adjusting a monitoring rule without testing creates blind spots. Treat rule changes like code deployments.
Done: You maintain a change log for all monitoring rules, including the business justification, test results showing expected alert volume change, and approval from compliance leadership before deployment.
Training and Organizational Readiness
11. Training scenarios reflect recent enforcement actions
Generic money laundering examples don't prepare staff for the schemes your institution actually faces.
Done: Your annual training includes at least two case studies from enforcement actions published in the past 18 months, with discussion of how your controls would detect similar activity.
12. Non-compliance staff understand their role in detection
Frontline employees spot suspicious behavior before it reaches the monitoring system, but only if they know what to report.
Done: Customer-facing staff have a documented escalation path for unusual customer behavior and complete scenario-based training (not just video modules) at least annually.
Audit and Program Governance
13. Independent testing covers rule effectiveness, not just existence
Confirming you have monitoring rules doesn't prove they work. Test whether your rules would detect known money laundering patterns.
Done: Your most recent independent audit included transaction testing where auditors seeded suspicious patterns into historical data and verified your system generated alerts.
14. Program updates are driven by threat intelligence, not just audit findings
Waiting for an audit to reveal gaps means you're always behind. Review enforcement actions and typology reports quarterly.
Done: You maintain a threat intelligence log that documents new typologies reviewed each quarter and lists corresponding program updates (new monitoring rules, procedure changes, or training topics).
Common Mistakes
Treating watchlist screening as one-time: Screening only at onboarding misses customers who become PEPs or entities added to sanctions lists after you established the relationship.
Tuning rules to reduce alerts without analyzing false negatives: Lower alert volume feels efficient until you realize you're missing actual suspicious activity. Track both false positive AND false negative rates.
Filing SARs without internal investigation: A SAR isn't a substitute for determining whether you should exit the relationship or freeze funds. Complete your investigation first.
Assuming technology solves the problem: Machine learning models detect patterns in historical data. They don't replace human judgment about whether new activity is suspicious.
Next Steps
Run through this checklist quarterly, not annually. Mark items you can't verify as "done" and assign owners to close those gaps within 30 days.
If more than three items remain incomplete after 30 days, you're operating with known blind spots. Document them as risks and present mitigation plans to your board or executive committee.
Your AML program isn't a compliance artifact. It's your institution's defense against being used for financial crime. Treat it accordingly.



