A 50% jump in AML fines in 2022, totaling nearly $5 billion, wasn't due to negligence by compliance officers. It happened because your program design hasn't kept up with how criminals move money today. Cross-border flows, unconventional laundering methods, and evolving regulatory expectations have all outpaced most institutions' compliance frameworks.
This checklist helps you close that gap. It's built around the reality that your AML program must function as an integrated system, not just a collection of separate controls. Each item includes a specific action, the compliance checkpoint, and what success looks like.
What This Checklist Covers
You'll find the core elements needed to align your AML program with current FATF recommendations and the regulatory expectations enforced by bodies like FinCEN, the FCA, and MAS. This isn't about checking boxes for your next audit. It's about building a program that can detect structuring patterns in real time, flag Politically Exposed Person (PEP) relationships before onboarding, and produce defensible Suspicious Activity Reports (SARs) when examiners ask why you filed.
Prerequisites
Before you start, confirm you have:
- Executive sponsorship with budget authority. AML technology investments require sign-off from someone who controls spending, not just compliance headcount.
- Access to your current transaction monitoring rules. You can't tune what you can't see. If your vendor won't share rule logic, that's a separate problem to solve first.
- A named owner for each regulatory jurisdiction you operate in. If you're licensed in multiple countries, someone must own the interpretation of local requirements, not just "corporate compliance."
AML Program Checklist
1. Risk Assessment Reflects Current Threat Vectors
Action: Update your institutional risk assessment to include Trade-Based Money Laundering (TBML) scenarios, cryptocurrency on/off-ramps, and high-risk sectors beyond traditional banking (e.g., used goods markets, digital asset exchanges).
Checkpoint: Your risk assessment document should cite specific typologies your institution is exposed to, not generic language about "emerging threats."
Good looks like: A risk matrix that maps each product line to FATF-identified laundering methods, with scoring that reflects your actual customer base and transaction patterns.
2. Customer Due Diligence Integrates Watchlist Screening at Onboarding
Action: Configure your KYC workflow to screen against OFAC, EU sanctions lists, and PEP databases before account activation, not after the first transaction posts.
Checkpoint: OFAC requires screening before establishing a customer relationship. If your system allows account opening before screening completes, you're non-compliant.
Good looks like: Zero accounts activated without a completed screening record. Your audit log should show screening timestamp before account status changed to "active."
3. Transaction Monitoring Rules Tuned Within the Last 90 Days
Action: Review alert volumes, false positive rates, and tune thresholds for structuring detection, rapid movement of funds, and layering patterns. Document what you changed and why.
Checkpoint: The FFIEC BSA/AML Examination Manual expects regular tuning. If your last tuning cycle was over six months ago, examiners will ask why alert volumes haven't improved.
Good looks like: A tuning log that shows threshold adjustments, the data analysis that supported each change, and measurable improvement in investigator efficiency (e.g., time-to-disposition on alerts decreased by 20%).
4. Enhanced Due Diligence Procedures for High-Risk Jurisdictions
Action: Define what "enhanced" means for your institution when dealing with customers or counterparties in FATF-identified high-risk jurisdictions. Document the additional information you collect and how you verify it.
Checkpoint: The FATF lists jurisdictions with strategic AML deficiencies. If you onboard customers with ties to these regions without enhanced procedures, you're accepting risk you can't defend.
Good looks like: A written procedure that specifies: source of wealth documentation required, additional screening steps, senior management approval before onboarding, and ongoing monitoring frequency (e.g., monthly transaction review, not quarterly).
5. SAR Filing Workflow Includes Legal and Operations Review
Action: Map your current SAR process from alert generation through FinCEN filing. Identify where bottlenecks occur and where decisions lack documentation.
Checkpoint: The Bank Secrecy Act requires SARs within 30 days of initial detection. If your average time-to-file exceeds 25 days, you have no buffer for complex cases.
Good looks like: A workflow diagram showing: investigator analysis (5 days), compliance review (3 days), legal review (2 days), final sign-off (1 day), filing (1 day). Each stage has a named owner and escalation path for delays.
6. AI-Driven Transaction Monitoring Pilot in Production
Action: If you haven't deployed machine learning for transaction monitoring, start a pilot on one product line. If you have deployed it, validate that your model isn't introducing bias or missing patterns your rules-based system caught.
Checkpoint: Regulators expect you to use technology that improves detection. Relying solely on static rules when better tools exist creates supervisory risk.
Good looks like: A pilot that processes at least 10,000 transactions per day, produces alerts that investigators can explain, and includes a feedback loop where investigators' decisions retrain the model.
7. Cross-Border Information Sharing Agreements Documented
Action: If you operate in multiple jurisdictions, document your legal basis for sharing customer information across entities for AML purposes. Confirm it complies with GDPR or other data protection regimes.
Checkpoint: The FATF emphasizes international cooperation, but you can't share data that violates data protection laws. Your legal team must reconcile these requirements.
Good looks like: A data-sharing agreement reviewed by counsel in each jurisdiction, with technical controls (e.g., data minimization, encryption) that limit exposure if a breach occurs.
8. Beneficial Ownership Verification for Entity Customers
Action: Implement procedures to identify and verify beneficial owners (25% or greater ownership) for all legal entity customers, per the Corporate Transparency Act requirements.
Checkpoint: FinCEN's beneficial ownership rule requires collection at account opening. If you're waiting for customers to volunteer this information, you're non-compliant.
Good looks like: A KYC form that explicitly requests beneficial ownership information, a process to verify it against public records or third-party data, and a system field that flags incomplete records before onboarding proceeds.
9. Employee Training Includes Scenario-Based Testing
Action: Replace annual click-through training with scenario-based exercises where employees identify red flags in realistic transaction patterns.
Checkpoint: Examiners test your staff during audits. If your employees can't articulate why a transaction pattern is suspicious, your training program failed.
Good looks like: Quarterly exercises where frontline staff review anonymized case studies, document their analysis, and receive feedback. Pass rate above 85% on identifying structuring and layering patterns.
10. Technology Stack Supports Real-Time Screening
Action: Evaluate whether your current systems can screen transactions before settlement, not just after. If they can't, build a business case for infrastructure upgrades.
Checkpoint: Real-time screening prevents sanctioned parties from receiving funds, not just detecting the violation after it occurs. Post-transaction screening creates remediation costs and regulatory exposure.
Good looks like: Payment processing that queries watchlists before authorization, with automatic blocking for matches and a manual review queue for near-matches. Average screening latency under 200 milliseconds.
Common Mistakes
Treating AML as an IT problem. Technology enables your program, but it doesn't design your risk appetite or write your procedures. Compliance must own the requirements; IT implements them.
Waiting for perfect data before tuning. You'll never have perfect transaction data. Tune your rules based on the data quality you have now, then improve data quality in parallel.
Filing SARs to avoid criticism, not because you identified suspicious activity. Defensive filing creates noise in the FinCEN system and wastes investigator time. File when you have a reasonable basis, not when you're uncertain and want cover.
Next Steps
Pick three items from this checklist where you know you're weakest. Assign an owner and a 60-day deadline for each. Don't try to fix everything at once, you'll fix nothing.
Schedule a quarterly review of this checklist with your compliance committee. Regulatory expectations evolve, and your program must evolve with them. The institutions that treat AML as a static compliance obligation are the ones writing $50 million settlement checks.


