Skip to main content
Your Board Isn't the Problem With AML ComplianceAML and KYC
5 min readFor AML/KYC Compliance Officers

Your Board Isn't the Problem With AML Compliance

The Conventional Wisdom

Ask any AML officer where their program struggles, and you'll often hear: "We need more board engagement." Regulatory guidance seems to support this view. The FFIEC BSA/AML Examination Manual emphasizes board oversight. Many sources stress that boards must set the "tone at the top" and form sub-committees to monitor compliance practices. The usual advice is clear: get your board more involved, and your AML program will improve.

So compliance officers prepare quarterly board presentations, schedule annual training sessions, and brief directors on regulatory changes. Yet, the program still underperforms.

The Real Issue

The board isn't your AML program's weak link. Your execution is.

I've observed this across many institutions: boards that receive monthly compliance briefings still produce programs that fail examinations. Meanwhile, institutions with boards that meet compliance committees quarterly but have empowered, properly resourced AML officers consistently pass scrutiny.

Focusing on board involvement treats a symptom, not the disease. When your Suspicious Activity Report (SAR) quality is poor, the problem isn't that your board didn't review enough SAR metrics. It's that your transaction monitoring system generates too many false positives, your analysts lack training on typologies, or your escalation criteria are vague. When your customer due diligence is inconsistent, more board meetings won't fix the fact that your front-line staff don't understand beneficial ownership requirements under the Corporate Transparency Act.

The board's actual job is structural: ensure the AML officer has authority, budget, and access. Set expectations that financial crime risk matters as much as credit risk or operational risk. Remove obstacles when the compliance function conflicts with business units. That's governance. Everything else is theater.

Effective Board Oversight

Consider what effective board oversight actually requires. Boards should "provide oversight and guidance to the Compliance Committee and Senior Management to implement the Compliance program." Notice what this doesn't say: it doesn't say boards should design transaction monitoring rules, review individual case files, or approve every policy update.

Institutions that excel at AML compliance share a pattern. Their boards focus on three specific activities:

Resource Allocation Decisions. When the AML officer requests budget for a new screening tool or additional analysts, the board evaluates that request against ML/TF risk assessment findings. They don't micromanage the tool selection, but they ensure the function isn't starved of resources while other departments expand.

Authority Clarification. The board makes clear that when the AML officer escalates a relationship for exit, business units can't override that decision by appealing to regional management. The compliance function's authority comes directly from board mandate, not from winning internal political battles.

Accountability for Risk Assessment Integration. The board requires that ML/TF risk assessment findings inform strategic decisions. If your assessment identifies correspondent banking relationships in high-risk jurisdictions as your top vulnerability, the board should ask why the business development team is still pursuing expansion there. This is integration, not just acknowledgment.

What doesn't move the needle? Monthly presentations where the AML officer reports the same metrics in slightly different formats. Training sessions where board members learn to spot structuring schemes they'll never personally encounter. Sub-committees that review individual SAR filings to demonstrate engagement.

What to Do Instead

Restructure your board engagement around decision points, not information dumps.

Annual: Risk Appetite and Resource Planning. Present your ML/TF risk assessment findings once per year, in depth. The board should understand your risk profile well enough to make informed decisions about acceptable risk levels and resource allocation. If your assessment shows increased risk from business email compromise schemes targeting your commercial clients, the board needs to decide whether to invest in enhanced monitoring or accept the residual risk. This is a strategic decision, not a compliance update.

Quarterly: Exception Reporting and Obstacle Removal. Brief the board only on material compliance issues and systemic problems. A material issue is a regulatory examination finding, a significant control failure, or a pattern of SAR quality deficiencies. A systemic problem is a business unit that consistently resists due diligence requirements or a technology limitation that prevents effective monitoring. The board's role is to direct resources toward fixing these problems and, if necessary, overrule business unit objections.

Ad Hoc: Authority Confirmation. When you need to exit a customer relationship, impose enhanced due diligence that affects profitability, or decline a new product line due to ML/TF risk, you need board backing. This shouldn't require a formal meeting. It requires a governance structure where the board has pre-authorized these actions within defined parameters.

Never: Operational Review. The board shouldn't review individual customer files, approve specific monitoring scenarios, or evaluate analyst performance. That's management's job. The board's involvement in operational details signals that you lack a qualified AML officer or that management doesn't trust the compliance function. Both are governance failures, but they're not solved by more board meetings.

Redirect the time you currently spend on board presentations toward strengthening your actual controls. Train your analysts on Wolfsberg Principles application. Tune your transaction monitoring to reduce false positive rates. Document your risk assessment methodology so it's defensible under examination. These activities improve compliance outcomes. Board presentations mostly improve board meeting attendance records.

When Board Engagement Matters

Board engagement does matter in specific circumstances.

If your institution is entering a new line of business with different ML/TF risk characteristics, the board needs to approve that expansion with full understanding of the compliance implications. If you're acquiring another institution, the board must ensure adequate due diligence on the target's AML program and approve integration plans. If you're facing a regulatory enforcement action, the board's visible commitment to remediation is both required and appropriate.

The board also sets culture, and culture does matter. When board members treat compliance as a cost center to minimize rather than a risk management function to resource appropriately, that attitude cascades through the organization. When they ask tough questions about why SAR filing timelines are slipping or why customer due diligence is inconsistent, management pays attention.

But culture-setting happens through resource decisions and accountability mechanisms, not through sitting through more presentations. A board that approves the AML officer's budget request and holds business unit leaders accountable for compliance cooperation sets a stronger tone than a board that attends monthly compliance briefings but cuts the compliance budget when earnings are under pressure.

Your board's job is to govern, not to manage. Stop asking them to do your job, and start asking them to let you do yours with appropriate authority and resources. That's the engagement that actually prevents money laundering.

You Might Also Like