ACAMS Elements of an AML Program 2 — Questions and Answers
Question 1: What are the 'five pillars' of an effective BSA/AML compliance program under U.S. federal requirements?
- Policies, procedures, internal controls, risk assessment, and training
- Internal controls, a designated compliance officer, employee training, independent testing, and customer due diligence (Correct answer)
- SAR filing, CTR filing, record retention, risk assessment, and OFAC screening
- Board oversight, senior management accountability, technology systems, legal review, and regulatory liaison
Correct answer: Internal controls, a designated compliance officer, employee training, independent testing, and customer due diligence
FinCEN and banking regulators require BSA/AML programs to have five pillars: (1) internal controls, (2) a designated BSA/AML compliance officer, (3) ongoing employee training, (4) independent testing/audit, and (5) customer due diligence (added as the fifth pillar by FinCEN's 2016 CDD Rule).
The BSA/AML program requirements are codified in 12 CFR 21.21 and related regulations. The five pillars are: (1) A system of internal controls to ensure ongoing BSA compliance — policies, procedures, transaction monitoring, CTR/SAR filing systems; (2) A designated compliance officer with day-to-day responsibility for BSA/AML compliance — must have sufficient authority, expertise, and resources; (3) An ongoing employee training program — must be risk-based, role-appropriate, and regularly updated; (4) Independent testing (audit function) — must be conducted by qualified individuals independent of the compliance function, on a risk-based schedule; (5) Customer due diligence — added as the explicit fifth pillar by FinCEN's 2016 rule to emphasize its foundational importance alongside the other four elements.
Question 2: What is the role of the 'board of directors' in overseeing the BSA/AML compliance program?
- The board has no AML responsibility — that rests entirely with the compliance officer
- The board approves the AML program and policies, receives regular reports on AML program performance, and is ultimately accountable for ensuring the institution maintains effective AML controls (Correct answer)
- The board's only role is to approve the AML budget annually
- The board only becomes involved when a regulatory enforcement action is initiated
Correct answer: The board approves the AML program and policies, receives regular reports on AML program performance, and is ultimately accountable for ensuring the institution maintains effective AML controls
The board of directors bears ultimate accountability for BSA/AML compliance. The board approves the AML program and policies, receives regular compliance reports, ensures adequate resources are allocated, and is held responsible by regulators for the effectiveness of the program.
Regulatory expectations for board oversight of BSA/AML programs include: board approval of the AML program and all significant policy changes; receipt of regular (at least annual) reports on AML program performance, significant violations, SAR activity, and regulatory examination findings; ensuring the compliance officer has sufficient authority and resources; demonstrating understanding of the institution's ML/TF risk profile; oversight of AML audit findings and management responses; and ensuring appropriate consequences for employees who violate AML policies. Regulators hold boards accountable even when they delegate day-to-day compliance operations to management. In enforcement actions, individual board members may be named personally if they failed to exercise appropriate oversight.
Question 3: What is 'enterprise-wide AML risk management' and how does it differ from a siloed approach?
- It means only the largest business units have AML programs
- An integrated approach where AML risk identification, assessment, and controls are consistent and coordinated across all business units, geographies, and product lines, rather than managed independently by each unit (Correct answer)
- It means all AML decisions are centralized in a single location regardless of business geography
- Enterprise-wide AML means applying only the strictest jurisdiction's rules globally
Correct answer: An integrated approach where AML risk identification, assessment, and controls are consistent and coordinated across all business units, geographies, and product lines, rather than managed independently by each unit
Enterprise-wide AML risk management integrates AML controls across the entire institution — all business lines, geographies, and legal entities — ensuring consistent risk identification, coordinated controls, and holistic visibility into the institution's total AML exposure.
Siloed AML programs allow individual business units to develop independent risk assessments, monitoring systems, and policies, leading to: inconsistent risk ratings for the same customer across different business lines; incomplete visibility into the customer's total relationship; gaps where no one business unit recognizes the full picture of suspicious activity; and redundant compliance costs. Enterprise-wide AML risk management requires: a consolidated customer risk view that aggregates information across all products and business lines; centralized or coordinated transaction monitoring; consistent global policies with local adaptations where required; enterprise-wide risk assessments; consolidated SAR decision-making for customers with multiple relationships; and board-level visibility into total institution AML exposure. Global banks face particular challenges coordinating enterprise-wide programs across hundreds of legal entities in dozens of jurisdictions.
Question 4: What is the purpose of AML 'policies and procedures' and how should they be maintained?
- Policies are for external reporting only; procedures are for internal staff reference
- Policies establish the institution's high-level AML framework and risk appetite, while procedures provide specific, actionable guidance for implementing the policies; both must be regularly reviewed and updated to reflect regulatory changes and lessons learned (Correct answer)
- Policies are set by regulators and cannot be customized; procedures are entirely flexible
- AML policies only need to be updated when a new BSA regulation takes effect
Correct answer: Policies establish the institution's high-level AML framework and risk appetite, while procedures provide specific, actionable guidance for implementing the policies; both must be regularly reviewed and updated to reflect regulatory changes and lessons learned
AML policies establish the institution's overall approach and risk appetite, while procedures provide detailed operational guidance. Both must be current, risk-based, accessible to relevant staff, and regularly reviewed and updated to reflect regulatory changes, examination findings, and evolving risks.
Effective AML policies and procedures should: be approved by the board or appropriate senior management committee; clearly articulate the institution's risk appetite and overall AML framework; provide specific operational guidance for CDD, SAR filing, CTR filing, transaction monitoring, and other compliance activities; be risk-based and proportionate to the institution's risk profile; be accessible and comprehensible to all relevant staff; be regularly reviewed (at least annually or when triggered by regulatory changes, new products, or examination findings); incorporate lessons learned from internal audit, examination findings, and SAR trends; and be clearly assigned to process owners with accountability for maintaining currency. Outdated or incomplete policies/procedures are a common regulatory examination finding.
Question 5: What should an effective AML training program include to meet regulatory expectations?
- A single annual training module covering all BSA topics for all employees
- Risk-based training tailored to employees' roles and responsibilities, covering relevant AML regulations, red flags specific to their business line, SAR filing obligations, and training on current typologies and schemes (Correct answer)
- Training only for new hires during their onboarding process
- AML training only for employees in the compliance department
Correct answer: Risk-based training tailored to employees' roles and responsibilities, covering relevant AML regulations, red flags specific to their business line, SAR filing obligations, and training on current typologies and schemes
Effective AML training must be risk-based and role-specific — front-line tellers receive different training than private bankers or trade finance officers — and must be regularly updated to cover current typologies, schemes, and regulatory developments.
Regulatory expectations for AML training (as outlined in the FFIEC BSA/AML Examination Manual) include: training appropriate to employees' specific job functions and levels of responsibility; covering BSA/AML requirements relevant to each role; including current money laundering and terrorist financing typologies and red flags specific to the institution's products and customer base; frequency appropriate for the level of employee risk exposure (at least annually for most staff, more frequently for high-risk roles); documentation of training completion and test scores; training for senior management and board members on their AML oversight responsibilities; new employee training within a reasonable time of hire; and updates when new regulations or significant typology changes occur. Training effectiveness should be periodically tested through knowledge assessments.
Question 6: What is the purpose of 'independent testing' (AML audit) and what are the key attributes of an effective AML audit?
- The AML compliance team audits itself to identify self-improvement opportunities
- An objective evaluation conducted by individuals independent of the AML function that assesses the adequacy and effectiveness of the AML program and its compliance with BSA requirements (Correct answer)
- A review of individual SAR filing decisions conducted by the BSA Officer
- An annual IT security audit of the transaction monitoring system
Correct answer: An objective evaluation conducted by individuals independent of the AML function that assesses the adequacy and effectiveness of the AML program and its compliance with BSA requirements
Independent testing provides objective assurance that the AML program is adequate, effective, and compliant with BSA requirements. It must be conducted by parties independent of the compliance function, on a risk-based schedule, with results reported to the board.
Key attributes of an effective AML audit (per FFIEC BSA/AML Examination Manual): Independence — auditors must be independent of the BSA/compliance function (can be internal audit, external auditors, or qualified consultants); Scope — should cover all significant AML program elements including policies, procedures, CDD quality, SAR filing, CTR filing, monitoring system effectiveness, training, and vendor management; Risk-based scheduling — higher-risk business units and products audited more frequently; Qualified auditors — personnel must understand BSA/AML requirements and the institution's specific risks; Complete documentation — findings, supporting workpapers, and management responses must be retained; Reporting to the board — audit results, including deficiencies and management corrective action plans, must be reported to the board or audit committee. Audit findings must be tracked to ensure timely remediation.
What are the 'five pillars' of an effective BSA/AML compliance program under U.S. federal requirements?