Anti-Money Laundering (AML) Compliance Project Plan
AML Programs Fail Exams When They're Built for Regulators, Not for Risk
The worst AML programs have excellent documentation and poor detection. Policies are comprehensive, training completion rates are high, and the transaction monitoring system generates thousands of alerts per month — most of which are cleared by analysts in 10 minutes without any investigation. The bank examiners note the high alert volume and fast clearance times, and they ask the uncomfortable question: if you're clearing 95% of alerts without escalation, are you actually detecting anything?
A properly designed AML program identifies the institution's actual money laundering risks, implements monitoring calibrated to detect those specific risks, and produces SAR filings that reflect genuine analysis. The project plan starts with risk, not documentation.
Phase 1: AML Risk Assessment (Weeks 1–4)
The risk assessment drives every subsequent program decision. It cannot be a box-checking exercise.
Risk dimensions:
Customer risk:
- Business type: cash-intensive businesses (restaurants, retail, car washes) carry higher risk
- Geographic origin: customers from FATF-identified high-risk jurisdictions
- PEP exposure: politically exposed persons and their family members
- Sanctions exposure: any customer with potential OFAC nexus
- Non-profit organizations: can be used for terrorist financing
Product and service risk:
- Cash-intensive products: always higher risk
- Anonymous or near-anonymous products: prepaid cards, crypto
- Cross-border products: wire transfers, international remittances
- High-volume low-value: structuring vulnerability
Channel risk:
- Online and mobile: non-face-to-face, harder to verify identity
- Agent or third-party: controls may vary
- Correspondent banking: relies on the AML program of the correspondent institution
Geographic risk:
- FATF grey list and blacklist countries
- Countries with significant narcotics trafficking or corruption
- High-risk domestic geographies
Output: AML risk rating matrix by business line — approved by the Board of Directors. The risk assessment is a living document updated annually and when material business changes occur.
Phase 2: AML Program Design (Weeks 4–8)
A BSA/AML program must have five elements (Bank Secrecy Act requirement):
1. Internal policies, procedures, and controls:
- BSA/AML Policy (board-approved)
- CDD and KYC Procedures
- SAR Filing Procedures (when to file, who approves, where to file)
- CTR Procedures (for $10,000+ cash transactions in banks)
- OFAC Screening Procedures
2. Designated BSA/AML Compliance Officer:
- Named individual responsible for day-to-day BSA/AML compliance
- Sufficient authority, resources, and independence
- Not subordinate to revenue-generating functions
3. Ongoing employee training:
- Annual AML training for all employees
- Role-specific training for front-line staff (enhanced — they see customers)
- Training records maintained
4. Independent testing:
- Annual audit of the AML program
- Conducted by internal audit or external party
- Findings reported to audit committee or board
5. Customer due diligence (CDD):
- Know Your Customer at onboarding
- Beneficial ownership collection for business accounts
- Ongoing monitoring and periodic review
Phase 3: Technology Selection and Configuration (Weeks 6–14)
Transaction monitoring systems generate alerts when transaction patterns match typologies for money laundering.
System selection:
- NICE Actimize: enterprise, highly configurable, expensive
- Verafin: strong for community banks and credit unions
- Featurespace: ML-native, adaptive fraud and AML
- Quantexa: network analytics, strong for identifying related-party risk
Alert scenario design:
The most common mistake is deploying a system with default scenarios tuned for a different institution type. Customize scenarios to your actual risk profile.
Key scenario types:
- Structuring: multiple transactions just below CTR reporting thresholds
- Rapid movement: funds in, funds out within a short window with no business purpose
- Dormant account activity: sudden high activity after long period of inactivity
- Velocity: transaction volume or amount significantly exceeds customer's established pattern
- Layering: complex series of transactions with no apparent business purpose
Threshold calibration:
- Alert thresholds set too low = alert fatigue; analysts clear thousands of alerts that reveal nothing
- Alert thresholds set too high = missed detection
- Start with tighter thresholds, measure false positive rate, tune upward where justified
Alert workflow:
- Alert → Analyst queue → Investigation → Disposition: clear, escalate, file SAR
- Escalation path: complex cases escalate to BSA Officer
- SAR decision → Legal/Compliance review → File or close with documented rationale
Phase 4: Customer Due Diligence Process (Weeks 8–12)
CDD is the foundation of AML. You can't monitor for suspicious activity if you don't know who your customer is.
Minimum required information (CDD Rule, 31 CFR 1020.220):
- Name
- Date of birth (individuals) or date of formation (businesses)
- Address
- Identification number: SSN/TIN or passport number
Beneficial ownership (for legal entity customers):
- Identify all individuals owning 25%+ of the legal entity
- Identify the individual with significant responsibility for managing the entity
- Collect name, DOB, address, and identification number for each beneficial owner
Enhanced due diligence (EDD) triggers:
- High-risk customer risk rating
- High-risk geography
- PEP relationship
- Complex ownership structure
- Unusual transaction activity at onboarding
EDD requires: understanding the nature and purpose of the account, source of funds, and source of wealth. Document EDD conclusions.
Periodic review:
- Low-risk customers: review every 3 years
- Medium-risk: every 2 years
- High-risk: every 1 year or more frequently
- Event-triggered: change of ownership, unusual transaction pattern, adverse news
Phase 5: Training and Independent Testing (Weeks 12–16)
Training program:
- Annual BSA/AML training: all employees
- Role-specific training: customer-facing staff, operations, compliance team
- New hire training: within 30 days of hire
- Topics: red flags by customer type, how to identify suspicious activity, how to escalate, SAR filing obligations
Independent testing:
- Conducted annually
- Scope: all five pillars of the BSA/AML program
- Testing areas: transaction monitoring effectiveness (sample of alerts cleared to verify conclusions), SAR quality (review filed SARs for completeness), CDD completeness (review customer files for required information), OFAC screening validation
- Findings reported to audit committee or board
Phase 6: Regulatory Examination Readiness (Weeks 16–20)
Bank examiners (OCC, FDIC, Federal Reserve, state regulators) examine AML programs on a defined cycle. Preparation is year-round.
Examination preparation:
- Organize program documentation: risk assessment, policies, procedures, training records, audit reports, SAR filings, OFAC screening documentation
- Conduct mock examination: have an experienced external compliance consultant conduct an exam
- Prepare work request responses: common exam information requests include transaction monitoring alert lists, SAR filings, CDD file samples, training completion records
Remediation readiness:
- If prior examination had findings: document remediation status for each finding
- Examiners will test whether prior findings were actually remediated or just documented
Build the AML compliance project plan in gantt-chart.io with clear milestones for Board approval of the risk assessment (Phase 1 output), BSA Officer designation, independent testing completion, and examination readiness sign-off. The risk assessment milestone in Week 4 is the critical path gating point — program design cannot be finalized until the institution's risk profile is documented and approved.