
Every AML enforcement action starts with a program that existed on paper. The policies were written, the officer was designated, the training was delivered. What failed was the gap between the document and the operation.
Capital One was fined $390 million for willful and neglectful BSA violations after failing to report $16 billion in transactions, despite repeated regulator warnings. That is not a program that was missing. It is a program that was not working, and nobody with authority acted on what they already knew.
This guide covers the five pillars a US AML program is required to have, the seven steps to build one on top of them, and what examiners actually test in 2026.
An AML compliance program is the set of policies and procedures establishing the infrastructure for an organization's compliance operations. It sets guidelines for risk and compliance teams and defines how a financial institution will identify and combat money laundering.
It cannot be one-size-fits-all. The program has to be tailored to the institution's business, the nature of its products and services, and its customer base. An institution serving cash-intensive merchants and one serving salaried consumers face different risks, and a program that does not reflect that is not risk-based, whatever it says on the cover.
Maintaining it is continuous rather than a project. Rules change, products launch, customer mixes shift, and a program calibrated correctly two years ago stops being calibrated.
An AML program provides the guidance risk and compliance professionals need to do their work, and it is the artifact examiners assess. Failure carries direct consequences, and they are large.
Beyond Capital One's $390 million, Sunrise Brokers LLP was fined over £600,000 for inadequate AML systems and controls, specifically a lack of screening processes, senior management engagement, independent assurance, and escalation procedures. In 2020, Westpac was fined AU$1.3 billion, the largest penalty an Australian bank had received at the time, for failing to report 23 million violations including inadequate KYC on transactions linked to child exploitation.
The pattern across all three is that the deficiency was in the operation rather than the paperwork.
In the United States the governing legislation is the Bank Secrecy Act, which requires financial institutions to maintain a program built on five pillars.
.png)
Designate a BSA compliance officer to own AML operations. In some jurisdictions the role is called a Money Laundering Reporting Officer.
This person is the focal point for money laundering and financial crime matters, and the intermediary between compliance and senior management. Their responsibilities typically include:
The requirement that matters most is authority. A compliance officer whose findings can be overruled by revenue priorities is a title rather than a control, and enforcement actions consistently show senior management having been warned before the failure.
Controls have to detect suspicious activity, not just describe how it would be detected. That starts with a strong KYC framework at onboarding, covering who the customer is, the nature of their business, and their expected activity.
Ongoing monitoring is the other half, and the more commonly deficient one. Customers need monitoring across the whole relationship rather than only at onboarding, because the customer who looked ordinary at account opening is the one whose behavior changes.
Key controls include corporate governance, risk assessment, senior management accountability, training, internal and external communication, audits, PEP and sanctions screening, escalation procedures, and documented risk mitigation.
Training requires clear documentation of policies and procedures, plus enough instruction that team members can perform their duties competently. Negligence and incompetence are not defenses.
The harder problem is reach. Compliance professionals consistently report difficulty getting other departments to understand why the program exists. Explaining the consequences of non-compliance, using real scenarios rather than abstractions, is what turns a training requirement into an actual control.
An independent audit evaluates whether the program works. It has to be conducted by someone unaffiliated with the program's development, which is the part institutions most often get wrong.
Audit is also where you find out whether employees and senior management are actually following the procedures, as distinct from whether the procedures exist.
Customer due diligence investigates the person behind an account to establish risk level. It must be applied on a risk basis, weighing the nature of the relationship, industry, jurisdiction, and source of funds.
It also has to be refreshed. Information collected at onboarding decays, and periodic review is what keeps a risk rating meaningful. The penalties for weak KYC procedures are among the largest on record.
A recurring theme in AML failures is the absence of proper risk management around customer due diligence and case escalation. Most would have been avoidable with clear CDD procedures and a working channel for escalating suspicious activity.
Every effective program starts with senior leadership actually engaging with the risk and compliance function early, rather than being briefed after decisions are made. A collaborative risk culture is what makes compliance efficient, because risk gets considered when a product is designed instead of discovered after launch.
Every program needs a clear leader responsible for guiding the team, resolving escalations, and enforcing the program across the organization. They work across departments, and their most valuable output is often getting product teams to consider AML implications during development.
A written policy establishes a governance structure with clear roles, opens a channel between departments, and defines how resources contribute to maintaining compliance.
It has to be accessible to the whole organization. A policy that exists in a folder nobody opens has no operational effect.
Access to the policy is not enough. Every team member should understand how the AML program affects their role and what is expected of them.
Build training that covers onboarding for new staff and periodic refreshers for existing staff, and update the material as typologies and regulations change.
Transaction and behavior monitoring is where a program either detects something or does not. It surfaces red flags, inconsistencies, and emerging patterns across the customer lifecycle.
The practical requirement is that detection logic can change quickly. When adjusting a rule requires an engineering ticket, the program moves at the speed of someone else's sprint planning while typologies do not wait. Our complete guide to AML transaction monitoring covers the mechanics.
Conduct audits periodically and update them against the organization's current risks and regulatory obligations. Detection methods have to evolve at the pace laundering methods do.
Review the program for weaknesses deliberately, and use both internal and external auditors. An AML quality assurance function is how most institutions evidence ongoing testing between formal audits.
Define guidelines and procedures for the incidents that will arise: security breaches, categories of suspicious activity, internal misconduct. Clear procedures written in advance are what allow a team to respond quickly rather than improvising under pressure.
Three areas have moved from good practice to examination focus.
Whether your risk assessment drives your controls. Examiners increasingly work backward: here is a rule, show me the identified risk it addresses. A control that cannot be traced to a documented risk assessment is a finding, even if the control works.
Whether you can explain an automated decision. As institutions adopt AI in compliance operations, the expectation is that you can demonstrate why the system produced the outcome it produced, in terms an examiner accepts. "The model scored it that way" is not an answer. Our FinCEN regulatory hub tracks current proposals.
Whether coverage matches the business. The largest recent enforcement actions turn on the gap between what a program claimed to cover and what it actually covered. Documented coverage, and documented reasoning behind tuning decisions, is now as important as detection performance.
Five things that make a policy usable rather than decorative.
Keep it simple. Written clearly enough to be understood at every level of the company, with concise language and explicit objectives. Review it periodically.
Explain the why. Departments motivated by different metrics need to understand why not every customer can be safely onboarded, and why some jurisdictions are off limits. Without the reasoning, the policy reads as an obstacle.
Give examples. Real scenarios make a policy comprehensible in a way abstract rules do not, and they convey the consequences of not following it.
Use a positive tone. People adopt policies they feel part of. A punitive tone produces the minimum compliance necessary and nothing more.
Define roles and responsibilities. Every person should understand their role's purpose and know who to go to with a compliance question or suspicion. That is what creates accountability across an organization rather than just inside the compliance team.
Unit21 provides the infrastructure for the operational side of a program: detection, investigation, case management, and regulatory filing in one place.
Your team owns the detection logic. Transaction monitoring rules are written and tuned in a no-code interface by the people who understand the risk, and changes can be tested against historical data before they go live. That closes the gap between identifying a new risk in your assessment and actually detecting it.
Every decision is explainable. Detection logic is explicit rather than an opaque score, and the audit trail records what changed, when, and by whom. For AI Agents, every action is logged: which tasks ran, what data was analyzed, what the output was, what the human did with it, and which agent configuration was running at the time. That last detail is the one examiners press on.
Investigation is automated, judgment is not. Unit21's AI Agents work an alert end to end, gathering evidence, mapping entity relationships, and drafting narratives for analyst review. Uphold reduced SAR preparation time from roughly a week to under 30 minutes after implementing them. [[ VERIFY, note 5 ]]
Your data stays yours. Customer data does not train Unit21's models. Each case produces a record for your compliance file, not training data for someone else's system.
Case management, customer risk rating, and regulatory filing run on the same platform, so outcomes feed back into tuning rather than disappearing into a separate tool.
For a deeper look at how agentic AI fits an AML operation, see our practitioner's guide and why configurable AI matters for compliance teams.
Unit21 is trusted by over 200 customers across 90 countries, including Sallie Mae, Chime, Intuit, and Green Dot. [[ VERIFY, note 5 ]]
To see it against your own program, book a demo. You can also watch a short video on how Unit21 handles AML compliance operations.
What are the 5 pillars of AML compliance?
Designation of a compliance officer, development of internal controls, an ongoing training program, independent audits and reviews, and customer due diligence. The first four derive from the Bank Secrecy Act, with customer due diligence added as the fifth pillar under FinCEN's CDD rule.
Is an AML compliance program legally required?
For regulated financial institutions in the US, yes, under the Bank Secrecy Act. An inadequate program is treated as a violation in its own right, separate from whether laundering is found. Specific obligations vary by institution type and jurisdiction.
How often should an AML compliance program be reviewed?
At minimum annually, and additionally whenever something material changes: a new product, a new payment rail, a new customer segment, a new jurisdiction, or a regulatory update. Programs decay because the business moves and the program does not.
Who is responsible for an AML compliance program?
The designated BSA compliance officer owns it, but accountability sits with senior management and the board. Enforcement actions consistently find that leadership had been warned before the failure, which is why authority for the compliance function matters as much as competence.
What is the difference between an AML policy and an AML program?
The program is the whole operational apparatus: people, controls, systems, training, monitoring, and audit. The policy is the written document that governs it. A strong policy with a weak program is the most common failure pattern in enforcement actions.
What does an examiner look for first?
Usually the risk assessment, and whether your controls trace back to it. A control that works but cannot be connected to an identified risk is difficult to defend, and a risk identified in the assessment with no corresponding control is a straightforward finding.
How long does it take to build an AML compliance program?
It varies with the institution's complexity, but the sequencing matters more than the timeline. The risk assessment comes first, because everything downstream, controls, thresholds, training focus, and monitoring scope, follows from it. Programs built to satisfy a regulation without a documented risk assessment underneath tend to fail examination on exactly that point.
You have reached the end of this guide. If you have not read the earlier chapters, jump back to the start to see everything covered.

Gal Perelman is the Product Marketing Lead at Unit21, where she spearheads go-to-market strategies for AI-driven risk and compliance solutions. With over a decade of experience in the fintech and fraud sectors, she has led high-impact launches for products like Watchlist Screening and AI Rule Recommendations.
Previously, Gal held marketing leadership roles at Design Pickle, Sightfull, and Lusha. She holds a Master’s degree from American University and a Bachelor’s from UCLA, and is dedicated to helping banks and fintechs navigate complex regulatory landscapes through innovative technology.