Unit21 for AML

7 steps to building an effective AML compliance program

Published
February 24, 2024
Read Time
9
mins
Gal Perelman
Gal Perelman
Product Marketing Lead, Unit21
Subscribe to stay informed
Table of contents

Every AML enforcement action starts with a program that existed on paper. The policies were written, the officer was designated, the training was delivered. What failed was the gap between the document and the operation.

Capital One was fined $390 million for willful and neglectful BSA violations after failing to report $16 billion in transactions, despite repeated regulator warnings. That is not a program that was missing. It is a program that was not working, and nobody with authority acted on what they already knew.

This guide covers the five pillars a US AML program is required to have, the seven steps to build one on top of them, and what examiners actually test in 2026.

The 8-Step AML Compliance Checklist
A 65-point framework covering the controls, procedures, and documentation examiners look for. Use it to audit the program you already have.
Get your copy

What is an AML compliance program?

An AML compliance program is the set of policies and procedures establishing the infrastructure for an organization's compliance operations. It sets guidelines for risk and compliance teams and defines how a financial institution will identify and combat money laundering.

It cannot be one-size-fits-all. The program has to be tailored to the institution's business, the nature of its products and services, and its customer base. An institution serving cash-intensive merchants and one serving salaried consumers face different risks, and a program that does not reflect that is not risk-based, whatever it says on the cover.

Maintaining it is continuous rather than a project. Rules change, products launch, customer mixes shift, and a program calibrated correctly two years ago stops being calibrated.

Why it matters

An AML program provides the guidance risk and compliance professionals need to do their work, and it is the artifact examiners assess. Failure carries direct consequences, and they are large.

Beyond Capital One's $390 million, Sunrise Brokers LLP was fined over £600,000 for inadequate AML systems and controls, specifically a lack of screening processes, senior management engagement, independent assurance, and escalation procedures. In 2020, Westpac was fined AU$1.3 billion, the largest penalty an Australian bank had received at the time, for failing to report 23 million violations including inadequate KYC on transactions linked to child exploitation.

The pattern across all three is that the deficiency was in the operation rather than the paperwork.

The 5 pillars of an AML compliance program

In the United States the governing legislation is the Bank Secrecy Act, which requires financial institutions to maintain a program built on five pillars.

5 pillars of AML compliance

Pillar What it requires Where programs fail
1. Compliance officer A designated BSA officer with defined responsibility for AML operations The role exists but lacks authority to override revenue priorities
2. Internal controls KYC at onboarding plus ongoing monitoring across the customer lifecycle Strong onboarding, weak ongoing monitoring
3. Training Documented procedures and training sufficient for competent performance Delivered to compliance staff only, not to the departments creating the risk
4. Independent audit Testing by someone unaffiliated with the program's development Reviewer sits inside the function being reviewed
5. Customer due diligence Risk-based investigation of the customer, refreshed periodically Collected once at onboarding and never updated

1. Designation of a compliance officer

Designate a BSA compliance officer to own AML operations. In some jurisdictions the role is called a Money Laundering Reporting Officer.

This person is the focal point for money laundering and financial crime matters, and the intermediary between compliance and senior management. Their responsibilities typically include:

  • Receiving and evaluating suspicious activity reports
  • Making the filing decision on those reports
  • Leading the AML and counter-terrorist-financing function
  • Overseeing risk management strategy
  • Reporting to senior management and regulatory authorities
  • Acting as the primary point of contact with regulators
  • Maintaining a culture of compliance
  • Staying current with regulatory change

The requirement that matters most is authority. A compliance officer whose findings can be overruled by revenue priorities is a title rather than a control, and enforcement actions consistently show senior management having been warned before the failure.

2. Development of internal controls

Controls have to detect suspicious activity, not just describe how it would be detected. That starts with a strong KYC framework at onboarding, covering who the customer is, the nature of their business, and their expected activity.

Ongoing monitoring is the other half, and the more commonly deficient one. Customers need monitoring across the whole relationship rather than only at onboarding, because the customer who looked ordinary at account opening is the one whose behavior changes.

Key controls include corporate governance, risk assessment, senior management accountability, training, internal and external communication, audits, PEP and sanctions screening, escalation procedures, and documented risk mitigation.

3. Establishing a BSA training program

Training requires clear documentation of policies and procedures, plus enough instruction that team members can perform their duties competently. Negligence and incompetence are not defenses.

The harder problem is reach. Compliance professionals consistently report difficulty getting other departments to understand why the program exists. Explaining the consequences of non-compliance, using real scenarios rather than abstractions, is what turns a training requirement into an actual control.

4. Independent audits and reviews

An independent audit evaluates whether the program works. It has to be conducted by someone unaffiliated with the program's development, which is the part institutions most often get wrong.

Audit is also where you find out whether employees and senior management are actually following the procedures, as distinct from whether the procedures exist.

5. Perform customer due diligence

Customer due diligence investigates the person behind an account to establish risk level. It must be applied on a risk basis, weighing the nature of the relationship, industry, jurisdiction, and source of funds.

It also has to be refreshed. Information collected at onboarding decays, and periodic review is what keeps a risk rating meaningful. The penalties for weak KYC procedures are among the largest on record.

7 steps to build an AML compliance program

A recurring theme in AML failures is the absence of proper risk management around customer due diligence and case escalation. Most would have been avoidable with clear CDD procedures and a working channel for escalating suspicious activity.

Step 1. Set the tone at the top

Every effective program starts with senior leadership actually engaging with the risk and compliance function early, rather than being briefed after decisions are made. A collaborative risk culture is what makes compliance efficient, because risk gets considered when a product is designed instead of discovered after launch.

Step 2. Appoint a compliance officer

Every program needs a clear leader responsible for guiding the team, resolving escalations, and enforcing the program across the organization. They work across departments, and their most valuable output is often getting product teams to consider AML implications during development.

Step 3. Establish and share a written compliance policy

A written policy establishes a governance structure with clear roles, opens a channel between departments, and defines how resources contribute to maintaining compliance.

It has to be accessible to the whole organization. A policy that exists in a folder nobody opens has no operational effect.

Step 4. Implement a training program

Access to the policy is not enough. Every team member should understand how the AML program affects their role and what is expected of them.

Build training that covers onboarding for new staff and periodic refreshers for existing staff, and update the material as typologies and regulations change.

Step 5. Perform ongoing monitoring

Transaction and behavior monitoring is where a program either detects something or does not. It surfaces red flags, inconsistencies, and emerging patterns across the customer lifecycle.

The practical requirement is that detection logic can change quickly. When adjusting a rule requires an engineering ticket, the program moves at the speed of someone else's sprint planning while typologies do not wait. Our complete guide to AML transaction monitoring covers the mechanics.

Step 6. Run internal audits

Conduct audits periodically and update them against the organization's current risks and regulatory obligations. Detection methods have to evolve at the pace laundering methods do.

Review the program for weaknesses deliberately, and use both internal and external auditors. An AML quality assurance function is how most institutions evidence ongoing testing between formal audits.

Step 7. Set up incident management

Define guidelines and procedures for the incidents that will arise: security breaches, categories of suspicious activity, internal misconduct. Clear procedures written in advance are what allow a team to respond quickly rather than improvising under pressure.

What examiners test in 2026

Three areas have moved from good practice to examination focus.

Whether your risk assessment drives your controls. Examiners increasingly work backward: here is a rule, show me the identified risk it addresses. A control that cannot be traced to a documented risk assessment is a finding, even if the control works.

Whether you can explain an automated decision. As institutions adopt AI in compliance operations, the expectation is that you can demonstrate why the system produced the outcome it produced, in terms an examiner accepts. "The model scored it that way" is not an answer. Our FinCEN regulatory hub tracks current proposals.

Whether coverage matches the business. The largest recent enforcement actions turn on the gap between what a program claimed to cover and what it actually covered. Documented coverage, and documented reasoning behind tuning decisions, is now as important as detection performance.

How to write an AML policy

Five things that make a policy usable rather than decorative.

Keep it simple. Written clearly enough to be understood at every level of the company, with concise language and explicit objectives. Review it periodically.

Explain the why. Departments motivated by different metrics need to understand why not every customer can be safely onboarded, and why some jurisdictions are off limits. Without the reasoning, the policy reads as an obstacle.

Give examples. Real scenarios make a policy comprehensible in a way abstract rules do not, and they convey the consequences of not following it.

Use a positive tone. People adopt policies they feel part of. A punitive tone produces the minimum compliance necessary and nothing more.

Define roles and responsibilities. Every person should understand their role's purpose and know who to go to with a compliance question or suspicion. That is what creates accountability across an organization rather than just inside the compliance team.

Building your program on Unit21

Unit21 provides the infrastructure for the operational side of a program: detection, investigation, case management, and regulatory filing in one place.

Your team owns the detection logic. Transaction monitoring rules are written and tuned in a no-code interface by the people who understand the risk, and changes can be tested against historical data before they go live. That closes the gap between identifying a new risk in your assessment and actually detecting it.

Every decision is explainable. Detection logic is explicit rather than an opaque score, and the audit trail records what changed, when, and by whom. For AI Agents, every action is logged: which tasks ran, what data was analyzed, what the output was, what the human did with it, and which agent configuration was running at the time. That last detail is the one examiners press on.

Investigation is automated, judgment is not. Unit21's AI Agents work an alert end to end, gathering evidence, mapping entity relationships, and drafting narratives for analyst review. Uphold reduced SAR preparation time from roughly a week to under 30 minutes after implementing them. [[ VERIFY, note 5 ]]

Your data stays yours. Customer data does not train Unit21's models. Each case produces a record for your compliance file, not training data for someone else's system.

Case management, customer risk rating, and regulatory filing run on the same platform, so outcomes feed back into tuning rather than disappearing into a separate tool.

For a deeper look at how agentic AI fits an AML operation, see our practitioner's guide and why configurable AI matters for compliance teams.

Unit21 is trusted by over 200 customers across 90 countries, including Sallie Mae, Chime, Intuit, and Green Dot. [[ VERIFY, note 5 ]]

To see it against your own program, book a demo. You can also watch a short video on how Unit21 handles AML compliance operations.

Frequently asked questions

What are the 5 pillars of AML compliance?

Designation of a compliance officer, development of internal controls, an ongoing training program, independent audits and reviews, and customer due diligence. The first four derive from the Bank Secrecy Act, with customer due diligence added as the fifth pillar under FinCEN's CDD rule.

Is an AML compliance program legally required?

For regulated financial institutions in the US, yes, under the Bank Secrecy Act. An inadequate program is treated as a violation in its own right, separate from whether laundering is found. Specific obligations vary by institution type and jurisdiction.

How often should an AML compliance program be reviewed?

At minimum annually, and additionally whenever something material changes: a new product, a new payment rail, a new customer segment, a new jurisdiction, or a regulatory update. Programs decay because the business moves and the program does not.

Who is responsible for an AML compliance program?

The designated BSA compliance officer owns it, but accountability sits with senior management and the board. Enforcement actions consistently find that leadership had been warned before the failure, which is why authority for the compliance function matters as much as competence.

What is the difference between an AML policy and an AML program?

The program is the whole operational apparatus: people, controls, systems, training, monitoring, and audit. The policy is the written document that governs it. A strong policy with a weak program is the most common failure pattern in enforcement actions.

What does an examiner look for first?

Usually the risk assessment, and whether your controls trace back to it. A control that works but cannot be connected to an identified risk is difficult to defend, and a risk identified in the assessment with no corresponding control is a straightforward finding.

How long does it take to build an AML compliance program?

It varies with the institution's complexity, but the sequencing matters more than the timeline. The risk assessment comes first, because everything downstream, controls, thresholds, training focus, and monitoring scope, follows from it. Programs built to satisfy a regulation without a documented risk assessment underneath tend to fail examination on exactly that point.

You have reached the end of this guide. If you have not read the earlier chapters, jump back to the start to see everything covered.

Gal Perelman
Gal Perelman
Product Marketing Lead, Unit21

Gal Perelman is the Product Marketing Lead at Unit21, where she spearheads go-to-market strategies for AI-driven risk and compliance solutions. With over a decade of experience in the fintech and fraud sectors, she has led high-impact launches for products like Watchlist Screening and AI Rule Recommendations.

Previously, Gal held marketing leadership roles at Design Pickle, Sightfull, and Lusha. She holds a Master’s degree from American University and a Bachelor’s from UCLA, and is dedicated to helping banks and fintechs navigate complex regulatory landscapes through innovative technology.

Learn more about Unit21
Unit21 is the leader in AI Risk Infrastructure, trusted by over 200 customers across 90 countries, including Sallie Mae, Chime, Intuit, and Green Dot. Our platform unifies fraud and AML with agentic AI that executes investigations end-to-end—gathering evidence, drafting narratives, and filing reports—so teams can scale safely without expanding headcount.
AI Risk Infrastructure
|
7
min

Why not just use Claude for financial crime investigations?

Kunal Datta
Kunal Datta
Chief Product Officer, Unit21
This is some text inside of a div block.
Product Updates
|
7
min

Unit21 MCP, customizable webhooks, and everything else we shipped in August

Kunal Datta
Kunal Datta
Chief Product Officer, Unit21
This is some text inside of a div block.
AI Tasks
|
6
min

AI Task Spotlight | Edition No. 09: One FinCEN Alert, Two AI Tasks

Gal Perelman
Gal Perelman
Product Marketing Lead, Unit21
This is some text inside of a div block.
See Us In Action

Boost fraud prevention & AML compliance

Fraud can’t be guesswork. Invest in a platform that puts you back in control.
Get a Demo