AML Program
An AML program is the documented set of controls a regulated firm must maintain to detect and deter money laundering. In the United States it is conventionally described as four pillars: written policies and procedures, a designated compliance officer, staff training, and independent review. Other regimes frame the same components differently.
Also called: AML programme · BSA/AML program · four pillars
The term describes a structure, not a document. An AML program is everything a firm does to keep criminal money out of its systems: what it writes down, who is accountable for it, how staff are trained to apply it, and how the whole thing is checked by someone other than the people running it.
The pillars
“Four pillars” is American industry shorthand rather than a phrase in any statute, but the four elements are real obligations: the Bank Secrecy Act rules require a US money services business to maintain all four.
- Written policies, procedures and internal controls, built around the risks the firm actually faces rather than a generic template.
- A designated compliance officer with day-to-day responsibility for the program.
- Training for the staff whose work touches the controls, and for the board that approves them.
- Independent testing of the program by someone who does not run it.
A fifth pillar is often added: risk-based customer due diligence, including identifying the beneficial owners behind corporate customers. In the United States that requirement covers banks, securities brokers and dealers, mutual funds and futures commission merchants — it is not part of the money services business program rule, which still has four elements. Elsewhere the same apparatus is assembled differently again: the European Union and the United Kingdom require internal policies and controls, employee screening, a compliance officer and an independent audit function, the last two only where they are appropriate to the size and nature of the business, and the United Kingdom names the responsible individual the MLRO. The family resemblance is real, because most of it descends from the standards set by FATF. FinCEN has proposed rewriting the US program rules and adding a mandatory risk assessment; as things stand in September 2026 that is still a proposal.
Why it matters
The program is the first document anyone asks for. A state licensing regulator wants it with the application. A sponsor bank wants it before opening an account. An examiner reads it and then tests it against what the firm actually did: transaction monitoring alerts and how they were cleared, training records, escalation decisions, and the last independent review and whether its findings were closed. The document is the claim; the evidence is what gets graded.
In practice
The four pillars are American shorthand, and they are a floor rather than a target: the rule requires a program to be implemented and maintained effectively, not merely written. A program that is not actually followed is treated as no program at all — examiners test the documents against alert queues, training records and escalation decisions, and it is the gap between them that gets written up.
Example
A five-person remittance startup writes a sixty-page manual, appoints its COO as compliance officer and buys a monitoring tool. Two years later an examiner asks for training records, the alert queue and the independent test. There are no training records, four hundred alerts sit unreviewed, and no review has ever been done. The manual is accurate, and the program still fails.
Commonly confused with
| Term | How it differs |
|---|---|
| Anti-Money Laundering | AML is the body of law and obligation; an AML program is the specific set of controls one firm builds to meet it. |
| Independent AML Review | The review is one pillar of the program — the periodic check on it, performed by someone who does not run it. |
See also
- Compliance OfficerA compliance officer is the individual a regulated firm formally designates as responsible for its anti-money-laundering program — the person named on a licensing application, asked for by a bank during onboarding, and interviewed by an examiner. In the United States the role is often called the BSA officer.
- Independent AML ReviewAn independent AML review is the periodic examination of a firm’s anti-money-laundering program by someone who is not responsible for running it. In the United States it is a mandatory element of the program; in the United Kingdom and European Union it is required where the size and nature of the business make it appropriate.
- Anti-Money LaunderingAnti-money laundering, usually shortened to AML, is the body of law, regulation and internal controls requiring financial firms to detect, prevent and report attempts to disguise the origin of criminal proceeds. It is an obligation placed on the firm, not a product the firm can buy.
- Bank Secrecy ActThe Bank Secrecy Act is the 1970 United States statute, heavily amended since, that requires banks, money services businesses and other financial institutions to keep records, register where applicable, report large cash transactions and suspicious activity, and maintain an anti-money-laundering program.
- Customer Due DiligenceCustomer due diligence, or CDD, is the baseline set of checks a regulated firm performs on a customer: who they are, who owns and controls them, and what activity to expect. It is done at onboarding and then kept current for as long as the relationship lasts, with risk rather than a fixed calendar setting when it is revisited.
