← All PostsSenior officer reviewing supporting documentation for the NYDFS Part 504 annual certification
Anti-Money Laundering

Where AML Compliance Programs Break Under Examination

By Thomas W. Raftery III —
A former Inspector General, Raftery has extensive experience advising boards and audit committees, and is a member of the Association of Inspector Generals. He built Falcon's associate network from former federal, state, and local law enforcement officers and certified financial professionals.

AML programs rarely fail on paper. They fail in execution. Examiners find transaction monitoring tuned to suppress alert volume, customer risk ratings that were never refreshed, and independent testing performed by people who report to the person being tested. Each finding carries lookback exposure that costs far more to remediate than to prevent.

Key Takeaways

Introduction

AML programs rarely fail on paper. They fail in execution. Examiners find transaction monitoring tuned to suppress alert volume, customer risk ratings that were never refreshed, and independent testing performed by people who report to the person being tested. Each finding carries lookback exposure that costs far more to remediate than to prevent.

And the standard those programs are measured against is currently being rewritten.


What examiners are actually testing

The FFIEC BSA/AML Examination Manual is the document your examiner works from, and it is publicly available. Compliance officers who have not read the relevant sections are preparing for an exam without reading the exam.

The structure is consistent. Scoping reviews prior findings, the institution's risk assessment, and any change in business model. Testing samples customer files, suspicious activity reports, transaction monitoring alerts, and training records to determine whether documented policy matches actual practice. Conclusions are graded against the manual's core procedures and reported as Matters Requiring Attention or, for serious gaps, formal enforcement.

Note the phrase that does the work: whether documented policy matches actual practice. Nearly every significant finding traces back to a divergence between the two. The program says annual refresh; the files show three-year-old risk ratings. The program says all alerts are dispositioned within 30 days; the queue shows a 900-item backlog. The program describes escalation criteria; no one can produce an escalated case.

The manual is also live. On February 27, 2026, the FFIEC revised five sections to remove references to reputational risk, consistent with Executive Order 14331 of August 7, 2025. Those revisions did not establish new requirements. A compliance officer relying on a manual excerpt downloaded two years ago is working from a superseded document.

Compliance officer comparing written AML policy against transaction monitoring output during a program review

The pillars, and which one actually fails

The BSA program requirements are commonly described as four pillars: internal controls, independent testing, a designated BSA compliance officer, and ongoing training. The 2016 customer due diligence rule added beneficial ownership requirements, frequently called the fifth pillar. A 2020 manual update established risk assessment as the foundational expectation underpinning all of them.

Programs almost never fail because a pillar is missing. Every institution has a designated BSA officer and a training deck. They fail on the quality of what sits underneath.


Failure one: transaction monitoring tuned to alert volume

This is the most common and most expensive finding in the discipline.

Monitoring thresholds get set at implementation, often by the vendor, using generic parameters. Alert volume proves unmanageable given staffing. Thresholds are widened. Volume becomes manageable. Nobody documents why the parameters changed, and nobody tests what the new settings stopped catching.

Two years later an examiner asks how the thresholds were derived, what tuning analysis supports them, when they were last validated, and what below-the-line testing shows. If the answers are "the vendor set them" and "we adjusted for volume," the institution has a monitoring system calibrated to its staffing model rather than its risk profile.

The remediation is a lookback. Lookbacks are priced in months of analyst time across a defined historical period, and the period scales with how long the deficiency ran undetected. This is why a monitoring finding is not a documentation problem. It is a budget event.


Failure two: a risk assessment that does not drive anything

The enterprise risk assessment is meant to be the foundation. In practice it is frequently an annual document produced by compliance, approved by the board, and referenced by nothing.

The examiner test is straightforward: show me where the risk assessment changed the program. If the assessment identifies elevated risk in a product line, monitoring rules, customer due diligence depth, and testing coverage should reflect it. Where the assessment and the operating program have no traceable connection, the assessment is documentation rather than governance.


Failure three: customer risk ratings assigned once and never refreshed

Risk rating at onboarding is universal. Ongoing refresh is not.

Customers change. A business banking relationship opened as low risk expands into international wire activity, adds beneficial owners, or shifts industry. If the rating still reflects the account opening, due diligence is calibrated to a customer who no longer exists.

Examiners sample for this specifically, and it is easy to find. Pull high-activity accounts, compare current activity to the rating, and check the refresh date.


Failure four: independent testing that is not independent

Independence has a structural meaning. Testing performed by someone who reports to the BSA officer, or by the consultant who built the program, is not independent regardless of how rigorous the work is.

The stakes on this one rose recently. Under OCC Bulletin 2025-37, community bank minimum examination procedures effective for examinations beginning February 1, 2026 emphasize examiner discretion to place reliance, as appropriate, on satisfactory independent testing when forming conclusions on specific procedures. Examiners may also carry forward prior cycle conclusions for one cycle on the training and BSA compliance officer pillars where the risk profile has not significantly changed.

Read that as an incentive structure. Credible independent testing can narrow the scope of your examination. Weak testing forfeits that benefit and invites full-scope review. Independent testing has moved from a compliance cost to a variable that determines how much examination you get.


Failure five: written procedures that describe a program you do not run

Procedures drift. Systems get replaced, staff turn over, workflows change, and the procedure document stays where it was three versions ago.

Examiners do not read procedures to evaluate their quality. They read them to build a test plan. Every commitment in the document becomes something to verify. An aspirational procedure manual is a list of findings the institution wrote for its own examiner.

Transaction monitoring dashboard showing alert volume and tuning parameters reviewed during AML examination

Findings, root causes, and what they cost

Common examination findings and what they cost

Monitoring thresholds unsupported
Root cause: Tuned to staffing capacity, no documented analysis
Remediation: Tuning study, below-the-line testing, model validation
Exposure: Lookback across the affected period, scaling with duration

Risk assessment disconnected from the program
Root cause: Produced as a deliverable, not used as governance
Remediation: Rebuild with traceability to controls
Exposure: Cascading findings, since other pillars lose their justification

Stale customer risk ratings
Root cause: No refresh trigger or ownership
Remediation: File remediation, refresh policy, event triggers
Exposure: Portfolio-wide file review

Independent testing that is not independent
Root cause: Reporting line or vendor conflict
Remediation: Re-perform testing through an independent party
Exposure: Loss of examiner reliance, broader examination scope

Procedures that do not match practice
Root cause: Version drift after a system or staffing change
Remediation: Rewrite to actual state, then govern change
Exposure: Each unmet commitment becomes a separate finding

SAR quality and timeliness gaps
Root cause: Backlog, inconsistent narrative standards
Remediation: Backlog clearance, quality program, retraining
Exposure: Potential enforcement, not just supervisory criticism

The cost of an AML finding is rarely the civil money penalty. It is the remediation, the lookback, and the consulting spend, and all three scale with how long the gap ran before anyone looked.


What the 2026 effectiveness proposal changes

On April 7, 2026, FinCEN issued a Notice of Proposed Rulemaking to reform AML/CFT program requirements under the Bank Secrecy Act for all regulated financial institutions. The FDIC, OCC, and NCUA issued a parallel joint proposal the same day to align their program requirements. Comments closed June 9, 2026. If adopted as issued, the final rules would take effect 12 months from issuance.

The core change is the standard itself. Existing regulations require programs to be reasonably designed to achieve compliance with the BSA, prevent money laundering, or both. The proposal would move toward evaluating whether a program is effective, meaning whether it actually detects financial crime and produces information useful to law enforcement and national security.

Per FinCEN's fact sheet, the proposal recenters the regulations on the purposes of the BSA, identifying, preventing, and reporting financial crime, and is intended to focus supervisory and enforcement actions on significant or systematic failures to implement an effective program rather than on technical deficiencies.

Three implications for a compliance officer reading this before the rule is final.

Risk assessment methodology becomes the center of gravity. An effectiveness standard means the institution must justify how it allocated compliance resources against its own risk profile. Institutions that have treated the risk assessment as an annual artifact have the most work to do, and it is work that takes quarters rather than weeks.

Resource allocation becomes a documented decision. Under a process standard, doing the required things was largely sufficient. Under an effectiveness standard, the institution must be able to show that it directed effort toward its highest risks and can demonstrate outcomes.

Much of the substance sits in the preamble. Commentators have noted that several of the most consequential expectations, particularly around national priorities, effectiveness, information sharing, and innovation, are articulated in the preamble rather than in the regulatory text. Compliance officers who read only the rule text will miss a meaningful portion of what supervisors are signaling.

A caution on timing. As of this writing the rule is proposed, not final, and proposals change between comment and adoption. Nothing here should be treated as a current legal obligation. The reason to act now is that the gap assessment work, particularly on risk assessment methodology, has a long lead time and is useful regardless of the rule's final form.


The New York overlay: Part 504

Institutions regulated by the New York State Department of Financial Services carry an obligation with no federal equivalent.

3 NYCRR Part 504, effective January 1, 2017, requires every regulated institution to maintain a transaction monitoring program reasonably designed to monitor transactions after execution for potential BSA/AML violations and suspicious activity reporting, along with a watchlist filtering program. The rule specifies attributes the program must have, including that it be based on the institution's risk assessment.

The distinguishing feature is Section 504.4. Each regulated institution must adopt and submit to the Superintendent a Board Resolution or Senior Officer Compliance Finding by April 15 each year, and must retain all records, schedules, and data supporting it for five years.

That is a personally attested annual certification, structurally similar to a Sarbanes-Oxley attestation, and it applies to bank and nonbank institutions licensed or chartered under New York's Banking, Insurance, or Financial Services Law. For New York metro institutions, Part 504 sets the practical calendar. The supporting evidence for an April certification cannot be assembled in April.

Senior officer reviewing supporting documentation for the NYDFS Part 504 annual certification

What a program review buys you before the exam

An independent program review conducted outside the examination cycle does three things a self-assessment cannot.

It finds what your examiner will find, while you still control the timeline. A deficiency discovered internally, with a documented remediation plan and evidence of progress, is a materially different conversation than the same deficiency discovered by an examiner. The finding may still be written. The characterization changes.

It tests execution rather than documentation. Internal self-assessment tends to verify that policies exist. An outside reviewer pulls files, samples alerts, traces dispositions, and checks whether the program described is the program running.

It establishes the independence that examiners can now rely on. Given the OCC's emphasis on examiner discretion to rely on satisfactory independent testing, a credible independent review has direct examination value beyond its findings.

Scope a review to cover the risk assessment methodology and its traceability to controls, transaction monitoring tuning and validation, customer risk rating currency, customer due diligence and beneficial ownership file quality, SAR timeliness and narrative quality, alert backlog and disposition standards, training records against role-based requirements, and the independence structure of testing itself.


Frequently asked questions

What are the pillars of an AML compliance program? Four pillars are codified: internal controls, independent testing, a designated BSA compliance officer, and ongoing training. The 2016 customer due diligence rule added beneficial ownership requirements, often called the fifth pillar. FFIEC guidance establishes the risk assessment as the foundational expectation underpinning all of them.

What is the FinCEN effectiveness rule? On April 7, 2026, FinCEN proposed replacing the existing "reasonably designed" program standard with an effectiveness-based framework focused on whether programs actually identify, prevent, and report financial crime. The FDIC, OCC, and NCUA issued a parallel joint proposal. Comments closed June 9, 2026. The rule is proposed, not final, and would take effect 12 months after issuance if adopted as written.

What is the most common AML examination finding? Transaction monitoring deficiencies, particularly thresholds that were tuned to manage alert volume rather than derived from the institution's risk profile, with no documented tuning analysis or validation.

What does NYDFS Part 504 require? Institutions regulated by NYDFS must maintain transaction monitoring and watchlist filtering programs meeting specified attributes, and must submit an annual Board Resolution or Senior Officer Compliance Finding by April 15 each year. Supporting records must be retained for five years.

Who can perform independent testing of an AML program? Someone structurally independent of the program being tested. Testing by staff reporting to the BSA officer, or by the consultant who designed the program, does not satisfy independence regardless of the work's quality. Qualified internal audit or an outside firm with no design role are the standard options.

How often should an AML risk assessment be updated? At minimum annually, and additionally on any material change: new products, new markets, new delivery channels, acquisitions, or significant shifts in customer composition. An assessment that has not changed across several years despite a changed business is itself a finding.

Does an AML finding always mean a penalty? No. Most supervisory findings are issued as Matters Requiring Attention with a remediation expectation. Formal enforcement is reserved for serious or systematic failures. The FinCEN proposal would further focus enforcement on significant or systematic implementation failures rather than technical deficiencies. That said, the cost of remediation and any required lookback frequently exceeds what a penalty would have been.


Where Falcon fits

Falcon conducts AML investigations, compliance program reviews, and in-house training, staffed by former FBI and IRS-CID agents and CAMS-certified specialists.

The relevant experience is operational rather than theoretical. Falcon associate Lionel Baren spent 22 years as an FBI Special Agent working money laundering, terrorism, and national security matters, rising to Supervisory Special Agent, and afterward served with the U.S. Department of the Treasury Office of Technical Assistance on assignments in Afghanistan, Jamaica, and Suriname, where his work included strengthening foreign capacity to investigate money laundering and public corruption. Investigators who have built money laundering cases read a monitoring program differently than reviewers who have only tested one. Meet the team.

For institutions whose exposure runs through third parties and foreign counterparties, see our guidance on building an FCPA compliance program that holds up under DOJ scrutiny and on vetting a foreign business partner before you sign. Where a review surfaces conduct requiring investigation, our article on the first 72 hours after you suspect internal fraud covers what happens next.

Contact Falcon to discuss an independent review of your AML program.

About the author. Thomas W. Raftery III is the Founder and Managing Partner of The Falcon Consulting Group. A former FBI Special Agent with 22 years in law enforcement, he was the first appointed Inspector General for the Delaware River Port Authority and deployed to Afghanistan with SIGAR. He specializes in white collar crime, money laundering, public corruption, and FCPA compliance. He is a Certified Fraud Examiner and holds an M.B.A. from Drexel University with a concentration in accounting.