What AML Compliance Actually Requires, Function by Function
Anti-money-laundering compliance is not a single software deployment or a checklist at account opening. It is a chain of accountable functions, evidence and escalation decisions that regulators test as one operating system.

Anti-money-laundering, or AML, rules require financial institutions and other covered firms to know who they deal with, identify suspicious activity and preserve evidence that the programme worked. The practical challenge is less about finding one perfect control than making five functions operate consistently from onboarding through account closure.
In most institutions, those functions are split across three broad groups: front-line customer or operations teams, financial-crime compliance teams, and technology, data and operations teams. They commonly report to different executives. That handoff problem is often the reason programmes fail. A screening tool may be sound, for example, but ineffective if onboarding data are incomplete, alert decisions are not fed back into customer risk ratings, or records cannot be retrieved.
1. Customer due diligence: owned by onboarding and customer operations
Customer due diligence, or CDD, establishes the customer’s identity and risk profile. Its accountable business owner is typically the onboarding or customer-operations leader, working to standards set by the AML compliance function. For legal entities, the work includes identifying beneficial owners, meaning the natural persons who ultimately own or control the customer. Enhanced due diligence is required for higher-risk relationships, such as those involving politically exposed persons, complex ownership or higher-risk geographies.
Examiners look beyond whether an identity document was collected. They test whether the institution verified it, resolved discrepancies, documented the purpose of the relationship, assigned a risk rating and refreshed the file when risk or customer information changed. Compliance should own the methodology and challenge process; operations should own execution and quality control.
2. Screening: owned by financial-crime compliance operations
Screening compares customers, beneficial owners and sometimes payments against sanctions lists, watchlists and adverse-media sources. Financial-crime compliance operations usually own alert disposition, while technology teams operate the matching engine and data feeds. The control is not simply a list search. It requires calibrated matching rules, prompt list updates, documented decisions on possible matches and escalation to sanctions specialists where required.
False positives are expected, especially where names are common or transliterated from other alphabets. The compliance issue is whether staff can show why an alert was cleared, who approved the decision and whether the underlying customer data were sufficient to make that decision.
3. Transaction monitoring: owned by AML investigations
Transaction monitoring detects patterns that may indicate money laundering, terrorist financing, fraud or sanctions evasion after a relationship begins. The usual owner is the AML investigations or financial-intelligence unit, with technology and data teams responsible for system availability, data completeness and model changes. Business teams must supply the expected customer activity captured at onboarding.
Monitoring scenarios should reflect the institution’s products, customers and geographic exposure, rather than a generic vendor template. Investigators need enough transaction context to close alerts or escalate cases. Management should regularly test coverage, backlogs, alert ageing, investigator quality and whether changes to products or payment flows created blind spots.
4. Reporting: owned by the BSA officer or MLRO
Reporting is the formal decision to file a suspicious activity report, or SAR, in the United States, or a suspicious transaction report, often called an STR, in EU regimes. The designated Bank Secrecy Act officer in the United States, or money laundering reporting officer, or MLRO, in many European firms, should own the filing decision and filing governance. Legal may advise, but should not replace the independent compliance judgement.
A report must be timely, factually supported and sufficiently clear for law enforcement or a financial-intelligence unit to understand the concern. The institution must also protect confidentiality around SARs and STRs. A closed monitoring alert is not necessarily a reporting failure, but the rationale must show that the institution considered the relevant facts.
5. Record-keeping: owned by compliance governance and data operations
Record-keeping turns a claimed control into an examinable one. Compliance governance usually sets retention rules and evidence standards, while records, data and technology teams maintain repositories and retrieval. As a baseline under US Bank Secrecy Act requirements and widely reflected in EU AML frameworks, institutions should retain customer identification documents, risk assessments, policies and procedures, and training records for five years from the end of the relationship or completion of the transaction, as applicable. Firms must also account for more specific national, product or litigation-hold obligations.
- Customer identification and beneficial-ownership evidence, including verification results and exceptions.
- Customer risk assessments, enhanced-due-diligence decisions and periodic review records.
- Screening alerts, transaction-monitoring cases, investigations and reporting decisions.
- Current and historical policies, procedures, model or rule changes, and governance approvals.
- Training completion records, quality-assurance testing, audit findings and remediation evidence.
The recurring enforcement finding is often not that a firm had no control, but that it could not evidence one. A policy that says reviews occur is weak evidence without timestamps, case notes, approvals, training logs and records showing that exceptions were managed.
The cost of disconnected ownership
Two large US resolutions show why regulators focus on programme-wide effectiveness. On 10 October 2024, FinCEN assessed TD Bank a $1.3 billion civil money penalty as part of coordinated actions concerning the bank’s AML programme. The case centered on significant deficiencies in transaction monitoring, reporting and governance, illustrating that staffing, data and escalation failures can compound across functions.
In December 2022, Danske Bank agreed to forfeit $2 billion in the United States in connection with its guilty plea over anti-money-laundering control failures tied to its former Estonia branch. The case demonstrated the risk of weak customer controls, inadequate oversight and poor escalation across an international organisation. Neither example means every control failure produces a headline penalty. They do show that regulators assess whether senior management connected ownership, resources, systems and evidence into a functioning programme.


