From BSA to AML/CFT: Is Your Program Ready to Prove It Works?

  • Policy and regulation
  • 9/17/2026
Young man is standing at a bank counter

Key insights

  • You still need the core AML/CFT program pillars, but regulators increasingly want to see how those pieces work together to identify, manage, and report real financial crime risk.
  • Your risk assessment should connect AML/CFT Priorities and National Money Laundering Risk Assessment themes to your institution’s customers, products, geographies, channels, controls, and decisions instead of sitting as a static annual exercise.
  • Effectiveness is becoming the key test, so documentation should show why monitoring thresholds, scenarios, governance decisions, testing results, and resource choices make sense for your actual risk profile.
  • If your program still feels like a checklist, now is a good time to refresh governance, scenario tuning, model risk documentation, and independent testing before examiners ask for stronger evidence.

Build a more defensible AML/CFT program.

Learn How

As regulators place greater emphasis on risk-based effectiveness, institutions should be prepared to demonstrate how their risk assessments, monitoring practices, governance processes, and independent testing support the detection and reporting of illicit activity.

Understanding these expectations can help you evaluate whether your program is positioned for increased scrutiny and evolving financial crime risks.

The foundations of an effective BSA/AML/CFT program

Policies, procedures, and internal controls

Written documentation should define the program’s objectives, scope, and responsibilities and be refreshed regularly to reflect regulatory changes and shifts in your institution’s risk profile. Internal controls should also ensure your governance and control environment addresses the independent validation of your automated AML system. 

Customer due diligence (CDD)

A risk-based program that identifies and verifies customer identity, supports an understanding of the nature and purpose of the customer relationship, and enables ongoing monitoring of customer activity.

Suspicious activity monitoring and reporting

Automated or manual monitoring systems should be sufficient to detect unusual or suspicious activity and support the timely filing of Suspicious Activity Reports (SARs) with FinCEN.

Training

Annual AML/CFT training should be provided to all staff, senior management, and board members, with content tailored to their specific roles and responsibilities.

Independent testing

An independent assessment of the AML/CFT program should be conducted every 12 to 18 months by qualified personnel who are independent of the AML/CFT function. This review should go beyond a check-the-box exercise and provide meaningful evaluation of the program’s effectiveness.

Updating program language from “BSA/AML” to “AML/CFT” isn’t a find-and-replace exercise. It’s an opportunity to refresh governance, controls, and testing.

These obligations are not limited to traditional depository institutions. Non-depository institutions, including trust companies, mortgage companies, and other covered financial services providers, may also be required to maintain AML/CFT programs tailored to their risk profiles.

In many cases, these institutions carry elevated inherent risk based on factors such as organizational structure, ownership transparency, customer activity, geographic exposure, and business purpose.

How to align your program with BSA/AML/CFT priorities

A risk-based, reasonably designed program starts with understanding the illicit finance threats the government has identified as the highest priorities and then aligning those threats to your products, customers, geographies, and delivery channels.

Many institutions are waiting to incorporate these priorities until they are finalized. However, when viewed holistically, organizations responsible for maintaining an AML/CFT program should already have measures in place to monitor and manage these critical risk areas.

Review these priorities and incorporate them, as appropriate, into your risk-based programs.

Financial crime trends to consider in your risk assessment

The U.S. Department of the Treasury releases a National Money Laundering Risk Assessment (NMLRA) every two years, with the most recent update issued in 2026. The Treasury also publishes assessments related to terrorist financing and proliferation financing. These resources are valuable references when evaluating and updating your AML/CFT program.

The NMLRA provides a current and emerging view of how illicit proceeds move through the financial system and where vulnerabilities are commonly concentrated. Key themes to consider in your risk assessment include:

  • Fraud, cybercrime, and drug trafficking drive most illicit proceeds. These activities remain among the largest sources of illegal funds entering the financial system.
  • Professional laundering networks significantly scale and enable criminal activity. Money mules, shell and front companies, and Chinese money laundering networks can amplify and facilitate underlying criminal schemes.
  • Artificial intelligence (AI) and digital assets are accelerating the speed and sophistication of money laundering. Criminals are increasingly using AI, synthetic identities, spoofed websites, digital assets, stablecoins, and peer-to-peer platforms to move and obscure funds.
  • Traditional channels persist: Cash and shell entities remain key components. Bulk cash, prepaid cards, money orders, and complicit insiders at financial institutions continue to play a role in money laundering activity.

Internally, organizations should take a step back and review their risk assessments, suspicious activity monitoring scenario libraries (whether automated or manual), training programs, and SAR narratives. These elements should demonstrate how each of these themes is considered, accepted, mitigated, or determined to be out of scope within the AML/CFT program.

This alignment is what auditors and examiners will increasingly look for as evidence that a program is risk-based and reasonably designed.

Explore our article on how financial institutions can evaluate where artificial intelligence may improve AML/BSA effectiveness.

Risk-based compliance programs

Important things to watch for within your program:

“Establishment” versus “maintenance” framework

  • Examiners will distinguish between program design issues (establishment) and day-to-day operational issues (maintenance), with a greater focus on whether the program is working.
  • Having a program is not the only important aspect; being able to illustrate the program works is paramount.

Resource allocation and risk-based expectations

  • Programs should focus resources on higher-risk customers and activities, rather than spreading effort evenly across lower-risk areas. Spend your time, money, and resources where the risk lies.
  • Programs must be effective, risk-based, and reasonably designed, supported by a dynamic, recurring risk assessment rather than a static annual checklist.

Connecting AML/CFT Priorities to program decisions and evidence

  • Programs should review and, as appropriate, incorporate trends and typologies into risk-based decisions, including significant supervisory and enforcement actions. In practice, think of this as using relevant themes and typologies in EDD reviews and SARs. Independent testing is expected to validate effectiveness for a risk-based, reasonably designed program.
  • Institutions, and those charged with complying with the rule, will need to illustrate the effectiveness of their program with evidence. Tuning rationale, risk-assessment outputs, governance documentation, and testing results should connect activity to outcomes, not simply confirm each pillar exists.

What this likely means for your BSA/AML/CFT program

Based on the areas most affected by this shift (model risk, SAR tuning, and governance), the highest-impact areas to address now are:

Scenario tuning must be risk-justified, not just conservative

Threshold and scenario decisions should be tied to documented risk rationale, productivity analysis, and above- and below-the-line testing, not to a default assumption that tighter is safer. If you have a manual program, this can mean making sure you can illustrate coverage adequate to your risk profile.

BSA risk assessments should be dynamic and defensible

A once-a-year refresh is unlikely to continue to be adequate. Risk assessments should be event-driven, integrate current trends and NMLRA themes, and clearly link inherent risk, controls, and residual risk to program decisions.

If your program risk assessment looks like Appendix J and M of the FFIEC manual, pick up your pen and paper for a revamp and reassess — those appendices are meant as baselines or guides, not templates.

Model risk and governance should be explicitly documented within AML programs

Automated monitoring systems are models. Their controls, validation, tuning governance, change management, and ongoing performance monitoring belong inside the AML/CFT program and the BSA risk assessment, not on a separate technology track.

Knowing where to go from here

The pillars anchor the program, but the standard has moved. “Good enough” is no longer the goal.

The question regulators, and your board, will increasingly ask is whether the program can demonstrate it detects and reports illicit activity in proportion to your institution’s risk and in ways useful to law enforcement.

How CLA can help with risk-based BSA/AML/CFT programs

CLA’s regulatory compliance financial services teams conduct AML/CFT independent tests, modernize risk assessments, evaluate model risk and scenario tuning through model validations, and conduct independent testing aligned with an effectiveness framework. If you’d like to have a readiness conversation, we’re here to help.

Contact us

Build a more defensible AML/CFT program. Complete the form below to connect with CLA.

Experience the CLA Promise


Subscribe