VeriKYCVeriKYC
Back to blog
Deep Dive13 min·July 2026

The Five Pillars of a BSA/AML Program: Building One That Holds Up Under U.S. Examination

Policies, officer, training, independent testing, and CDD. What each pillar actually requires, and where U.S. firms fail.

RS

Rodolfo Santos

Real Estate Compliance Attorney & Co-Founder, VeriKYC

The Five Pillars of a BSA/AML Program: Building One That Holds Up Under U.S. Examination

Five Pillars, and the Gap Between Having Them and Passing

Ask a U.S. compliance officer to describe their BSA/AML program and most will recite the pillars: internal policies and controls, a designated compliance officer, ongoing training, independent testing, and risk-based customer due diligence. The framework is well known, taught in every certification course, and reproduced in every consultant's template.

Ask an examiner what they find in practice, and the answer is different. Programs that satisfy the pillars on paper and fail in operation. Policies that describe a process nobody follows. Compliance officers with titles but not authority. Training completion rates without evidence anyone learned anything. Independent testing performed by someone who reports to the person being tested. And customer due diligence that collects information at onboarding and never looks at it again.

The gap between having the pillars and passing an examination is the subject of this article. Each section covers what the pillar actually requires, the specific failure mode that examiners find most often, and what a program that works looks like in practice.


Pillar One: Internal Policies, Procedures, and Controls

The requirement is that the institution develop internal policies, procedures, and controls reasonably designed to achieve compliance with the Bank Secrecy Act and to prevent the institution from being used to facilitate money laundering or terrorist financing.

Three words carry the weight: reasonably designed. The standard is not whether you have documents. It is whether the documents describe a system that would plausibly work for your institution's actual risk profile.

The failure mode: the inherited template

The most common deficiency is a policy manual that was adapted from another institution and never made specific. The tell is easy to spot: policies that reference products the firm does not offer, thresholds that bear no relationship to actual transaction sizes, escalation paths naming roles that do not exist, and a customer risk rating methodology that has never been applied to a real customer.

Examiners test this by asking a front-line employee to describe what they do, then comparing it to the manual. Divergence is the finding.

What works

Policies should be derived from the risk assessment rather than written independently of it. If the assessment identifies foreign entity investors as a high-risk category, the policies should specify what enhanced diligence applies to that category, who performs it, what evidence is required, and who approves acceptance.

Procedures should be operational documents that a new employee could follow. "Enhanced due diligence will be conducted for high-risk customers" is a policy statement. "For customers rated high risk, obtain the following four items, escalate to the BSA Officer, and document approval before account opening" is a procedure.

Controls should be testable. A control that cannot be verified after the fact is a preference.


Pillar Two: A Designated Compliance Officer

The institution must designate an individual responsible for coordinating and monitoring day-to-day BSA compliance.

The failure mode: responsibility without authority

The title is easy to assign. The substance is not. Examiners look at whether the BSA Officer has genuine authority to halt a transaction or reject a customer, sufficient resources and staff for the institution's volume, direct access to the board or senior governing body, and independence from revenue-generating functions.

The classic deficiency is a BSA Officer who reports to the head of sales, or who is simultaneously the head of operations, or who holds the title as one of six responsibilities. When the incentive structure makes it costly to say no, the officer's independence is compromised regardless of the org chart.

A second, subtler failure is the officer who is overwhelmed. An institution that has grown its customer base fivefold while the compliance function stayed the same size has a resourcing deficiency, and examiners increasingly treat resourcing as a program adequacy question rather than a business decision.

What works

Documented authority, in writing, approved by the board. A clear reporting line that does not pass through a revenue function. Regular, minuted reporting to the board or its equivalent covering program status, SAR volumes and trends, testing findings, and remediation progress. And staffing that scales with volume.


Pillar Three: Ongoing Training

The program must provide for ongoing training of appropriate personnel.

The failure mode: attendance as evidence

Most institutions can produce a training completion report. Far fewer can produce evidence that the training was role-appropriate, that it covered the institution's actual risks, that it was updated to reflect regulatory changes, or that anyone retained anything.

Generic annual AML training delivered identically to everyone is the standard finding. The person opening accounts, the person reviewing transactions, and the person approving high-risk relationships need materially different content.

What works

Role-differentiated content. Front-line staff need to recognize red flags in the situations they actually encounter and to know exactly how to escalate. Compliance staff need investigative technique and SAR narrative drafting. Senior management and the board need enough to exercise oversight, including their own personal exposure.

Frequency tied to change. Annual training is a floor. When a rule changes (the Residential Real Estate Rule, a new sanctions program, a revised SAR filing requirement) targeted training should follow within weeks, not at the next annual cycle.

Assessment, not just attendance. A short test that demonstrates comprehension converts a completion record into evidence of effectiveness.

Documentation that survives. Materials used, attendees, dates, and assessment results, retained for the examination cycle.


Pillar Four: Independent Testing

The program must be independently tested. Contrary to persistent belief, this does not require an external auditor. It requires independence from the function being tested.

The failure mode: testing the documents instead of the system

The weakest independent tests confirm that policies exist, that a compliance officer has been designated, and that training was delivered. That is a checklist exercise, and it identifies nothing.

Effective testing samples actual outcomes. It pulls a set of customer files and verifies that the required information was collected, that verification was performed, that risk ratings were applied consistently, and that documentation supports the conclusions. It pulls a set of alerts and verifies that dispositions were reasoned and timely. It tests whether SARs that should have been filed were filed, and whether filed SARs were complete and on time. It tests whether screening actually ran against current lists.

The second failure mode is compromised independence. Testing conducted by a person who reports to the BSA Officer, or by the consultant who wrote the policies being tested, is not independent in substance even if the engagement letter says otherwise.

What works

Risk-based scope and frequency. Annual is conventional; higher-risk areas may warrant more frequent testing, and a full-scope test should occur at defined intervals.

Transaction-level and file-level sampling with documented methodology, including how the sample was selected.

Findings with severity ratings, assigned owners, and target dates, tracked to closure. An open finding from two examination cycles ago is worse than no testing at all, because it demonstrates that the institution identified a problem and did not fix it.

Reporting directly to the board or audit committee, not filtered through management.


Pillar Five: Risk-Based Customer Due Diligence

The fifth pillar, added by FinCEN's Customer Due Diligence Rule, has four components. It is the pillar most institutions execute least well, because it is the only one that requires continuous operation rather than periodic activity.

Component one: customer identification

The institution must obtain name, date of birth, address, and an identification number for each customer, and verify identity through documentary or non-documentary means sufficient to form a reasonable belief that it knows the customer's true identity.

The frequent gap is verification quality. Collecting a photograph of a driver's license is collection. Determining whether that license is authentic (checking security features, validating the document format, confirming the data is internally consistent, matching the photo to a live capture of the person) is verification. Given the volume of AI-generated fraudulent identity documents now in circulation, the distinction is no longer academic.

Component two: beneficial ownership

For legal entity customers, the institution must identify and verify each individual owning 25 percent or more of the equity interests, plus one individual with significant responsibility for controlling or managing the entity.

The failure mode is accepting a certification form at face value. The rule permits reliance on the information provided by the person opening the account, but reliance is not blindness. Where the structure is complex, where the stated ownership does not reconcile with other documents, or where the jurisdictions involved are high risk, corroboration is expected.

The absence of a usable federal beneficial ownership registry for domestic U.S. entities, following the 2025 narrowing of Corporate Transparency Act reporting, makes this component substantially harder than it was designed to be. The registry that was supposed to corroborate customer-provided ownership information does not cover the entities that matter most.

Component three: understanding nature and purpose

The institution must understand the nature and purpose of the customer relationship in order to develop a customer risk profile.

This is the component most often reduced to a dropdown field. A meaningful risk profile records what the customer does, why they are using this institution, what activity is expected in terms of type, volume, frequency, and counterparties, and what the specific risk factors are. Without an expected-activity baseline, the fourth component is impossible.

Component four: ongoing monitoring

The institution must conduct ongoing monitoring to identify and report suspicious transactions and, on a risk basis, to maintain and update customer information.

Two obligations sit here. Transaction monitoring, detecting activity inconsistent with the expected profile. And information currency, refreshing customer and beneficial ownership data when circumstances change or on a risk-based schedule.

Information currency is where most programs quietly decay. A customer onboarded four years ago whose file has not been touched since is a file describing a customer who may no longer exist in that form. Ownership changes. Control changes. People become politically exposed. Sanctions designations occur. A static file is a stale file.


What the AML Act Changed

The Anti-Money Laundering Act of 2020 shifted the framing from technical compliance to program effectiveness. Programs are expected to be risk-based, to be reasonably designed to achieve effectiveness, and to give appropriate consideration to the government's published AML/CFT National Priorities, which include corruption, cybercrime, terrorist financing, fraud, transnational criminal organizations, drug trafficking, human trafficking, and proliferation financing.

The practical implication is that a documented, current risk assessment is becoming the foundational artifact of the program rather than a supporting document. An institution that cannot explain why its controls are calibrated the way they are, by reference to identified risks, has a problem that no amount of policy documentation will solve.


Making the Pillars Operational

The institutions that pass examinations comfortably tend to share a structural characteristic: their pillars are connected to each other rather than maintained separately.

The risk assessment drives the policies. The policies define the procedures. The procedures generate records automatically as work is performed, rather than requiring separate documentation. The records feed the independent testing. Testing findings update the risk assessment and the training curriculum. The cycle closes.

The institutions that struggle maintain each pillar as an independent artifact. A risk assessment written once and filed. Policies updated when the consultant is re-engaged. Training procured as a product. Testing scoped to whatever fits the budget. Customer due diligence performed in a system that does not talk to any of it.

Technology matters here in a specific way. The value is not that automation performs verification faster, though it does. It is that a well-designed system produces the evidence as a byproduct of doing the work. Every verification generates a timestamped record. Every screening run against every party is logged. Every risk rating carries the inputs that produced it. Every ownership structure is stored as data that can be re-screened when lists change.

When an examiner asks for evidence that a control operated, the answer is a query rather than a search through files. That difference, between evidence being generated and evidence being assembled, is the practical difference between a two-week examination and a six-month one.


Conclusion: The Pillars Are the Floor

Regulators do not award credit for having a program. They assess whether it works.

The distinction shows up in specific, testable ways. Are the policies describing what people actually do? Does the compliance officer have the authority to stop something? Does training reflect the risks this institution actually faces? Does independent testing sample outcomes rather than confirm documents? Is customer information current, or is it a snapshot from the day the account opened?

Each of those questions has an answer that is either evidenced or not. And the institutions that can evidence them are, almost invariably, the ones that built their program as a connected operating system rather than as five separate compliance artifacts maintained to satisfy five separate requirements.

The pillars are the floor. Effectiveness is the standard.

Rodolfo Santos

Rodolfo Santos is a real estate compliance attorney with 10+ years of experience in cross-border transactions and the co-founder of VeriKYC, an AI-powered compliance platform for real estate professionals. He has closed over 150 property transactions worth more than €50 million.

Ready to modernize your KYC?

Join 100+ funds, law firms, and real estate teams already using VeriKYC to onboard clients in under 60 seconds.