VeriKYCVeriKYC
Back to blog
Compliance Operations12 min·July 2026

Surviving an SEC AML Examination: A Document-by-Document Readiness Guide

What examiners request, what they infer from gaps, and how to assemble an evidence file before the deficiency letter arrives.

RS

Rodolfo Santos

Real Estate Compliance Attorney & Co-Founder, VeriKYC

Surviving an SEC AML Examination: A Document-by-Document Readiness Guide

The Examination Starts Before the Letter Arrives

An SEC examination begins, formally, when the Division of Examinations sends a notice letter and an initial document request list. In practice, it begins years earlier, on every day that your firm either did or did not generate the records the request list will ask for.

That is the central insight most firms learn too late. An examination is not a test of what you know. It is a test of what you can produce. A compliance officer with an encyclopedic understanding of the firm's AML program and no documentation of its operation will have a difficult examination. A compliance officer with a mediocre grasp of theory and complete, timestamped, retrievable records will have an easy one.

The 2026 examination priorities confirm what has been consistent for several cycles. Examiners will assess whether firms appropriately tailor and update their AML programs to their business model and risks, including risks associated with omnibus accounts maintained for foreign financial institutions; whether independent testing is adequate; whether customer identification procedures are established and followed; whether beneficial owners of legal entity customers are verified; whether suspicious activity reports are filed when required; and whether OFAC screening operates against current lists.

This guide works through the request list document by document: what is asked for, what examiners are actually testing, and what a gap communicates.


Before Anything: Who Gets Examined for What

The scope depends on registration status, and it changed recently.

Broker-dealers have full BSA obligations and are examined by both the SEC and FINRA. AML is a standing examination topic.

Registered investment companies that are subject to BSA program requirements are examined on the same basis, with particular attention to omnibus arrangements.

Registered investment advisers occupy an unusual position in 2026. FinCEN's Investment Adviser AML Rule was delayed to January 1, 2028, and the SEC has confirmed that compliance with the adopted IA AML rules is not an examination focus for advisers in the current cycle.

That does not mean advisers are unexamined on adjacent ground. Rule 206(4)-7 requires policies reasonably designed to prevent Advisers Act violations. Where an adviser has represented to investors (in a private placement memorandum, a due diligence questionnaire, or a side letter) that it conducts AML diligence, the adequacy of that diligence is a compliance program question. And OFAC sanctions obligations apply to every U.S. person independently of BSA status. An adviser with no sanctions screening is exposed regardless of the delay.


The Document Request List, Item by Item

1. The AML program document and all prior versions

What is asked: the current written program, with version history and evidence of board or governing body approval.

What is tested: whether the program is current, whether it was formally approved, and whether it has been updated in response to regulatory change. Examiners compare version dates against known regulatory events. A program last approved in 2022 that does not reference the 2026 residential real estate reporting framework, or that describes sanctions screening against a list configuration that has since changed, demonstrates that updating is reactive rather than systematic.

What a gap says: that governance is nominal.

2. The AML risk assessment

What is asked: the current risk assessment, the methodology, and the supporting analysis.

What is tested: whether the assessment is specific to this firm and whether the program's controls map to the risks it identifies. This is the document examiners read first, because it establishes whether everything else is calibrated correctly.

What a gap says: that the program was designed from a template rather than from an understanding of the business. A generic risk assessment is the single most damaging document a firm can produce, because it undermines the defensibility of every control decision that follows.

3. Customer identification program procedures and sample files

What is asked: written CIP procedures, plus a sample of customer files, usually selected by the examiner, not the firm.

What is tested: whether the required identifying information was collected, whether verification was actually performed and by what method, whether the timing was correct relative to account opening, and whether the documentation supports the conclusion.

What a gap says: the most common finding here is not missing files but thin ones. A file containing a photocopied passport and nothing else does not evidence verification. It evidences collection. Examiners look for a record of what was done with the document: was it authenticated, was the data extracted and checked for internal consistency, was the person matched to it.

4. Beneficial ownership records for legal entity customers

What is asked: certification forms, supporting documentation, and evidence of verification for a sample of entity customers.

What is tested: whether all individuals owning 25 percent or more were identified, whether a control person was identified, whether the identities were verified, and whether the information was corroborated where the structure or risk profile warranted it.

What a gap says: the recurring deficiency is a certification form accepted at face value for a multi-layered structure. Where an entity customer sits behind two or three ownership layers and the file contains only a one-page certification naming two individuals, examiners will ask how the firm satisfied itself that the certification was complete. "The customer told us" is not a sufficient answer for a high-risk structure.

The absence of a federal beneficial ownership registry for domestic U.S. entities makes this harder, and examiners know it. That is not mitigation. It raises the expectation that the firm performed its own corroboration.

5. Customer risk rating methodology and applied ratings

What is asked: how customers are risk-rated, and the ratings applied to the sample.

What is tested: consistency. Examiners look for materially similar customers rated differently, or for a methodology that produces "low risk" for essentially everyone.

What a gap says: that risk rating is a formality. A distribution in which 97 percent of customers are low risk invites the question of what the rating is actually measuring.

6. Enhanced due diligence records for high-risk customers

What is asked: what additional steps were taken, what was found, and who approved the relationship.

What is tested: whether EDD is a defined process with specific required elements, or an unstructured "we looked into it."

What a gap says: the classic finding is a high-risk designation with no corresponding enhanced procedure. If the file for a high-risk customer looks identical to the file for a low-risk one, the risk rating had no operational consequence.

7. Sanctions screening records

What is asked: which lists are screened, at what frequency, with what matching logic, plus alert logs and dispositions.

What is tested: whether screening ran against current lists, whether it covers all relevant parties including beneficial owners, whether match logic accommodates name variants, and whether alerts were dispositioned with recorded reasoning.

What a gap says: two findings dominate. First, screening performed at onboarding and never repeated, which cannot detect a customer designated after account opening. Second, alert dispositions consisting of the word "cleared" with no explanation. An examiner reviewing a cleared alert wants to know why it was cleared: different date of birth, different jurisdiction, confirmed different individual. A bare disposition is unreviewable.

The 2026 priorities specifically reference real-time screening against OFAC lists. Batch screening on a monthly cycle is increasingly hard to defend.

8. Transaction monitoring configuration and alert history

What is asked: monitoring rules or scenarios, thresholds, tuning documentation, and a sample of alerts with dispositions.

What is tested: whether monitoring is calibrated to the firm's actual activity, whether thresholds have ever been tuned, and whether alerts are investigated or cleared.

What a gap says: thresholds that have never been adjusted since implementation indicate that nobody has asked whether the system is detecting anything. A monitoring system generating almost no alerts is as concerning as one generating thousands.

9. SAR filing records and decision documentation

What is asked: filed SARs, plus, critically, documentation of cases investigated where a decision was made not to file.

What is tested: timeliness, narrative quality, and the reasoning behind no-file decisions.

What a gap says: the no-file documentation is where firms are most often deficient, because there is a natural tendency to document what you did and not what you decided against. Examiners specifically look for this. A firm that investigated fifteen matters and filed three should have decision records for the twelve.

10. Independent testing reports and remediation tracking

What is asked: the most recent tests, the scope and methodology, findings, and evidence that findings were remediated.

What is tested: independence, depth, and follow-through.

What a gap says: an unremediated finding from a prior cycle is the worst possible artifact. It converts a control weakness into a governance failure, because it demonstrates that the firm identified the problem and did not act. Examiners escalate on repeat findings.

11. Training records

What is asked: materials, attendance, dates, and role differentiation.

What is tested: whether training was substantive and relevant.

What a gap says: a completion spreadsheet without materials proves that people clicked something.

12. Board and senior management reporting

What is asked: minutes and reporting packages showing AML matters presented to the governing body.

What is tested: whether senior management is genuinely informed.

What a gap says: if the board minutes contain no substantive AML discussion, the firm cannot credibly claim senior-level oversight.


What Examiners Infer From Gaps

Understanding examiner reasoning helps prioritize preparation.

A missing document is a deficiency. A pattern of missing documents is a program failure. The distinction determines whether you receive a deficiency letter with corrective recommendations or a referral to Enforcement.

Records that were assembled after the request arrived are usually detectable. Metadata, formatting inconsistency, and the absence of contemporaneous detail all give it away. Reconstructing a file is far worse than acknowledging a gap, because it converts a control deficiency into a candor problem.

Inconsistency between documents and testimony is heavily weighted. When a front-line employee describes a process that differs from the written procedure, examiners conclude the written procedure is decorative.

Conversely, a firm that identifies its own gap, documents it, and can show a remediation plan with dates and owners is in a substantially better position than one where the examiner finds it first. Self-identification is a genuine mitigating factor.


Preparing: The Mock Examination

The most effective preparation is to run the request list against yourself, unannounced, before anyone else does.

Pull a random sample of twenty customer files, selected by someone other than the person who maintains them, and attempt to produce, for each: the identifying information collected, evidence of verification, the beneficial ownership determination and its support, the risk rating and its basis, the screening record with dates and lists used, and any alerts with dispositions.

Time it. If assembling one complete file takes more than a few minutes, an examination requesting fifty files will consume weeks and will surface inconsistencies you did not know existed.

The firms that complete this exercise comfortably almost always share one characteristic: their evidence is generated by the system that performs the work rather than assembled afterward from separate sources. When verification, screening, ownership resolution, and risk rating all occur in one workflow that writes a durable, timestamped record, producing the file is a query. When those functions live in four systems and an email archive, producing the file is an investigation.

That architectural difference is what VeriKYC is designed to address: not making compliance faster, but making it evidenced by default.


The Deficiency Letter and Response

Most examinations end in a deficiency letter rather than enforcement. The response matters more than firms typically appreciate.

Address every item, including ones you dispute. Silence reads as concession or inattention. Where you disagree, say so clearly and explain the basis, without argumentativeness.

Provide specific remediation with owners and dates rather than commitments to "review" or "enhance." Where remediation is already complete, include the evidence.

And treat the letter as an input to the risk assessment. Findings that do not flow back into the program's design will reappear in the next cycle, and repeat findings are how a routine examination becomes something else.


Conclusion: Build the Record as You Go

The uncomfortable truth about AML examinations is that preparation in the weeks before one is largely futile. You cannot retroactively create evidence that a control operated on a date two years ago.

What you can do is ensure that from today forward, every verification, every screening run, every ownership determination, every risk rating, and every alert disposition writes a record that includes what was checked, what was found, who decided, and when.

Firms that do this find examinations tedious but unthreatening. Firms that do not find them existential, not because their compliance was necessarily worse, but because they cannot demonstrate that it was better.

The examination tests your records. Build them accordingly.

Rodolfo Santos

Rodolfo Santos is a real estate compliance attorney with 10+ years of experience in cross-border transactions and the co-founder of VeriKYC, an AI-powered compliance platform for real estate professionals. He has closed over 150 property transactions worth more than €50 million.

Ready to modernize your KYC?

Join 100+ funds, law firms, and real estate teams already using VeriKYC to onboard clients in under 60 seconds.