Ask three compliance officers how many pillars an AML program has and you may get three answers. Four is the traditional count. Five is correct after the customer due diligence rule. Six is what many practitioners now say, and they are not wrong either.
The disagreement is not pedantry — it reflects a real change in how examiners evaluate programs. This article explains each pillar, why the count moved, and what "reasonably designed" means when applied to each one.
The original program requirement, in place for decades, listed four elements: internal controls, independent testing, a designated compliance officer, and training. Institutions built their programs around those four and examiners tested against them.
The customer due diligence rule, effective May 11, 2018, added a fifth: risk-based procedures for ongoing customer due diligence, including identification and verification of beneficial owners of legal entity customers. That was a formal regulatory addition, and five became the correct answer.
The sixth is a matter of practice rather than a separate regulatory element. The BSA/AML risk assessment is not listed as a pillar, but no program can be shown to be reasonably designed without one, and examiners begin nearly every examination with it. Because it functionally governs the design of all the other pillars, many practitioners now count it as the foundation — the sixth pillar, or more accurately the one the other five stand on.
Answer the question either way in an interview. In an examination, what matters is that all six things exist and work.
Internal controls are the policies, procedures, and processes that operationalize compliance. In practice this pillar is the largest by volume and covers:
Two design questions determine whether this pillar survives an examination.
Is the control calibrated to the risk? Monitoring rules delivered as vendor defaults and never tuned are the most common failure. If the risk assessment identifies significant cash-intensive business exposure and the structuring rules are running at out-of-the-box thresholds, the control does not match the risk and the mismatch is documented in the institution's own risk assessment.
Can you prove it operated? A procedure that exists but leaves no evidence of execution is treated as absent. Alert dispositions need documented rationale, exemption reviews need dated records, and screening needs logs. "We do this" is not a defense; "here is the record" is.
The person who reviews alerts should not be the person who can suppress them. The person who maintains customer records should not unilaterally approve exemptions. Small institutions cannot always achieve textbook segregation, and the accepted answer is compensating controls — supervisory review, sampling, or independent verification — documented as deliberate choices rather than left as gaps.
Independent testing is the audit function for the AML program. Independence means the tester does not report to, and is not evaluated by, the function being tested. Internal audit, a qualified external consultant, or in a small institution a knowledgeable employee outside the BSA function can perform it.
Scope should cover the adequacy of the program against current regulatory requirements, the effectiveness of monitoring including transaction testing, the accuracy and timeliness of filings, training adequacy, and the status of prior findings. Frequency is risk-based; annual is the practical norm, with higher-risk institutions testing more often.
The recurring criticisms are worth naming plainly. Testing that reviews policies without testing transactions verifies that documents exist, not that controls work. Testing performed by the same consultant who wrote the policies is not independent. And unresolved prior findings are treated far more seriously than new ones — a repeat finding reads to an examiner as a governance failure rather than a process failure.
The institution must designate an individual responsible for coordinating and monitoring day-to-day compliance. The designation must be board-approved and documented.
The regulation names a person, not a department, and that is deliberate: accountability is meant to be individual. The corollary is that the role carries personal exposure. Enforcement actions have been brought against BSA officers individually, and penalties have been assessed against them.
Three attributes get tested:
Authority. The officer must be able to escalate directly to the board or a board committee without passing through someone whose business the finding affects. An officer who reports through the head of retail banking is structurally compromised.
Competence. The officer must have knowledge proportional to the institution's risk profile. Examiners assess this through conversation, and an officer who cannot explain the institution's own risk assessment is a finding.
Resources. A program with an insufficient number of qualified staff to clear alerts within defined timeframes is not reasonably designed, and pointing to a diligent officer does not cure it. Chronic alert backlogs are usually a resourcing finding, not an individual one.
Institutions building depth in this role generally start with structured credentialing — a Certificate in BSA and AML Compliance covers the full framework rather than isolated topics.
Training must reach "appropriate personnel," which examiners read functionally. Anyone who opens accounts, processes transactions, makes lending decisions, monitors activity, or supervises those who do is in scope — plus the board, which needs enough understanding to exercise oversight.
Effective programs share four characteristics:
Frequency is not specified in the regulation. At least annually is the settled expectation, supplemented when roles change, when regulations change, or when testing reveals a gap. Our AML compliance training catalog is organized by role for exactly this reason.
The fifth pillar has three components that are often collapsed into one and should not be.
Customer identification. The CIP requirement: collect name, date of birth, address, and identification number, and verify identity within a reasonable time. This is a discrete, one-time obligation at account opening.
Beneficial ownership. For legal entity customers, identify and verify each individual owning 25 percent or more of the equity, plus one individual with significant responsibility to control or manage the entity. The obligation runs at account opening and when the institution becomes aware of changes.
Ongoing due diligence. Understanding the nature and purpose of the relationship to develop a customer risk profile, and conducting ongoing monitoring to identify suspicious transactions and maintain current customer information. This component is continuous, and it is where programs most often fall behind — information collected at onboarding and never refreshed produces a risk profile describing a customer who no longer exists.
Enhanced due diligence sits on top for higher-risk relationships, with the categories defined in the institution's own procedures and justified by its risk assessment.
The risk assessment identifies and analyzes the money laundering and terrorist financing risk the institution actually faces, across four dimensions:
Each risk is assessed inherently, mitigating controls are identified, and residual risk is stated. The output should then be traceable into the program: monitoring thresholds, EDD categories, training content, and testing scope should all reference it.
Refresh at least annually and whenever the profile changes materially — a new product, a new market, an acquisition, or a significant shift in customer mix. An assessment that has not moved in three years while the institution has grown is itself the finding.
Programs rarely fail on one pillar. The characteristic pattern is a chain:
A risk assessment is not refreshed after the institution begins serving a new higher-risk customer segment. Because the assessment does not identify the risk, monitoring rules are never tuned for it. Because alerts are not generated, nothing escalates. Because nothing escalates, training never covers the typology. Because independent testing scopes to the risk assessment, testing never looks. Nothing appears wrong anywhere in the program — until an examiner reviews the customer base directly and asks why an entire segment is invisible in the controls.
This is why the risk assessment is treated as foundational. Every other pillar inherits its blind spots.
Before your next examination, confirm you can produce evidence for each of these in under an hour:
Anything you cannot produce quickly is a pillar with a documentation problem, whether or not it has a control problem.
All three answers appear in current use. Four is the original statutory program requirement: internal controls, independent testing, a designated compliance officer, and training. Five is correct after the customer due diligence rule added CDD and beneficial ownership effective in 2018. Six is common practice, counting the BSA/AML risk assessment, which is not a listed pillar but is required in substance and drives the design of all the others.
That the person or firm performing the testing does not report to, and is not evaluated by, the function being tested. Internal audit qualifies, as does a qualified external party. In small institutions a knowledgeable employee outside the BSA function may perform it. A consultant who wrote the institution's policies is not independent when testing those policies.
Yes, and in community institutions it is common. The constraints are that the role must have sufficient authority, direct access to the board, adequate time and resources, and no conflict with a business line whose activity the officer must challenge. Combining the BSA officer role with a revenue-producing position creates exactly that conflict.
At least annually as a practical standard, and whenever the risk profile changes materially — new products or services, entry into new markets, mergers or acquisitions, or a significant shift in customer composition. The update should be documented with its date and methodology so the currency of the assessment can be demonstrated.
Section 8(s) of the Federal Deposit Insurance Act requires the federal banking agencies to issue a cease and desist order when an institution fails to establish and maintain a reasonably designed program, or fails to correct previously reported problems. Beyond that, consequences can include civil money penalties against the institution and responsible individuals, and restrictions on growth such as acquisitions and branch expansion.
Yes. The pillars apply to every covered institution; what scales is the depth of each one. A small bank with a simple retail deposit base needs a proportionally simpler program, but it still needs written internal controls, genuinely independent testing, a designated officer, role-appropriate training, customer due diligence, and a documented risk assessment supporting the whole design.


