How to Prepare for an AML Regulatory Examination
An examination is not a test of whether your programme is good. It is a test of whether your programme does what your documents say it does, and whether you can demonstrate that with evidence. Those are different things, and the gap between them is where findings come from.
The document request
The initial request list is broadly predictable. Preparing these in advance converts a scramble into an administrative exercise.
- The enterprise-wide risk assessment, with evidence of board approval
- AML policies and procedures, with version history
- The MLRO's annual report and management information pack
- Organisation chart, showing the compliance function's reporting line and independence
- Training records: curriculum, completion rates, and testing results by role
- Transaction monitoring rule inventory, thresholds, and tuning or model validation documentation
- Screening configuration: lists used, match thresholds, update frequency
- Alert and case statistics, with disposition breakdown
- SAR or STR filing statistics and a sample of filed reports
- Internal audit reports covering AML, with management responses and remediation status
- Customer files for a sample the examiner selects — not one you offer
That last point matters. Volunteering a curated sample signals that the general population may not bear inspection.
How examiners test a risk-based approach
"Risk-based" is the most-claimed and least-evidenced phrase in compliance. Examiners test it by tracing in both directions.
Downward: take a risk named in the assessment and ask which control addresses it, then ask for evidence that control operates. A named risk with no traceable control is a finding.
Upward: take a control — a monitoring threshold, a review cycle, an EDD trigger — and ask why it is set where it is. "It was set at implementation" is not an answer. "It was set here because the risk assessment identified this exposure, and tuning analysis in March showed this threshold produces this detection profile" is.
Run both traces yourself on three or four controls before the examiner does. The exercise takes a day and reliably finds the weak links.
Findings that recur
Across published enforcement actions and supervisory commentary, the same themes repeat.
Monitoring coverage gaps
Products, channels or typologies with no corresponding rule. The test is simple and rarely performed internally: list your typologies, list your rules, and identify typologies no rule addresses.
Unvalidated models and thresholds
Rules running at implementation defaults years later, with no tuning record. See rule tuning — the absence of documented tuning is itself the finding, regardless of whether thresholds happen to be reasonable.
Alert backlogs and disposition quality
Ageing alerts, or dispositions with reasoning too thin to reconstruct. An investigator's note reading "no concerns" does not evidence an investigation.
Incomplete customer files
Missing source of wealth evidence on high-risk relationships, stale beneficial ownership, or EDD that was triggered but not completed.
Governance and independence
An MLRO without sufficient authority, seniority or resource; compliance reporting into a revenue line; or management information that reports activity volumes without reporting risk.
The pre-examination self-assessment
A self-assessment is only useful if it is allowed to find things. Run it against the examination manual for your jurisdiction, not against your own policies — testing yourself against your own documents guarantees you pass.
Sample the way an examiner would: random selection from the full population, weighted toward high risk, not a convenience sample. Write findings down, with owners and dates. An open remediation plan with evidence of progress is a far better position than a clean self-assessment an examiner subsequently disproves — the first demonstrates a working control environment, the second demonstrates the opposite.
During the examination
Three practices consistently help. Route every request through a single coordinator so the institution speaks with one voice and responses stay consistent. Answer precisely what was asked — volunteered material expands scope. And where you know something is weak, say so alongside the remediation plan; examiners respond considerably better to a known issue being managed than to one they discover.
Related: the MLRO role and personal liability covers the accountability the examiner is testing, and the AML compliance checklist covers the first-line controls being examined.
The Interviews: What Examiners Ask Staff
Document review establishes what the programme claims. Interviews establish whether it operates. Examiners commonly speak to the MLRO, a first-line analyst, a relationship manager and someone from technology — and they are listening for consistency between those accounts.
Front-line staff
Typical questions: what would make you escalate a customer? Who do you go to? What happens after you escalate? Has anything you raised resulted in a report? The last question is telling. Staff who have never seen an outcome from an escalation tend to stop escalating.
Analysts
Expect to walk through a case the examiner selects, explaining the reasoning rather than the workflow. An analyst who can describe which screens they clicked but not why they concluded what they did indicates a process that produces dispositions without producing judgement.
The MLRO
Questions turn to authority and resource: can you escalate without going through the business? Have you ever been overruled? What did you do about it? Do you have the budget you asked for? Honest answers are better received than confident ones, particularly where a resourcing gap has been documented and escalated.
Prepare staff by explaining the purpose and the likely themes. Do not script them. Rehearsed answers are obvious, and an examiner who suspects coaching will widen the sample.
After the Examination: Handling Findings
How a firm responds to findings shapes the supervisory relationship more than the findings themselves.
Agree the facts before arguing the conclusion. Where a finding rests on a factual error — a sample drawn from the wrong population, a control the examiner did not see — correct it promptly and with evidence. Where the facts are right, accept them. Disputing a well-evidenced finding costs credibility that is needed later.
Respond with a remediation plan carrying named owners, dated milestones and a stated completion test. "Improve alert quality" is not a plan; "re-tune the four rules generating 60% of false positives, validated by a documented above- and below-the-line test, by Q3" is.
Report progress against that plan to the audit committee on a standing basis, including slippage. A supervisor who sees a firm tracking its own overdue items closely is looking at a working control environment. One who discovers the slippage independently is looking at something else.
Documentation Gaps That Recur
Certain documents are requested in nearly every examination and are absent or stale in a surprising number of firms. Assembling them in advance converts several days of scramble into an afternoon.
- Board approval of the risk assessment, minuted by version. "The board has seen it" is materially weaker than a minute referencing the version and date approved.
- The monitoring rule inventory with parameter rationale. Firms routinely hold the rule list and not the reasoning behind the thresholds. The reasoning is what gets tested.
- Model validation or tuning reports. Where none exist, the honest position is to say so and show the remediation plan rather than to present a vendor document as validation.
- The MLRO annual report, with evidence it was considered. A report produced and filed without discussion does not demonstrate governance.
- Training records by role, including assessment results and non-completions. Completion percentages alone invite the question of who the remainder are.
- Prior findings and their closure evidence. An examiner will check whether last time's issues were genuinely closed, and re-testing is the only acceptable evidence.
Keep this set in one place, refreshed quarterly. The exercise of assembling it is itself a control test: anything you cannot produce within a day is something you could not produce under examination either.
Evidence Ready Before the Examiner Asks
One Constellation keeps the audit trail examiners test — tuning records, alert dispositions, EDD completion and decision logs — retrievable from one place.
