One Constellation
Compliance

AML Training: What Regulators Expect Beyond Completion Rates

Training is a pillar of every AML programme and the pillar most often reduced to a single statistic: percentage completed. That number answers a question nobody is really asking. The question examiners ask is whether the people making risk decisions were equipped to make them.

Published: September 2026 Category: Compliance Read time: ~4 minutes
Quick Answer
The obligation itself is consistent across regimes — FATF Recommendation 18, MLR 2017 Regulation 24 in the UK, the training pillar of the US AML programme requirement, and equivalent provisions in MAS Notice 626. The differences are in the detail; the expectation is universal.

Role-based, not population-based

The dominant weakness in AML training is a single annual module delivered to everyone. It is necessarily pitched at the least specialised audience, which means the people doing the most consequential work receive the least useful training.

A defensible curriculum distinguishes at least five audiences.

All staff

What money laundering is, the firm's risk exposure in plain terms, how to recognise and escalate a concern, and the tipping-off prohibition. Short, annual, and genuinely universal — including contractors with system access.

Customer-facing staff

Adds recognition of behavioural indicators at onboarding and during the relationship, how to handle a customer who resists providing information, and the boundary between asking legitimate questions and tipping off. This group needs scenarios, not definitions.

Onboarding and CDD analysts

Adds the firm's risk rating methodology, EDD triggers and what satisfies them, source of funds versus source of wealth evidence standards, and beneficial ownership in complex structures.

Alert investigators

Adds typologies relevant to the firm's products, how to write a disposition that an independent reader can follow, escalation criteria, and the SAR decision. This is the group where training quality most directly affects programme outcomes.

Senior management and board

Adds the firm's specific risk profile, the regulatory environment, personal accountability, and how to read AML management information critically. Board training is frequently the weakest element of a programme and one of the first things a supervisor examines, because a board that cannot challenge AML reporting cannot govern the programme.

Frequency and triggers

Annual is a floor, not a schedule. Training should additionally be delivered on joining, before a role change takes effect rather than after, when a new product or market is launched, when a regulation changes materially, and in response to findings — an internal audit or QA finding that staff misapplied a control is a training trigger.

Short, frequent, targeted delivery generally outperforms an annual set-piece. A fifteen-minute module on one typology, delivered when that typology appears in your alerts, is retained. A ninety-minute annual refresher is largely not.

Measuring effectiveness

Completion is an input measure. Four measures say more.

  • Assessment results, retained and analysed. Not merely pass rates — which questions were failed most often, and does that pattern match where operational errors occur?
  • Quality outcomes after training. Did disposition quality scores improve? Did EDD completeness improve? If a module was delivered specifically to address a QA finding, did that finding rate move?
  • Escalation behaviour. A healthy programme sees internal escalations from customer-facing staff. Zero escalations from a large front-line population is a signal about training, not about the customer base.
  • Knowledge retention over time. A short assessment some months after delivery tells you far more about whether training worked than one taken immediately afterwards.

The link between training and QA outcomes is what converts training from a compliance formality into a control with evidence behind it — and it is exactly the evidence an examiner asks for when testing control effectiveness in the risk assessment.

Records to keep

Maintain, per individual: the modules completed, dates, assessment results, and the role the training was matched to. Retain the content itself by version — being able to show what was taught in a given year, not merely that something was, is the difference between evidence and assertion when a historic decision is questioned.

Also record non-completion and what was done about it. A completion rate of 97% invites the question of what happened to the other 3%, and "we do not track that" is a poor answer if any of them handle customer risk decisions.

A practical improvement

If your training is currently one annual module for everyone, the highest-value single change is to split out alert investigators and give them scenario-based training built from your own closed cases, with the identifying details removed. It is cheap to produce, directly relevant, measurable against disposition quality scores, and it addresses the group whose decisions carry the most risk.

Related: AML internal audit covers how the training pillar is independently tested.

Building Scenario Training From Your Own Cases

Generic training teaches typologies. Scenario training teaches judgement, and the raw material is already in your case management system.

Selecting cases

Take closed cases from the last year across three groups: those that resulted in a report, those closed correctly after genuine consideration, and those where QA identified an error. The third group is the most instructive and the most uncomfortable, which is why it is usually omitted.

Removing identifying detail

Strip names, account numbers and anything that identifies the customer or the staff member. Change amounts proportionally rather than rounding them, so patterns survive. This also keeps the exercise clear of the tipping-off prohibition.

Running it

Present the alert as the analyst saw it, without the outcome. Ask participants to state their disposition and their reasoning before the actual outcome is revealed. The value is in the divergence — where a group splits on the same facts, you have located a genuine inconsistency in how your programme applies its own standards.

Closing the loop

Feed the divergences back into procedure. If capable analysts disagree about when a case meets the escalation threshold, the threshold is under-specified, and that is a control weakness the training has just surfaced for you.

Training the Board Is a Different Exercise

Board training fails when it is a shortened version of staff training. Directors do not need to recognise typologies; they need to govern a programme.

Four things belong in it. The firm's own risk profile — where its exposure actually sits, drawn from the risk assessment rather than from industry generalities. Personal accountability, including the regime that applies to them specifically. How to read the management information critically: what a falling alert volume might mean, why a rising SAR count is not automatically bad news, what a growing backlog implies. And the questions worth asking — is the function adequately resourced, what has the MLRO escalated this year, what did internal audit find and is it fixed.

Record attendance and content by version. A supervisor examining governance will look for evidence that the board was equipped to challenge, and a generic slide deck delivered annually does not establish it.

Measuring Whether It Stuck

Assessment immediately after delivery measures attention, not retention. Programmes that want evidence of effectiveness need to look later and elsewhere.

Delayed assessment

A short assessment some months after delivery — five or six questions, not a repeat of the original — gives a far better picture of what was retained. Where retention is poor on a specific topic, that topic needs different delivery rather than more of the same.

Behavioural indicators

Three operational measures respond to training and are already collected: internal escalation volume from front-line staff, disposition quality scores from QA, and EDD completeness on files opened after delivery. If none of them moves, the training did not change behaviour whatever the completion rate says.

Error-driven refresh

Route QA and audit findings back into the curriculum on a standing basis. Where the same error recurs across analysts, it is a training gap rather than an individual performance issue, and treating it as the latter is both unfair and ineffective.

Recording this loop matters as much as running it. Being able to show a supervisor that a finding produced a training change, and that the finding rate then fell, is among the strongest evidence of control effectiveness a programme can offer.

Training That Shows Up in Your QA Scores

One Constellation surfaces the disposition quality and error patterns that tell you which training changed behaviour — and which team needs it next.

← MAS Notice 626 Enhanced Due Diligence (EDD) All Articles
Scroll to Top