AML

Master this essential documentation concept

Quick Definition

Anti-Money Laundering - a set of laws, regulations, and procedures designed to prevent criminals from disguising illegally obtained funds as legitimate income, requiring specific compliance documentation.

How AML Works

graph TD A[Customer Onboarding] --> B[KYC Verification] B --> C{Risk Assessment} C -->|Low Risk| D[Standard Monitoring] C -->|High Risk| E[Enhanced Due Diligence] C -->|Prohibited| F[Account Rejection] D --> G[Transaction Screening] E --> G G --> H{Suspicious Activity?} H -->|No| I[Transaction Approved] H -->|Yes| J[SAR Filing] J --> K[FinCEN / Regulatory Reporting] E --> L[PEP & Sanctions Check]

Understanding AML

Anti-Money Laundering - a set of laws, regulations, and procedures designed to prevent criminals from disguising illegally obtained funds as legitimate income, requiring specific compliance documentation.

Key Features

  • Centralized information management
  • Improved documentation workflows
  • Better team collaboration
  • Enhanced user experience

Benefits for Documentation Teams

  • Reduces repetitive documentation tasks
  • Improves content consistency
  • Enables better content reuse
  • Streamlines review processes

Turning AML Training Videos into Auditable SOPs

Compliance teams frequently rely on recorded walkthroughs to train staff on AML procedures — covering everything from customer due diligence steps to suspicious activity reporting workflows. These videos work well for onboarding, but they create a real problem when regulators or auditors ask your team to demonstrate documented, repeatable processes.

The core challenge is that video is difficult to audit. When an examiner requests evidence that your staff follows a consistent AML screening process, pointing them to a recorded walkthrough is rarely sufficient. Regulators expect written SOPs with clear steps, version histories, and named accountabilities — not a timestamp in a training video. Your team also loses time scrubbing through recordings every time a procedure changes or a new hire needs to verify a specific step.

Converting those existing AML process videos into formal written SOPs closes this gap directly. A structured document captures each compliance checkpoint in a searchable, referenceable format — making it straightforward to update procedures when regulations change, assign ownership to specific steps, and provide auditors with the traceable documentation they require. For example, a video demonstrating your transaction monitoring review process can become a versioned SOP that your compliance officer can sign off on and your team can follow consistently across every case.

If your AML compliance documentation still lives primarily in video form, learn how to convert those recordings into audit-ready SOPs →

Real-World Documentation Use Cases

Documenting SAR Filing Workflows for a Regional Bank's Compliance Team

Problem

Compliance officers at regional banks struggle to maintain consistent Suspicious Activity Report filing procedures across branches, leading to missed deadlines, incomplete narratives, and regulatory penalties from FinCEN audits.

Solution

AML compliance documentation standardizes the SAR filing process by defining trigger thresholds, narrative templates, escalation paths, and submission timelines in a single authoritative reference, ensuring every branch follows the same procedure.

Implementation

['Map the end-to-end SAR lifecycle from initial alert triage through FinCEN submission, documenting each decision point and responsible role (analyst, BSA officer, legal).', 'Create narrative templates for common suspicious patterns (structuring, layering, smurfing) with required data fields, dollar thresholds, and supporting evidence checklists.', 'Define escalation SLAs: document the 30-day filing window from detection, internal review steps, and approval authority levels required before submission.', "Publish the workflow in the compliance knowledge base with version history and link it to the bank's case management system so analysts access it during active investigations."]

Expected Outcome

Branches reduce SAR filing errors by standardizing narratives and deadlines, resulting in fewer FinCEN rejection notices and demonstrable audit readiness during BSA examinations.

Building KYC Onboarding Documentation for a Fintech Launching in Multiple Jurisdictions

Problem

Fintechs expanding into the EU, UK, and US simultaneously face conflicting KYC requirements—FATF guidelines, EU's 6AMLD, and FinCEN's CDD Rule—and their compliance teams cannot clearly document which verification steps apply in which jurisdiction, causing onboarding delays and regulatory gaps.

Solution

AML documentation creates jurisdiction-specific KYC runbooks that map each regulatory requirement to concrete onboarding steps, identity verification methods, and document retention policies, allowing product and compliance teams to implement correctly from day one.

Implementation

['Create a regulatory matrix document mapping KYC obligations by jurisdiction: beneficial ownership thresholds (25% US vs. 10% EU high-risk), acceptable ID documents, and liveness check requirements.', 'Write step-by-step onboarding runbooks for each jurisdiction, specifying which third-party identity verification tools (Jumio, Onfido, Persona) satisfy local regulatory standards.', 'Document customer risk-tiering criteria—PEP status, high-risk country of origin, business type—and link each tier to its required Enhanced Due Diligence checklist.', "Establish a documentation review cadence tied to regulatory updates, assigning a compliance owner to each jurisdiction's runbook with a quarterly review schedule."]

Expected Outcome

The fintech achieves consistent onboarding compliance across all three markets at launch, with auditors able to trace every onboarding decision back to a documented regulatory requirement.

Documenting Transaction Monitoring Rules for a Crypto Exchange's Compliance Program

Problem

Crypto exchanges operating under FinCEN's Money Services Business rules and FATF's Travel Rule must document why specific transaction monitoring thresholds and alert rules were chosen, but engineering and compliance teams maintain these rules in separate systems with no shared rationale, creating defensibility gaps during regulatory exams.

Solution

AML documentation bridges the gap by creating a Transaction Monitoring Rule Library that records each rule's regulatory basis, threshold logic, expected alert volume, and tuning history, giving examiners a complete audit trail of compliance intent.

Implementation

["Inventory all active monitoring rules in the exchange's blockchain analytics tool (Chainalysis, Elliptic) and document each rule's name, trigger condition, dollar/crypto threshold, and the specific regulatory requirement it satisfies.", 'For each rule, write a rationale document explaining threshold selection methodology—statistical analysis of transaction patterns, peer benchmarking, or regulatory guidance—to demonstrate the rule is not arbitrary.', 'Document the alert disposition workflow: how analysts triage blockchain alerts, what on-chain evidence they review, and when a disposition escalates to a SAR versus closes as a false positive.', 'Maintain a tuning log for each rule capturing date of change, reason for threshold adjustment, who approved it, and post-change alert volume metrics.']

Expected Outcome

During a FinCEN examination, the exchange can produce a complete, defensible record of every monitoring rule's regulatory basis and operational history, significantly reducing examiner findings.

Creating AML Training Documentation for Frontline Staff at a Money Services Business

Problem

Check cashing and money transfer businesses (MSBs) face high employee turnover, and without structured AML training documentation, new tellers frequently miss red flags for structuring and cash smurfing, exposing the business to BSA civil money penalties.

Solution

AML compliance documentation provides role-specific training materials—red flag recognition guides, structured scenario walkthroughs, and quick-reference cards—that new employees can use immediately and that demonstrate a documented training program to FinCEN examiners.

Implementation

['Document a Red Flag Reference Guide specific to MSB operations: list behavioral indicators (customer breaking a $12,000 transaction into two $6,000 transactions), transaction patterns, and required teller responses for each scenario.', 'Create scenario-based training modules with realistic customer interaction scripts showing compliant versus non-compliant teller responses to structuring attempts, including when to file a CTR.', 'Write a Currency Transaction Report completion guide with annotated field-by-field instructions, common errors (incorrect aggregation of same-day transactions), and submission deadlines.', 'Document the training completion tracking process, including how to record employee acknowledgments, test scores, and annual refresher completion in a format auditors can review.']

Expected Outcome

New teller onboarding time for AML procedures decreases, CTR error rates drop, and the MSB can demonstrate a documented, ongoing training program during FinCEN examinations—a key component of an adequate BSA compliance program.

Best Practices

âś“ Map Every AML Document to Its Specific Regulatory Citation

Each procedure, threshold, or control in your AML documentation should reference the exact regulation, guidance, or rule that requires it—such as 31 CFR 1020.320 for SAR filing or FATF Recommendation 10 for CDD. This creates an auditable chain of compliance intent that examiners can follow. Without explicit citations, regulators cannot distinguish deliberate compliance decisions from accidental omissions.

âś“ Do: Include a 'Regulatory Basis' field in every AML procedure document citing the specific statute, regulation section, or regulatory guidance (e.g., FinCEN FIN-2012-G002) that mandates the control.
âś— Don't: Do not write AML procedures as standalone internal policies without linking them to external regulatory requirements, as this makes it impossible to defend threshold choices or procedural gaps during an examination.

âś“ Version-Control AML Procedures with Dated Change Rationales

AML regulations evolve—FATF mutual evaluations, new FinCEN guidance, and amended BSA rules require corresponding updates to internal procedures. Every version of an AML document should record what changed, why it changed, and who approved the change. Examiners frequently request historical versions to assess whether the institution responded appropriately to regulatory developments.

âś“ Do: Maintain a version history table at the top of every AML procedure document listing version number, effective date, summary of changes, and the name and title of the approving compliance officer.
âś— Don't: Do not overwrite AML documents without preserving prior versions, as regulators may ask for the procedure that was in effect during a specific historical period when a suspicious transaction occurred.

âś“ Write AML Risk Assessments as Living Documents with Defined Review Triggers

An AML/BSA risk assessment is only valid at the point it was written; new products, customer segments, geographies, and typologies can materially change an institution's risk profile. Documentation should specify not just an annual review date but also event-driven triggers—such as launching a new payment product or acquiring a high-risk customer portfolio—that mandate an immediate reassessment.

âś“ Do: Include a 'Review Triggers' section in the AML risk assessment document listing specific business events (new wire transfer product, expansion to a high-risk jurisdiction, merger) that require an out-of-cycle reassessment.
âś— Don't: Do not treat the AML risk assessment as a static annual compliance checkbox; failing to update it after material business changes is a common examination finding that signals a deficient BSA program.

âś“ Separate Customer Risk-Tiering Criteria from Monitoring Threshold Documentation

Customer risk tiers (low, medium, high, PEP) and transaction monitoring alert thresholds are related but distinct compliance controls, and conflating them in a single document creates confusion during audits and system implementation. Risk-tiering documentation should define classification criteria and the due diligence level each tier triggers, while monitoring documentation should define the alert rules that apply to each tier.

âś“ Do: Maintain separate, cross-referenced documents: a Customer Risk Rating Methodology document defining tier criteria and a Transaction Monitoring Rule Library defining which alert rules activate at each risk tier.
âś— Don't: Do not embed transaction monitoring thresholds inside customer onboarding procedures, as this makes it difficult for both analysts and system administrators to locate the authoritative source for alert configuration.

âś“ Document False Positive Disposition Rationale to Demonstrate Monitoring Effectiveness

Regulators evaluating a transaction monitoring program look not only at alert volumes but at how alerts are closed—particularly false positives. Documentation of the analytical rationale used to close an alert as a false positive (reviewing account history, verifying business purpose, checking sanctions lists) demonstrates that the monitoring program is genuinely investigative rather than a checkbox exercise.

âś“ Do: Create a standardized Alert Disposition Template requiring analysts to document the specific evidence reviewed, the logic applied, and the conclusion reached for every alert closed as a false positive, and retain these records for the BSA-required five-year period.
âś— Don't: Do not allow analysts to close transaction monitoring alerts with generic disposition codes or single-word rationales like 'known customer' without supporting analysis, as this pattern is a significant red flag for examiners assessing program adequacy.

How Docsie Helps with AML

Build Better Documentation with Docsie

Join thousands of teams creating outstanding documentation

Start Free Trial