AML Compliance Programme Review Checklist Template
Most AML failures that end in enforcement were visible in the firm’s own management information months earlier. The alert backlog was growing, periodic reviews were overdue and training had slipped, and nobody was required to look at all of it together and sign their name.
An anti-money laundering programme is not a policy document. It is a set of controls that run every day: transaction monitoring, suspicious activity reporting, customer due diligence, sanctions screening and staff training. Each is usually owned by a different team, working in a different system. The monthly programme review is the control over those controls. Once a month the MLRO or BSA officer looks at the numbers from every part of the programme, challenges what looks wrong, records a conclusion and assigns actions. This free AML compliance checklist gives banks, payment firms, wealth managers, fintechs and other regulated firms a repeatable review. The monthly steps run in the same order every time, and a conditional annual section covers the risk assessment refresh, the independent test and the MLRO’s annual report. Every step has an owner, every conclusion is signed off and every month leaves an evidence trail that an examiner can follow.
Running the Controls vs Reviewing the Programme: Two Different Jobs
Transaction monitoring systems, KYC platforms and screening tools do the operational work. They generate alerts, collect documents and flag names. What they cannot do is tell you whether the programme as a whole is working. A monitoring system will happily report that it closed 4,000 alerts last month. It will not tell you that 300 of them were closed with a one-word rationale, that one scenario has produced no alerts since its threshold was changed, or that the team closing them is two analysts short.
Regulators on both sides of the Atlantic expect a named senior individual to own that judgement. In the US, the Bank Secrecy Act requires a designated BSA compliance officer. In the UK, the Money Laundering Regulations 2017 and the FCA’s SYSC rules require a nominated officer and an MLRO who reports to senior management. A monthly review is how that person turns a regulatory title into a documented, repeatable act of oversight.
Operational AML controls
Run by first line and financial crime operations
Examples: alert investigation, KYC onboarding, screening hit review, SAR drafting.
Output: a signed conclusion on effectiveness, escalations and an action log.
Tooling: a structured checklist with evidence, owners and sign-off.
What the AML Programme Review Checklist Covers
Six monthly phases take the review from data collection to MLRO sign-off. A seventh phase switches on automatically for the annual review.
Phase 1
Phase 1: Prepare the Review Pack
Assign this phase to a compliance analyst so the data is ready before the MLRO’s review is scheduled. The review is only as good as the MI that goes into it.
Open the review record for the period — confirm the month under review and carry forward every open action from last month’s review
Pull transaction monitoring MI — alerts generated, closed and outstanding, with backlog ageing broken down by scenario
Pull suspicious activity MI — internal referrals received, reports filed, filing timeliness and any consent (DAML) requests
Pull CDD and KYC MI — onboarding volumes, enhanced due diligence cases, overdue periodic reviews and approved exceptions
Pull sanctions screening MI — potential matches, confirmed matches and the dates each list was last updated in the screening tool
Pull training MI — completion rate against target, overdue staff by team and new joiners still to complete
Phase 2
Phase 2: Transaction Monitoring & Alert Quality
Review the alert backlog against the agreed service level — escalate any alert older than the threshold, with a named owner and a clearance date
Quality-check a sample of closed alerts — is the rationale specific, consistent and supported by the evidence on file?
Review scenario performance — false-positive rates, scenarios producing no alerts at all and volumes that have moved sharply since last month
Confirm there were no unapproved rule or threshold changes in the period — check the change log against model governance approvals
Record QA failures and tuning requests in the issues log — each with an owner and a due date
Phase 3
Phase 3: Suspicious Activity Reporting
Reconcile internal referrals to decisions — every referral is either reported or closed with a documented no-file rationale
Check filing timeliness — US SARs within 30 calendar days of initial detection (60 where no suspect is identified); UK SARs to the NCA as soon as practicable
Root-cause any late filing and record the remediation in the issues log
For UK consent (DAML) requests — confirm the 7-working-day notice period and any 31-day moratorium were tracked and respected
Confirm SAR confidentiality — access to reports is restricted and no tipping-off risk arose from customer contact
Phase 4
Phase 4: Customer Due Diligence & Sanctions
Review overdue periodic KYC reviews by customer risk rating — high-risk overdue reviews get a remediation date this month
Check high-risk and PEP relationships approved in the period — senior management approval and source-of-wealth evidence on file
Review CDD exceptions and waivers — each approved by an authorised person and time-limited
Confirm sanctions list updates were loaded within the firm’s defined timeframe after OFAC, UN, UK and EU changes, and the customer base was re-screened
For confirmed sanctions matches — confirm assets were frozen or the transaction rejected, and reported (OFAC within 10 business days; OFSI as soon as practicable)
Phase 5
Phase 5: Training, Issues & Regulatory Change
Chase overdue AML training — escalate to line managers for staff past the deadline; confirm role-specific training for high-risk functions
Update the AML issues and actions log — new findings from QA, internal audit and regulators; close items with evidence; flag anything overdue
Scan for regulatory change — new FinCEN, FCA, JMLSG, OFSI or AMLA publications, each with an impact assessment and an owner
Draft the monthly MI summary for senior management or the financial crime committee
Phase 6
Phase 6: MLRO / BSA Officer Review & Sign-Off
This phase is assigned to the MLRO or BSA officer by name. It cannot be completed by the analyst who prepared the pack.
Review the pack and challenge the numbers — record questions and the answers received
Record a conclusion on programme effectiveness for the month — effective, effective with actions, or not effective
Escalate to senior management or the board where the conclusion requires it — record who was told and when
Confirm every new action has an owner and a due date, then sign off the review
Phase 7 — Annual Only
Phase 7: Annual Programme Review
Shown only when the review is marked as the annual review. Conditional logic keeps the monthly checklist short for the other eleven months.
Refresh the firm-wide ML/TF risk assessment — customers, products, geographies, channels and the national risk assessment or FinCEN priorities
Review AML policies and procedures against the refreshed risk assessment, and obtain senior management approval
Confirm the independent test or audit has been completed, and that its findings are in the issues log with owners
Prepare the MLRO’s annual report on the operation and effectiveness of AML systems and controls, for the board or senior management
Confirm the MLRO or BSA officer designation is current and that the financial crime function is adequately resourced
Set next year’s training plan and QA sampling approach based on this year’s findings
US and UK rules describe the same core programme in different words. Most practitioners know the US version as the “pillars” of a BSA/AML programme. The table maps each element to its main source and to the part of the review that produces evidence for it. Your own obligations depend on your firm type and regulator, so treat the table as a starting point, not legal advice.
Programme element
United States
United Kingdom
Evidenced in
Risk assessment
Expected by examiners; FinCEN’s April 2026 proposal would make it an explicit requirement
Firm-wide risk assessment, MLR 2017 reg. 18
Phase 7
Policies, controls & procedures
Internal controls, e.g. 31 CFR 1020.210 for banks
MLR 2017 reg. 19
Phases 2–5, Phase 7
Responsible officer
Designated BSA compliance officer
MLR 2017 reg. 21 and the FCA’s MLRO rules in SYSC
Phase 6
Training
Ongoing employee training
MLR 2017 reg. 24
Phases 1 and 5
Independent testing
Independent testing of the programme
Independent audit function where appropriate to size and nature, reg. 21
Phase 7
Customer due diligence
CDD and beneficial ownership rule, 31 CFR 1010.230
MLR 2017 Part 3, including EDD and PEPs
Phase 4
EU firms should plan for the Anti-Money Laundering Regulation (EU) 2024/1624, which applies directly across member states from 10 July 2027. The new EU Anti-Money Laundering Authority will begin directly supervising a small group of the highest-risk cross-border institutions from 2028. The review structure above carries over: only the references change.
Why Run Your AML Programme Review in CheckFlow?
1
It starts itself every month
A recurring schedule creates the review on the first working day of each month and assigns Phase 1 to the analyst who prepares the pack. Nobody has to remember to start it, and a missed month shows up as an overdue checklist rather than a gap discovered during an examination.
2
Sign-off belongs to a named person
The MLRO sign-off phase is assigned to one person by name, and each task records who completed it and when. MI extracts, QA samples and committee papers are attached to the task they support, so the evidence for every conclusion sits in one place.
3
Twelve months of reviews, ready for the examiner
When the examiner asks for evidence of ongoing oversight, you export the last twelve completed reviews with their timestamps, attachments and actions. The annual phase shows the risk assessment refresh and the MLRO report sitting in the same trail.
CheckFlow is not a transaction monitoring or KYC platform, and it does not replace one. It runs the human review and attestation work around those systems. Our guide to financial services workflow automation explains where that line sits, and lists the other recurring compliance workflows (sanctions list checks, SOX control testing and DORA ICT risk reviews) that follow the same pattern.
It is a scheduled, documented assessment of whether a firm’s anti-money laundering controls are working. The MLRO or BSA officer reviews management information from each part of the programme: transaction monitoring, suspicious activity reporting, customer due diligence, sanctions screening and training. They then challenge anything that looks wrong, record a conclusion and assign actions. Most firms run a lighter review monthly and a full review annually, alongside the risk assessment refresh.
How often should an AML programme be reviewed?
+
Regulations set some fixed points and leave the rest to a risk-based judgement. In the UK, the FCA expects the MLRO to report to senior management at least annually on how the AML systems and controls operate and how effective they are. In the US, independent testing is commonly carried out every 12 to 18 months, depending on the institution’s risk profile. A monthly MI review sits between those points. It catches backlogs, overdue reviews and training gaps while they are still small, and it gives the annual report twelve documented data points to draw on.
What should an AML compliance checklist include?
+
At minimum it should cover the core programme elements: the risk assessment, policies and controls, a responsible officer, training, independent testing and customer due diligence. In practice it also needs the operational checks that show those elements are working. Those include alert backlog and QA, SAR timeliness, overdue periodic reviews, PEP and high-risk approvals, sanctions list update dates, and an issues log with owners. Most importantly it should end in a signed conclusion, because the review is only evidence of oversight if someone accountable records a judgement.
Who should sign off the AML programme review?
+
The MLRO in the UK, or the designated BSA/AML compliance officer in the US. An analyst can prepare the pack, but the conclusion and sign-off should belong to the person accountable for the programme. That keeps preparation separate from review. Where the conclusion is that the programme is not effective, or a material issue has emerged, the checklist should also record the escalation to senior management or the board.
Does this checklist replace our transaction monitoring or KYC system?
+
No. Monitoring, case management, KYC and screening systems do the operational work, and CheckFlow does not replace them. This checklist runs the oversight layer on top of them: collecting their output, reviewing it, recording decisions and tracking actions to closure. The MI extracts from those systems are attached to the relevant tasks as evidence.
Can the template be adapted for a smaller firm?
+
Yes. The template is fully editable. A small payment institution or wealth manager might merge Phases 2 and 3, drop the scenario-tuning tasks if it uses a vendor’s standard rules, and run the full review quarterly rather than monthly. The principle stays the same at any size: collect the evidence, review it, sign it off and track the actions.
Is CheckFlow free for this template?
+
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.
Twelve Signed Reviews a Year, Not a Scramble Before the Exam
Free trial — no credit card required.
Do you like cookies? 🍪 We use cookies to ensure you get the best experience on our website. Learn more