FINRA AML & KYC Compliance Checklist

Last updated: 2026-04-09 — ComplianceStack Editorial Team

20 items
Progress 0 of 20 reviewed

FinCEN assessed .2 billion in penalties for BSA/AML violations in 2023. FINRA and the SEC share AML examination responsibility for broker-dealers, and AML deficiencies consistently rank among the top findings in FINRA's Annual Report on examination priorities. In 2023, FINRA fined firms 3M for AML program failures. The 2024-2026 examination priorities specifically identify digital asset AML controls as a target area. This checklist covers the 20 requirements that appear most frequently in AML enforcement actions and examination deficiency letters against broker-dealers.

Priority Legend:
● Critical ● High ● Medium ● Ongoing

FINRA Compliance Checklist for AML & KYC

1

Adopt a written AML program approved by senior management

Critical 1-2 weeks

The written AML program must be tailored to the firm's specific business model, products, customer types, and geographic markets. Generic programs copied from other firms are cited as deficiencies. The program must be reviewed and updated annually and formally approved by senior management.

FINRA Rule 3310; BSA 31 U.S.C. § 5318(h)
2

Designate an AML Compliance Officer with sufficient authority and resources

Critical 1 day

The AML Officer must have direct access to senior management and the board, sufficient authority to investigate and escalate issues, and adequate resources (staff and systems) to fulfill the role. The AML Officer cannot be the firm's sole compliance officer for a large, complex firm.

FINRA Rule 3310(a); FinCEN CDD Final Rule (2018)
3

Implement a Customer Identification Program (CIP) meeting 31 CFR 1023.220 requirements

Critical 2-3 days

For individuals: name, date of birth, address, and SSN/TIN are required. For entities: name, address, and TIN are required. Verify identity using documentary or non-documentary methods. Record the information collected and verification method. Provide CIP notice to customers.

31 CFR 1023.220; BSA § 326; FinCEN CIP Rule
4

Implement a Customer Due Diligence (CDD) program including beneficial ownership identification

Critical 2-3 days

FinCEN's CDD Final Rule (effective 2018) requires broker-dealers to identify and verify the beneficial owners of legal entity customers — any individual owning 25%+ and one person with significant control. Collect beneficial ownership information at account opening and update when the firm becomes aware of changes.

31 CFR 1010.230; FinCEN CDD Final Rule (2018)
5

Establish risk-based Enhanced Due Diligence (EDD) procedures for high-risk customers

Critical 3-5 days

High-risk categories requiring EDD include: Politically Exposed Persons (PEPs), non-resident aliens, high-risk jurisdictions (FATF blacklist and greylist countries), cash-intensive businesses, correspondent banks, and customers with complex or opaque ownership structures. EDD must include additional source of funds verification.

FINRA Rule 3310; FinCEN CDD Rule; FATF Recommendations
6

Implement a transaction monitoring program to detect suspicious activity

Critical 1-2 weeks

Monitor for: large cash transactions (0,000+ reporting threshold), structuring activity (multiple transactions designed to avoid reporting), unusual wire transfer patterns, round-dollar transactions, and activity inconsistent with customer profile. Automated transaction monitoring systems are the industry standard for any firm with meaningful transaction volumes.

31 U.S.C. § 5313; 31 CFR 1023.310 (CTR); FinCEN Advisory FIN-2014-A007
7

File Currency Transaction Reports (CTRs) for cash transactions exceeding 0,000

Critical Ongoing

Any currency transaction or series of related transactions exceeding 0,000 must be reported to FinCEN within 15 days using FinCEN Form 112. Structuring transactions to avoid CTR filing is a federal crime (31 U.S.C. § 5324). Ensure tellers and operations staff recognize structuring patterns.

31 U.S.C. § 5313; 31 CFR 1023.310
8

File Suspicious Activity Reports (SARs) within 30 days of detecting suspicious activity

Critical Ongoing

SARs are required when a transaction involves ,000+ and the firm knows, suspects, or has reason to suspect: proceeds of illegal activity, designed to evade reporting, no lawful purpose, or use of the firm to facilitate criminal activity. SAR filings are confidential — never tip off the subject of a SAR.

31 CFR 1023.320; 31 U.S.C. § 5318(g)
9

Screen customers against OFAC sanctions lists before account opening and on an ongoing basis

Critical 1-2 days

Transactions with Specially Designated Nationals (SDNs) and sanctioned countries are prohibited. Screen at account opening, on a daily basis against updated OFAC lists, and upon triggering events (new beneficial owner, change of name). OFAC violations carry strict liability — intent is not required.

31 CFR Part 594; OFAC SDN List; International Emergency Economic Powers Act
10

Conduct independent AML testing at least annually by a qualified party

Critical 1-2 weeks

The BSA requires broker-dealers to conduct independent testing of the AML program. Testing must be conducted by a qualified independent party — this can be internal audit (if independent from the AML function) or an outside firm. The test must evaluate all components of the AML program and produce a written report to senior management.

FINRA Rule 3310(c); BSA 31 U.S.C. § 5318(h)(2)(C)
11

Provide ongoing AML training to all relevant employees

High Half day per year

Annual AML training is required for all employees involved in customer-facing activities, account opening, transaction processing, and supervision. Training must cover: identification of suspicious activity, SAR filing procedures, CIP requirements, OFAC screening, and consequences for AML failures. Document completion.

FINRA Rule 3310(d); BSA 31 U.S.C. § 5318(h)(2)(D)
12

Establish a process to escalate and document AML red flags identified by staff

High 1-2 days

Employees must have a clear escalation path when they identify suspicious activity. Red flags should be documented, reviewed by the AML Officer, and either resolved with documentation or escalated to a SAR. Ensure employees understand that failing to report red flags is itself a compliance failure.

FINRA Rule 3310; FinCEN SAR Filing Instructions
13

Implement correspondent account due diligence for accounts held for foreign financial institutions

High 2-3 days

The USA PATRIOT Act requires enhanced due diligence for correspondent accounts held for foreign financial institutions. This includes: identifying the owners of the foreign bank, evaluating its AML controls, and prohibiting accounts for foreign shell banks (banks with no physical presence).

31 U.S.C. § 5318(i); 31 CFR 1010.610, 1010.620
14

Screen for Politically Exposed Persons (PEPs) and apply enhanced due diligence

High 2-3 days

PEPs — current or former senior foreign political officials and their close associates and family — present heightened corruption risk. Screen all new customers and beneficial owners against PEP databases at account opening and annually. If a PEP is identified, EDD applies: obtain senior management approval, verify source of funds, and conduct enhanced ongoing monitoring.

FinCEN CDD Rule; FATF Recommendation 12
15

Monitor for unusual wire transfer patterns and correspondent banking red flags

High Ongoing

Wire transfers are among the highest-risk AML vectors. Monitor for: wires to/from high-risk jurisdictions, wires that reverse previous wires, multiple wires from multiple customers to the same beneficiary, and wires inconsistent with the customer's stated business. SWIFT gpi and LEI verification improve counterparty identification.

31 CFR 1023.320; FinCEN Wire Transfer Rules 31 CFR 1010.410(f)
16

Implement a digital asset AML program if the firm facilitates digital asset transactions

High 1-2 weeks

FINRA's 2024 examination priorities specifically target digital asset AML controls. Virtual asset transactions present unique AML challenges: pseudonymous addresses, cross-border peer-to-peer transfers, and mixing services. Firms facilitating digital asset transactions must apply blockchain analytics tools (Chainalysis, Elliptic) and apply source of funds requirements.

FINRA Regulatory Notice 23-08; FinCEN Virtual Currency Guidance (2019)
17

Maintain AML records for at least five years

Medium Ongoing

All AML program records must be maintained for five years: CIP records, CDD files, SAR filings, CTR reports, OFAC screening records, and training documentation. Retain SAR supporting documentation separately and securely — SAR tipping is a federal crime. Electronic records must meet 17a-4 WORM storage requirements.

31 CFR 1023.430; Exchange Act Rule 17a-4
18

Review and update the AML program following regulatory or business changes

Medium Ongoing

Trigger events for AML program review: new FINRA or FinCEN guidance, new products or customer types, new geographic markets, significant growth in transaction volumes, or a SAR or CTR that reveals a program gap. Do not wait for the annual review cycle if a material change occurs.

FINRA Rule 3310; BSA 31 U.S.C. § 5318(h)
19

Establish procedures to address AML law enforcement requests and legal process

Medium 1 day

When law enforcement serves a subpoena, civil investigative demand, or Section 314(a) information request, the firm must respond within 14 days (314(a)) or the deadline specified in legal process. Designate a point of contact for law enforcement. Ensure that records are accessible and can be produced in the format required.

31 CFR 1010.520 (Section 314(a)); BSA 31 U.S.C. § 5318
20

Assess AML controls for newly introduced products before launch

Medium 2-3 days

New products — particularly those involving digital assets, international transfers, or anonymous funding mechanisms — should undergo an AML risk assessment before launch. The AML Officer should review and approve new product launches from an AML perspective. Post-launch monitoring requirements should be specified before product goes live.

FINRA Rule 3310; OCC Risk Management Guidance for New Products

See How Your AML & KYC Scores on FINRA

Run a free gap analysis to find out which items you have covered and where the risks are.

Gap Analyzer →   Training Tracker →

Common Mistakes That Trigger Enforcement

Copying another firm's AML program without customizing it to the firm's business model
FINRA examiners are experienced enough to identify generic programs. A program that does not reflect the firm's actual products, customer types, and risk profile is treated as the absence of a program.
Treating the ,000 SAR threshold as the only trigger for filing
The SAR obligation is triggered by suspicious activity regardless of dollar amount — the ,000 threshold applies to transaction-based SARs. Structuring, impersonation, and attempted violations require SAR consideration even below the dollar threshold.
Using annual OFAC screening rather than daily screening against updated lists
OFAC adds and removes names from the SDN List continuously. Annual screening will miss names added in the past year. Firms must screen against the current OFAC list before processing any transaction, and run daily batch screens on existing customers.
Allowing the AML Officer to report to the CCO rather than directly to senior management
The AML Officer must have direct access to senior management. If the AML Officer's escalations can be filtered by the CCO before reaching the board or CEO, the independent escalation path required by the BSA is compromised.
Failing to file SARs for structuring activity when no single transaction exceeds 0,000
Structuring — breaking transactions into smaller amounts to avoid CTR reporting — is itself a federal crime and requires a SAR. The SAR obligation for structuring applies regardless of the size of any individual transaction.

Frequently Asked Questions

Is a broker-dealer required to have a separate AML program from its parent company?

Yes. Each FINRA member must maintain its own written AML program that is tailored to its specific business. A broker-dealer cannot simply adopt its bank holding company parent's AML program. The programs can be coordinated and share resources, but the broker-dealer's program must specifically address the AML risks of its securities business and meet the BSA requirements applicable to broker-dealers.

What is the difference between a CTR and a SAR?

A Currency Transaction Report (CTR) is required for any cash transaction exceeding 0,000 — it is a mandatory disclosure of a specific transaction, not an allegation of wrongdoing. A Suspicious Activity Report (SAR) is required when the firm suspects illegal activity — it is a report of suspected money laundering or other financial crime and is confidential. A single transaction can trigger both a CTR (if over 0,000 in cash) and a SAR (if the transaction is suspicious).

Can we use a third-party vendor for CIP verification?

Yes. FINRA members can rely on third-party vendors for CIP verification, provided the firm has a written agreement with the vendor, the vendor is subject to AML program requirements, and the firm retains ultimate responsibility for CIP compliance. Third-party CIP reliance does not relieve the broker-dealer of responsibility for any CIP failures. Common third-party CIP providers: Socure, Alloy, Jumio.

✉ Save This Checklist

Enter your email and we'll send you a clean copy — plus updates when requirements change.

We also offer a free personalized gap analysis for your specific situation.

Related Resources