AML Scenario Gap Finder

Activity above the expected profile

Which scenario compares each customer with their own history or the profile on file, rather than with a flat line for everyone?

A scenario that places here

example

"Profile deviation: monthly credits 300% above 6-month average"

Read this scenario

Channels it applies to

4 of the 20 in the dictionary

CSH ACH WDM WIN

Cash, branch and ATM, ACH and direct entry, domestic wires and international wires: one sector each on the coverage chart, hatched where no scenario reaches it.

Obligations

3 regimes
RegimeObligation
Bank Secrecy Act and its regulations (31 CFR Chapter X)BSA BSA-AML-15 Transaction Monitoring · BSA BSA-CDD-3 Customer Risk Profiling
FATF 40 RecommendationsFATF R.10 Customer due diligence
Anti-Money Laundering and Counter-Terrorism Financing Act (Australia)AUSTRAC AMLCTF-PartA-TxnMon Transaction Monitoring · AUSTRAC AMLCTF-PartA-OCDD Ongoing Customer Due Diligence

The obligations, quoted

BSA BSA-AML-15 Transaction Monitoring

Automated and manual transaction monitoring shall identify unusual or suspicious activity using risk-based scenarios and thresholds.

What an examiner asks to see: TM scenario inventory; Threshold tuning documentation; Above-the-line/below-the-line testing; Model validation reports
Where programmes usually fall short: No model validation; Scenarios not aligned to risk assessment
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-CDD-3 Customer Risk Profiling

Financial institutions must develop a customer risk profile for each customer, understanding the nature and purpose of the customer relationship. Risk profiles guide ongoing monitoring.

What an examiner asks to see: Registration certificate copies; Filing submission evidence; Renewal calendar; Public register screenshots; Registration fee payment records
Where programmes usually fall short: Renewals tracked informally; Filings missed on minor updates
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
FATF R.10 Customer due diligence

Financial institutions may not keep anonymous accounts or accounts in obviously fictitious names and must, by a principle set out in law, undertake customer due diligence when establishing a business relationship, carrying out an occasional transaction above USD or EUR 15,000 or a payment or value transfer covered by INR.16, when money laundering or terrorist financing is suspected, or when they doubt previously obtained identification data: identify and verify the customer from reliable independent sources; identify the beneficial owner and take reasonable measures to verify that identity, understanding the ownership and control structure of legal persons and arrangements; understand and where appropriate obtain information on the purpose and intended nature of the relationship; and conduct ongoing due diligence and transaction scrutiny consistent with the customer's profile including, where necessary, the source of funds. The extent of each measure follows a risk-based approach; verification takes place before or during establishment of the relationship, or as soon as reasonably practicable after it where risks are managed and business would otherwise be interrupted; an institution that cannot complete CDD does not open the account or perform the transaction, or terminates the relationship, and considers a suspicious transaction report; the requirements apply to new customers and, on materiality and risk, to existing ones. The Interpretive Note sets the risk-based approach, enhanced and simplified measures, the specific measures for legal persons, arrangements and beneficiaries of life insurance, reliance on prior verification and the timing rules.

What an examiner asks to see: CDD policy and procedures with triggers and thresholds; Customer files with identity, beneficial ownership, purpose and risk rating; Ongoing monitoring and periodic review records
Where programmes usually fall short: Beneficial owner identified but never verified; Ownership and control structure of corporate customers not understood
Source: FATF 40 Recommendations
AUSTRAC AMLCTF-PartA-TxnMon Transaction Monitoring

Systems and controls for monitoring customer transactions for unusual or suspicious activity.

What an examiner asks to see: Transaction monitoring system & rules; Alert investigation records
Where programmes usually fall short: No transaction monitoring
Source: Anti-Money Laundering and Counter-Terrorism Financing Act (Australia)
AUSTRAC AMLCTF-PartA-OCDD Ongoing Customer Due Diligence

Processes to ensure customer information remains up-to-date, including enhanced customer due diligence (ECDD) for high-risk customers.

What an examiner asks to see: OCDD program incl. trigger-based reviews
Where programmes usually fall short: No ongoing CDD
Source: Anti-Money Laundering and Counter-Terrorism Financing Act (Australia)

Other typologies in profile change and dormant reactivation