8.1 AML Program, Independent Testing, Training, and Governance
Key Takeaways
Rule 3310 requires a written AML program approved in writing by senior management and reasonably designed for the firm's business and BSA risks.
The program includes internal policies and controls, independent testing, a designated AML compliance person, ongoing training, and risk-based customer due diligence.
Independent testing is generally annual (every two years for firms that do not execute customer transactions, hold customer accounts, or act as introducing brokers) and may not be performed by the AML compliance person or anyone who performs or reports to the tested functions.
The AML compliance contact information must be current in FINRA's contact system, and findings require documented correction and follow-up.
The Written Program
FINRA Rule 3310 requires each member to develop and implement a written anti-money laundering program reasonably designed to achieve and monitor compliance with the Bank Secrecy Act and its implementing regulations. Senior management must approve the program in writing. The program must reflect the firm's customers, products, account types, funding methods, distribution channels, geography, intermediaries and clearing or direct-business model.
The familiar laundering stages help organize risk: placement introduces illicit value, layering obscures ownership or origin through transactions, and integration returns apparently legitimate funds to the economy. Packaged-product red flags include indifference to surrender charges, rapid purchase and redemption, third-party funding, refunds to a different destination, repeated free-look cancellations, unexplained offshore wires and complex entity ownership with no business rationale.
Program Elements
| Element | Principal's evidence |
|---|---|
| Written policies and internal controls | Risk assessment, monitoring scenarios, escalation, reporting and records tailored to the business |
| Independent testing | Qualified independent tester, appropriate scope, findings, remediation and retest |
| AML compliance person | Clear authority, resources and current contact information reported through FINRA's required system |
| Ongoing training | Role-based instruction, current red flags, attendance and comprehension evidence |
| Customer due diligence | Understanding customer relationships, beneficial owners where required, and ongoing monitoring and updating |
Rule 3310(d) requires the member to designate the AML compliance person or persons, who must be associated persons of the member, to identify them to FINRA by name, title, mailing address, email address, telephone and fax number, and to notify FINRA promptly of any change; Rule 3310.02 applies the Rule 4517 annual review of that contact information. The designated person administers the program but does not absorb every supervisor's responsibility. Representatives and operations personnel must recognize and escalate activity; principals must review exceptions and ensure corrective action; senior management must fund and support the program.
Independent Testing Frequency and Independence
Testing is generally required each calendar year. A member that does not execute transactions for customers, hold customer accounts, or act as an introducing broker with respect to customer accounts may conduct testing every two calendar years. The firm should confirm that it actually satisfies the rule's conditions before using the longer cycle.
Testing may be conducted by member personnel or by a qualified outside party, and the tester must have a working knowledge of the Bank Secrecy Act requirements. Under Rule 3310.01, testing may not be conducted by a person who performs the functions being tested, by the designated AML compliance person, or by anyone who reports to either of them. Firms should test more often than the minimum when circumstances warrant. Scope should follow risk and include governance, CIP, CDD, monitoring, SAR decision processes, CTR controls if currency is accepted, OFAC escalation, information sharing, training, record retention and prior remediation.
Training and Issue Closure
Training must be ongoing and appropriate to duties. A representative needs product-specific red flags and a confidential escalation channel. Operations personnel need controls for wires, checks, ownership changes and returned funds. Analysts need alert investigation and SAR confidentiality. Principals need case escalation, documentation, reporting timelines and anti-retaliation expectations.
An audit report is not closure. Management should assign an owner, risk rating and deadline; preserve evidence of correction; validate that data and systems changed as intended; and retest high-risk findings. Repeated overrides, a backlog of unresolved alerts, incomplete customer risk ratings, or a tester lacking access to data can make an apparently complete program unreasonable.
Supervisory Perspective
AML decisions should be based on the total pattern, not a single threshold. A transaction below a reporting amount can be suspicious; a transaction above a threshold is not necessarily illegal. The principal should prevent frontline personnel from telling a customer that a SAR is being considered and should route government and law-enforcement contacts through authorized staff.
Risk Assessment and Data Quality
The AML risk assessment should link inherent risk to specific controls and residual risk. Customer type, product liquidity, funding method, geography, intermediaries, transaction volume and remote onboarding all matter. A low-cash business can still face fraud, cyber-enabled account takeover, sanctions and rapid movement of redemption proceeds.
Monitoring is only as reliable as its data. Testing should reconcile alerts to orders, wires, ACH, checks, customer ownership and transfer-agent activity; confirm that excluded accounts were legitimately excluded; and challenge thresholds through below-threshold scenarios. A monitoring rule that never generates an alert can be a sign of bad data rather than low risk.
Governance includes timely escalation of backlogs. Management should know alert age, investigator capacity, high-risk customer reviews, overdue SAR decisions and repeat findings. Temporary staffing or system problems need documented compensating controls and a plan to clear risk in priority order.
Board or senior-management reporting should describe significant risk and remediation without exposing SAR information to unauthorized recipients. Metrics need context: fewer alerts may reflect lower risk, a broken data feed or an overly restrictive scenario.
A firm does not execute customer transactions, hold customer accounts, or act as an introducing broker for customer accounts. How often may it generally perform Rule 3310 independent testing?
Every two calendar years, if it continues to satisfy the rule's conditions.
Monthly, because all firms use the same testing interval.
Only after FINRA requests a test.
Every five years because it has no AML risk.
May the employee who runs the firm's transaction-monitoring program perform the required independent test of that same program?
No, because independent testing may be performed only by FINRA staff.
No. The tester must be independent of the functions being tested and qualified to assess them.
Yes, if the employee does not find any exceptions.
Yes, because subject-matter knowledge always establishes independence.
Sections you finish are checked off in the contents.