Skip to main content
    Free Download · Effective January 1, 2028

    The AML Program Starter Kit

    Everything an adviser needs to stand up a written AML/CFT program under FinCEN's investment adviser rule — five-pillar outline, customer due diligence sheet, SAR decision tree, and an independent testing scope.

    • Five-pillar program outline you can adopt and tailor
    • Customer due diligence and beneficial ownership worksheet
    • SAR / CTR decision tree with escalation timing
    • Independent testing scope and evidence list

    Get the starter kit

    PDF arrives in your inbox in under a minute.

    No spam. One-click unsubscribe. You'll also receive our weekly compliance digest.

    What's inside

    9 sections, 56 line items — the documents, decisions, and evidence a regulator or independent tester will ask to see in your first AML review.

    1

    Applicability: which advisers and which advisory activities are covered

    2

    Pillar 1 — Designated AML compliance officer and governance

    3

    Pillar 2 — Internal policies, procedures, and risk assessment

    4

    Pillar 3 — Ongoing employee training program

    5

    Pillar 4 — Independent testing scope and cadence

    6

    Pillar 5 — Customer due diligence and beneficial ownership

    7

    Suspicious activity: red flags, escalation, SAR timing, and confidentiality

    8

    Recordkeeping, information sharing, and OFAC / sanctions screening

    9

    Implementation timeline and first-year evidence file

    Who the rule reaches

    FinCEN's final rule extends Bank Secrecy Act obligations to SEC-registered investment advisers and exempt reporting advisers, treating them as financial institutions for AML/CFT purposes. Certain advisory activities are excluded — the kit includes the applicability test so you scope the program to the business you actually run rather than adopting a bank manual wholesale.

    Even where an adviser relies on a qualified custodian or fund administrator for parts of the workflow, the program obligation stays with the adviser. Delegation is permitted; abdication is not.

    • Applicability test for RIAs, ERAs, and excluded advisory activities
    • Mapping of delegated functions to retained adviser responsibility
    • Where private fund subscription reviews fit into the program

    The five pillars, written for an adviser

    A compliant program has a designated officer with authority and access, risk-based written policies, ongoing training, independent testing, and customer due diligence including beneficial ownership identification for legal entity clients. The starter kit gives you the outline for each pillar with the language advisers commonly get wrong — most notably a risk assessment that is generic rather than tied to the firm's client base, geographies, products, and distribution channels.

    The training section includes a role-based matrix: what client-facing staff need versus operations, versus the designated officer, and how to evidence completion.

    • Designated officer appointment resolution and reporting line
    • Risk assessment factors: clients, geographies, products, channels
    • Role-based training matrix with evidence of completion
    • CDD file standards and beneficial ownership thresholds

    Suspicious activity: know the clock

    Suspicious activity reporting has hard deadlines and strict confidentiality rules. The kit's decision tree walks an escalated concern from the first observation through internal review, the filing decision, and the recordkeeping that follows — including what to do when no suspect is identified and when a continuing-activity report becomes due.

    It also lists adviser-specific red flags: unusual subscription and redemption patterns, reluctance to provide beneficial ownership information, third-party funding, and rapid movement of funds inconsistent with the stated investment objective.

    • Escalation path and internal documentation standard
    • Filing deadlines and continuing-activity timing
    • SAR confidentiality and no-tipping rules
    • Adviser-specific red flag catalog

    Independent testing is where programs fail

    Independent testing must be performed by someone who is not the designated AML officer and does not report to them for AML purposes. The tester reviews program design and operating effectiveness, samples client files, and reports findings to senior management or the board with tracked remediation.

    The kit includes the scope, sampling approach, and evidence list we use in fixed-fee reviews so you can prepare before the tester arrives — or run a self-assessment gap analysis first.

    • Independence criteria and acceptable testers
    • Scope: design review, transaction and file sampling, screening validation
    • Evidence request list to prepare in advance
    • Findings, remediation tracking, and reporting to management

    Built by working CCOs

    Compiled from live engagements across SEC-registered, state-registered, and exempt-reporting firms.

    2026-current

    Reflects the rules and guidance in effect for the 2026 examination cycle.

    Examiner-tested

    Organized around the deficiency themes regulators actually cite in exam letters.

    Frequently asked questions

    When do investment advisers have to have an AML program in place?

    FinCEN's AML/CFT rule for investment advisers takes effect January 1, 2028. Covered advisers should have a written program adopted, an AML officer designated, training delivered, and an independent testing plan scheduled before that date.

    Does the rule apply to exempt reporting advisers?

    Yes — the rule covers both SEC-registered investment advisers and exempt reporting advisers, with certain advisory activities excluded. The starter kit includes an applicability test so you can scope the program correctly.

    Who can perform AML independent testing?

    Anyone sufficiently independent of the AML function — an outside firm, or qualified internal personnel who are not the designated AML officer and do not report to them for AML purposes. Most advisers outsource it for documented independence.

    Can I rely on my custodian's or administrator's AML checks?

    You can rely on their processes as part of your program, but the obligation remains yours. You need documented diligence on the provider, a clear division of responsibility, and your own escalation and reporting path.

    Need the program built or tested?

    FIN Group writes adviser AML programs and performs fixed-fee BSA/AML independent testing for RIAs, broker-dealers, funds, and fintechs.

    More free tools in the compliance resources hub.