Risk Assessment
Document the institution-wide risk assessment, including methodology, risk scoring, data sources, and dates of last update; attach model output and approval records.
A consistent checklist reduces gaps by turning regulatory requirements into verifiable tasks, improving audit readiness and making deficiencies visible early so they can be remediated before enforcement action or operational failure.
Organizations use the checklist during initial program implementation, annual reviews, vendor assessments, and targeted remediation projects.
Use the checklist as a working record: attach evidence, note dates, list responsible parties, and retain the completed checklist with program documentation.
Document the institution-wide risk assessment, including methodology, risk scoring, data sources, and dates of last update; attach model output and approval records.
Record CDD steps for sampled customers: identity verification, beneficial owner identification, risk tier assignment, enhanced due diligence where applicable, and documentary evidence retained.
List monitoring rules, thresholds, tuning logs, alerts generated, investigation outcomes, and model-change records showing ongoing maintenance and false-positive reduction efforts.
Include SAR decision logs, filing dates, narrative summaries, internal approvals, and evidence of timeliness and confidentiality controls around SAR handling.
Attach current policies and procedures, training schedules and completion records, role-specific curricula, and attestations demonstrating staff understanding.
Show retention schedules, audit trails, management reporting, board minutes addressing AML matters, and evidence that corrective actions were tracked to completion.
Use secure platforms that support fillable PDFs, audit trails, and controlled access for evidence collection.
Choose a platform that preserves audit trails, supports role-based access, and integrates with case-management or ticketing systems for remediation workflows.
| Field | Configuration |
|---|---|
| Customer ID | Auto-populate from CRM |
| Risk Tier | Dropdown with required justification |
| Evidence Upload | Require attachment, PDF preferred |
| Reviewer Sign-off | Electronic signature + timestamp |
Annual program review is standard practice
Quarterly or on model change
File promptly after detection per FinCEN guidance
File per 31 C.F.R. requirements (standard filing windows)
At least annually for covered employees
| Criteria | AML Checklist | AML Policy |
|---|---|---|
| Purpose | operational verification | governing rules |
| Owners | compliance team | board + compliance |
| Frequency | periodic evidence checks | annual review |
| Legal Effect | evidence file | binding policy |
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies by vendor | Varies by vendor | Varies by vendor | Varies by vendor |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies | Varies | Varies |