Glossary
5 Pillars of AML Compliance
The five pillars
- Internal controls: written policies, procedures, and controls built around the firm's actual risk
- BSA/AML compliance officer: a named person responsible for day-to-day compliance
- Training: ongoing, role-appropriate training for relevant staff
- Independent testing: periodic review of the program by someone outside the compliance function
- Customer due diligence: understanding who customers are, why they're transacting, and monitoring on a risk basis
Where the term comes from
The first four pillars have been the basis of US AML exams since the late 1980s. The fifth came from FinCEN's 2016 Customer Due Diligence Rule, which took effect in May 2018 and added beneficial ownership requirements for legal entity customers. "Pillars" is industry shorthand. The regulations themselves describe these as minimum program requirements.
Who it applies to
Every institution with a BSA program obligation, including banks, broker-dealers, and MSBs such as crypto exchanges. The formal CDD Rule applies to banks, broker-dealers, mutual funds, and futures firms. MSBs handle customer verification through their own AML program requirements.
What's changing
In April 2026, FinCEN proposed rules that would reshape AML program requirements, including formally requiring a risk assessment as the foundation of the program. The proposal was still pending at last check.
How it connects to the Travel Rule
Travel Rule compliance sits inside the pillars. It's part of a firm's internal controls, and it's in scope for independent testing.
Help us keep this page up to date! Any comments, corrections or suggestions on this page can be sent to [email protected].

