---
title: "AML audit readiness: what regulators ask for and how to prove your risk monitoring works"
seoTitle: "AML audit readiness: the evidence examiners ask for"
description: "The evidence examiners expect from automated risk monitoring: a 10-item evidence table, good vs poor practice, SAR timelines, RFIs, and a 30-day plan."
date: "2026-10-04"
updated: "2026-10-04"
category: "compliance"
author: "BlindPay Team"
howto:
  name: "30-day AML audit readiness plan for automated risk monitoring"
  steps:
    - name: "Week 1: inventory"
      text: "List every control the program claims to run: the AML policy, the customer risk rating method, each monitoring rule and threshold, sanctions lists and refresh jobs, case management, SAR process, reporting, and retention. Name an owner and the artifact that proves each one."
    - name: "Week 2: gap review"
      text: "Compare the policy with what the system actually does. Flag rules with no written rationale, tuning changes with no approval, cases with no closure note, and list updates with no log. Rank gaps by risk, not by how easy they are to fix."
    - name: "Week 3: test scenarios"
      text: "Run known typologies through the system, such as split payments under a threshold or a counterparty added to a sanctions list, and confirm the right alert fires. Pull a sample of closed alerts and SAR decisions and check that each one can be reconstructed from the records alone."
    - name: "Week 4: fix and document"
      text: "Close the high-risk gaps, write the missing rule rationales, update the policy to match reality, and record every change with an approver and a date. Package the evidence in one place, indexed to the examiner's likely request list."
faq:
  - q: "What do AML examiners usually ask for first?"
    a: "The written AML policy, the risk assessment behind it, and a list of the monitoring rules with their thresholds. Then they pull a sample of alerts, cases, and SAR decisions and check whether the records match the policy. A program that can produce those documents in a day starts the exam in a much better position than one that has to rebuild them."
  - q: "How long must a money services business keep AML records?"
    a: "Five years. FinCEN's general rule in 31 CFR 1010.430 requires records kept under the Bank Secrecy Act to be retained for five years, and the MSB SAR rule requires a copy of each SAR and its supporting documentation to be kept for five years from the filing date. Retrievable matters as much as retained: an examiner will ask for specific files."
  - q: "When does a money services business have to file a SAR?"
    a: "A US money services business files a suspicious activity report when a transaction involves or aggregates at least USD 2,000 and it knows, suspects, or has reason to suspect the activity is suspicious under 31 CFR 1022.320. The report is due no later than 30 calendar days after the date of initial detection. Other countries set their own thresholds and deadlines."
  - q: "Do you have to document a decision not to file a SAR?"
    a: "Not under US rules. FinCEN's October 2025 SAR FAQs say a financial institution is not required to document a decision not to file, though FinCEN encourages it, and a short, concise statement usually suffices. Most programs record one anyway, because it is the only way to show an examiner why a closed alert was closed."
  - q: "What is independent testing in an AML program?"
    a: "It is a review of whether the AML program is adequate and working, done by someone other than the compliance officer who runs it. For money services businesses, 31 CFR 1022.210 requires it and says its scope and frequency must match the risk of the services offered. It can be internal staff or an outside firm, as long as the reviewer is independent."
  - q: "How should a fintech prepare for a partner bank compliance review?"
    a: "Treat it like an exam. Have the policy, risk assessment, rule inventory, tuning log, independent test report, sample case files, SAR statistics, and sanctions list logs ready in one indexed folder. Partner banks focus on whether your controls cover the flows they carry for you, so map each control to a product and corridor."
---

Regulators expect proof that automated risk monitoring fits your risks and actually works. In practice that means a written AML policy, a customer risk rating method, a documented reason for every rule and threshold, tuning records, independent testing, timestamped case trails, SAR decision records, sanctions list update logs, management reporting, and records kept for five years.

This article is general information, not legal advice. Exam scope differs by regulator and license, so confirm yours with counsel.

**Key takeaways**

- Examiners test whether the system matches the policy, not whether the policy reads well.
- Every rule needs a written rationale tied to a risk you identified. "The vendor set it" is not a rationale.
- A case file should let a stranger reconstruct the decision: alert, evidence, reviewer, reason, date.
- US money services businesses file SARs within 30 calendar days of initial detection and keep records for five years.
- Independent testing is a legal requirement for MSBs, scoped to risk, and run by someone other than the compliance officer.
- Thirty focused days can close most documentation gaps before an exam or a partner bank review.

## What do regulators expect from an automated risk monitoring program?

They expect a program that is risk based, documented, tested, and able to show its own work. Automation doesn't change the standard. It changes the evidence, because every decision now leaves a record.

The global baseline is FATF Recommendation 1, the risk-based approach: identify and assess your money laundering and terrorist financing risks, then apply controls proportionate to them. FATF Recommendation 20 adds prompt reporting of suspicious transactions. The [automated risk monitoring explainer](/resources/more/what-is-automated-risk-monitoring-fintech) covers the components that sit under those obligations.

For a US money services business (MSB), the requirement is concrete. [31 CFR 1022.210](https://www.law.cornell.edu/cfr/text/31/1022.210) sets four minimum pillars for the AML program:

1. **Policies, procedures, and internal controls**, covering customer identification, filing reports, keeping records, and responding to law enforcement.
2. **A designated compliance officer** who owns day-to-day compliance.
3. **Training** for the right staff, including how to detect suspicious transactions.
4. **Independent review**, with scope and frequency matched to the risk of the services offered. The reviewer can be internal, but can't be the compliance officer.

FinCEN and the IRS publish the [Bank Secrecy Act/AML Examination Manual for Money Services Businesses](https://www.fincen.gov/sites/default/files/shared/MSB_Exam_Manual.pdf). It dates from 2008, but the method holds: scope the risk, read the program, test transactions against it.

## Why do vendor default rules fail an exam?

Because a default rule was tuned for someone else's customers. When an examiner asks why a velocity rule fires at five transfers a day for a freelancer segment, the answer has to come from your risk assessment, not from a vendor's setup guide.

FinCEN said this directly in its [October 2025 SAR FAQs](https://www.fincen.gov/system/files/2025-10/SAR-FAQs-October-2025.pdf): monitoring parameters should be commensurate with the money laundering and terrorist financing risk of the specific institution, considering its products, locations, and customers. The UK's [FCA Financial Crime Guide](https://handbook.fca.org.uk/handbook/FCG/3/2.html) lists, as poor practice, threshold-based systems that are poorly calibrated, where the firm struggles to explain why a particular rule exists.

So the default isn't the problem. The undocumented default is. The [12 red flags rule library](/resources/more/transaction-monitoring-red-flags-stablecoin-payments) is a useful starting point for that inventory.

## What evidence do examiners ask for?

Examiners ask for artifacts that prove each control exists, runs, and gets reviewed. The table below covers the ten items that come up most in reviews of automated monitoring.

| Evidence item | What examiners look for | Example artifact | Owner |
| --- | --- | --- | --- |
| Written AML policy | Approved, current, and matching what the system does | Policy with version history and approval date | Compliance officer |
| Customer risk rating methodology | Clear factors, how ratings change, who can override | Methodology document plus rating distribution | Compliance |
| Rule and threshold rationale | Each rule tied to a risk and a customer segment | Rule inventory with typology, threshold, rationale | Compliance with engineering |
| Calibration and tuning records | Changes tested before release and approved | Change log with before and after alert counts | Compliance with engineering |
| Independent testing results | Scope matched to risk, findings tracked to closure | Review report and remediation tracker | Independent reviewer |
| Alert to closure case trails | Timestamps, reviewer, evidence, and a reason | Case export for a sample period | Compliance analysts |
| SAR decision records | Filed on time, consistent reasoning | SAR log with detection, decision, and filing dates | Compliance officer |
| Sanctions list update logs | Lists loaded promptly and rescreening ran | List version log and rescreen job output | Engineering with compliance |
| Management information and board reporting | Leadership sees volumes, backlog, SARs, findings | Monthly report pack and meeting minutes | Compliance officer |
| Record retention | Five years, and retrievable on request | Retention policy plus a retrieval test | Operations |

Two rows go missing most. Sanctions list logs, because list refreshes run as a background job nobody watches (the [ongoing sanctions screening guide](/resources/more/ongoing-sanctions-screening-how-often-to-rescreen) covers what to log). And tuning records, because rule changes ship like ordinary code. Route both through one approval step.

## What does good practice look like compared with poor practice?

Good practice shows the program understands its own output. The table below is drawn from the FCA Financial Crime Guide's good and poor practice examples on monitoring, paraphrased.

| Area | Good practice | Poor practice |
| --- | --- | --- |
| Monitoring design | Looks at customer behavior as a whole, at several levels of aggregation | Single-transaction thresholds used where they don't fit the risk |
| Rule calibration | The firm can explain the rationale for each rule | Rules are poorly calibrated and their rationale is unclear |
| New approaches | New monitoring methods are piloted and tested before replacing old ones | Systems are swapped without comparing alert quality |
| Control framework | Management oversees performance and resolves issues | The control framework around automated monitoring is weak |
| Customer explanations | Staff test explanations against evidence | Staff accept a customer's explanation at face value |
| Use of results | Monitoring results show whether due diligence is still adequate | Little evidence that unusual transactions reach the compliance officer |

One more contrast that isn't from the FCA guide, but that examiners everywhere probe: a customer risk rating that refreshes on triggers (new corridor, volume jump, ownership change) versus a rating set once at onboarding and never touched. The second is a snapshot, not a control.

## How do SAR timelines work, and what happens when a deadline slips?

Under [31 CFR 1022.320](https://www.law.cornell.edu/cfr/text/31/1022.320), a US MSB must report suspicious transactions that involve or aggregate at least USD 2,000, no later than 30 calendar days after initial detection. It keeps the SAR and supporting documents for five years from filing. Timelines differ in other jurisdictions, so check the local rule for each license.

The 30-day clock is where programs get caught. Examiners compare three dates in every sampled case: when the alert fired, when someone decided it was suspicious, and when the SAR was filed. Long unexplained gaps between them are findings even if the filing itself was "on time."

FinCEN's October 2025 FAQs clarified two points that many programs over-engineered:

- **Continuing activity.** Earlier guidance suggested reviewing and filing on continuing activity every 90 days, with a deadline 120 days after the previous SAR. FinCEN now says that cadence isn't required; risk-based procedures can govern it.
- **No-SAR decisions.** Documenting a decision not to file is encouraged, not required. A short statement usually suffices.

When an internal deadline slips, escalate it, don't hide it:

1. Flag any case past its internal review target automatically, before it nears the filing deadline.
2. Escalate to the compliance officer with the case age and the blocker.
3. File as soon as the decision is made, and record why the review took longer.
4. Never backdate a detection or decision date. A late filing with an honest record is a finding; a falsified date is a much bigger problem.
5. Report late cases in the monthly management pack, with the root cause.

## What is a 30-day readiness plan?

A 30-day plan turns "we think we're ready" into an indexed evidence folder. Run it before a scheduled exam, a partner bank review, or a funding round's compliance diligence.

1. **Week 1: inventory.** List every control the policy claims, its owner, and the artifact that proves it. Use the evidence table above as the index.
2. **Week 2: gap review.** Compare the policy with system behavior. Flag rules with no rationale, tuning changes with no approval, cases with no closure note, and list refreshes with no log.
3. **Week 3: test scenarios.** Run known typologies through the system and confirm the right alerts fire. Pull a sample of closed alerts and rebuild each decision from the records alone. The [false positive tuning guide](/resources/more/reduce-false-positives-transaction-monitoring) explains how to test below-the-line cases.
4. **Week 4: fix and document.** Close high-risk gaps first, update the policy to match reality, and log every change with an approver and a date.

**Illustrative example.** A fintech pulls 40 closed alerts from the last quarter as a mock exam sample. Six have no closure reason, three were closed by the analyst who also tuned the rule, and one SAR shows 41 days between alert and filing with no note. That's ten findings from one sample, and all ten are documentation gaps a regulator would find in the first week. The fix took two weeks: a mandatory closure reason field, a separation rule for tuning and review, and an aging alert on open cases. These numbers are illustrative, not drawn from a real program.

## How do you respond to a compliance request for information?

Answer completely, once, with documents rather than assertions. A request for information (RFI) from a regulator, partner bank, or payment provider usually covers a customer or a transaction, and a partial answer invites a second round.

Prepare these before you need them:

- The customer's verified identity or business file, including beneficial owners.
- Transaction history for the period in question, with counterparties.
- The relationship between sender and receiver and the purpose of the payment.
- Source of funds evidence where the amount or pattern calls for it.
- Your own case notes, if the activity already raised an alert.

Response windows are set by whoever asks, and they vary from hours to weeks. BlindPay, for example, gives partners 27 days to answer a customer KYC or KYB request for information before the customer is automatically rejected. The window is printed on the request. Read it on day one, not day twenty. Travel Rule data gaps follow their own hold and return logic, covered in the [travel rule workflow guide](/resources/more/travel-rule-workflow-hold-return-reject).

## What are the common mistakes in AML audit readiness?

The common mistakes are records that don't explain decisions and controls that nobody re-checks.

- **Gaps in case notes.** "Closed, no concern" without the evidence reviewed tells an examiner nothing.
- **No validation after rule changes.** A threshold edit that ships without a before and after comparison is an untested control.
- **No board or management reporting.** If leadership never sees alert volumes, backlog, and SAR counts, the program has no oversight on record.
- **A policy nobody has reviewed.** A policy that still describes last year's products is evidence the program and the business drifted apart.
- **Unjustified risk rating overrides.** Staff able to lower a customer's risk rating without a written reason and a second approver is one of the first things examiners test.
- **Same person tunes and reviews.** Separation between whoever writes the rules and whoever checks them is basic independence.

## How does BlindPay support audit readiness?

BlindPay is registered with FinCEN as a money services business and lists its registrations on the [licenses page](/licenses). KYC, KYB, sanctions screening, travel rule compliance, and transaction monitoring run inside the API before money moves, so each customer and payment carries a status rather than a decision buried in email.

For partners, that means the evidence trail starts in the data. Customers move through documented statuses such as `verifying`, `approved`, `compliance_request`, and `rejected`, described in the [KYC reference](/docs/kb/kyc). RFIs can be handled through the [RFI API](/docs/learn/rfi), which returns the deadline as `expires_at`. Flagged payments land on hold for manual review, as described in [on-hold transactions](/docs/kb/on-hold-transactions). Your own AML program remains yours to document; these records make that easier to evidence.

## What to do next

Pull 25 closed alerts from last month and try to rebuild each decision from the records alone. Every case you can't rebuild is a finding waiting for an examiner. Start the 30-day plan with those.

## Sources and further reading

- [31 CFR 1022.210: AML programs for money services businesses](https://www.law.cornell.edu/cfr/text/31/1022.210)
- [31 CFR 1022.320: SAR reporting by money services businesses](https://www.law.cornell.edu/cfr/text/31/1022.320)
- [FinCEN: SAR frequently asked questions, October 2025](https://www.fincen.gov/system/files/2025-10/SAR-FAQs-October-2025.pdf)
- [FinCEN and IRS: BSA/AML Examination Manual for Money Services Businesses](https://www.fincen.gov/sites/default/files/shared/MSB_Exam_Manual.pdf)
- [FATF Recommendations](https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html)
- [FCA Financial Crime Guide, FCG 3.2](https://handbook.fca.org.uk/handbook/FCG/3/2.html)

*This article is general information, not legal advice.*
