TL;DR: AML independent testing is the BSA audit pillar: a qualified party with no role in running the program assesses whether the program complies with BSA requirements and is adequate for the institution's risk profile. The FFIEC BSA/AML Examination Manual sets no fixed frequency, using every 12 to 18 months as an example, while FINRA Rule 3310(c) generally requires calendar-year testing for broker-dealers. Examiners read the report, scope, and workpapers first; under OCC Bulletin 2025-37, satisfactory testing can reduce what community-bank exams re-test.
The Pillar Examiners Open First
AML independent testing requirements sit in statute and agency rule as one of the five pillars of an AML compliance program: independent testing for compliance, conducted by bank personnel or an outside party. The test is an audit of the program, not a walkthrough of the policy binder. Its purpose, in the FFIEC manual's words, is to assess BSA compliance relative to the bank's risk profile and the overall adequacy of the BSA/AML compliance program.
That dual purpose is what examiners grade. A report that recites procedures without concluding whether the program works fails the standard. The manual expects an explicit statement about overall BSA compliance, or enough information for the board or an examiner to reach that conclusion. Independent testing is not day-to-day quality control, and it is not model validation. Confusing those three produces a document that looks complete and still fails on exam.
Why the Test Now Changes the Exam Itself
Examiners obtain the independent testing report, its scope, and supporting workpapers during scoping. The FFIEC risk-focused supervision section is direct: if independent testing is adequate, findings may be leveraged to reduce examination areas and the testing needed to assess the program. Thin workpapers, a missing overall conclusion, or a tester who also wrote the procedures reverse that logic. The exam expands.
For OCC-supervised community banks, that leverage is now explicit. OCC Bulletin 2025-37, effective for examinations beginning February 1, 2026, tells examiners they may place reliance, as appropriate, on satisfactory independent testing when forming conclusions on specific procedures. The bulletin also lets examiners carry forward prior-cycle conclusions for one cycle on the training and BSA officer pillars when the risk profile has not changed in a significant way. Independent testing is not on that carry-forward list. The audit has to earn its own weight every cycle.
Enforcement keeps the same theme. According to Corlytics data reported in February 2026, FINRA brought 20 AML enforcement actions in 2025, up from 14 in 2024, with fines rising from $2.56 million to nearly $10 million, including cases where firms had not independently tested their AML programs. Crowe's 2025 analysis of 2024 BSA/AML enforcement counted 42 actions from federal banking agencies, NYDFS, and FinCEN, with 54 percent of bank actions issued to institutions under $1 billion in assets.
That is why community bank BSA exam preparation now starts with the last independent test, not with a last-minute policy refresh.
Independence That Survives the First Examiner Question
Independence is a reporting line and a conflict screen, not a job title. The FFIEC manual allows internal audit, outside auditors, consultants, or other qualified independent parties. Banks without an audit department may use qualified staff who are not involved in the function being tested. Outside firms cannot also train BSA staff or write the policies and procedures they are testing. Either arrangement creates a conflict the manual names by example.
Whoever performs the test should report directly to the board of directors or to a designated board committee composed primarily of outside directors. Reporting through the BSA officer or the vendor that built the monitoring rules is not independent testing. Community-focused banks with less complex operations and lower ML/TF risk may use a shared resource under the October 2018 interagency statement on sharing BSA resources. The board still owns the engagement, the scope, and the findings.
Examiners may evaluate subject-matter expertise and qualifications as well as independence. A tester who has never sampled a SAR file, or who cannot challenge monitoring logic, fails that review even if the org chart looks clean.
Frequency Follows Risk, Except Where the Calendar Is the Rule
There is no regulatory requirement establishing BSA/AML independent testing frequency for banks. The FFIEC manual says frequency should be commensurate with the ML/TF and other illicit financial activity risk profile and the bank's overall risk management strategy. Periodic intervals of every 12 to 18 months are an example, not a safe harbor. Testing should also follow significant changes in risk profile, systems, compliance staff, or processes. More frequent testing is appropriate when deficiencies have already been identified, or to verify that remediation actually worked.
Waiting 18 months after a core conversion, a fintech partnership, or a jump in correspondent activity is a frequency failure even if the last calendar cycle looked ordinary.
Broker-dealers live under a different clock. FINRA Rule 3310(c), as summarized in FINRA's 2025 Annual Regulatory Oversight Report, requires independent testing each calendar year, or every two calendar years in specialized cases. Observed failures include skipping that cycle, not testing suspicious-activity detection after a material shift in products or clients, and using testers who lack independence or qualifications. Banks should not import the FINRA annual rule as a BSA requirement, or treat the FFIEC's 12-to-18-month example as permission to skip a year after risk moved.
Scope, Sampling, and Workpapers
Risk-based independent testing uses the BSA/AML risk assessment to put depth where risk is highest. The manual's illustrative review list is the exam checklist in all but name: whether the risk assessment matches products, services, customers, and geographies; whether policies match that profile and are followed; whether CIP, CDD, beneficial ownership, SARs, CTRs, CTR exemptions, and information-sharing requests actually comply; whether the suspicious-activity process is adequate; whether IT sources feeding monitoring and aggregation are complete and accurate; whether training is tailored and documented; and whether management closed prior testing and examination findings.
Policy review without transaction testing is the most common way to fail that list. Sampling should be large enough, and biased toward higher-risk activity enough, for the tester to support an overall conclusion. Typical samples include customer files, alert dispositions, SAR narratives and timelines, CTR accuracy, OFAC hit clearing, and exception handling on the systems that generate program reports. Low-risk retail files alone cannot support a conclusion about a correspondent book or a new channel the risk assessment flags as elevated.
Auditors should document scope, procedures performed, transaction testing completed, and findings. Workpapers should be available for examiner review. A glossy report with no sampling methodology, population definition, or exception logs is not evidence. Examiners who cannot reconstruct what was tested will not leverage the test.
When independent testing finds that monitoring failed over a defined period, the next conversation is often a lookback review. The audit pillar is supposed to surface that need before the examiner does.
What the Board Has to See, and Track
Violations, exceptions to policies or processes, and other deficiencies should be documented and reported to the board or a designated board committee in a timely manner. The board, or that committee, and appropriate staff should track deficiencies and document progress implementing corrective actions. A finding that reappears in the next cycle is not an audit observation. It is evidence that governance around the last audit did not work.
The report should be usable by a director who does not live in BSA: an overall conclusion, findings ranked by severity, owners, due dates, and status of prior findings. Minutes should show the board received the report and required follow-up. Routing it to the BSA officer for "handling" without a board record is a reporting failure even if the analysis was sound. Examiners review management responses and the status of issues during scoping. The same exceptions two cycles in a row tell the examiner the control environment does not close gaps.
Keep the Audit Distinct From QA and Model Validation
Ongoing quality assurance samples dispositions, files, and narratives while the program is running. Independent testing is periodic, structurally independent, and charged with concluding on the program as a whole. Model validation, including SR 11-7-style work on monitoring and screening models, tests whether a model is conceptually sound, implemented correctly, and performing as intended. Sphinx covers those adjacent topics separately in its guides to an AML quality assurance program and AML model validation requirements. Substituting either for the BSA independent test leaves the third pillar empty.
A strong program runs all three. Independent testers should read QA results and validation reports as evidence, not as a substitute for their own transaction testing. When one function impersonates another, examiners treat that as a control-design flaw.
Where Sphinx Fits
Sphinx's agents work inside existing case, monitoring, and screening systems and leave a written trail for every disposition: the data used, the reasoning, and the outcome. Independent testers and examiners sample that trail. Sphinx does not replace the BSA audit, QA, or model validation. It makes those reviews reconstructible enough to support an overall conclusion rather than an attestation that policies exist.
Frequently Asked Questions
How often is BSA independent testing required?
For banks, the FFIEC BSA/AML Examination Manual sets no fixed interval. Frequency should match ML/TF risk and should also follow material changes in systems, products, staff, or processes, with every 12 to 18 months cited as an example. Broker-dealers subject to FINRA Rule 3310(c) generally must test each calendar year, or every two calendar years in specialized cases.
Who is allowed to perform AML independent testing?
Internal audit, outside auditors, consultants, or other qualified independent parties may perform the test. The tester cannot be involved in the function under review or in conflicting BSA work such as writing policies or delivering training, and should report to the board or a committee of primarily outside directors. Smaller banks may use qualified staff outside the function or a shared resource under the 2018 interagency statement on sharing BSA resources.
How is independent testing different from QA or model validation?
Independent testing is the BSA program audit: periodic, independent of operations, and required to conclude on overall program adequacy. QA is ongoing sampling of decisions and files inside the program. Model validation tests whether monitoring or screening models are conceptually sound and performing as intended, which is a different question from whether the BSA program as a whole complies.
What do examiners expect in the independent testing report?
Examiners expect a documented scope, procedures, transaction testing, findings, available workpapers, and typically an explicit statement on overall BSA compliance. Deficiencies must go to the board or a designated committee in a timely way, with tracking of corrective action. OCC Bulletin 2025-37 lets OCC community-bank examiners rely on satisfactory testing for specific procedures, which makes incomplete reports more costly, not less.
Can a weak independent test increase exam scope?
Yes. The FFIEC scoping procedures allow examiners to leverage adequate independent testing to reduce examination areas and testing. If the test was not independent, missed material risks, lacked workpapers, or failed to report and track findings, examiners cannot rely on it and typically expand their own procedures. For OCC community banks after February 1, 2026, that lost leverage is now written into the minimum exam procedures.

.png)