TL;DR: An AML lookback review is a retrospective re-examination of historical transactions to find suspicious activity a monitoring program missed the first time, ending in late SAR filings and a written report to the regulator. Lookbacks are usually mandated by consent orders from the OCC, FDIC, FinCEN, or NYDFS after a system gap or enforcement action, and they are expensive: TD Bank disclosed roughly US$500 million in fiscal 2025 remediation spend, with its SAR lookback not expected to finish until calendar 2027. Cost is driven by analyst hours per alert, which is the one variable automation actually changes.
What a Lookback Is Actually For
An AML lookback review re-runs a defined population of historical transactions through monitoring logic that should have applied at the time, reviews every resulting alert, and decides whether a SAR should have been filed. The OCC's October 2024 consent order against TD Bank states the purpose plainly: determine whether SARs should be filed for previously unreported suspicious activity, including cases where staff spotted the activity but failed to support a decision not to file, review the accuracy of prior SAR filings, and identify transactions that represent excessive BSA/AML risk.
Three things separate a lookback from ordinary alert review. The population is closed and historical. The output is a formal deliverable to a regulator, not an internal case file. And the exercise exists to prove a specific failure was remediated, so scope, method, and results will be pulled apart by an examiner who already knows something went wrong.
What Triggers One
Most lookbacks start with an enforcement action. When a regulator finds that monitoring failed to identify and report suspicious activity, the consent order typically includes a lookback article alongside program remediation. FinCEN's $1.3 billion TD Bank penalty came with a four-year monitorship and a requirement that an independent consultant analyze historical transaction data to remediate missed SARs; FinCEN found that in 2023 alone, coverage gaps left several trillion dollars of transactions unscreened. Binance's 2023 resolution followed the same pattern: the U.S. Treasury reported that Binance never filed a single SAR, willfully failed to report well over 100,000 suspicious transactions, and agreed to a lookback as part of a $3.4 billion settlement and five-year monitorship.
Not every trigger is a headline penalty. Lookbacks also follow from:
The voluntary case matters. A 2024 Law360 analysis by Jenner & Block notes that a self-initiated lookback lets the institution control scoping, methodology, and reviewer selection. Once a regulator orders it, those decisions require prior non-objection, and the regulator can expand scope at will.
Scoping: Period, Population, Scenarios

Under-scoping is the most common reason a lookback gets rejected and redone. Three dimensions have to be fixed and documented before any transaction is reviewed.
The period is set by when the control failed and how far back records exist. BSA record retention runs five years, which sets the practical ceiling, but orders usually tie the window to the deficiency. One FDIC order required review of all higher-risk accounts and activity from June 30, 2020 through the order's effective date. The OCC's 2020 order against M.Y. Safra Bank scoped the lookback to medium-risk or higher activity between January 1 and November 15, 2019.
The population is the set of customers, accounts, and transaction types in scope. Regulators steer toward where missed activity is most likely to hide: high-risk customers, high-risk jurisdictions, and accounts that generated alerts the institution closed without filing. The M.Y. Safra order named both of those last categories explicitly. If the trigger was a specific gap, the population is that product or channel for the full period the gap existed.
The scenarios are the detection logic applied to the population. In practice that means the corrected rule set, not the deficient one that missed the activity. Sampling is sometimes permitted for very large universes, but the design has to be documented, statistically defensible, and approved in advance.
How the Work Actually Runs

A lookback runs in four phases, and most of the cost lands in the third.
Late filing is the expected outcome, not a failure of the exercise. Regulators penalize the original miss, not the remedial filing.
What It Costs and Who Does the Work
Consent orders almost always require an independent third-party consultant to conduct or oversee the lookback, with name, qualifications, and engagement terms submitted for regulatory non-objection before work begins. The TD Bank order requires that submission within 60 days and cites OCC Bulletin 2013-33 on independent consultants. The consultant reports to the board and the examiner simultaneously, and all work papers must be available on request.
The economics follow from the staffing model. Engagements are billed on analyst hours, and hours equal alert volume multiplied by minutes per alert. A backlog of 4,378 alerts, the figure NYDFS cited in its 2022 Robinhood Crypto order, is a few analyst-months. A multi-year lookback across a large bank's high-risk population is hundreds of contractors for years.
Public disclosures give the scale. TD Bank expects approximately US$500 million pre-tax in U.S. BSA/AML remediation spend in fiscal 2025 and a similar amount in fiscal 2026, with the SAR lookback targeted for completion in calendar 2027, roughly three years after the order. Those figures cover the whole program, and TD's U.S. CEO told analysts the 2026 mix would shift toward "more validation work, more lookbacks, monitor costs." Coinbase's NYDFS settlement paired a $50 million penalty with a further $50 million compliance investment over two years, monitor fees included.
The hourly rate is the visible cost. The invisible cost is internal staff pulled off live queues to feed data requests and re-review inconsistent contractor dispositions, which is how a lookback creates the next backlog.
What Regulators Expect to See
The deliverable lists are consistent across agencies. The TD Bank order requires the consultant's report to cover the methodologies used, the investigation process, the number and types of customers and transactions reviewed, SARs recommended for filing or amendment, every instance where the bank declined to follow a filing recommendation and why, and recommended corrective actions. That overridden-recommendation item matters: rejecting a consultant's filing recommendation without a written rationale creates a second enforcement issue inside the remediation of the first.
Independent validation runs alongside. The same orders typically mandate ongoing validation of rules, thresholds, and filters so the gap does not recur, and the model validation requirements that apply to the live system apply equally to the rule set used for the retrospective run. Every disposition needs a reason a stranger could follow, and every data exclusion needs an explanation. FDIC lookback language requires the plan to commit that interim reports, drafts, and work papers will be available to supervisors on request, so there is no such thing as an informal working note.
Where Lookbacks Go Wrong
How Automation Changes the Economics
Every cost driver reduces to alert volume times review time per alert. The regulator largely controls volume through scope and scenarios. Review time per alert is what the institution controls, and it is where AI-assisted review has changed the numbers.
A lookback suits automation better than live monitoring does. The population is fixed, every customer's full history is available up front, and the rule set is agreed. The investigative steps for each alert, pulling the customer profile, tracing counterparties, checking prior alerts and filings, screening names, and drafting a disposition, repeat thousands of times against a closed data set. That is the profile of work AI agents handle well, with a human making the file decision on escalated cases.
Production results support this. Conduit, a cross-border payments platform, cleared a six-month alert backlog in two days using Sphinx agents, cutting disposition time from about an hour per alert to under a minute. Alviere automated 86 percent of compliance cases while giving auditors the documented reasoning they required for every decision. Neither was a consent-order lookback, but both were the same operational problem: a large, closed population of historical alerts needing consistent, documented dispositions fast.
Two caveats. Automation does not recover data that was never captured. And an agent's dispositions are only defensible if the reasoning is written down in a form an examiner can follow. A lookback run on an opaque model is a lookback the regulator will ask to have redone.
Evaluating an Approach or Partner
Whether the work is done by a consultancy, in-house, or with AI agents, the same questions decide whether the output survives examination.
The partner that answers with specifics about documented reasoning, throughput, and consistency is describing a lookback that ends. The one that answers with headcount is describing one that gets extended.
Where Sphinx Fits
Sphinx deploys AI compliance agents that log into an institution's existing monitoring and case management systems, review each alert the way a trained analyst would, and document the full reasoning behind every disposition. Customers have used those agents to clear six-month alert backlogs in days with an audit trail their auditors accepted, which is the operational core of a lookback: a fixed population of historical alerts needing consistent, defensible decisions at a pace that ends the engagement. Scoping, methodology approval, and the filing decision on escalated cases stay with the compliance team and the independent reviewer, as they should.
Frequently Asked Questions
How far back does an AML lookback review usually go?
The period is set by when the control failed and how long records exist. BSA record retention requires five years, which is the practical ceiling, and consent orders typically tie the window to the deficiency. Recent OCC and FDIC orders have scoped lookbacks from roughly eleven months to several years, and regulators reserve the right to extend the period based on what the review finds.
Is a lookback required after every transaction monitoring gap?
No regulation mandates a lookback for every gap, but once a gap is material and known, the institution has to determine whether suspicious activity went unreported during it. A self-initiated lookback lets the institution control scope, method, and reviewer selection. Waiting for an examiner to find the gap usually means those decisions require regulatory non-objection and can be expanded at the regulator's discretion.
Are late SARs from a lookback penalized?
The filings themselves are the expected outcome of the review, not a new violation. Regulators penalize the original failure to detect and report, and any failure to conduct the lookback thoroughly. Lookback SAR narratives should state that the activity was identified through a retrospective review and describe the gap that caused the miss.
Does a lookback have to be done by an outside consultant?
Under a consent order, almost always. The OCC, FDIC, and NYDFS typically require an independent third party whose qualifications and engagement terms receive regulatory non-objection before work begins, reporting directly to the board and the examiner. Voluntary lookbacks can be staffed internally if the reviewers are independent of the functions being tested and can defend the methodology.
How much does an AML lookback cost?
Cost is driven by alert volume and review hours per alert, so it ranges from a few analyst-months for a small backlog to hundreds of millions of dollars for a multi-year review at a large bank. TD Bank disclosed approximately US$500 million in annual remediation spend for fiscal 2025 and 2026 covering its full program including the lookback. Reducing review time per alert is the main lever an institution has, since scope is largely set by the regulator.

.png)