TL;DR: The five pillars of an AML compliance program are a designated BSA compliance officer, internal policies, procedures and controls, independent testing, ongoing training, and customer due diligence, the fifth pillar added by FinCEN's 2016 CDD Rule. Pillar failures still drive enforcement: Crowe found BSA officer deficiencies cited in 23 of 42 BSA/AML enforcement actions in 2024 and CDD gaps in 26. FinCEN's April 2026 proposed AML/CFT program rule, unfinalized as of September 2026, folds CDD and a mandatory risk assessment process into internal controls and shifts supervision toward whether a program is effective rather than merely documented.
The Five Pillars, Defined
The five pillars are the minimum components a BSA/AML program must contain under 31 U.S.C. 5318(h) and the banking agencies' rules at 12 CFR 21.21 (OCC), 12 CFR 208.63 (Federal Reserve), 12 CFR 326.8 (FDIC) and 12 CFR 748.2 (NCUA). The statute named four. FinCEN's 2016 Customer Due Diligence Rule, codified at 31 CFR 1020.210, added the fifth by making risk-based CDD and beneficial ownership identification an explicit program requirement for banks.
The FFIEC BSA/AML Examination Manual is blunt about the standard: written policies, procedures and processes alone are not sufficient. The program must be written, board-approved, and matched by practices that correspond to what is on paper. Examiners assess it against the institution's own risk profile, which is why two banks with identical policy manuals can receive very different exam conclusions.
What Examiners Test Under Each Pillar
Each pillar has its own section in the FFIEC manual. The pattern is the same across all five: examiners want evidence that the component exists, that it is proportionate to risk, and that it operates in practice.
Pillar 1: The BSA compliance officer
Examiners confirm the board has designated a qualified individual, then evaluate four attributes: authority, independence, access to resources, and competence. Appointing an officer is not by itself sufficient. Indicators include clear reporting lines to the board, evidence that management seeks the officer's input before launching new products or markets, staffing commensurate with risk, and regular board reporting that includes SAR filing notifications. Title is irrelevant. Stature is not.
Pillar 2: Internal policies, procedures and controls
Internal controls are the operational core: the risk assessment, customer risk rating methodology, monitoring rules, screening, SAR and CTR decisioning, recordkeeping, and the governance around them. Examiners check whether controls are tailored to the products, customers and geographies the institution actually has, and whether they change when the risk profile does. Board approval is the baseline; the substantive question is whether the controls produce the detection and reporting outcomes they were designed for.
Pillar 3: Independent testing
The FFIEC manual sets no fixed frequency, offering every 12 to 18 months as an example and tying frequency to risk. Examiners test three things: whether the testing was truly independent (the auditor should not also write policies or deliver training), whether the scope covered the institution's actual high-risk areas, and whether findings reached the board and were tracked to remediation. The report should state a conclusion on overall compliance, and workpapers must be available. Smaller institutions may use qualified staff outside the function being tested, or a shared resource under the 2018 interagency statement on sharing BSA resources.
Pillar 4: Training
Training must reach every employee whose duties touch BSA compliance and must be tailored to the role: tellers on currency transactions and structuring, lenders on laundering through loan arrangements, the board on enough fundamentals to oversee the program. Examiners check who was trained, what the materials covered, whether attendance was documented, and what happened when someone missed it. Identical annual modules for every role are a common and visible weakness.
Pillar 5: Customer due diligence
Under the CDD Rule, examiners test whether the institution understands its customer relationships well enough to build a risk profile, identifies and verifies beneficial owners of legal entity customers, and updates customer information on a risk basis. Sphinx covers the mechanics in its guide to customer due diligence requirements for banks. The exam focus is the link to everything else: a customer risk rating that never changes after onboarding, or that does not feed monitoring thresholds, signals that the fifth pillar is disconnected from the second.
How the AML Act and FinCEN's 2026 Proposal Reframe the Pillars
The Anti-Money Laundering Act of 2020 directed FinCEN and the banking agencies to make programs risk-based and effectiveness-oriented, to publish national AML/CFT Priorities, and to require that more resources go to higher-risk customers and activities than to lower-risk ones. FinCEN's first implementation attempt, a July 2024 proposed rule, would have made the risk assessment a standalone sixth pillar. It was withdrawn.
On April 7, 2026, FinCEN issued a superseding proposed rule, with the OCC, FDIC and NCUA proposing parallel amendments on April 10 and the Federal Reserve on July 9. Comments on FinCEN's proposal closed June 9, 2026; the Federal Reserve's period closes September 8, 2026. As of September 2026 no final rule has been issued, and FinCEN proposes a 12-month implementation window once one is. The five-pillar framework remains the binding standard until then.
The proposal restructures the pillars in three ways. It defines four core pillars: internal policies, procedures and controls (now explicitly including risk assessment processes and, where applicable, ongoing CDD), independent program testing, a U.S.-based designated compliance officer, and ongoing training. It codifies the risk assessment as a required process that must evaluate products, services, distribution channels, customers and geographies, incorporate the AML/CFT Priorities, and be updated promptly when risk changes. And it introduces a two-prong test: a program must be established (the pillars exist and are reasonably designed) and maintained (implemented in all material respects), with significant supervisory action generally reserved for failures to establish or for significant or systemic implementation failures.
The practical effect is that the risk assessment becomes the foundation the pillars stand on rather than one item among them. An institution that cannot show how its staffing, control design, audit scope and training curriculum each trace back to a documented risk assessment will struggle to demonstrate it has established a program at all. Sphinx's explainer on FinCEN's effectiveness-based AML rule covers the establish-versus-maintain distinction in more detail.
Where Programs Fail: Exam Findings by Pillar
Public enforcement actions read like a catalogue of pillar failures, and the same ones recur at every size. Crowe's analysis of 2024 BSA/AML enforcement actions counted 42 actions from the federal banking agencies, NYDFS and FinCEN, up from 29 in 2023, with 54 percent of bank actions issued to institutions under $1 billion in assets. Suspicious activity monitoring deficiencies appeared in 28 actions, CDD and EDD gaps in 26, BSA officer failures in 23, and AML staffing concerns in 21.
The OCC's October 2024 order against TD Bank, which carried a $450 million civil money penalty within more than $3 billion in combined penalties, cited deficiencies in internal controls, risk assessments, customer due diligence, customer risk ratings, suspicious activity reporting, governance, staffing, independent testing and training. Every pillar, in one order. At the other end of the spectrum, the OCC's 2024 order against Summit National Bank in Hulett, Wyoming, cited weak internal controls, a weak independent testing framework, insufficient BSA staffing and a weak training program, plus a CDD violation under 31 CFR 1020.210(a)(2)(v).
Independent testing failures compound. The OCC's 2025 order against Community Federal Savings Bank found that the internal auditor failed to identify program weaknesses and failed to scope in high-risk areas, in that case digital asset customers. When the third pillar misses what the second is getting wrong, the board never hears about it and the finding arrives from the examiner instead. Nor is this a bank-only pattern: in July 2025, six state regulators fined the U.S. arm of Wise $4.2 million for failing to conduct timely independent reviews of its AML program, failing to address audit deficiencies, and filing SARs late.
How the Pillars Apply Across Institution Types
The statutory pillars do not change by charter, but the calibration does. FinCEN's 2026 proposal states that community banks may rely on direct customer knowledge and simpler qualitative risk assessments rather than model-driven systems, provided the program stays risk-based and current.
The bank-fintech model is where pillar ownership gets contested. A sponsor bank cannot delegate the program requirement, only the execution of tasks within it, and examiners treat a fintech's onboarding and monitoring controls as the bank's controls. Sphinx's guide to bank-fintech partnership compliance oversight covers how sponsor banks give each pillar a named owner and an evidence trail.
How to Evaluate Program Maturity
A useful maturity assessment asks one question of each pillar: what evidence would convince an examiner this component operates as designed, and does it exist today? Programs tend to sit at one of four levels.
Two diagnostics separate the upper levels from the lower. The ratio of audit findings to exam findings: a mature program surfaces its own problems first. And traceability: pick any monitoring rule, training module or staffing decision and ask whether it ties to a specific line in the risk assessment. Resource strain erodes both, and it shows up first in the officer. A compliance officer who spends most of the week clearing alert queues is not exercising the oversight examiners test under pillar one, and the program slides from implemented back to documented. Sphinx's guide to community bank BSA exam preparation covers what to assemble before that slide becomes a finding.
Where Sphinx Fits
Most of the evidence examiners request under the five pillars comes from repetitive review work: alert dispositions with documented reasoning, CDD refreshes, screening resolutions, and the case files independent testers sample. Sphinx's AI compliance agents perform that work inside the systems a team already uses and record the reasoning behind every decision, so the evidence trail for pillars two, three and five is produced as a byproduct of operations rather than assembled before an exam. Judgment about risk appetite, program design and escalation stays with the compliance officer, which is where pillar one requires it to be.
Frequently Asked Questions
Are there four or five pillars of an AML compliance program?
Both answers are in use. The Bank Secrecy Act at 31 U.S.C. 5318(h) names four: a designated compliance officer, internal controls, independent testing and training. FinCEN's 2016 Customer Due Diligence Rule added risk-based CDD, including beneficial ownership identification, as a program requirement for banks at 31 CFR 1020.210, and practitioners have called it the fifth pillar since. FinCEN's April 2026 proposed rule returns to four core pillars by folding CDD into internal controls.
Is risk assessment a pillar of an AML program?
Not as a standalone pillar under current rules, although examiners treat it as the foundation of a reasonably designed program. FinCEN's withdrawn July 2024 proposal would have made it a sixth pillar. The April 2026 proposal instead requires risk assessment processes as a mandatory component of internal policies, procedures and controls, covering products, services, distribution channels, customers and geographies, and incorporating FinCEN's AML/CFT Priorities.
How often is independent testing of an AML program required?
No regulation sets a fixed frequency. The FFIEC BSA/AML Examination Manual offers every 12 to 18 months as an example and states that frequency should match the institution's risk profile, with more frequent testing after significant changes to systems, staff, products or risk, or when deficiencies have been identified. Enforcement orders routinely impose an annual requirement as a remediation condition.
Has FinCEN's AML/CFT program rule been finalized?
No. FinCEN issued its proposed rule on April 7, 2026, superseding the withdrawn July 2024 proposal, and the comment period closed June 9, 2026. The OCC, FDIC and NCUA proposed parallel amendments on April 10, 2026, and the Federal Reserve on July 9, 2026, with comments due September 8, 2026. FinCEN proposes a 12-month implementation period after any final rule, so the current five-pillar framework remains the operative standard.
Does a fintech partnering with a sponsor bank need its own five-pillar program?
The legal obligation usually sits with the sponsor bank, which cannot delegate the program requirement itself. In practice the fintech performs pillar functions such as onboarding CDD, monitoring and training under contract, and examiners evaluate those functions as the bank's controls. Fintechs that are themselves registered MSBs carry an independent program obligation under 31 CFR 1022.210 on top of their contractual duties to the bank.

.png)