Four Core Elements of a Mortgage Company's AML Program
A covered residential mortgage lender or originator's Bank Secrecy Act anti-money-laundering program must include internal policies, procedures and controls; a designated compliance officer; ongoing employee training; and independent testing.
More key points
- The program must be tailored to the business's risks and comply with applicable FinCEN rules.
On this page12 sections
- The four core elements
- Make the program risk-based
- Officer, training and independent testing
- Suspicious activity and records
- The four elements must work together
- Example: tailoring controls to a correspondent channel
- AML program is separate from SAR duties
- What risk-based controls can look like
- Make independent testing genuinely independent
- A sample independent test
- Translate the four elements into a working program
- Exam takeaway
An AML program is more than a written policy binder. Covered mortgage businesses need a functioning system that detects and addresses money-laundering risks in their operations.
The four core elements
- Internal policies, procedures and controls reasonably designed to assure ongoing compliance.
- Designation of a person responsible for coordinating and monitoring day-to-day compliance.
- Ongoing employee training relevant to the business and employee roles.
- Independent testing to assess the program's effectiveness.
Make the program risk-based
The controls should reflect the institution's size, locations, products, customers, transaction types and delivery channels. A business that originates residential mortgages may face different risks from a bank or broker-dealer, but its program must still address the applicable rules and risk profile.
Officer, training and independent testing
The compliance officer needs sufficient authority, resources and access to senior management. Training should help employees recognize suspicious patterns and follow escalation procedures. Independent testing must be performed by someone sufficiently independent from the functions being tested; the review should lead to tracked corrective action.
Suspicious activity and records
The AML program supports required monitoring, escalation, suspicious-activity reporting and recordkeeping. Mortgage professionals should not tip off a customer about a suspicious activity report. The exact reporting and retention rules depend on the covered entity and applicable regulations.
The four elements must work together
A written AML program for covered residential mortgage lenders and originators must use risk-based policies, procedures, and internal controls; designate a compliance officer; provide ongoing training; and include independent testing. The controls should reflect products, geography, customer types, origination channels, agents, and brokers. A static policy copied from another lender may not address the company’s actual exposure.
The compliance officer oversees implementation, updates the program, and ensures appropriate training. Independent testing evaluates whether controls operate as designed and whether agents and brokers comply. The tester may be internal or external, but cannot be the designated compliance officer under the rule.
Example: tailoring controls to a correspondent channel
A lender that works through third-party brokers should include them in its AML risk assessment, define what customer and transaction information the company receives, and specify escalation steps for suspicious patterns. Training should match each role: processors may learn document red flags, while underwriters may focus on inconsistent income, ownership, or funding details. Independent testing should sample transactions and test whether staff followed the controls.
The risk assessment informs how often and how deeply the company tests. The regulation requires the scope and frequency to be commensurate with risks. That does not mean a small lender is exempt; it means the program can be scaled while still addressing its real operations.
AML program is separate from SAR duties
The AML program and suspicious activity reporting obligations are related but distinct. A sound program helps identify, investigate, document, and escalate activity that may require a report. The company should protect SAR information and follow FinCEN’s filing and confidentiality rules. Do not place a blanket statement in a public record that confirms whether a SAR was filed.
For exams, list all four minimum elements and explain that the program must be written, risk-based, senior-management approved, and appropriate to covered company operations. The independent tester assesses program operation, not just whether a policy document exists.
What risk-based controls can look like
A lender’s controls may verify borrower identity, understand beneficial ownership and source of funds, flag unusual payment arrangements, detect inconsistent property or income information, and escalate suspicious activity. The controls should reflect the company’s origination model and include agents and brokers. A high-volume channel may need automated flags; a small lender may rely on manual review with documented escalation.
A risk-based program is not a fixed checklist that ignores new products or fraud patterns. Reassess the risks when the company enters a new market, adds a broker channel, changes its customer base, or sees a new typology. Senior management must approve the written program and support the compliance officer’s role.
Make independent testing genuinely independent
Testing should evaluate whether the written program is implemented and effective, including whether agents and brokers follow their duties. The designated AML compliance officer cannot perform the independent test under §1029.210(b)(4). Another officer or employee may test if independent of the compliance officer role; an outside party is also possible. Scope and frequency must match risk.
A useful test samples files, follows alerts from detection through disposition, tests training records, and checks whether corrective actions were completed. A policy review alone is insufficient if it does not test operations. Document findings, owners, due dates, and remediation evidence.
A sample independent test
A tester selects a sample of recent originations from different channels, checks whether identity and source-of-funds red flags were handled under written procedures, confirms broker training, and traces alerts to documented dispositions. The tester reports exceptions and verifies management assigns owners and dates for corrective action. This provides evidence that the program operates, rather than merely exists on paper.
The compliance officer should not perform the independent test of their own program. Testing frequency and scope should correspond to risk, so a new broker channel or rising suspicious activity may warrant broader sampling. FinCEN examines compliance under BSA authority, and failures can constitute violations of the regulation.
Translate the four elements into a working program
A written policy should name the person responsible for administering the program, describe how staff identify and escalate suspicious activity, and set a schedule for risk-based training and independent testing. Procedures should cover customer or business relationships, transaction monitoring, documentation, escalation, and recordkeeping as applicable to the company’s risk. The exact control design should fit the institution’s size, products, customer types, and delivery channels rather than copying a bank manual without adaptation.
Independent testing should be performed by personnel who are not responsible for the controls being tested, or by a qualified outside party. The tester samples actual files, checks whether the written policy matches practice, and reports findings to management for remediation. Training completion records, test plans, sample results, corrective actions, and board or senior-management review provide evidence the program operates. A policy document alone does not establish an effective program.
Exam takeaway
Remember policies and controls, a designated compliance officer, employee training and independent testing. The program must be risk-based and implemented, not merely documented.
Common questions
Does every mortgage company have the same AML obligations?
Coverage depends on the business and applicable FinCEN rules; determine whether the entity is a covered residential mortgage lender or originator.
Can the compliance officer perform the independent test?
The testing function must be independent enough to provide an objective assessment; avoid self-review of the officer's own work.
Is training a one-time onboarding presentation?
The rule calls for ongoing training suited to employee roles and the institution's risks.