- name
- anti-money-laundering-compliance-method
- description
- Institution-specific evidence method for AML and CFT program risk and controls, customer and beneficial-owner review, transaction-monitoring populations, alerts, cases, confidentiality, quality assurance and independent testing. Use without suspicion, reportability, filing, sanctions, blocking, account-exit or legal decisions.
# Anti-Money Laundering Compliance Method
## Establish applicability and program boundary
Record entity, institution type, jurisdiction, as-of date, products, services, customer types, channels, geographies, delivery model, controlled regulation and policy versions, program owner and requested decision. FATF material is an international framework, not self-executing local law. FinCEN, FFIEC or OFAC material applies only when current counsel-controlled sources establish scope. Do not inherit a threshold, deadline or requirement from the upstream Skill.
Trace business and customer risk factors to the enterprise risk assessment, program components, policies, controls, systems, training and independent testing. Preserve supplied inherent and residual ratings as attributed human assessments. This Skill can test traceability and evidence; it cannot interpret applicability or approve risk acceptance.
## Examine customer and relationship evidence
Map the authorized customer or relationship identifier, customer type, legal arrangement and beneficial-owner evidence, products/services, channels, geographies, expected activity, source-of-funds or source-of-wealth records, correspondent or omnibus visibility, review trigger, evidence dates and supplied risk disposition.
Distinguish missing evidence, stale evidence, conflicting identity attributes and a documented exception. Never verify identity, infer ownership, search external sources, contact a customer or assign a rating. Privacy, bank-secrecy and purpose limitations govern access.
## Reconcile monitoring populations
Treat transaction monitoring as a controlled evidence pipeline from in-scope source population through transformations, scenario or model execution, alert creation, case handling and attributed human disposition. Do not collapse those stages or infer a case outcome from an alert.
Define transaction source systems, entities/accounts, period, transaction types, currencies and sign/amount basis, inclusion/exclusion rules and control totals. Reconcile extracted and eligible populations before interpreting alerts. Preserve data transformations, joins, deduplication, late arrivals and missing fields.
For each monitoring scenario or model record version, effective period, supplied rationale, parameters or threshold source, input fields, segmentation, suppressions and change approval. Link eligible transactions to alert and case IDs. Never change, tune or deploy a scenario, model or threshold.
## Separate indicators from suspicion decisions
A red flag or alert is a prompt for authorized review, not proof of money laundering, terrorist financing, sanctions violation or unlawful conduct. Record facts, transaction patterns, customer context, alternative explanations, supporting and contradictory evidence and analyst inference separately.
Preserve the human case disposition and decision-maker as supplied. Do not recommend or decide a suspicious-activity report, currency report, blocking, rejection, account exit or enforcement referral. Do not create a filing-ready narrative. Report confidentiality and tipping-off controls restrict who may know that a report exists or is contemplated.
## Evaluate monitoring quality
Trace alert counts, case conversions, sampled non-alerts, known outcomes, overrides, backlog and ageing with precise definitions and denominators. False-positive and false-negative evidence depends on mature labels, sampling and outcome windows. Do not infer effectiveness from a low alert volume or high closure rate.
Document model/scenario validation, data-quality controls, override governance, change history and exception populations. Keep fraud, sanctions and AML labels distinct. A payment-fraud decision is not an AML suspicion determination.
## Test program governance independently
Record the independent-testing mandate, tester independence and competence, universe, sample design, procedures, evidence, findings, root causes, management responses, remediation and effectiveness verification. Preserve testing limitations. This Skill does not issue an audit opinion or certify program effectiveness.
Map training audience, role relevance, content/version, assigned/completed date, assessment evidence and exceptions. Completion counts do not prove competence. Governance bodies and qualified compliance officers own program changes and risk decisions.
## Join and stop
Run program/control, customer/beneficial-owner, monitoring/alert/case and quality/testing branches from one frozen applicability boundary. Join by stable IDs. Reconcile periods and populations; preserve contradictions, confidentiality segmentation and decisions not made.
Stop on unclear jurisdiction or institution scope, stale controlled source, unreconciled population, unknown scenario/model/threshold version, missing case authority, confidentiality risk, unsupported label or absent qualified reviewer. Never file, block, freeze, exit, contact or determine suspicion or law.
Ver no GitHub