A compliance program often uses the “five pillars” as industry shorthand, not as a statutory term. You will not find the phrase in the Bank Secrecy Act or in FinCEN’s regulations. What you will find is a list of minimum elements — and the list is genuinely five items long for banks, four for money services businesses, and worded differently again in the rewrite FinCEN proposed in April 2026.
That variation is not pedantry. A template written for a different sector can omit a required control or introduce a standard that does not answer the institution’s actual rule. This article sets out what each pillar requires, in the regulation’s own language, and where the differences fall. Compliance Officers supports the pillar most institutions cannot staff internally.
Where the Compliance Program Elements Come From
The statutory hook is 31 U.S.C. 5318(h)(1), which requires financial institutions to establish anti-money laundering programs. Sector-specific regulations supply the content. For banks regulated by a federal functional regulator, 31 CFR 1020.210(a)(2) says a program must include, at a minimum:
| Pillar | The regulation's words |
|---|---|
| 1. Internal controls | “A system of internal controls to assure ongoing compliance” |
| 2. Independent testing | Bank personnel or an outside party conducts independent compliance testing |
| 3. A designated individual | “Designation of an individual or individuals responsible for coordinating and monitoring day-to-day compliance” |
| 4. Training | “Training for appropriate personnel” |
| 5. Ongoing customer due diligence | “Appropriate risk-based procedures for conducting ongoing customer due diligence” — understanding the nature and purpose of customer relationships to develop a customer risk profile, and conducting ongoing monitoring to identify and report suspicious transactions |
The fifth bank-program element is risk-based ongoing customer due diligence. Note what it expressly includes: for these purposes, customer information “shall include information regarding the beneficial owners of legal entity customers” as defined in 31 CFR 1010.230.
Four pillars, not five, if you are a money services business
31 CFR 1022.210(d) lists four minimum elements: policies, procedures and internal controls; a designated person for day-to-day compliance; training; and independent review. The MSB rule does not list ongoing customer due diligence as a separate element. A five-pillar bank template does not satisfy the MSB rule merely because it contains more headings; it can still miss MSB-specific requirements such as registration.
Pillar 1 — Internal Controls
Controls are where the program stops being a document. For a money services business the regulation is unusually specific: policies, procedures and internal controls must include provisions for verifying customer identification, filing reports, creating and retaining records, and responding to law enforcement requests (31 CFR 1022.210(d)(1)(i)).
The regulation adds a line worth quoting to any operations team: businesses with automated data processing systems should integrate their compliance procedures with such systems. Staff will bypass controls that sit outside the systems the business actually uses.
Pillar 2 — Independent Testing
Independence here means independence from the program, not necessarily from the company. Bank personnel or an outside party may conduct it. For money services businesses, the scope and frequency must match the risk of the services, and the rule imposes one hard constraint: the business may not assign the day-to-day compliance designee as reviewer (31 CFR 1022.210(d)(4)).
If one person performs both day-to-day MSB compliance and the independent review, the structure fails the rule’s independence condition. Better documentation cannot cure that conflict.
Pillar 3 — The Designated Individual
Someone must own this. For an MSB, the rule assigns the designated person three responsibilities: ensure proper reports and records; update the compliance program as necessary to reflect current requirements and Treasury guidance; and provide appropriate training (31 CFR 1022.210(d)(2)).
The update duty is event-driven. If current requirements or Treasury guidance change in a way that affects the business, leaving the program unchanged would not satisfy the obligation to update it as necessary. The file should therefore record review dates, the changes considered and the reason an amendment was or was not required.
Pillar 4 — Training
The business must train appropriate personnel and, where SAR rules apply, expressly teach them how to detect suspicious transactions.
The practical test is not attendance. It is whether a front-line employee, seeing one of the FFIEC Appendix F red flags, recognises it and knows the escalation path — without discussing it with the customer.
Pillar 5 — Ongoing Customer Due Diligence
The fifth pillar has two related halves that must be connected in the program.
Understanding the relationship means developing a customer risk profile at onboarding: what this customer does, why the account exists, what normal will look like. Without it, no monitoring rule can fire, because there is nothing to compare activity against.
Ongoing monitoring means identifying and reporting suspicious transactions and, on a risk basis, maintaining and updating customer information — including beneficial ownership information for legal entity customers. The beneficial ownership test is specific: each individual owning 25 percent or more of the equity, plus a single individual with significant responsibility to control, manage or direct the entity, such as a chief executive officer, chief financial officer, chief operating officer, managing member, general partner, president, vice president or treasurer (31 CFR 1010.230(d)).
Current customer-due-diligence duties remain ongoing, but FinCEN’s February 13, 2026 exception matters: covered institutions need not identify and verify beneficial owners again whenever an existing legal-entity customer opens another account. Event-driven monitoring and updates remain a separate part of the analysis.
How the 2026 Proposal Would Restate the Pillars
FinCEN’s proposed rule of 10 April 2026 (RIN 1506-AB72) would rewrite these requirements. The text remains a proposal; comments closed June 9, 2026, and FinCEN proposed a twelve-month implementation period after any final rule. Still, its structure offers useful context.
Under the proposed text, a bank would establish a program by: setting a risk-based set of internal policies, procedures and controls that identify, assess and document illicit finance risks through risk assessment processes; reviewing and incorporating the AML/CFT priorities issued under 31 U.S.C. 5318(h)(4); updating promptly when risks change significantly; mitigating risk by directing more attention and resources toward higher-risk customers and activities; conducting ongoing customer due diligence; establishing independent testing; designating an individual located in the United States and accessible to FinCEN; and establishing ongoing training. The board, an equivalent governing body or appropriate senior management would need to approve a written program.
Two shifts stand out. The risk assessment moves to the front and drives everything else. The proposal would judge both whether the institution established the program and whether it maintained the program by implementing all material elements.
Risk Assessment Connects the Compliance Program Elements
A list of pillars does not explain why a control exists. The written risk assessment supplies that connection. It should identify customers, products, services, delivery channels, transaction types, geographies, intermediaries and other facts that can expose the institution to illicit finance. The program then shows how controls respond to those identified risks.
Internal controls translate the assessment into onboarding, monitoring, escalation, reporting and retention. Training gives relevant personnel the information needed for their roles. The designated person coordinates the program and has access to decision-makers and records. Independent testing examines whether the design is appropriate and whether the controls operate as described. Where a sector’s rule includes ongoing customer due diligence, the institution must integrate that duty instead of treating it as a separate document.
Frequency should also follow risk and change. A static annual calendar can miss a new product, acquisition, payment channel, high-risk jurisdiction, enforcement lesson or material control failure. The institution should document review triggers, and each remediation item should identify an owner, deadline, completion evidence and validation.
FinCEN’s April 2026 program proposal emphasizes risk-based effectiveness, but it remains a proposal as of August 14, 2026. Current sector-specific rules remain binding unless and until a final rule changes them. A sound AML compliance program can anticipate clearer risk-assessment discipline without representing proposed text as current law or applying a bank’s five-element formulation to every non-bank institution.
How Compliance Officers Supports AML Review
Compliance Officers provides documented AML checks and due-diligence support for U.S. and international clients. We examine the legal, financial and reputational background of the person or company in scope, verify identity and legal existence from available records, and organize the findings in a written report for the client’s decision file.
The service does not issue a legal opinion, determine guilt, replace the institution’s designated decision-maker or guarantee a regulator’s response. It helps establish facts, identify inconsistencies and preserve a review record before the company commits to a transaction or closes an alert.
A useful engagement begins with a defined subject, purpose and risk question. The client defines the review subject—a person, entity, transaction or relationship—and provides the available identifiers and context. The resulting work can address legal existence, ownership information, relevant public-record findings, sanctions and adverse-information indicators, and inconsistencies that require clarification. The report records its scope and limitations so readers do not mistake an absence of findings for proof that no risk exists.
Due diligence is also time-specific. A report reflects the sources and facts available during the review; it does not remain current indefinitely. A new owner, jurisdiction, product, payment route, regulatory event or material adverse fact can justify an update. The client should connect the report to its own risk classification, escalation process, retention rules and authorized decision-maker. That creates an auditable handoff between external research and the company’s internal compliance responsibility.
For related context, review our resources on corporate KYC, FinCEN filing and compliance and FinCEN requirements for small businesses. These topics overlap, but they are not interchangeable: counterparty due diligence, BSA program duties and beneficial-ownership reporting each have their own trigger and scope.
Frequently Asked Questions
Does the law use the phrase five pillars?
The phrase is industry shorthand. The minimum elements appear in regulation: five for banks at 31 CFR 1020.210(a)(2), four for money services businesses at 31 CFR 1022.210(d). The statutory requirement to have a program is at 31 U.S.C. 5318(h)(1).
Which is the fifth pillar?
Risk-based procedures for ongoing customer due diligence: understanding the nature and purpose of customer relationships to develop a customer risk profile, and ongoing monitoring to identify and report suspicious transactions and, on a risk basis, to maintain and update customer information including beneficial ownership of legal entity customers.
Can the compliance officer run the independent test?
Not for a money services business. 31 CFR 1022.210(d)(4) permits an officer or employee to conduct the review only if the reviewer is not the person designated under paragraph (d)(2) for day-to-day compliance.
Does the program have to be in writing?
For money services businesses, expressly yes, and copies must be available for inspection by the Treasury Department on request (31 CFR 1022.210(c)). FinCEN’s 2026 proposal would make a written, formally approved program explicit across sectors.
How often must an institution update its program?
The MSB rule requires the designated person to update the program as necessary for current requirements and related Treasury guidance. FinCEN’s 2026 proposal would also require institutions to update risk assessments promptly after any change that significantly alters their risks.
Do we need to redesign our program for the 2026 proposed rule?
Not yet — it is a proposal and not in force, and FinCEN proposed a twelve-month implementation period after a final rule. A documented risk assessment can make current controls easier to justify and may reduce later rework, but it requires resources proportionate to the institution’s activities and does not replace any operative sector-specific requirement.
Build the Pillar You Cannot Staff Internally
Do you need customer and counterparty due diligence performed and documented to a standard that survives examination?
Compliance Officers examines legal, financial and reputational background, verifies legal existence and identity, and delivers a written report for the customer file.
Phone and WhatsApp: +1 305-647-3000
Email: info@complianceofficers.org
Legal disclaimer: This article provides general information about United States anti-money laundering rules and does not constitute legal advice, a legal opinion or a guarantee of any regulatory outcome. Obligations depend on the type of institution, its activities and its regulator, and the rules change. Citations reflect the text in force on the date shown. Confirm current requirements with FinCEN, your functional regulator or qualified counsel before acting.







