The role has a title that sounds senior and a legal definition that is remarkably spare. U.S. regulation does not set qualifications for an AML compliance officer, does not require a certification, and does not specify a reporting line. What it requires is that someone is designated, that the person is identifiable, and that specific duties sit with them.
That spareness is deceptive. The obligations attached to the designation are concrete, and FinCEN’s April 2026 proposal would add a condition that changes the calculus for internationally structured groups. This article sets out what the role actually carries. Compliance Officers works alongside designated officers on the investigative work the role generates.
When the Appointment Becomes Mandatory
The trigger is not headcount or revenue. It is being a financial institution under the Bank Secrecy Act with a program duty under 31 U.S.C. 5318(h)(1). Once that duty attaches, the designation is one of the minimum elements of the program — not an optional refinement.
| Sector | What the rule says | Citation |
|---|---|---|
| Banks | “Designation of an individual or individuals responsible for coordinating and monitoring day-to-day compliance” | 31 CFR 1020.210(a)(2)(iii) |
| Money services businesses | “Designate a person to assure day to day compliance with the program and this chapter” | 31 CFR 1022.210(d)(2) |
Note that the bank rule permits individuals, plural. The duty can be shared — but it must be allocated. A program that names no one has not satisfied the element, however good its written procedures.
For a money services business there is also a date. The program — including the designation — must be in place by the later of 24 July 2002 or the end of the 90-day period beginning the day after the business is established (31 CFR 1022.210(e)). Ninety days from launch, not ninety days from the first regulatory letter.
What the Designated Person Actually Owes
For money services businesses the regulation itemises the responsibilities, and the list is the clearest statement of the role in U.S. law. The designated person must assure that:
- the business properly files reports, and creates and retains records, in accordance with the applicable requirements;
- the compliance program is updated as necessary to reflect current requirements and related guidance issued by the Treasury Department; and
- the business provides appropriate training and education.
Read together, these are three continuing duties, not three one-off tasks. The second has no permanent completion state: when current requirements or Treasury guidance change in a way that affects the business, the designated person must assure that the program is updated as necessary. A dated review record should show what changed and whether an amendment was required.
The conflict that invalidates a pillar
The person designated under 31 CFR 1022.210(d)(2) may not conduct the independent review required by paragraph (d)(4). The rule permits an internal officer or employee to perform the review — just not that person. In small firms where one individual holds every compliance responsibility, the fourth element of the program is structurally unmet, and no amount of documentation fixes it. Engaging an independent outside reviewer is one available option when the organization lacks a separate qualified internal reviewer.
What the Rules Do Not Require
Being precise about the absences matters because the regulation assigns responsibilities without prescribing a particular credential. U.S. regulation does not require the AML compliance officer to:
- hold a specific certification — ACAMS or otherwise;
- hold a law or accounting qualification;
- be a full-time employee, or work exclusively on compliance;
- hold a board seat or report directly to the board;
- be registered with or approved by FinCEN.
What those absences do not mean is that competence is optional. The obligations are strict and the penalties are real: a willful violation of the subchapter or its regulations carries a fine of up to $250,000, imprisonment for up to five years, or both (31 U.S.C. 5322(a)). The regulation leaves the qualification question to the institution because the institution bears the consequence.
The 2026 Proposal Would Add a Location Requirement
This proposal could be operationally significant for internationally structured businesses.
Under FinCEN’s proposed rule of 10 April 2026 (RIN 1506-AB72), a bank would establish its program by designating an individual who is:
- located in the United States;
- accessible to, and subject to oversight and supervision by, FinCEN and its designee; and
- responsible for establishing and implementing the AML/CFT program and coordinating and monitoring day-to-day compliance.
Two things are new. The U.S. location and accessibility condition would be written into the program rule — reflecting the requirement in the Bank Secrecy Act, as amended by the AML Act, that the duty to establish, maintain and enforce an AML/CFT program be performed by persons in the United States accessible to and subject to oversight by U.S. supervisors. And the role would expand from monitoring compliance to establishing and implementing the program.
The proposal would also require the program to be written and approved by the board of directors, an equivalent governing body, or appropriate senior management — making accountability above the officer explicit.
None of this is in force. Comments closed on 9 June 2026 and FinCEN proposed a twelve-month implementation period after any final rule. A group that allocates relevant U.S. compliance responsibilities outside the country should compare its structure with the existing statutory duty in 31 U.S.C. 5318(h)(5) and the more specific proposed language. Changes to personnel, supervision or location may require substantial lead time.
One Sector Has Extra Time
Registered investment advisers and exempt reporting advisers were due to have AML/CFT programs — and therefore designated officers — in place by 1 January 2026. A FinCEN final rule published 2 January 2026 delayed that effective date by two years, to 1 January 2028, and amended the date by which an investment adviser must develop and implement its program. Advisers that paused were reading the rule correctly.
Governance Matters More Than the Job Title
A designation is effective only if the person can perform the work. The record should identify the applicable regulatory requirement, the appointment date, scope of responsibility, reporting line, delegated tasks, authority to obtain records, access to senior management and the resources available. A title on an organization chart is not a control.
The role should also fit the institution’s size and risk. One person may carry several responsibilities in a smaller organization, but incompatible duties must be managed. In particular, the person responsible for day-to-day AML compliance should not independently test that same work where the governing rule requires independent review. An outside reviewer can perform testing, but the institution remains responsible for responding to findings.
Escalation authority should be practical. The AML compliance officer needs a route to address delayed information, override pressure, repeated control failures and activity that may require reporting. Minutes, issue logs, training records, risk-acceptance decisions and remediation evidence should allow an examiner to see what the officer raised and how management responded.
FinCEN’s April 2026 proposal included additional concepts for program governance and certain designated individuals. Those provisions are not final law as of August 14, 2026. Current appointment duties remain industry-specific. The defensible approach is to satisfy the operative rule now while building clear authority, access and oversight that can absorb later changes without misrepresenting a proposal as mandatory.
How Compliance Officers Works With Designated Officers
Compliance Officers provides documented AML checks and due-diligence support for U.S. and international clients. We examine the legal, financial and reputational background of the person or company in scope, verify identity and legal existence from available records, and organize the findings in a written report for the client’s decision file.
The service does not issue a legal opinion, determine guilt, replace the institution’s designated decision-maker or guarantee a regulator’s response. It helps establish facts, identify inconsistencies and preserve a review record before the company commits to a transaction or closes an alert.
A useful engagement begins with a defined subject, purpose and risk question. The client defines the review subject—a person, entity, transaction or relationship—and provides the available identifiers and context. The resulting work can address legal existence, ownership information, relevant public-record findings, sanctions and adverse-information indicators, and inconsistencies that require clarification. The report records its scope and limitations so readers do not mistake an absence of findings for proof that no risk exists.
Due diligence is also time-specific. A report reflects the sources and facts available during the review; it does not remain current indefinitely. A new owner, jurisdiction, product, payment route, regulatory event or material adverse fact can justify an update. The client should connect the report to its own risk classification, escalation process, retention rules and authorized decision-maker. That creates an auditable handoff between external research and the company’s internal compliance responsibility.
For related context, review our resources on corporate KYC, FinCEN filing and compliance and FinCEN requirements for small businesses. These topics overlap, but they are not interchangeable: counterparty due diligence, BSA program duties and beneficial-ownership reporting each have their own trigger and scope.
Frequently Asked Questions
When must a business appoint an AML compliance officer?
As soon as it owes a Bank Secrecy Act program duty, because the designation is one of the program’s minimum elements. For a money services business the program must be in place by the later of 24 July 2002 or the end of the 90-day period beginning the day after the business is established.
Does the officer need an ACAMS certification?
No U.S. regulation cited here requires a specific certification. An institution may adopt credential or experience standards as part of its staffing and governance process, but those internal standards are not the regulatory condition described in these program rules.
Can one person hold the role at several companies?
The regulations do not prohibit it, and the bank rule contemplates an individual or individuals. The practical constraints are capacity and conflict — in particular, the designated person may not conduct the independent review required of a money services business program.
Can our AML officer be located outside the United States?
Current law already states that the duty to establish, maintain and enforce an AML/CFT program must remain with and be performed by persons in the United States who are accessible to and supervised by Treasury and the appropriate federal functional regulator (31 U.S.C. 5318(h)(5)). The current sector rules do not phrase that duty as a universal location rule for every compliance employee. FinCEN’s April 2026 proposal would expressly require the designated individual described in the proposed bank rule to be located in the United States. The proposal is not in force, and a specific staffing structure requires legal analysis under the current statute and applicable sector rule.
Is the officer personally liable?
The Bank Secrecy Act provides for civil and criminal penalties for willful violations, and liability is not limited to the institution as an abstraction. This is a question for qualified counsel on specific facts; nothing here is legal advice.
Do investment advisers need one yet?
Not yet. The AML/CFT program and SAR filing requirements for registered investment advisers and exempt reporting advisers were delayed to 1 January 2028 by a final rule published 2 January 2026.
Support the Role Without Expanding the Payroll
Does your designated compliance officer need counterparty investigation or an independent review performed by someone outside the program?
Compliance Officers examines legal, financial and reputational background, verifies legal existence and identity, and delivers a written report for the customer file.
Phone and WhatsApp: +1 305-647-3000
Email: info@complianceofficers.org
Legal disclaimer: This article provides general information about United States anti-money laundering rules and does not constitute legal advice, a legal opinion or a guarantee of any regulatory outcome. Obligations depend on the type of institution, its activities and its regulator, and the rules change. Citations reflect the text in force on the date shown. Confirm current requirements with FinCEN, your functional regulator or qualified counsel before acting.







