Normfin

How advisory firms actually comply with FinCEN's AML rule

There is no single right answer here, and no option below is the wrong one for every firm. What decides more than the price tag is who is allowed to test the program once it is built, and that rule applies no matter which path gets you there.

One disclosure, because this page compares a path I sell. I run Praxtrust, which builds AML programs for advisory firms and runs the annual independent test. That is the fifth option below. I have tried to describe the other four as a firm choosing between them would, including where they beat mine, and the independence rule that limits all of them applies to me exactly as it does to anyone else. praxtrust.com

The rule that decides more than the price tag

Whichever path below a firm picks to build its AML program, the rule's annual independent test sits on top of all four. The tester does not need any specific certification. What the rule actually requires is narrower: the tester has to be independent of the function being tested, meaning not the person or firm that designed the program or runs it day to day. A firm cannot test its own program. A CCO firm or law firm that built and runs a client's program cannot also be the one that tests it for that same client. That single constraint rules out some combinations of the options below before cost ever enters the picture. Read the full breakdown of the independent test.

Build it in-house

FinCEN's own estimate for building a new AML program from nothing: " FinCEN estimates it will take approximately 120 hours... to develop the necessary policies, procedures, and controls to establish an AML/CFT program." (FinCEN, final rule, 89 FR 72156, regulatory impact analysis, pp. 72229-72230 (September 4, 2024)). For a firm with the internal staff and time to do that work, in-house is a legitimate answer, not the cheap fallback other comparisons sometimes make it out to be. What in-house does not remove is the annual test: a firm small enough that the same one or two people touch everything has nobody left inside the firm who is independent of the program, so it still needs an outside tester every year, at FinCEN's own estimated cost of roughly "FinCEN estimates the average cost of such testing will be approximately $17,000... a new recurring cost for all RIAs and ERAs." (FinCEN, final rule, 89 FR 72156, regulatory impact analysis, pp. 72229-72230 (September 4, 2024)). Building in-house buys back the setup cost. It does not buy back the recurring one.

Hire an outsourced CCO or compliance consultant

Retainer pricing for outsourced compliance officer services on the market today runs roughly $1,500 to $6,000 a month, with a further $3,000 to $20,000 to build the initial program, a wide range because it depends heavily on a firm's size and risk factors (private funds, custody, a wrap fee program, and the rest: see the checker's own result for what a specific firm discloses). The independence rule still applies here: if the same outsourced CCO both builds and runs the program, that firm cannot also be the one that tests it. The annual test still has to come from a genuinely separate party.

Hire a law firm

A law firm or compliance boutique can build the same program a CCO firm would, typically billed hourly or as a fixed engagement fee that varies by firm and by how complex a client's risk factors are. The same constraint applies: a firm that designed and is running the program for a client cannot also be the one testing it for that client. Some firms keep the law firm relationship for building and interpreting the rule, and hire a separate party for the recurring test.

Buy AML software

A growing set of AML software vendors, Flagright among them, build transaction monitoring, policy templates and workflow tools aimed at exactly the population this rule covers. Software can carry a real share of the ongoing work: monitoring, recordkeeping, alerting. It does not replace the rule's other requirement for a designated compliance officer, a named person, not a subscription, and running your program on a vendor's software does not make that vendor an independent tester of it. The annual test is still a separate decision.

The path the independence rule pushes firms toward

Because whoever builds and runs the program day to day cannot also test it, a common pattern is to split the two decisions on purpose: build and run the program in-house, through a CCO firm, a law firm, or software, then hire a different, genuinely independent party for the annual test alone. That is not a fifth product to buy. It is what any of the four paths above turns into once the annual test comes due, and it is worth deciding on purpose rather than discovering the year the test is due.

This site is independent research, not legal advice, and using it creates no advisor-client or attorney-client relationship of any kind. It reads a firm's own public Form ADV filing against FinCEN's published rule text and reports a result; it does not review a firm's actual compliance program, does not account for facts outside that public filing, and makes no promise about a firm's actual compliance status. Decisions about a firm's AML obligations should be made with qualified counsel, not from this site alone.