The AML compliance checklist for a firm with no compliance team
FinCEN’s rule names four minimum requirements for every covered adviser’s AML program, regardless of size: written policies and controls, a designated compliance officer, ongoing employee training, and an independent test. Two-thirds of the firms in FinCEN’s own scope run on 10 or fewer staff, which means for most covered firms, all four of those requirements land on the same one or two people who also run the advisory business itself. This page maps each pillar to what it concretely means when there is no separate compliance department to hand it to.
Where the four pillars come from
The requirement is not FinCEN’s own invention for this rule; it is the BSA’s standard structure for every type of covered financial institution. “The BSA provides that Treasury may prescribe minimum standards for AML/CFT programs that include, at a minimum, (1) the development of internal policies, procedures, and controls; (2) the designation of a compliance officer; (3) an ongoing employee training program; and (4) an independent audit function to test the programs” (89 FR 72156, p. 72190, September 4, 2024). FinCEN adopted all four without modification for investment advisers.
Pillar 1: written policies, procedures, and controls
This is the document that has to exist before anything else does: a risk-based description of how the firm identifies and responds to money laundering, terrorist financing, and other illicit finance risk in its own advisory business. For a firm without a compliance department, the honest failure mode here is not having no document; it is having a generic template nobody customized to the firm’s own client base, custody arrangements, and risk factors. FinCEN’s rule requires the program be “risk-based,” which a template copied wholesale is not.
Pillar 2: a designated AML/CFT compliance officer, and the tension small firms live inside
The rule requires a named person, not a committee or a vendor, “responsible for implementing and monitoring the internal policies, procedures, and controls” of the program, and that person “need not be an ’officer’” by formal title (89 FR 72156, p. 72193, September 4, 2024). A small firm’s chief compliance officer under the SEC’s own Compliance Rule can be the same person who takes on this role: “An RIA that is subject to the SEC’s Compliance Rule... could designate its chief compliance officer... to be responsible for this provision of this final rule. The final rule does not, however, require that an investment adviser designate the same person” (89 FR 72156, p. 72193, footnote 165). One person can legally hold both hats. Here is the tension worth stating plainly rather than glossing over: FinCEN’s own rule text warns that “an AML/CFT officer that has multiple additional job duties or conflicting responsibilities that adversely impact the officer’s ability to effectively coordinate and monitor day-to-day AML/CFT compliance generally would not fulfill this requirement” (89 FR 72156, p. 72193). At the same time, the industry’s own annual practitioner survey found that “the majority of CCOs (63 percent) continue to wear more than one hat (with 17 percent also serving in some legal capacity)” (2025 Investment Management Compliance Testing Survey, Investment Adviser Association, ACA Group, and Yuter Compliance Consulting, 577 responding firms, fielded May 2025, published July 22, 2025). The rule permits a multi-hat officer in principle and cautions against it in the same breath; a small firm cannot resolve that tension by policy alone; it resolves it by making sure whoever holds the role genuinely has the authority, time, and access FinCEN’s text describes, not just the title.
Pillar 3: ongoing employee training
Training has to reach “appropriate persons,” meaning whoever’s job functions bring them near money laundering, terrorist financing, or illicit finance risk, not necessarily the whole firm (89 FR 72156, p. 72193-72194, September 4, 2024). For a firm with one or two people doing everything client-facing, that usually means everyone gets trained, since there is no back-office role narrow enough to exclude. FinCEN’s own analysis assumes annual refreshers, not a one-time session: the program has to keep pace with the firm’s own risk profile, not sit unchanged after year one.
Pillar 4: independent testing, and the option built for exactly this size of firm
The test has to come from someone independent of the people who built or run the program day to day; a firm cannot test itself (89 FR 72156, p. 72192-72193). One commenter raised exactly this page’s scenario during the rulemaking, that “the requirement for an independent audit of the AML/CFT program would significantly burden investment advisers with few employees” and asked FinCEN to let firms under 100 employees use internal staff instead. FinCEN declined to change the rule, but did point to a specific way small firms can lower the cost of genuine independence: “investment advisers with less complex operations, and lower money laundering, terrorist financing, or other illicit finance activity risk profiles may consider utilizing a shared resource as part of a collaborative arrangement with similarly less complex and lower risk profile advisers to conduct testing, as long as the testing is independent” (89 FR 72156, p. 72193, citing FinCEN’s Interagency Statement on Sharing Bank Secrecy Act Resources, October 3, 2018). A small firm does not have to face this pillar alone or hire a national firm: peer firms of similar size and risk profile can test each other, as long as neither tests its own program. See the dedicated page on who may perform this test, linked below, for the full detail.
What most small firms actually have today, and what that means for this checklist
The same 2025 industry survey found that “83 percent of firms have some AML policies, but only 22 percent have updated their policies to align with the new rule” (2025 Investment Management Compliance Testing Survey, IAA/ACA Group/Yuter, 577 firms, July 22, 2025). Read against the four pillars above: most firms already have SOMETHING for pillar 1, inherited from a prior voluntary practice or a broker-dealer affiliation, and the actual gap for most small firms is not starting from nothing, it is confirming the existing document, officer, training, and testing arrangement each actually meet this specific rule’s requirements rather than an older or looser standard.
FAQ
Can one person be both my firm’s chief compliance officer and its AML/CFT officer? Yes. FinCEN’s rule does not require two different people, and a firm’s existing CCO under the SEC’s Compliance Rule can take on this role. What the rule does require is that the person have genuine authority, independence, and access to resources, not that the title be split. Does having other job duties disqualify our compliance officer? Not automatically, but FinCEN’s own text cautions that “multiple additional job duties or conflicting responsibilities” that get in the way of actually running the program can disqualify the arrangement. Most CCOs at advisory firms already wear more than one hat (63 percent, per the 2025 industry survey); the rule’s concern is with whether the role gets done, not with the number of hats itself. Does every employee need AML training, even at a two-person firm? If both people’s roles bring them near client relationships, money movement, or account opening, in most small firms the practical answer is yes: the rule requires training reach anyone whose duties bring them in contact with these risks, and a small firm rarely has a role narrow enough to carve out. We have no one independent enough on staff to test our own program. What are our options? Hire an outside tester, or, per FinCEN’s own suggestion, form a collaborative testing arrangement with other similarly small, similarly low-risk advisory firms, so long as none of them tests its own program. See the independent testing page linked below for who specifically qualifies. Does this rule really apply to a firm as small as ours? FinCEN considered and rejected an exemption for advisers under 20 or 100 employees. Check your own firm’s specific scope profile, linked below, rather than assuming size alone settles the question. Cta: Check my own firm’s scope profile Whether your own firm is in scope, and which risk factors apply to it, is what the checker at normfin.com reads off the SEC’s own adviser roster.
Sources
- FinCEN, final rule, “Anti-Money Laundering/Countering the Financing of Terrorism Program and Suspicious Activity Report Filing Requirements for Registered Investment Advisers and Exempt Reporting Advisers,” 89 FR 72156 (September 4, 2024). RIN 1506-AB58. Retrieved 2026-08-23 via a stealth fetch of https://www.govinfo.gov/content/pkg/FR-2024-09-04/html/2024-19260.htm (HTTP 200; every quoted sentence located by direct text search in the retrieved document). Specific pinpoint pages used: p. 72190 (four-pillar minimum requirement), pp. 72192-72194 (compliance officer designation, the multi-duty caution, independent testing and the shared-resource option, employee training scope), pp. 72256-72257 (final regulatory flexibility analysis: the “small entity” legal definition, 385 small advisers nationwide, over 80 percent of covered advisers manage at least $110 million in assets). - FinCEN, Interagency Statement on Sharing Bank Secrecy Act Resources (October 3, 2018), https://www.fincen.gov/news/news-releases/interagency-statement-sharing-bank-secrecy-act-resources , cited within 89 FR 72156 at p. 72193 as the basis for the shared-testing-resource option for small, low-risk advisers. - FinCEN.gov, press release on the final rule (August 28, 2024), https://www.fincen.gov/news/news-releases/fincen-issues-final-rules-safeguard-residential-real-estate-investment-adviser , and the accompanying fact sheet, https://www.fincen.gov/sites/default/files/shared/IAFinalRuleFactSheet-FINAL-508.pdf . Cited for the FinCEN.gov-hosted restatement of the rule’s adoption date and scope, alongside the Federal Register text itself. - 2025 Investment Management Compliance Testing Survey, Investment Adviser Association, ACA Group, and Yuter Compliance Consulting, 577 responding investment adviser firms, fielded May 2025, published July 22, 2025. Retrieved 2026-08-23 via WebFetch of https://www.acaglobal.com/news-and-announcements/2025-imct-survey-results-press-release/ . Quoted figures: 63 percent of CCOs wear more than one hat (17 percent also serving in some legal capacity); 83 percent of firms have some AML policies, 22 percent have updated them to align with the new rule. - ~/Code/normfin/data/firms.json and data/meta.json: SEC investment-adviser roster, roster date 2026-08-03, 11,223 firms in scope, computed 2026-08-23 (see command and output above). - ~/Code/normfin/lib/fincen/citations.ts: confirmed SMALL_FIRM_DECLINE_QUOTE / SMALL_FIRM_DECLINE_CITE are already used on /check/[crd]/page.tsx only, not on any /use-cases page, so this draft’s use of the underlying rulemaking discussion (89 FR 72156, pp. 1710-1729 in the retrieved text, the employee-count exemption FinCEN declined) is a new treatment, not a repeated one.
Published by Neige AI, Inc., last reviewed August 25, 2026. See the method and sources.
This page is independent research, not legal advice. It quotes FinCEN’s own rulemaking with pinpoint citations. Verify anything load-bearing against the Federal Register text itself before acting on it.