r/AMLCompliance

Wachovia's AML officer flagged cartel accounts in 2005. He was told to back off. A cocaine plane crash ended it instead.

Wachovia moved $378.4 billion for Mexican currency exchange houses between 2004 and 2007, over $4 billion of it physically trucked across the border as bulk cash.

Martin Woods joined Wachovia in 2005 as the bank's FSA-approved Money Laundering Reporting Officer in London. He flagged CDC-linked accounts. He flagged Hezbollah-connected transactions during the 2006 Lebanon war. In testimony to the UK Parliament, he described a senior colleague telling him the matter had nothing to do with him and that he shouldn't have looked at the transactions in the first place. He eventually left the bank. The FCA later had to publicly deny it had blacklisted him from the industry.

The red flags themselves weren't subtle. Multiple round-dollar wires through the same account on the same day. Sequentially numbered traveler's checks deposited in batches, structuring markings and all. Bulk cash shipments consistently running larger than the CDC's own account documentation projected. Despite all this a random event forced Wachovia to act, as a DC-9 plane that made an emergency landing in Mexico in April 2006 carrying 5.5 tons of cocaine, bought with funds traced back through a Wachovia-linked account was the last straw. Wells Fargo later admitted in court the same channel had financed four planes carrying 22 tons combined.

$160 million in penalties against $378.4 billion in unmonitored volume is its own conversation about whether the fine ever mattered to the math. An officer with the actual title and the actual authority raised the concern through the correct channel, and one colleague with no documented override authority was enough to kill it. No committee vote, no risk acceptance memo, nothing that shows up in an audit trail. Just someone telling him to stop looking.

If an analyst or compliance officer at your firm disagrees with a decision to keep an account open, where does that disagreement actually go? Is there a real path above the person who wants to say no, or does it end wherever the first person with more seniority decides it ends?

reddit.com
u/TheAMLBrief — 1 day ago

Future plans?

for all of the AML analysts out there, what do you think you will be doing in the future?

one can’t go solo like a doctor or a lawyer? and as megacorp employees, once people reach a certain age the employment grim reaper starts doing its rounds.

plus then there’s AI and threats like that

reddit.com
u/Peakychu6 — 2 days ago

For people working in finance or regulatory reporting: when does an LEI actually become important in day-to-day work?

I've been reading more about how Legal Entity Identifiers are used across financial transactions and regulatory reporting.

On paper, the idea is straightforward: a unique identifier makes it easier to identify the legal entity involved in a transaction.

What I'm more interested in is the practical side.

For those working in banking, treasury, trading, regulatory reporting, KYC, or entity-data management:

At what point does an LEI become something you actually have to think about?

Is it normally during onboarding, transaction reporting, trading, counterparty checks, opening financial accounts, or somewhere else?

And when an LEI is missing or has lapsed, does it cause real operational problems, or is fixing it usually straightforward?

Interested in hearing how this works in actual workflows rather than just the regulatory definition.

reddit.com
▲ 0 r/AMLCompliance+1 crossposts

Building a multi-jurisdiction AML report validator (FinCEN/FINTRAC/AUSTRAC) — questions on automated submission validation

I’m building the rule engine directly off each agency’s published validation documentation — a local validation layer that checks regulatory reports against FinCEN, FINTRAC, and AUSTRAC rules before submission, to cut down on rejections for MSBs filing across jurisdictions.

Planning to eventually release this as a free tool for small MSBs who can’t justify enterprise compliance platform pricing.

A few questions for anyone who’s automated this on the filing side:

  1. Do you validate locally before submitting, or send everything through and fix what bounces?

  2. How do you track when validation rules change across agencies?

  3. Any Excel, Google Sheets, or other tools you think this kind of validator should integrate with? Curious what format or workflow would make things easiest for small MSBs.

reddit.com
u/AdEastern3028 — 1 day ago
▲ 1 r/AMLCompliance+1 crossposts

Trying to break into remote ops/analyst roles from retail banking, any advice?

I’ve got close to five years of experience across banking and insurance. On the banking side I’ve done everything from transaction processing and reconciliation to KYC/CIP compliance, check fraud detection, signature verification, monitoring for suspicious activity, and working with ops and risk teams on escalations. I also have some insurance background handling underwriting support and compliance documentation.

I’m currently in retail banking and while I’m good at the sales side of it, it’s not where I want to be long term. I want to move into something more focused on the backend — remote ops, operations analyst, fraud analyst, loan processing, BSA/AML, compliance, that kind of thing.

I don’t have a degree, just a high school diploma, but I do have real hands on experience and was recognized as Top Performer at my current employer two quarters in a row.

My questions are:

What job boards or resources did you use to find remote roles in this space?

Did the lack of a degree hold you back and how did you get around it?

Any specific roles or companies that are worth targeting with a background like mine?

Anything you wish you knew before making the transition?

Appreciate any advice, this community seems like a good place to ask.

reddit.com
u/Connect_Move_4337 — 2 days ago

A fraudster in Spain passed video ID checks 38 times with a live AI face swap. What exposed him was a one-second software glitch, not a security control.

Spanish National Police announced this on 11 August, and the effort involved is what makes it worth a read.

He held forged Spanish IDs up to the webcam while a live face swap changed his appearance to match the photo on the document. A static image would not survive that, so he handled the rest by hand. He tilted the documents to imitate hologram movement, and used coloured lights to fake the reflections real security features throw off. Behind it all sat VPNs and over 320 phone lines across 24 devices, most registered to stolen identities.

What he wanted was digital signature certificates, which is the part I keep coming back to. Those carry legal weight. A certificate in someone else's name is a durable instrument, not a one-off account takeover.

38 attempts. More than 30 real people's identities.

And here is how it ended. Mid-call, the deepfake dropped for about a second. His real face appeared. That is what investigators used to identify him.

So nothing detected the method. The tooling just crashed.

Two things I would like other people's read on.

  1. If what caught him was the software failing rather than a check working, what happens once the software stops failing? These tools leave fewer artifacts with every release.
  2. Does anything short of reading the document chip and proving the camera feed is unmodified actually help here? Everything else seems to assume the image arriving is real, and this attack breaks that assumption before any check runs.
reddit.com
u/Shufti-Global — 2 days ago

ICA Diploma (level 5) or ACAMS

Hi guys I’m thinking of pursuing either one of them. Feel free to advise🙌😁

About me
Female, 28 years old

UK resident (I’ve been living in the UK for 6 years)

Bachelor’s degree in Business Administration

Master’s degree in Business Administration (MBA)

2+ years of KYC/KYB experience, mainly working with SME clients

Which one should I pursue?

reddit.com
u/Special_Ad8876 — 2 days ago

Can a crypto card really be no KYC if it runs on normal card rails?

I keep seeing crypto cards marketed as no KYC and it raises a few questions about whats really meant after Visa or Mastercard rails are involved.

In practice it’s not always clear if no KYC refers to the cardholder level, the platform level or only the marketing layer on top. Since card networks and issuing banks typically require some form of identity verification the phrase can feel a bit at odds with how traditional card infrastructure works.

One common misconception seems to be that no KYC means no identity checks anywhere in the flow. Another is that a card can be issued and used freely without any verified user behind it when in reality theres often a verified account somewhere upstream even if the end user experience feels lighter.

There also seems to be confusion between unverified access and models where a verified card or account is being accessed indirectly through shared, pooled or embedded services. Those are very different setups but they often get described under the same “no KYC” umbrella

Overall the phrase seems to blur more distinctions than it clarifies especially when traditional card infrastructure is part of the stack

reddit.com
u/Fun_Perspective_3320 — 4 days ago
▲ 3 r/AMLCompliance+1 crossposts

General Question

I have completed my masters in finance and have 2+ years job experience in a bank and 9 months in an mnc.

The job experience in the bank was mostly as a relationship manager while the 9 moths experience was of AML domain drafting SAR.

I need to understand if I'm moving forward to pursue CFE, 40 credits I'm having easily, how to go beyond to earn 10 more.

Can I appear and qualify with 40 credits? After that what is generally needed to be done?

Country India.

reddit.com
u/Appropriate_Yak7319 — 3 days ago
▲ 1 r/AMLCompliance+1 crossposts

How much of an Anti-Money Laundering (AML) investigation still happens outside the case-management system?

I’ve been reading about how AML alert investigations work and wanted to check my understanding with people who have actually done this job.

As I understand it, an alert usually lands in the case-management system with the triggering activity and some customer information. But before making a decision, the investigator may still need to look elsewhere for transaction history, KYC/CDD records, connected accounts, previous cases and other context. They then document what they found, close or escalate the case, and send it through quality review.

I’m curious how this works in practice today:

  • How much of what you need is already available inside the case-management system?
  • What do you still have to pull from other systems, separate queries, spreadsheets or documents?
  • Have newer investigation platforms actually reduced handling time, or have they mostly made alerts easier to view and assign?
  • When quality review sends a case back, what is usually missing or wrong?
  • Where is the real bottleneck: the software, integrations, data quality, access restrictions or the internal process itself?
  • Are there things the system tries to automate that investigators simply don’t trust?

The reason I’m asking is that, from what I’ve read, investigators still seem to spend a fair amount of time pulling information together instead of analysing it. I’m looking into whether a better workflow could reduce some of that repetitive work while keeping the actual decision with the investigator.

But it’s also possible that newer platforms already handle this well and I’m working from an outdated picture. That’s what I’m trying to figure out.

Would appreciate any perspective you’re comfortable sharing!

reddit.com
u/International_Tip241 — 4 days ago

How hard is it to transition into this field?

I have a law degree and several years of experience in tasks and fields I would consider “adjacent”. I don’t want to get too much into specifics, but if you’re curious feel free to DM me.

I do not have cams, but I have a lesser known certification too.

reddit.com
u/JobQman — 5 days ago

Potential Job Opportunity

Currently on 40K a year as a Senior AML Analyst at a law firm where I have been for 6 months. I have 5 years of experience and currently studying for an ICA qualification.

I have been offered a contract role at a larger law firm at £375 a day for 6 months with the possibility of an extension. This would increase my commute time to 2 hours each way three times a week.

The recruiter keeps mentioning the possibility for an extension and the strength of the AML market. My gut instinct is this is unlikely.

I want just wanted a sense check on others views on this opportunity.

reddit.com
u/Dapper_Reason8005 — 6 days ago

How did your job search change once you had your certifications? (ACAMS, CFE)

So I’m about to start my CAMS and CFE exams prep and I’ve been wondering if it’s actually worth it all.
Many keep saying it’s a global standard and signals that you’re ready to work right off the bat which should be a job guarantor but is that truly the case?

Are you free to apply wherever you want with realistic chances of hiring (without selling yourself short)?
Are you actually in DEMAND or do you need to apply and hope for the best?

The certs will be paid by me since my employer doesn’t wanna do it and it’s fine but if getting these certs won’t turn my job search / job possibilities from the person that’s looking for job openings into person that’s being contacted by company xyz recruiter then it doesn’t seem worth it

reddit.com
u/Proof_Concern6928 — 7 days ago

Would ACAMS help me move from retail banking into compliance?

I have around 3 years of experience in retail banking as a Banking Associate and Financial Advisor. I've been getting recruiter messages, but most of the roles are sales/client-facing, which I'm trying to move away from.

I'm interested in AML/KYC/compliance and was wondering if getting ACAMS would actually help me make the switch. I don't have any direct compliance experience, so I'm not sure if the certification would be enough to get me considered for entry-level roles.

For those already working in AML/compliance, do you think ACAMS is worth doing in my situation? Or would my time and money be better spent trying to get into a junior compliance role first?

Also, what kind of roles would you recommend someone with my background target?

reddit.com
u/minnieaaa99 — 7 days ago

FinCEN Permanently Ends Corporate Transparency Act - Beneficial Ownership Requirement from AML Act of 2020

Seems obviously intended to enable money laundering by certain members of the federal government...

fincen.gov
u/Darthmullet — 8 days ago

Guidance on salary expectations please

Hi everyone, Apologies if this is weird, its my first time doing something like this - I’m 21 (turning 22 soon) and I’m looking for some career guidance from people who are further along in AML/compliance than I am.

I’ve been working in compliance for just under three years at a UK regulated conveyancing firm (going to be 3 years on the 21st). My day-to-day work involves KYC, CDD/EDD, sanctions and PEP screening, source of funds/source of wealth reviews, beneficial ownership checks, ongoing monitoring, and investigating higher-risk matters involving overseas funds, third-party payments, and complex ownership structures. I’ve also been involved in preparing and escalating SARs through the UK National Crime Agency (NCA) portal and supporting financial crime investigations. My SAR reporting has minimal supervision and my role in itself has minimal supervision in the sense that on multiple occasions I have been the sole member of the compliance team for an extended period of time (mainly due to holidays and stuff like that)

I completed my ICA Certificate in Anti-Money Laundering (Merit) this year and currently earn £25k. I’ve recently been shortlisted for a UK-based KYC & Compliance Analyst role at a global fintech/crypto firm and I’m not really sure what salary range someone with my background should realistically ask for.

I know I’m still early in my career, so I’m trying not to overestimate myself, but I also don’t want to undersell my experience. I’d really appreciate any honest advice from senior AML/compliance professionals, especially those in fintech, banking, or crypto, about what level I’m currently at and what salary range you’d consider reasonable.

It is a fully remote role which i have been shortlisted for.

thank you for your time.

reddit.com
u/Key_Wrap_7 — 9 days ago

Original wire was blocked as “remittance involving OFAC SDN,” but no SDN is identified — what should the blocking file normally contain?

I’m looking for an operational/sanctions-compliance perspective from people who have actually worked with OFAC screening, blocked payments, or correspondent banking.

This is not a request for legal advice. There is already ongoing federal litigation concerning the funds, and I’m trying to better understand what the underlying compliance record would normally look like.

The basic facts are:

A cross-border USD wire was stopped at a U.S. correspondent bank in 2022.

A contemporaneous document from the originating bank later described the block using the wording:

“remittance involving OFAC SDN.”

However, the records currently available to me do not identify:

  • the alleged SDN individual or entity;
  • the relevant OFAC sanctions program;
  • what field or party generated the match;
  • whether it was an exact match or a screening alert;
  • what investigation was performed after the alert;
  • or what the final disposition of the sanctions review was.

The funds remained blocked.

OFAC later issued a specific license authorizing the return of the funds, and OFAC subsequently provided additional clarification regarding the authorized transaction.

The original blocking rationale has now become relevant in the litigation, but the underlying blocking file has not been produced, and the bank is arguing that issues surrounding the original block should not form part of the present dispute.

That leaves me with a very basic compliance question:

If a U.S. bank genuinely blocked a payment because it involved an OFAC SDN, what would you normally expect to exist in the contemporaneous blocking file?

For example, would you ordinarily expect the file to contain:

  • the actual SDN name that generated the alert;
  • the sanctions program involved;
  • the matching fields/data points;
  • screening-system output;
  • analyst review notes;
  • escalation or sanctions-officer approval;
  • the basis for concluding that the match was a true positive;
  • the OFAC blocking report;
  • and subsequent review/disposition records?

The second question is the one I find even more interesting.

If the original alert was actually a false positive, what would normally happen operationally?

Would you expect to see a documented false-positive analysis, release/unblocking decision, correction of any prior report, and retention of the relevant review records?

I am asking because the combination seems unusual to me:

“remittance involving OFAC SDN” appears in the contemporaneous record, but no SDN is actually identified in the materials currently available.

So from a sanctions-compliance perspective, I am trying to understand what should normally be behind that notation.

For those who have worked inside sanctions teams, correspondent banks, or transaction-screening operations:

Would a blocking file normally make it possible to identify exactly who or what the supposed SDN nexus was?

And if not, what would explain a file containing an SDN-based blocking determination without an identifiable SDN match?

Interested particularly in practical experience rather than legal conclusions.

reddit.com
u/SevereDaikon7247 — 9 days ago

Laid off

After an unexpected layoff, I’m currently looking for new opportunities in AML, Financial Crime, Transaction Monitoring, KYC/KYB, and Compliance.

With 7+ years of experience in AML, EDD, CDD, Transaction Monitoring, SOF/SOW verification, and Financial Crime Risk Assessment, I’m ready to contribute from day one.
If your organization is hiring or you can refer me, I’d truly appreciate your support. Please feel free to connect or send me a message.

Thank you!

reddit.com
u/AdJolly9788 — 13 days ago