• Home
  • 5
  • Article
  • 5
  • AML Oversight: What Regulators Expect from IMB Leadership

AML Oversight: What Regulators Expect from IMB Leadership

Aug 21, 2026

Independent Mortgage Banks rarely question whether an independent AML testing and program review is required. Most know it is. Where issues continue to surface is in the details of how AML programs are governed, maintained, and executed between reviews and exams. Across institutions of all sizes, we continue to see the same core weaknesses flagged by regulators, not because lenders are ignoring AML requirements, but because expectations around governance, documentation, and execution are more specific than many realize.  

Below, our mortgage industry experts outline the AML requirements regulators focus on most closely today and the recurring issues we consistently identify during reviews and exams, so you can best prepare your business. 

Independent AML Testing Expectations

All residential mortgage lenders, mortgage bankers, and mortgage brokers are considered financial institutions under the Bank Secrecy Act and are required to maintain a written AML program that includes independent testing. While independent testing frequency should be risk-based, many institutions perform testing every 12 – 18 months, with increased frequency often warranted following growth, organizational changes, elevated risk, or significant compliance findings. Gaps beyond 18 months often attract examiner scrutiny, particularly if the institution has experienced growth, structural changes, or turnover in compliance leadership. 

Increasingly, examiners are less concerned with whether an independent review occurred and more focused on what it covered, how issues were addressed, and whether leadership is actively engaged in the program. They are looking to see that the program demonstrates sustained oversight.  

Where AML Programs Most Often Fall Short

Governance and Documented Oversight

One of the most common findings we see is the lack of formal approval and oversight of the AML program. Regulations require the AML program to be approved by senior management, and regulators expect governance oversight to be documented and maintained. In practice, we often find that approval was never formally documented, occurred years ago and was not refreshed, or oversight responsibilities were not clearly assigned.  

Examiners view governance as a baseline control, so missing or outdated approvals are often interpreted as a lack of oversight, even when operational controls are otherwise strong. 

Increasingly, regulators are evaluating whether management receives sufficient reporting to understand AML-related risks, training completion trends, SAR activity, remediation efforts, and the results of independent testing.

AML Training That Does Not Demonstrate Control Effectiveness

Ongoing AML training is another frequent source of exam findings. Common issues include: 

  • No structured AML training for new hires 
  • Training that does not address rolespecific responsibilities, including suspicious activity identification 
  • Employees missing training entirely or completing it late 
  • Inadequate documentation of completion 

From a regulatory perspective, training is evidence that AML responsibilities are understood and operationalized. Completion rates, timeliness, and relevance matter, not just the existence of a training policy.

Incomplete or Missing Written Risk Assessments

The written AML risk assessment is expected to reflect the institution’s actual risk profile and serve as the foundation of the AML program. Our teams regularly encounter risk assessments that: 

  • Do not exist in written form 
  • Are generic and not tailored to the lender’s customers, products, geography, or delivery channels 
  • Do not account for thirdparty or broker relationships 
  • Are disconnected from the controls described in the AML program 

Regulators expect the risk assessment to drive program design. When it does not, examiners often conclude the program is not truly riskbased.

Suspicious Activity Reporting Breakdown

Suspicious Activity Reporting is one of the most scrutinized components of AML exams, and one of the most timesensitive. Recurring findings include: 

  • Inconsistent identification of potentially suspicious activity 
  • Lack of clear internal escalation procedures 
  • Delays in filing SARs once activity is identified and verified 
  • Insufficient documentation supporting decisions not to file 

Once suspicious activity is identified and determined to be reportable, strict timelines apply for filing with FinCEN. More information about these reporting timelines can be found here. Weaknesses in this process frequently lead to formal exam findings.

AML Programs Missing Required Components

In some cases, our experts encounter AML programs that are missing required elements altogether, such as: 

  • Documented independent testing 
  • Clearly designated AML compliance oversight 
  • Written procedures aligning with regulatory requirements 

These gaps often stem from legacy programs that have not been revisited as regulatory expectations evolved. 

Why Regulators Are Paying Closer Attention

Regulators today focus less on whether AML documentation exists and more on whether the program is effective, current, and supported by management.  During exams, independent AML reviews, governance records, training logs, SAR documentation, and remediation tracking are reviewed together to assess whether the institution understands and actively manages its risk as part of its broader control environment. 

Independent testing, when done thoroughly and independently, is one of the clearest ways an institution can demonstrate that oversight. 

What This Means for Leadership

AML compliance is no longer about meeting baseline requirements. It is about demonstrating that leadership is informed, programs are current, and risks are actively addressed. The most successful AML programs are those that are regularly reviewed and approved by leadership, reflect the institution’s realworld operations, include timely, relevant training, and address issues proactively through independent review.  

Addressing these areas before an examiner identifies them can materially improve exam outcomes and reduce regulatory friction. 

If you have questions about your program or want to get on Richey May’s schedule, contact us at info@richeymay.com 

Tags: AML

Explore More Insights

Some of these items predate Richey May’s restructuring to an alternative practice structure. Richey May is no longer a CPA firm. All Attest services are provided by Richey, May & Co., LLP.

Our Latest Insights

Looking for more industry expertise and to stay up to date? Check out more from the experts at Richey May below: