Run the process, in order

Compliance Checklists for Risk and AML Teams

Step-by-step checklists for the four processes compliance teams run most often, written so the order of the steps is the content — because the order is what audits question.

Last updated

Crowded office shelving packed with box files, folders and stacked papers

Why checklists, and not another guide

A guide explains a subject. A checklist runs a process. The difference matters more here than in most fields, because the common failure in compliance is not ignorance of a control, it is running the controls in the wrong order and producing evidence that does not hold.

Screening a customer before you have verified who they are gives you a clean result against the wrong identity. Setting a risk rating before assessing jurisdiction and product means the rating cannot explain itself. Both look fine in a monthly report. Neither survives someone asking why.

So each checklist below is ordered, and the ordering is the argument.

The four

ChecklistUse it whenRuns for
AML/CTF programmeStanding a programme up, or reviewing one you inheritedWhole programme
Customer risk assessmentRating a customer at onboarding or reviewPer customer
Enhanced due diligenceA customer has been rated high riskPer customer
Sanctions alert reviewA screening match needs a decisionPer alert

If you are not sure which one you need, the readiness check asks ten questions and names the weakest area first.

How to use them

Work down. Do not skip a step because a system already does it — note which system, because "the platform handles it" is not an answer an assessor accepts without knowing how.

Where a step says record something, record it at the time. Reconstructed rationale is the single most common weakness found in file reviews: the decision was probably right, and there is no way left to show it.

Questions

Common questions about compliance checklists for risk and aml teams.

Are these checklists a substitute for legal advice?
No. They set out the sequence a competent process usually follows and the questions an assessor tends to ask. What your business is actually required to do depends on your jurisdiction, your sector and your own risk assessment, and that is a question for your regulator's guidance and your own advisers.
Why is the order of the steps emphasised so heavily?
Because most findings against a compliance programme are sequencing failures rather than missing controls. Screening before you have identified the customer, or setting a risk rating before you have assessed the jurisdiction, produces a control that runs but proves nothing. A checklist that lists the same steps in no particular order will not catch that.
Can we adapt these for our own internal documentation?
Yes. They are written to be adapted rather than adopted — the wording is deliberately generic so you can add your own thresholds, systems and approver roles without unpicking someone else's assumptions.