Pre-Examination Preparation: The 90-Day Readiness Programme
A 90-day AML examination readiness programme helps a regulated business assess its AML/CFT framework, remediate priority gaps, organise examination evidence and prepare staff to answer supervisory questions accurately and confidently.
A practitioner guide for compliance officers and MLROs on the four-phase 90-day pre-examination preparation programme, covering internal assessment, gap remediation, evidence organisation, and team preparation. Written by Pathik Shah for AML Guild.
AML Expert
Get tailored guidance on your compliance obligations, SAR filing, or AML program review.
- Phase One: The Internal Assessment
- Phase Two: Gap Remediation
- Phase Three: Evidence Organisation
- Phase Four: Team Preparation
The 90-Day Timetable at a Glance
| Period | Main focus |
|---|---|
| Days 1 to 30 | Internal assessment, document request simulation, sample testing, interviews and findings report |
| Days 31 to 60 | Remediation of high-risk gaps, quick fixes, governance updates and evidence strengthening |
| Days 61 to 75 | Evidence library, index, version control, sample file preparation and board reporting |
| Days 76 to 90 | Team briefing, mock interviews, issue escalation protocol and final readiness review |
Where the institution receives less than 90 days' notice, the same four phases should be compressed, with priority given to high-risk gaps, regulator-facing evidence and staff preparation.
Phase One: The Internal Assessment
The internal assessment should be structured as a mock examination, using the applicable AML/CFT laws, supervisory guidance, regulatory themes and FATF effectiveness principles as reference points. For most major jurisdictions, this means using relevant FATF effectiveness themes as a reference point for the institution's programme across the relevant immediate outcomes, supplemented by any specific examination themes published by the relevant supervisory authority. The compliance officer should review the most recent thematic reviews, examination findings, and enforcement decisions published by the relevant regulator and use those as additional assessment criteria.
When I run a readiness programme, I insist the internal assessment is brutal about weaknesses, because that report is what drives the whole remediation plan. A flattering self-review just guarantees the examiner finds what you chose not to. I would rather a client hear the bad news from me, with time to fix it, than from a regulator with none.
Jyoti Maheshwari | CAMS, ACA, AML/CFT Practitioner, AML Guild
The internal assessment should produce a written findings report that honestly identifies programme strengths and weaknesses. The temptation to write an internal assessment report that emphasises strengths and minimises weaknesses should be resisted, because the internal assessment report is the document that drives the remediation planning. An internal assessment that does not identify genuine weaknesses produces a remediation plan that does not address them, and the examination that follows will find what the internal assessment did not.
Phase Two: Gap Remediation
The gap remediation phase addresses the genuine programme weaknesses identified in the internal assessment. The most important principle for this phase is that remediation must be genuine and sustainable rather than cosmetic and temporary. The institution that temporarily changes its STR/SAR or suspicious activity reporting behaviour, depending on the jurisdiction, before an examination, without addressing the underlying detection, escalation and reporting process, is not remediating a weakness. It risks being seen as indicator management rather than genuine remediation, and experienced examiners may identify this pattern by reviewing multi-year trend data.
The remediation priority should be determined by the severity and nature of the weakness. Weaknesses that represent genuine financial crime risk, such as monitoring gaps that may have allowed suspicious activity to go unreported, should be addressed as a matter of urgency regardless of the examination timeline. Weaknesses that are primarily presentational, such as documentation that is accurate but poorly organised, can be addressed in a more measured way.
Phase Three: Evidence Organisation
The evidence organisation phase prepares the documentation library that the examination will draw on. The compliance officer should anticipate the specific documentation requests that are most likely to be made and should ensure those documents are organised, current, and easily retrievable.
- The business risk assessment and its most recent review.
- The AML/CFT policy and procedures manual.
- Transaction monitoring rule documentation and tuning records.
- A sample of alert investigation records.
- A sample of STR decision memos, including decisions not to file.
- CDD files for a sample of higher-risk customers.
- Training records.
- Management information presented to the board.
- The compliance officer role description, reporting lines, and evidence of board access.
The evidence file should be organised in a way that allows the examiner to navigate it efficiently, with a clear index and consistent naming conventions. The compliance officer who can produce any requested document within minutes of a request is presenting a picture of organisational competence that reinforces the overall examination narrative. The one who cannot find documents, or who produces documents that appear to have been created recently for the purpose, is undermining it.
Phase Four: Team Preparation
The team preparation phase prepares the people who will interact with the examiners to answer questions accurately, consistently, and confidently. This is not about rehearsing scripted answers. It is about ensuring that the people who operate the compliance programme every day can explain clearly what they do, why they do it, and how it connects to the programme objectives. The examiner who asks a transaction monitoring analyst how they investigate an alert should receive an accurate description of the actual investigation process, not a recitation of the policy.
In my experience the team rarely fails on the policy, they fail on being able to describe what they actually do day to day. So when I prepare a monitoring or CDD team for examination, I get them explaining their real workflow in their own words rather than reciting the manual. An examiner can tell within minutes whether someone lives the process or has memorised it.
Dipali Vora | CAMS, ACA, AML/CFT Practitioner, AML Guild
The specific preparation for different team members differs by role. The MLRO needs to be able to articulate the overall programme design, the business risk assessment, the governance framework, and the areas of known weakness and the plans to address them. The monitoring team needs to be able to explain the monitoring rules, the alert investigation process, and the escalation criteria. The CDD team needs to be able to explain the risk segmentation approach, the EDD process, and the periodic review cycle. The training should be tailored to what each person actually does and what they are likely to be asked.
Frequently Asked Questions
Everything you need to know about examination readiness and how AML Guild supports your business.
The internal assessment report may attract legal privilege in some circumstances, particularly where it is prepared for the purpose of obtaining legal advice or in anticipation of a regulatory investigation or enforcement risk. However, privilege is jurisdiction-specific and depends on how the review is commissioned, conducted, documented and circulated. The compliance officer should take legal advice before deciding whether the report should be disclosed, summarised or withheld. As a general principle, a well-written internal assessment that identifies genuine weaknesses and credible remediation plans may support the institution's governance narrative, but disclosure should still be a considered legal and strategic decision.
The identification of a weakness by the examiner that the internal assessment did not identify is a significant event that warrants an honest response: acknowledgement of the finding, commitment to understanding how the internal assessment process failed to identify it, and a credible remediation plan. The institution that responds defensively without engaging with the substance of the finding may prolong the supervisory concern.
Dealing with this in your own business? Put a vetted, CAMS-certified AML/CFT professional from AML Guild on it and get hands-on support that holds up to scrutiny. Find your expert at amlguild.com.
- What Regulators Are Really Looking For in an AML Examination (series hub)
- The Examination Day: Managing the Process Without Undermining the Programme
- When the MLRO Says No and the CEO Says Yes: Managing the Disagreement Professionally
- How to Read a FATF Mutual Evaluation Report
Work With Pathik Shah Through AML Guild
Pathik Shah and the AML Guild network provide on-demand, CAMS-certified AML/CFT support for regulated businesses, from building and remediating compliance programmes to preparing for regulatory examination and selecting the right technology.