Broker-Dealer AML Audits and FINRA AML Compliance Programs
FINRA Rule 3310 requires most FINRA member firms to conduct an annual independent AML audit to test the firm’s AML Compliance Program.
FINRA provides resources to assist Firm’s in complying with Bank Secrecy Act (BSA) and applicable SEC and FINRA rules and regulations. FINRA Rule 3310 sets forth minimum standards for a firm’s written AML compliance program, which includes but is not limited to the following:
The program has to be approved in writing by a senior manager.
It must be reasonably designed to ensure the firm detects and reports suspicious activity.
It must be reasonably designed to achieve compliance with the AML Rules, including, among others, having a risk-based customer identification program (CIP) that enables the firm to form a reasonable belief that it knows the true identity of its customers.
It must be independently tested to ensure proper implementation of the program.
Each FINRA member firm must submit contact information for its AML Compliance Officer through the FINRA Contact System (FCS).
Ongoing training must be provided to appropriate personnel.
The program must include appropriate risk-based procedures for conducting ongoing customer due diligence, including (i) understanding the nature and purpose of customer relationships for the purpose of developing a customer risk profile; and, (ii) conducting ongoing monitoring to identify and report suspicious transactions and, on a risk basis, to maintain and update customer information, including information regarding the beneficial owners of legal entity customers.
Ref: https://www.finra.org/rules-guidance/key-topics/aml
There is also a FINRA FAQ page where member firms may find additional information and further details AML and Rule 3310 requirements, including but not limited to the following:
establish and implement policies and procedures that can be reasonably expected to detect and cause the reporting of suspicious transactions;
establish and implement policies, procedures, and internal controls reasonably designed to achieve compliance with the Bank Secrecy Act and implementing regulations;
provide for annual (on a calendar-year basis) independent testing for compliance to be conducted by member personnel or by a qualified outside party. If the firm does not execute transactions with customers or otherwise hold customer accounts or act as an introducing broker with respect to customer accounts (e.g. engages solely in proprietary trading or conducts business only with other broker-dealers), the independent testing is required every two years (on a calendar-year basis);
designate and identify to FINRA (by name, title, mailing address, e-mail address, telephone number, and facsimile number) an individual or individuals responsible for implementing and monitoring the day-to-day operations and internal controls of the program. Such individual or individuals are associated persons of the firm with respect to functions undertaken on behalf of the firm. Each member must review and, if necessary, update the information regarding a change to its AML compliance person within 30 days following the change and verify such information within 17 business days after the end of each calendar year;
provide ongoing training for appropriate personnel; and,
include appropriate risk-based procedures for conducting ongoing customer due diligence, including (i) understanding the nature and purpose of customer relationships for the purpose of developing a customer risk profile; and (ii) conducting ongoing monitoring to identify and report suspicious transactions and, on a risk basis, to maintain and update customer information, including information regarding the beneficial owners of legal entity customers.
Ref: https://www.finra.org/rules-guidance/key-topics/aml/faq