The four pillars of AML are the original core of a US anti-money laundering program: internal controls, a designated compliance officer, ongoing training, and independent testing. Since 2018, a fifth pillar, customer due diligence, has been added, so modern programs are often described as having five.
Key takeaways
- The four pillars of AML are the original core of a US AML program.
- They are internal controls, a compliance officer, training, and independent testing.
- They trace back to the US Bank Secrecy Act, enacted in 1970.
- In 2018, a fifth pillar, customer due diligence, was added.
- Modern US programs are often described as having five pillars.
- The pillars are the backbone of an AML compliance program.
On this page
What they areThe four pillarsEach in practiceTheir originFour vs fiveWhy they matterPart of a programWeak pillarsFAQsRead more
4
Original pillars of a US AML program
Source: US Bank Secrecy Act
1970
Year the Bank Secrecy Act was enacted
Source: US Bank Secrecy Act
2018
Year a fifth pillar, customer due diligence, was added
Source: FinCEN CDD Rule
What are the four pillars of AML?
The four pillars of AML are the original foundation of a US anti-money laundering program. For decades, these four elements defined what a compliant program had to contain.
They come from the Bank Secrecy Act, the US law that first required banks to help detect money laundering. The four pillars became the standard way to describe a program’s core parts.
They remain the backbone of AML today, even after a fifth was added. Read more: the pillars are the required parts of an AML compliance program.
The four pillars
Each pillar covers a different part of the job. Together they form a program that can spot and prevent laundering.
- Internal controls. The rules, policies, and procedures a firm builds to detect and prevent laundering.
- A designated compliance officer. A named person, the BSA officer, responsible for running the program.
- Ongoing training. Regular education so staff can recognize and act on laundering risk.
- Independent testing. A separate, periodic review that checks the program actually works.
These four have anchored US AML programs since long before the fifth pillar arrived.
Each pillar in practice
The four pillars are simple to name but demanding to run well. Here is what each looks like day to day.
- Internal controls. More than a policy on a shelf, they are the working rules staff follow to onboard customers, monitor activity, and report suspicion.
- Compliance officer. A real owner with the time, authority, and support to run the program, not just a name on a form. See the MLRO role.
- Training. Education tailored to each role, so a teller and an executive each learn what they need.
- Independent testing. A genuine, arm’s-length review, often by internal audit or an outside party.
Build your program on the pillars
Generate a tailored AML policy draft that sets out your controls, roles, training, and testing.
Where the four pillars come from
The four pillars are not a modern invention. They grew out of the US Bank Secrecy Act, passed in 1970, which first required banks to help the government detect money laundering.
Over the years, regulators and examiners settled on four core elements that a compliant program had to contain, and these became known as the four pillars. The framing gave banks a clear, memorable way to describe what a program needed.
The language stuck because it works. Even now that a fifth pillar exists, people still reach for the four-pillar framing as the foundation, because it captures the original core of what an AML program is for.
Four pillars vs five pillars
The four pillars became five in 2018, which is the source of a common question. The difference is a single addition.
In May 2018, FinCEN’s Customer Due Diligence Rule added customer due diligence, including beneficial ownership, as a formal fifth pillar. The original four did not change; a fifth was placed alongside them.
| Pillar | In the four | In the five |
|---|---|---|
| Internal controls | Yes | Yes |
| Compliance officer | Yes | Yes |
| Training | Yes | Yes |
| Independent testing | Yes | Yes |
| Customer due diligence | No | Yes |
So a modern US program is usually described as having five pillars. Read more: the current set is covered in the five pillars of AML.
Screen customers with your controls
Run one search across sanctions, PEP, and adverse media data as part of the checks your controls require.
Why the four pillars matter
The four pillars matter because they still form the core of every US AML program. The fifth pillar added to them; it did not replace them.
Each of the four does a job the others cannot. Controls set the rules, the officer runs them, training carries them to staff, and testing proves they work. Remove any one and the program has a hole, which is why regulators weigh them as a set.
It is worth stressing that the fifth pillar did not demote the four. Customer due diligence was added because knowing the customer proved essential to managing risk, but the original four remain the frame that holds a program together, and a firm that neglects them cannot be saved by strong due diligence alone.
How the four pillars form a program
The four pillars are not a one-time setup. They run together as a continuous program that a firm maintains over time.
Controls provide the framework, the compliance officer keeps it running, training keeps staff sharp, and independent testing catches what the others miss. A weakness in one pillar spreads to the rest, so a program is only as strong as its weakest pillar.
That interdependence is why examiners rarely praise a single strong pillar. They look at how the four work together, because a program with three excellent pillars and one hollow one still leaves a gap a launderer can use.
Signs of a weak pillar
A pillar can be present and still fail. A few signs point to a weak one.
- Paper controls. Policies that exist but are not followed.
- A powerless officer. A compliance officer without time, budget, or authority.
- Hollow training. Courses finished but not understood.
- Soft testing. Reviews that are shallow or not genuinely independent.
Get an indicative AML risk rating
See where your money laundering risk is concentrated so you can strengthen your weakest pillar.
Frequently asked questions
What are the four pillars of AML?
The four pillars of AML are the original core of a US anti-money laundering program: internal controls, a designated compliance officer, ongoing training, and independent testing. They come from the Bank Secrecy Act and defined a compliant program for decades. Since 2018, a fifth pillar, customer due diligence, has been added.
What are the four pillars in order?
The four pillars are usually listed as internal controls, a designated compliance officer, ongoing training, and independent testing. The order can vary, but all four are required parts of a US AML program. Since 2018 they are often joined by a fifth pillar, customer due diligence.
What is the difference between four and five pillars of AML?
The difference is a single addition. The four pillars are internal controls, a compliance officer, training, and independent testing. In 2018, FinCEN’s Customer Due Diligence Rule added a fifth pillar, customer due diligence. The original four did not change; a fifth was placed alongside them, so modern programs usually have five.
Why were there originally four pillars?
There were four pillars because that was the core set of requirements for a US AML program under the Bank Secrecy Act. Internal controls, a compliance officer, training, and independent testing together defined a compliant program. This framework held for decades before customer due diligence was added as a fifth pillar in 2018.
When did the four pillars become five?
The four pillars became five in 2018, when FinCEN’s Customer Due Diligence Rule took effect in May of that year. The rule added customer due diligence, including beneficial ownership, as a formal fifth pillar. The original four pillars remained unchanged, with the fifth placed alongside them.
What is the first pillar of AML?
The first pillar is usually internal controls: the rules, policies, and procedures a firm builds to detect and prevent money laundering. Internal controls are the working framework staff follow to onboard customers, monitor activity, and report suspicion. They are the foundation the other pillars support.
Are the four pillars still relevant?
Yes. The four pillars still form the core of every US AML program. The fifth pillar, customer due diligence, was added to them rather than replacing them. Internal controls, a compliance officer, training, and independent testing remain required, and each does a job the others cannot, so all four still matter.
What is independent testing in the four pillars?
Independent testing is the fourth pillar. It is a separate, periodic review that checks whether the AML program actually works. It is often carried out by internal audit or an outside party, and it must be genuinely arm’s-length. Its purpose is to catch weaknesses the day-to-day program might miss, and to give leadership an honest picture.
Do the four pillars apply outside the US?
The four pillars are a US framework, tied to the Bank Secrecy Act. Other countries have similar program requirements but may not use the pillar language. The underlying elements, such as controls, a designated officer, training, and independent review, appear in anti-money laundering rules worldwide, even where they are described differently.
What are the four pillars of BSA compliance?
The four pillars of BSA compliance are the same as the four pillars of AML: internal controls, a designated compliance officer, ongoing training, and independent testing. The name reflects that they come from the Bank Secrecy Act. Since 2018, customer due diligence has been added as a fifth pillar on top of this original foundation.
What happens if a firm lacks one of the four pillars?
A US AML program missing any of its required pillars is not compliant and can face regulatory findings and penalties. Beyond the legal risk, a missing pillar leaves a real gap: without training, staff miss warning signs, and without controls, there are no rules to follow. A program is only as strong as its weakest pillar.
Which is correct, four pillars or five pillars?
Both are correct, at different times. A US AML program had four pillars until 2018, when customer due diligence was added as a fifth. References to four pillars usually describe the framework before that change or a simplified summary, while five pillars reflects the current requirement under FinCEN’s rules.
Read more: our ultimate guides, whitepapers and templates
Related guides and resources to help you act on what you just read.
Last reviewed July 12, 2026 · 10 min read · Written for compliance and risk professionals · By the WhoWiki editorial team
Key takeaway: the four pillars of AML are the original core of a US anti-money laundering program: internal controls, a compliance officer, training, and independent testing.