The five pillars of AML are the required parts of a US anti-money laundering program: internal controls, a compliance officer, ongoing training, independent testing, and customer due diligence. The fifth pillar, customer due diligence, was added in 2018, turning the original four pillars into five.
Key takeaways
- The five pillars of AML are the required parts of a US AML program.
- They are internal controls, a compliance officer, training, independent testing, and CDD.
- The fifth pillar, customer due diligence, was added in 2018.
- Before that, US programs were built on four pillars.
- The fifth pillar includes identifying the beneficial owners of companies.
- The pillars together form an AML compliance program.
On this page
What they areWhy five, not fourThe five pillarsThe fifth pillarFive vs fourPart of a programBuilding itWeak pillarsFAQsRead more
5
Pillars of a US AML program today
Source: FinCEN
2018
Year customer due diligence became the fifth pillar
Source: FinCEN CDD Rule
$3B
Paid by TD Bank in 2024 after pillar failures
Source: US Department of Justice
What are the five pillars of AML?
The five pillars of AML are the building blocks every US anti-money laundering program must contain. They are set by regulation, and a program missing any one of them is not compliant.
The pillars give a program its structure. Each covers a different part of the job, from writing the rules to checking that they work and knowing who the customer is.
Together, the five pillars are what a regulator expects to see. Read more: the pillars are the required parts of an AML compliance program.
Why five pillars, and not four?
For years, a US AML program rested on four pillars. In 2018 a fifth was added, which is the source of the common four-versus-five confusion.
The change came from FinCEN’s Customer Due Diligence Rule, which took effect in May 2018. It made customer due diligence, including identifying the beneficial owners of company customers, a formal requirement in its own right. What had been part of good practice became a named pillar.
So both numbers are correct, at different times. Programs built before 2018 spoke of four pillars, while modern programs speak of five. If you come across either number, it helps to know which one a source means, since the requirement today is five.
The five pillars, one by one
Each pillar covers a distinct part of an AML program. Here is what each one means in practice.
- Internal controls. The written policies and procedures that put the program into action, from onboarding to reporting.
- A compliance officer. A designated person, the BSA or AML officer, who owns and runs the program.
- Ongoing training. Regular education so staff can recognize and respond to laundering.
- Independent testing. A periodic, independent review that checks the program actually works.
- Customer due diligence. Knowing who the customer is, and who really owns a company customer.
The first four are the original set. The fifth, customer due diligence, is the one added in 2018.
Build your program on the pillars
Generate a tailored AML policy draft that sets out controls, roles, training, and due diligence.
Screen customers as part of due diligence
Run one search across sanctions, PEP, and adverse media data to support the fifth pillar of your program.
The fifth pillar explained
The fifth pillar, customer due diligence, is worth a closer look, since it is the one that changed the count. It has two parts.
The first is knowing the customer: verifying who they are and understanding the nature of the relationship, through customer due diligence. The second is beneficial ownership: for company customers, identifying the real people who own or control them, so a firm cannot be fooled by a shell company.
Adding this as a pillar reflected a simple truth. A program cannot manage risk if it does not truly know its customers.
Five pillars vs four pillars
The difference between five and four is just the fifth pillar. Everything else is shared.
| Four pillars | Five pillars | |
|---|---|---|
| Internal controls | Yes | Yes |
| Compliance officer | Yes | Yes |
| Training | Yes | Yes |
| Independent testing | Yes | Yes |
| Customer due diligence | No | Yes (added 2018) |
If you see a reference to four pillars, it is usually describing a program before 2018, or a simplified summary. Read more: the original set is covered in the four pillars of AML.
How the pillars form a program
The five pillars are not a checklist to tick once. They work together as a living program that a firm runs continuously.
Controls set the rules, the compliance officer runs them, training equips staff, due diligence keeps customer risk in view, and independent testing checks the whole thing works. A weakness in any one pillar undermines the others, which is why regulators look at them as a set.
This is also why the pillars are described as a program, not a checklist. A checklist is done once, while a program runs continuously, adapting as the firm and its risks change.
Building a program around the five pillars
Standing up the five pillars follows a natural order, where each rests on the one before it.
- Assess the risk first. Base the whole program on where the firm’s laundering risk actually sits.
- Write the controls. Turn that risk picture into clear policies and procedures staff can follow.
- Name the officer. Give a senior person real ownership of the program, with the authority to run it.
- Build due diligence. Set how the firm identifies customers and the beneficial owners behind companies.
- Train, then test. Equip staff to play their part, then check independently that the whole thing works.
Notice the order. The risk assessment comes first, even though it is not itself a pillar. Without it, the pillars are built on guesswork rather than evidence, and a program built on guesswork tends to fail where it is least expected.
Signs of a weak pillar
A pillar can exist and still be weak. A few signs point to trouble.
- Controls on paper only. Policies that no one follows in practice.
- An overloaded officer. A compliance officer with no time, budget, or authority.
- Tick-box training. Courses completed but not understood.
- Weak testing. Reviews that are shallow or not truly independent.
- Thin due diligence. Customers onboarded without knowing who really owns them.
Get an indicative AML risk rating
See where your money laundering risk is concentrated so you can strengthen the pillars that matter most.
Frequently asked questions
What are the five pillars of AML?
The five pillars of AML are the required parts of a US anti-money laundering program: internal controls, a designated compliance officer, ongoing training, independent testing, and customer due diligence. A program must contain all five to be compliant. The fifth pillar, customer due diligence, was added in 2018.
Why are there five pillars and not four?
For years a US AML program rested on four pillars. In 2018, FinCEN’s Customer Due Diligence Rule added a fifth by making customer due diligence, including beneficial ownership, a formal requirement. Both numbers are correct at different times: four pillars before 2018, and five pillars in modern programs.
What is the fifth pillar of AML?
The fifth pillar is customer due diligence. It has two parts: knowing who the customer is and understanding the relationship, and, for company customers, identifying the real people who own or control them. It was added in 2018 by FinCEN’s CDD Rule, reflecting that a program cannot manage risk without truly knowing its customers.
When was the fifth pillar added?
The fifth pillar was added in 2018, when FinCEN’s Customer Due Diligence Rule took effect in May of that year. The rule made customer due diligence, including identifying the beneficial owners of company customers, a formal requirement. This turned the original four pillars of a US AML program into five.
What are the five pillars in order?
The five pillars are usually listed as internal controls, a designated compliance officer, ongoing training, independent testing, and customer due diligence. The first four are the original set, and customer due diligence is the fifth, added in 2018. The order can vary, but all five are required for a compliant program.
What is the difference between four and five pillars of AML?
The only difference is the fifth pillar, customer due diligence. Both versions share internal controls, a compliance officer, training, and independent testing. The four-pillar version describes a US AML program before 2018, while the five-pillar version reflects the addition of customer due diligence by FinCEN’s CDD Rule that year.
What is the fifth pillar’s beneficial ownership requirement?
The fifth pillar requires firms to identify the beneficial owners of company customers, meaning the real people who ultimately own or control them. This stops criminals from hiding behind shell companies. It is part of customer due diligence, and it became a formal requirement when the fifth pillar was added in 2018.
Do the five pillars apply outside the US?
The five pillars are a US framework, tied to the Bank Secrecy Act and FinCEN rules. Other countries have similar program requirements, but they may not use the pillar language or the exact same five elements. The underlying ideas, such as controls, a compliance officer, training, and due diligence, appear in AML rules worldwide.
What happens if a pillar is missing?
A US AML program that is missing any of the five pillars is not compliant and can face regulatory findings and penalties. Beyond the legal risk, a missing pillar leaves a real gap. Without training, staff miss warning signs, and without due diligence, a firm does not know its customers, so the whole program is weaker.
Are the five pillars a legal requirement?
Yes. In the US, the five pillars are effectively required for regulated firms under the Bank Secrecy Act and FinCEN’s rules, including the 2018 CDD Rule that added the fifth pillar. A compliant AML program must contain all five, and regulators expect each one to work in practice, not merely exist on paper.
How do the five pillars fit into an AML program?
The five pillars are the required components of an AML program. Controls set the rules, the compliance officer runs them, training equips staff, customer due diligence keeps customer risk in view, and independent testing checks it all works. The program is the whole system, and the pillars are the parts a regulator expects to see.
Is customer due diligence really the fifth pillar?
Yes. Customer due diligence is widely recognized as the fifth pillar of a US AML program, added by FinCEN’s Customer Due Diligence Rule in 2018. Before then, it was part of good practice but not a named pillar. Its addition reflected the view that knowing the customer is fundamental to managing money laundering risk.
Read more: our ultimate guides, whitepapers and templates
Related guides and resources to help you act on what you just read.
Last reviewed July 12, 2026 · 10 min read · Written for compliance and risk professionals · By the WhoWiki editorial team
Key takeaway: the five pillars of AML are the required parts of a US anti-money laundering program, the original four plus customer due diligence, added in 2018.