Four Pillars of AML

Four Pillars of AML

The four pillars of AML are the original core of a US anti-money laundering program: internal controls, a designated compliance officer, ongoing training, and independent testing. Since 2018, a fifth pillar, customer due diligence, has been added, so modern programs are often described as having five.

Key takeaways

  • The four pillars of AML are the original core of a US AML program.
  • They are internal controls, a compliance officer, training, and independent testing.
  • They trace back to the US Bank Secrecy Act, enacted in 1970.
  • In 2018, a fifth pillar, customer due diligence, was added.
  • Modern US programs are often described as having five pillars.
  • The pillars are the backbone of an AML compliance program.

4

Original pillars of a US AML program

Source: US Bank Secrecy Act

1970

Year the Bank Secrecy Act was enacted

Source: US Bank Secrecy Act

2018

Year a fifth pillar, customer due diligence, was added

Source: FinCEN CDD Rule

What are the four pillars of AML?

The four pillars of AML are the original foundation of a US anti-money laundering program. For decades, these four elements defined what a compliant program had to contain.

They come from the Bank Secrecy Act, the US law that first required banks to help detect money laundering. The four pillars became the standard way to describe a program’s core parts.

They remain the backbone of AML today, even after a fifth was added. Read more: the pillars are the required parts of an AML compliance program.

The four pillars

Each pillar covers a different part of the job. Together they form a program that can spot and prevent laundering.

  • Internal controls. The rules, policies, and procedures a firm builds to detect and prevent laundering.
  • A designated compliance officer. A named person, the BSA officer, responsible for running the program.
  • Ongoing training. Regular education so staff can recognize and act on laundering risk.
  • Independent testing. A separate, periodic review that checks the program actually works.

These four have anchored US AML programs since long before the fifth pillar arrived.

Each pillar in practice

The four pillars are simple to name but demanding to run well. Here is what each looks like day to day.

  1. Internal controls. More than a policy on a shelf, they are the working rules staff follow to onboard customers, monitor activity, and report suspicion.
  2. Compliance officer. A real owner with the time, authority, and support to run the program, not just a name on a form. See the MLRO role.
  3. Training. Education tailored to each role, so a teller and an executive each learn what they need.
  4. Independent testing. A genuine, arm’s-length review, often by internal audit or an outside party.

Build your program on the pillars

Generate a tailored AML policy draft that sets out your controls, roles, training, and testing.

Open the AML Policy Generator →

Where the four pillars come from

The four pillars are not a modern invention. They grew out of the US Bank Secrecy Act, passed in 1970, which first required banks to help the government detect money laundering.

Over the years, regulators and examiners settled on four core elements that a compliant program had to contain, and these became known as the four pillars. The framing gave banks a clear, memorable way to describe what a program needed.

The language stuck because it works. Even now that a fifth pillar exists, people still reach for the four-pillar framing as the foundation, because it captures the original core of what an AML program is for.

Four pillars vs five pillars

The four pillars became five in 2018, which is the source of a common question. The difference is a single addition.

In May 2018, FinCEN’s Customer Due Diligence Rule added customer due diligence, including beneficial ownership, as a formal fifth pillar. The original four did not change; a fifth was placed alongside them.

Pillar In the four In the five
Internal controls Yes Yes
Compliance officer Yes Yes
Training Yes Yes
Independent testing Yes Yes
Customer due diligence No Yes

So a modern US program is usually described as having five pillars. Read more: the current set is covered in the five pillars of AML.

Screen customers with your controls

Run one search across sanctions, PEP, and adverse media data as part of the checks your controls require.

Try Combined AML Screening →

Why the four pillars matter

The four pillars matter because they still form the core of every US AML program. The fifth pillar added to them; it did not replace them.

Each of the four does a job the others cannot. Controls set the rules, the officer runs them, training carries them to staff, and testing proves they work. Remove any one and the program has a hole, which is why regulators weigh them as a set.

It is worth stressing that the fifth pillar did not demote the four. Customer due diligence was added because knowing the customer proved essential to managing risk, but the original four remain the frame that holds a program together, and a firm that neglects them cannot be saved by strong due diligence alone.

Worth knowing. The four pillars are sometimes called the four pillars of BSA compliance, since they come from the Bank Secrecy Act. Whatever the label, the point is the same. They are the minimum a US program needs, and the fifth pillar, customer due diligence, sits on top of this original foundation rather than replacing it.

How the four pillars form a program

The four pillars are not a one-time setup. They run together as a continuous program that a firm maintains over time.

Controls provide the framework, the compliance officer keeps it running, training keeps staff sharp, and independent testing catches what the others miss. A weakness in one pillar spreads to the rest, so a program is only as strong as its weakest pillar.

That interdependence is why examiners rarely praise a single strong pillar. They look at how the four work together, because a program with three excellent pillars and one hollow one still leaves a gap a launderer can use.

Signs of a weak pillar

A pillar can be present and still fail. A few signs point to a weak one.

  • Paper controls. Policies that exist but are not followed.
  • A powerless officer. A compliance officer without time, budget, or authority.
  • Hollow training. Courses finished but not understood.
  • Soft testing. Reviews that are shallow or not genuinely independent.

Get an indicative AML risk rating

See where your money laundering risk is concentrated so you can strengthen your weakest pillar.

Try the AML Risk Assessment →

Frequently asked questions

What are the four pillars of AML?

The four pillars of AML are the original core of a US anti-money laundering program: internal controls, a designated compliance officer, ongoing training, and independent testing. They come from the Bank Secrecy Act and defined a compliant program for decades. Since 2018, a fifth pillar, customer due diligence, has been added.

What are the four pillars in order?

The four pillars are usually listed as internal controls, a designated compliance officer, ongoing training, and independent testing. The order can vary, but all four are required parts of a US AML program. Since 2018 they are often joined by a fifth pillar, customer due diligence.

What is the difference between four and five pillars of AML?

The difference is a single addition. The four pillars are internal controls, a compliance officer, training, and independent testing. In 2018, FinCEN’s Customer Due Diligence Rule added a fifth pillar, customer due diligence. The original four did not change; a fifth was placed alongside them, so modern programs usually have five.

Why were there originally four pillars?

There were four pillars because that was the core set of requirements for a US AML program under the Bank Secrecy Act. Internal controls, a compliance officer, training, and independent testing together defined a compliant program. This framework held for decades before customer due diligence was added as a fifth pillar in 2018.

When did the four pillars become five?

The four pillars became five in 2018, when FinCEN’s Customer Due Diligence Rule took effect in May of that year. The rule added customer due diligence, including beneficial ownership, as a formal fifth pillar. The original four pillars remained unchanged, with the fifth placed alongside them.

What is the first pillar of AML?

The first pillar is usually internal controls: the rules, policies, and procedures a firm builds to detect and prevent money laundering. Internal controls are the working framework staff follow to onboard customers, monitor activity, and report suspicion. They are the foundation the other pillars support.

Are the four pillars still relevant?

Yes. The four pillars still form the core of every US AML program. The fifth pillar, customer due diligence, was added to them rather than replacing them. Internal controls, a compliance officer, training, and independent testing remain required, and each does a job the others cannot, so all four still matter.

What is independent testing in the four pillars?

Independent testing is the fourth pillar. It is a separate, periodic review that checks whether the AML program actually works. It is often carried out by internal audit or an outside party, and it must be genuinely arm’s-length. Its purpose is to catch weaknesses the day-to-day program might miss, and to give leadership an honest picture.

Do the four pillars apply outside the US?

The four pillars are a US framework, tied to the Bank Secrecy Act. Other countries have similar program requirements but may not use the pillar language. The underlying elements, such as controls, a designated officer, training, and independent review, appear in anti-money laundering rules worldwide, even where they are described differently.

What are the four pillars of BSA compliance?

The four pillars of BSA compliance are the same as the four pillars of AML: internal controls, a designated compliance officer, ongoing training, and independent testing. The name reflects that they come from the Bank Secrecy Act. Since 2018, customer due diligence has been added as a fifth pillar on top of this original foundation.

What happens if a firm lacks one of the four pillars?

A US AML program missing any of its required pillars is not compliant and can face regulatory findings and penalties. Beyond the legal risk, a missing pillar leaves a real gap: without training, staff miss warning signs, and without controls, there are no rules to follow. A program is only as strong as its weakest pillar.

Which is correct, four pillars or five pillars?

Both are correct, at different times. A US AML program had four pillars until 2018, when customer due diligence was added as a fifth. References to four pillars usually describe the framework before that change or a simplified summary, while five pillars reflects the current requirement under FinCEN’s rules.

Read more: our ultimate guides, whitepapers and templates

Related guides and resources to help you act on what you just read.

Last reviewed July 12, 2026 · 10 min read · Written for compliance and risk professionals · By the WhoWiki editorial team

Key takeaway: the four pillars of AML are the original core of a US anti-money laundering program: internal controls, a compliance officer, training, and independent testing.

Learn & stay current

A compliance reference that keeps up with the regulators

Plain-English explainers, country rules, and data you can cite, updated as the landscape moves.

Comparing tools before you commit?

See how WhoWiki lines up against the platforms you already know, and which free tools fit which job.

See how current your screening could be

Book a walkthrough with our team, or start with the tools today. No account needed to run your first check.