For US BSA officers, compliance leads, and financial institution training teams

AML Training Quiz Generator: Anti Money Laundering Quiz Questions and BSA Training Tests From Your Own Program

Upload your BSA/AML compliance program, SAR escalation procedure, red flags appendix, or training deck and get a scored quiz with a matching answer key. The questions come from your document, so the record shows staff understood your escalation path rather than a vendor's.

PDF, Word, PowerPoint, and photos of a printed procedure all work. Files are processed securely and deleted automatically.

Upload your program and generate the quiz

Click to upload or drag and drop

PDF, DOCX, PPTX, TXT, JPG, JPEG, PNG, HEIC, ODP, ODT, BMP, or TIFF

up to 20MB

Please wait, your quiz is being created...

Uploading...

The short answer

Annual AML training is not a rule. It is a norm that everyone repeats as if it were a citation. 31 CFR 1020.210 requires a bank's program to include training for appropriate personnel and sets no interval. 31 CFR 1022.210 requires an MSB to provide education and or training of appropriate personnel, again with no interval. FINRA Rule 3310(e) requires ongoing training for appropriate personnel. The word annual does appear in Rule 3310, in paragraph (c), and it attaches to independent testing, not to training. That gap is not an excuse to train less; it is the reason examiners judge your program on whether the training was tailored and whether it landed, since there is no interval for them to tick off. A scored quiz built from your own program is the cheapest evidence that it landed. Upload the program here and the questions come from your escalation path.

Last updated July 2026. Regulatory text quoted from 31 CFR 1020.210 and 1022.210 as published by the Government Publishing Office, and FINRA Rule 3310 as published by FINRA. This page is general information, not legal or compliance advice.

What each AML rule actually says about training

Six regimes, six different sentences, and only one of them puts a number on anything. Reading them side by side is the fastest way to see where your real obligation ends and where examiner expectation begins.

Regime Who it covers What the training language says Stated interval
31 CFR 1020.210
Banks
Banks and other institutions in Chapter X part 1020 The program must at a minimum include a system of internal controls to assure ongoing compliance, independent testing for compliance, designation of an individual responsible for coordinating and monitoring day to day compliance, training for appropriate personnel, and risk based customer due diligence procedures. None
31 CFR 1022.210
Money services businesses
Money transmitters, check cashers, currency dealers, prepaid access providers Provide education and or training of appropriate personnel concerning their responsibilities under the program, including training in the detection of suspicious transactions. Detection is named in the text, which the bank rule does not do. None
FINRA Rule 3310
Broker dealers
FINRA member firms Paragraph (e) requires the firm to provide ongoing training for appropriate personnel. Paragraph (c) requires annual independent testing on a calendar year basis, dropping to every two years for firms that do not execute for customers, hold customer accounts, or act as an introducing broker. Annual, but for independent testing, not training
Registered investment advisers
FinCEN IA AML rule
RIAs and exempt reporting advisers The AML/CFT program and SAR rule adopted in 2024 was scheduled to apply from January 1 2026. FinCEN finalized a two year delay of the effective date, published January 2 2026, and stated it intends to review and tailor the rule in coordination with the SEC. Not in force until January 1 2028
31 U.S.C. 5318(h)
The statute behind all of it
Financial institutions generally The statutory minimum standards for an AML program are internal policies procedures and controls, a designated compliance officer, an ongoing employee training program, and an independent audit function to test programs. None. Ongoing is the only qualifier.
Examiner expectation
FFIEC BSA/AML manual practice
Everyone examined Training is expected to be risk based and tailored to specific roles, refreshed when products, services, customers, or regulations change, extended to the board and senior management, and documented with materials, attendance, and dates. Annual in practice, by convention rather than by citation

State money transmitter licensing regimes add their own training conditions in several states. Confirm your obligations with counsel before you set a training calendar.

Why no interval makes the evidence bar higher, not lower

When a rule names an interval, compliance is arithmetic. Every person, once every twelve months, and an examiner can test it with a spreadsheet. The BSA program rules do not give anyone that comfort. They say training for appropriate personnel, and they leave both words open.

So the examination question shifts. Instead of asking whether you hit a date, an examiner asks who you decided was appropriate and why, whether the content matched what that role actually does, and whether the people who received it could act on it. Those are qualitative questions, and attendance records answer none of them.

This is where a role weighted quiz earns its place. It documents the scope decision, because the roster of who sat the assessment is your definition of appropriate personnel written down. It documents tailoring, because a wire operations quiz that asks about wire red flags is self evidently tailored in a way a single firmwide deck is not. And it documents comprehension, which is the only one of the three that a training log cannot fake.

The MSB rule pushes even harder in that direction. It names detection of suspicious transactions in the regulatory text itself, so an MSB training file that shows policy attendance and no evidence of red flag recognition is thin against the words of the rule it is meant to satisfy.

What to test by role, since appropriate personnel is your decision

One firmwide quiz is the default and it is the weakest possible answer to a tailoring question. Split the shared core from the role items, and the roster itself starts documenting your scope decision.

Role The items that matter for them The failure this catches
Everyone, shared core The internal escalation path and how fast to use it, the prohibition on telling a customer a SAR was filed or is being considered, and what to do when a colleague asks them to hold something off the system The tipping off failure, which is a personal exposure and the single item nobody should be allowed to get wrong
Branch and teller staff The currency transaction reporting threshold, how structuring actually looks across a week rather than in one visit, and what to do when a customer asks how to stay under a limit Structuring recognized only as a single day pattern, which is how deliberate structuring is designed to be missed
Wire, payments, and operations Red flags in the payment corridors you actually serve, missing or stripped originator information, and the sanctions screening hit handling procedure Speed pressure. Operations staff clear queues, and the red flag has to be recognizable inside that workflow or it will not be
Onboarding, KYC, and relationship management The customer due diligence steps their role owns, beneficial ownership collection, when enhanced due diligence triggers, and what to do with a customer who will not answer Commercial pressure to complete an onboarding with a gap noted for later, which is the most common documented CDD finding
Lending and credit Source of funds and source of wealth questions, collateral that does not match the stated business, and early payoff patterns A team that reads AML as a deposits problem and does not see it in a credit file at all
IT and systems staff who tune monitoring Change control on alert thresholds, who has to approve a rule change, and why a suppressed alert type is a compliance decision rather than a tuning decision The role most often left off the appropriate personnel roster, despite quietly controlling how much the monitoring system sees
Board and senior management Their own oversight duties, what the reporting they receive is supposed to tell them, and what a program deficiency escalation looks like Board training treated as a courtesy briefing with no record, when examiners expect governance level training documented like any other
Statutory history and legislative background Cap at one item for everyone Nobody files a better SAR because they know what year the Bank Secrecy Act passed. This is what generated drafts over produce if you let them

How to build the quiz from your own program

1

Upload the program staff are governed by

The BSA/AML compliance program, the CIP and CDD procedures, the suspicious activity escalation and SAR filing procedure, the red flags appendix, or the deck your BSA officer presents.

2

Generate the draft and rebalance it once

You get questions with a matching answer key. Expect a cluster on definitions and program governance from the front of the document. Trade those for red flag scenarios.

3

Split the shared core from the role sets

Keep escalation and the tipping off prohibition for everyone, then add the role items from the table above. The rosters become your written scope decision.

4

Score it and file it with the training record

Attach the named employee, the role set, the program version, the threshold, and the result. Keep it with the materials and the attendance record as one package.

What an examiner ready AML training record contains

No regulation lists these fields, which is precisely why the file needs to speak for itself. Capture all eight and the record answers the questions asked in an examination without anyone reconstructing the year from memory.

Named employee and role

The role is what makes the tailoring argument, so record it alongside the name rather than only in the HR system.

Date delivered

With no regulatory interval, your own stated cycle becomes the standard you are held to. Keep it consistent.

Materials used, kept in full

Not a title. The actual deck or document, so the content can be assessed years later against what happened.

Program version the quiz was built from

Trained on last year's escalation path after a reorganization is a finding that writes itself.

Score and the threshold you set

Decide the bar before you run the assessment. A score with no stated bar proves nothing either way.

Retake and remediation, if there was one

A failed assessment with no documented follow up records a known gap that you left open.

Board and senior management sessions

Governance level training is expected and is the session most often delivered without a record.

Third parties and agents acting in your name

Appropriate personnel is not the same list as your payroll. Decide the boundary and write it down.

Trigger that prompted the session

A new product, a new corridor, an audit finding, or the annual cycle. The trigger shows the program is risk based.

Questions people ask about AML training quizzes

Is AML training required to be annual?

Not by the regulation. 31 CFR 1020.210 requires a bank's program to include training for appropriate personnel and names no interval at all. FINRA Rule 3310(e) requires ongoing training for appropriate personnel, also with no interval. The word annual does appear in Rule 3310, in paragraph (c), where it attaches to independent testing on a calendar year basis. Annual AML training is an examiner expectation and an industry norm, not a rule citation.

Who counts as appropriate personnel for AML training?

The regulation deliberately does not define it, which puts the definition on you and makes it worth writing down. In practice it is expected to reach anyone whose role touches onboarding, transactions, monitoring alerts, or approvals: branch staff, operations, wire and payments, lending, compliance, internal audit, and the board. The roles most often missed are IT staff who tune the monitoring thresholds and third party agents acting in your name.

Does a quiz satisfy the BSA training requirement?

No. The training satisfies the requirement and the quiz sits on top as evidence that it worked. What a quiz answers is the question an examiner actually asks, which is whether training was tailored to the role and whether the person could act on it. Attendance logs prove delivery. A scored assessment tied to a named employee, a role, and a program version proves comprehension.

What should an AML training quiz cover?

Cover what the person has to do, not what the statute says. The red flags for their specific product and channel, the internal escalation path and the timing, the prohibition on telling a customer that a SAR was filed or considered, the currency transaction reporting threshold and how structuring looks across days rather than in one visit, and the customer due diligence steps their role owns. Cap the legislative history at one item.

Do money services businesses have a different AML training requirement?

The wording differs in a way that matters. 31 CFR 1022.210 requires an MSB program to provide education and or training of appropriate personnel concerning their responsibilities under the program, including training in the detection of suspicious transactions. Detection is named explicitly, which the bank rule does not do, so an MSB assessment should be weighted toward red flag recognition scenarios rather than policy recall items.

When does the FinCEN investment adviser AML rule take effect?

January 1 2028. The rule adopted in 2024 originally applied from January 1 2026, but FinCEN finalized a two year delay of the effective date, published in the Federal Register on January 2 2026, and said it intends to review and tailor the rule in coordination with the SEC. Registered investment advisers and exempt reporting advisers therefore have no federal AML program or SAR obligation under that rule yet, though many are building toward it anyway.

What documents should I upload to build an AML training quiz?

Upload the documents your staff are actually governed by: the BSA/AML compliance program, the customer identification and customer due diligence procedures, the suspicious activity escalation and SAR filing procedure, the red flags appendix for your products, and the deck your compliance officer presents. A quiz built from your own program tests your escalation path. A generic AML quiz tests a program nobody at your institution follows.

Turn your BSA/AML program into a scored quiz

Upload the program, get questions with an answer key, and file the score alongside the materials and the attendance record. It takes about a minute.

Upload your program