Click to upload or drag and drop
PDF, DOCX, PPTX, TXT, JPG, JPEG, PNG, HEIC, ODP, ODT, BMP, or TIFF
up to 20MB
Uploading...
No. There is no federal regulation that requires anti money laundering training to be delivered annually. 31 CFR 1020.210 requires a bank's program to include "training for appropriate personnel" and names no interval. 31 CFR 1022.210 requires a money services business to "provide education and/or training of appropriate personnel" and names no interval. FINRA Rule 3310(e) requires a member firm to "provide ongoing training for appropriate personnel" and names no interval either.
Annual AML training is real as an expectation and unreal as a citation. It is worth knowing the difference, because the reason the rules leave the interval open changes what your training file has to prove.
The confusion has a specific source. FINRA Rule 3310 does contain the word annual, in paragraph (c), and that paragraph is about independent testing rather than training:
"Provide for annual (on a calendar-year basis) independent testing for compliance to be conducted by member personnel or by a qualified outside party, unless the member does not execute transactions for customers or otherwise hold customer accounts or act as an introducing broker with respect to customer accounts (e.g., engages solely in proprietary trading or conducts business only with other broker-dealers), in which case such 'independent testing' is required every two years (on a calendar-year basis)."
Training is the next paragraph down, (e), and it runs to nine words in total: provide ongoing training for appropriate personnel. Two obligations, a paragraph apart, one with a calendar attached and one without. Over years of secondary summaries the calendar migrated from the testing pillar to the training pillar, and now much of the industry repeats it as a training rule.
| Rule | Who it covers | Training language | Stated interval |
|---|---|---|---|
| 31 U.S.C. 5318(h) | Financial institutions generally | Minimum standards include an ongoing employee training program, alongside internal policies and controls, a designated compliance officer, and an independent audit function | None. Ongoing is the only qualifier |
| 31 CFR 1020.210 | Banks | The program must at a minimum include a system of internal controls, independent testing, a designated individual coordinating day to day compliance, "training for appropriate personnel", and risk based customer due diligence procedures | None |
| 31 CFR 1022.210 | Money services businesses | "Provide education and/or training of appropriate personnel concerning their responsibilities under the program, including training in the detection of suspicious transactions" | None |
| FINRA Rule 3310(e) | Broker dealers | "Provide ongoing training for appropriate personnel" | None |
| FINRA Rule 3310(c) | Broker dealers | Independent testing for compliance, not training | Annual, on a calendar year basis |
| FinCEN investment adviser rule | RIAs and exempt reporting advisers | The AML/CFT program and SAR requirements adopted in 2024 | Effective date delayed to January 1 2028 |
That last row deserves a flag of its own, because many adviser firms spent 2025 building toward a January 1 2026 start date. FinCEN finalized a two year delay of the effective date, published in the Federal Register on January 2 2026, and said it intends to review and tailor the rule in coordination with the SEC. Registered investment advisers and exempt reporting advisers therefore have no federal AML program obligation under that rule today.
Because examiners behave as though it were true, and they are not being unreasonable about it. When a rule declines to set an interval, the burden does not vanish, it changes shape. Instead of asking whether you hit a date, an examination asks three harder questions.
Twelve months became the convention because it is a defensible cadence nobody has to argue about. But an institution that runs a yearly session and stops there has answered a question the rule never asked, while leaving the three it did ask untouched.
The statute uses the language of an ongoing program, and examination practice reads training as risk based. In practice that means a baseline cycle plus event triggers, and the triggers are what separate a real program from a calendar entry.
| Trigger | Who needs training | How fast |
|---|---|---|
| Baseline cycle | Everyone on the appropriate personnel roster | Most US institutions run twelve months and document that choice as policy |
| New hire or role change | The individual moving into the role | Before independent work, not at the next annual cycle |
| New product, channel, or payment corridor | The teams that touch it, plus monitoring staff | Before launch. A corridor opened in March and trained in December is nine months of thin coverage |
| Regulatory change or a new FinCEN advisory | The roles the change reaches | Promptly, with the advisory itself kept in the file |
| Audit finding or examination criticism | The team named in the finding | As part of remediation, with the reassessment documented |
| Suspicious activity that was missed internally | The team that missed it | Immediately, and this is the session most worth assessing |
You prove it the way you would prove any other comprehension claim: by asking the people who received it to demonstrate something, and keeping the result. An attendance sheet records that a person was in a room or logged into a session. A scored assessment tied to a named employee, a role, and a specific version of your program records that they could identify the escalation path when asked.
The distinction matters most on items where being wrong is a personal exposure. The prohibition on telling a customer that a suspicious activity report has been filed or is being considered is the clearest example. Nobody should leave an AML session unsure about that, and there is no way to know whether they are unsure without asking them.
The practical route is to build the assessment from your own program rather than from a generic question bank: your escalation path, your reporting timeline, your red flags for the products you actually sell. If you want to do that from documents you already have, you can turn your BSA/AML program into a scored quiz with the questions drawn from the procedure itself, which has the side effect of making the roster document your scope decision.
No regulation lists the fields, which is exactly why the file has to speak for itself two years later when nobody remembers the year. Capture the named employee and their role, the date, the materials in full rather than by title, the version of the program the session covered, the score and the threshold you set in advance, any retake, whether the board and senior management were covered, and the trigger that prompted the session. That last field is what shows the program is risk based rather than habitual.
Third parties are the boundary drawn wrong most often. Appropriate personnel is not the same list as your payroll, and agents acting in your name sit inside the risk even when they sit outside the HR system. Decide where the line falls and write the reasoning down, because the reasoning is the part being assessed.
No, and it is worth being precise. The training satisfies the requirement. The quiz is evidence about the training. An institution that emails a question set and files the scores has not delivered training at all, it has run an assessment, and the pillar in 31 CFR 1020.210 is still unmet.
The sequence that works is ordinary. Deliver role appropriate training, assess immediately afterward while the material is fresh, set the passing threshold before you run it rather than after somebody fails, and document the retake when there is one. A failed assessment with no recorded follow up is worse than no assessment, because it files evidence of a gap you knew about and left open.
Annual is not in the training rules. It is in FINRA's independent testing rule, and it is in examiner habit. Keeping a twelve month baseline is sensible and nothing here argues otherwise. What the missing interval should change is where the effort goes: less into proving a session happened on schedule, more into defining who needed it, tailoring it to what they do, and keeping something in the file that shows it landed.
Rules and advisories in this area also move faster than most training calendars, so a program that only refreshes annually will always be behind a mid year change. Some teams now run continuous monitoring of regulatory changes against their own obligation list, so a new advisory becomes a training trigger the week it lands rather than the following January. Automated or tracked by hand, that trigger list is the part of the program the annual myth has been quietly crowding out.
For the underlying obligations and a role by role breakdown of what to assess, the AML training quiz generator page carries the full comparison. If your institution runs security awareness and general compliance training on the same calendar, the security awareness training quiz generator and the compliance training quiz pages cover the frequency rules there, which genuinely do differ.
This article is general information, not legal or compliance advice. Confirm your own obligations with counsel.
From the same family of tools