Is AML Training Required Annually? What the Rules Actually Say

2026/07/23

Click to upload or drag and drop

PDF, DOCX, PPTX, TXT, JPG, JPEG, PNG, HEIC, ODP, ODT, BMP, or TIFF

up to 20MB

Please wait, your quiz is being created...

Uploading...

No. There is no federal regulation that requires anti money laundering training to be delivered annually. 31 CFR 1020.210 requires a bank's program to include "training for appropriate personnel" and names no interval. 31 CFR 1022.210 requires a money services business to "provide education and/or training of appropriate personnel" and names no interval. FINRA Rule 3310(e) requires a member firm to "provide ongoing training for appropriate personnel" and names no interval either.

Annual AML training is real as an expectation and unreal as a citation. It is worth knowing the difference, because the reason the rules leave the interval open changes what your training file has to prove.

Where the word annual actually appears

The confusion has a specific source. FINRA Rule 3310 does contain the word annual, in paragraph (c), and that paragraph is about independent testing rather than training:

"Provide for annual (on a calendar-year basis) independent testing for compliance to be conducted by member personnel or by a qualified outside party, unless the member does not execute transactions for customers or otherwise hold customer accounts or act as an introducing broker with respect to customer accounts (e.g., engages solely in proprietary trading or conducts business only with other broker-dealers), in which case such 'independent testing' is required every two years (on a calendar-year basis)."

Training is the next paragraph down, (e), and it runs to nine words in total: provide ongoing training for appropriate personnel. Two obligations, a paragraph apart, one with a calendar attached and one without. Over years of secondary summaries the calendar migrated from the testing pillar to the training pillar, and now much of the industry repeats it as a training rule.

What each rule says, side by side

RuleWho it coversTraining languageStated interval
31 U.S.C. 5318(h)Financial institutions generallyMinimum standards include an ongoing employee training program, alongside internal policies and controls, a designated compliance officer, and an independent audit functionNone. Ongoing is the only qualifier
31 CFR 1020.210BanksThe program must at a minimum include a system of internal controls, independent testing, a designated individual coordinating day to day compliance, "training for appropriate personnel", and risk based customer due diligence proceduresNone
31 CFR 1022.210Money services businesses"Provide education and/or training of appropriate personnel concerning their responsibilities under the program, including training in the detection of suspicious transactions"None
FINRA Rule 3310(e)Broker dealers"Provide ongoing training for appropriate personnel"None
FINRA Rule 3310(c)Broker dealersIndependent testing for compliance, not trainingAnnual, on a calendar year basis
FinCEN investment adviser ruleRIAs and exempt reporting advisersThe AML/CFT program and SAR requirements adopted in 2024Effective date delayed to January 1 2028

That last row deserves a flag of its own, because many adviser firms spent 2025 building toward a January 1 2026 start date. FinCEN finalized a two year delay of the effective date, published in the Federal Register on January 2 2026, and said it intends to review and tailor the rule in coordination with the SEC. Registered investment advisers and exempt reporting advisers therefore have no federal AML program obligation under that rule today.

So why does everyone say annual?

Because examiners behave as though it were true, and they are not being unreasonable about it. When a rule declines to set an interval, the burden does not vanish, it changes shape. Instead of asking whether you hit a date, an examination asks three harder questions.

  • Who did you decide was appropriate personnel, and can you defend that boundary? The regulation does not define the phrase, so your roster is your definition.
  • Was the content tailored to what those people actually do? One firmwide deck delivered to tellers, wire operators, credit officers and the board is the weakest available answer.
  • Did it land? Attendance proves delivery. Nothing in an attendance log speaks to whether anyone could act on what they heard.

Twelve months became the convention because it is a defensible cadence nobody has to argue about. But an institution that runs a yearly session and stops there has answered a question the rule never asked, while leaving the three it did ask untouched.

What a risk based training cycle looks like instead

The statute uses the language of an ongoing program, and examination practice reads training as risk based. In practice that means a baseline cycle plus event triggers, and the triggers are what separate a real program from a calendar entry.

TriggerWho needs trainingHow fast
Baseline cycleEveryone on the appropriate personnel rosterMost US institutions run twelve months and document that choice as policy
New hire or role changeThe individual moving into the roleBefore independent work, not at the next annual cycle
New product, channel, or payment corridorThe teams that touch it, plus monitoring staffBefore launch. A corridor opened in March and trained in December is nine months of thin coverage
Regulatory change or a new FinCEN advisoryThe roles the change reachesPromptly, with the advisory itself kept in the file
Audit finding or examination criticismThe team named in the findingAs part of remediation, with the reassessment documented
Suspicious activity that was missed internallyThe team that missed itImmediately, and this is the session most worth assessing

How do you prove AML training worked?

You prove it the way you would prove any other comprehension claim: by asking the people who received it to demonstrate something, and keeping the result. An attendance sheet records that a person was in a room or logged into a session. A scored assessment tied to a named employee, a role, and a specific version of your program records that they could identify the escalation path when asked.

The distinction matters most on items where being wrong is a personal exposure. The prohibition on telling a customer that a suspicious activity report has been filed or is being considered is the clearest example. Nobody should leave an AML session unsure about that, and there is no way to know whether they are unsure without asking them.

The practical route is to build the assessment from your own program rather than from a generic question bank: your escalation path, your reporting timeline, your red flags for the products you actually sell. If you want to do that from documents you already have, you can turn your BSA/AML program into a scored quiz with the questions drawn from the procedure itself, which has the side effect of making the roster document your scope decision.

What should be on the training record?

No regulation lists the fields, which is exactly why the file has to speak for itself two years later when nobody remembers the year. Capture the named employee and their role, the date, the materials in full rather than by title, the version of the program the session covered, the score and the threshold you set in advance, any retake, whether the board and senior management were covered, and the trigger that prompted the session. That last field is what shows the program is risk based rather than habitual.

Third parties are the boundary drawn wrong most often. Appropriate personnel is not the same list as your payroll, and agents acting in your name sit inside the risk even when they sit outside the HR system. Decide where the line falls and write the reasoning down, because the reasoning is the part being assessed.

Does an AML quiz satisfy the training requirement?

No, and it is worth being precise. The training satisfies the requirement. The quiz is evidence about the training. An institution that emails a question set and files the scores has not delivered training at all, it has run an assessment, and the pillar in 31 CFR 1020.210 is still unmet.

The sequence that works is ordinary. Deliver role appropriate training, assess immediately afterward while the material is fresh, set the passing threshold before you run it rather than after somebody fails, and document the retake when there is one. A failed assessment with no recorded follow up is worse than no assessment, because it files evidence of a gap you knew about and left open.

The short version

Annual is not in the training rules. It is in FINRA's independent testing rule, and it is in examiner habit. Keeping a twelve month baseline is sensible and nothing here argues otherwise. What the missing interval should change is where the effort goes: less into proving a session happened on schedule, more into defining who needed it, tailoring it to what they do, and keeping something in the file that shows it landed.

Rules and advisories in this area also move faster than most training calendars, so a program that only refreshes annually will always be behind a mid year change. Some teams now run continuous monitoring of regulatory changes against their own obligation list, so a new advisory becomes a training trigger the week it lands rather than the following January. Automated or tracked by hand, that trigger list is the part of the program the annual myth has been quietly crowding out.

For the underlying obligations and a role by role breakdown of what to assess, the AML training quiz generator page carries the full comparison. If your institution runs security awareness and general compliance training on the same calendar, the security awareness training quiz generator and the compliance training quiz pages cover the frequency rules there, which genuinely do differ.

This article is general information, not legal or compliance advice. Confirm your own obligations with counsel.

From the same family of tools