Field Guide

AML Program Gap Analysis: A Practitioner's Guide

The short version

An AML gap analysis compares a BSA/AML program as it actually runs against the standard it is required to meet: the program pillars, the FFIEC BSA/AML Examination Manual, and the regulations that apply to the institution. It rates each shortfall and orders what to fix. Its output is a prioritized remediation plan with named owners and dates. A gap analysis delivered as a standalone document, and not tied to a remediation plan that is tracked and updated, becomes inaccurate as the program changes.

An AML gap analysis is a structured comparison of a BSA/AML compliance program as it actually operates against the standard it should meet: the BSA program pillars at 31 CFR 1020.210 and 31 U.S.C. 5318(h), the FFIEC BSA/AML Examination Manual, and the regulations that apply to the institution. It identifies where the program falls short, rates the severity of each shortfall, and produces an ordered list of what to remediate.

This article sets out what a gap analysis is, when an institution needs one, what to measure against, the step-by-step method, how to score findings, and how findings become a remediation plan.

Definition and distinction from a risk assessment

A gap analysis is a structured comparison: current state (how the program operates today, in practice, not on paper) versus required state (what the law, guidance, and the institution's risk profile demand). The output is a list of gaps, each rated by severity, with a path to close it.

A gap analysis is distinct from a risk assessment. A risk assessment identifies what the institution is exposed to. A gap analysis identifies, given that exposure, where the program falls short of what is required. The risk assessment scopes the gap analysis: the analysis measures most closely where the institution is most exposed.

When a gap analysis is warranted

A gap analysis is overdue any time the program has materially changed since it was last assessed. The common triggers:

Benchmarks

A gap analysis is only as credible as its benchmark. The program is measured against three layers, in order:

BenchmarkWhat it anchors
The BSA program pillars (31 CFR 1020.210; 31 U.S.C. 5318(h))Internal controls · a designated BSA officer · training · independent testing · customer due diligence and beneficial ownership. The foundational structure every program must have.
The FFIEC BSA/AML Examination ManualHow examiners evaluate each area. It is the interagency supervisory standard against which the program is examined.
The regulations that apply to the institutionThe specific obligations for its products, customers, and jurisdictions, including OFAC sanctions-program expectations. Risk-based: depth follows actual exposure.

Anchoring to these means a finding is not a matter of opinion. It points to a specific expectation the program does not yet meet.

Method

  1. Scope the analysis to the institution's risk. The risk assessment is the starting point. The most testing goes where the institution is most exposed, rather than equal effort across a low-risk corner and the highest-volume product.
  2. Gather the evidence. Policies, procedures (WSPs), training records, prior independent tests, system configurations, sample SARs and alerts. What the program does, not just what it says.
  3. Compare current against required state, area by area. Each pillar and each applicable obligation is walked. For each, the analysis records what is expected, what exists, and the delta.
  4. Test rather than read alone. Samples are pulled. A policy stating that alerts are reviewed in five days is a gap if the queue shows fifteen. Documented compliance and operating compliance are separate claims.
  5. Document each gap specifically. The expectation, the shortfall, the evidence, and the exposure are named. A finding reads "no role-specific training for the fintech partner's onboarding staff since Q3," rather than "training is weak."
  6. Score and prioritize. Each gap is rated on severity and likelihood (below), then sorted.
  7. Build the remediation plan. Every gap is assigned an owner, an action, and a date.

Scoring the gaps

Gaps are scored on two axes, and the score drives the sequence of remediation:

Severity →
Likelihood ↓
Low severityHigh severity
High likelihoodSchedule: fix in the normal cycleRemediate first: material exposure, likely to surface
Low likelihoodMonitor: document and revisitPlan: high impact if it lands, mitigate deliberately

Where the data supports it, the exposure is priced in dollars: the cost of the likely enforcement outcome, the remediation, or the delayed launch. A gap rated "high" states a severity. A gap stated as "$400k of exposure and a blocked product launch" states the same severity in terms an executive can act on when allocating budget.

From findings to a remediation plan

Treating the analysis itself as the deliverable is a recurring failure mode. The operative deliverable is the remediation plan the analysis feeds: each gap mapped to an owner, an action, a due date, and a status tracked to closure. Open findings from the last cycle are among the first items an examiner reviews. A plan that closes its own gaps is itself evidence of a functioning program.

Common failure modes

Pre-start checklist

Common questions

What is an AML gap analysis?
A structured comparison of a BSA/AML program as it actually operates against the standard it should meet: the BSA program pillars, the FFIEC examination manual, and the regulations that apply to the institution. It identifies where the program falls short, rates the severity of each gap, and produces a prioritized list of what to fix.
When does a company need an AML gap analysis?
Common triggers: launching a new product or entering a new customer segment, preparing for or responding to an exam, onboarding with a sponsor bank, a merger or acquisition, entering a new registration category, a regulatory change, or simply that it's been a year. A program that has materially changed since its last assessment is overdue.
What is an AML program measured against?
The BSA program pillars (internal controls, a designated BSA officer, training, independent testing, and CDD / beneficial ownership), the FFIEC BSA/AML Examination Manual, and the specific regulations that apply to the institution's products and jurisdictions, including OFAC sanctions-program expectations. The analysis is risk-based.
How are identified gaps prioritized?
Each gap is scored on severity (regulatory and financial exposure if unaddressed) and likelihood (how probable it is to cause a problem given current activity). High-severity, high-likelihood gaps come first. Pricing exposure in dollars turns an abstract finding into a fundable business decision.
Why do most AML gap analyses go stale?
Because they're delivered as a static document, accurate the day it ships and out of date the moment a product launches, a regulation changes, or a finding is partially fixed. A gap analysis holds value only if it's tied to a living remediation plan with owners and dates, and re-run when the program changes.
About this library

This reference library is maintained by Rupture Labs, the company behind Compliance Command Center, compliance software built and reviewed by practitioners. Contact.

Primary sources

The authoritative texts this guide is grounded in. Government sites may block automated access but resolve in a browser.