2026-01-28 · Field notes
Building an AML sample that survives scrutiny
How to choose customer due diligence and alert samples so testing reflects real risk rather than convenience.
Convenience samples—the easiest twenty files in the shared drive—tell a comforting story and a false one. Risk-based sampling for fintech AML work should deliberately include borderline cases, high-value transfers, and accounts that triggered more than one alert in the review period.
Document why each case entered the sample. A one-line rationale (“cross-border remittance above threshold”) helps later when management asks why a clean retail wallet was skipped. Auditors reading your working papers will look for that rationale first.
Separate design testing from operating effectiveness. Confirming that a CDD checklist exists is not the same as confirming staff completed it before the account went live. Both layers belong in an AML control assessment.
Escalate thoughtfully. If your sample turns up a pattern—missing source-of-funds notes on a particular product—widen the sample rather than burying the finding. Narrow fixes on a single file rarely satisfy a correspondent bank or supervisor.
Close the loop with training evidence. When a finding points to staff habit rather than missing policy text, pair the remediation with attendance records and a short refresher memo dated after the change.
AML sampling controls