skills/legal/aml-compliance-program/SKILL.md
Drafts board-ready Anti-Money Laundering compliance programs for U.S. financial institutions under BSA/FinCEN requirements. Covers CIP, CDD, EDD, SAR/CTR reporting, OFAC screening, risk assessment, training, independent testing, and governance structures. Use when creating or updating AML policies, BSA compliance programs, or financial institution regulatory documentation. Trigger keywords: AML, BSA, FinCEN, Bank Secrecy Act, anti-money laundering, SAR, CTR, OFAC, CIP, CDD, KYC, compliance program.
npx skillsauth add casemark/skills aml-compliance-programInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Produces a comprehensive, board-ready AML compliance program tailored to a financial institution's risk profile, satisfying BSA, FinCEN, and federal/state requirements.
Before drafting, collect from the user:
Do not proceed until items 1–2 are addressed. Items 3–4 may be developed during drafting if unavailable.
Draft a numbered policy document covering all sections below. Calibrate depth to the institution's size, complexity, and risk profile.
| Element | Requirement | |---|---| | Board endorsement | Explicit board/senior management approval and oversight | | Scope | All business lines, customer relationships, geographies, transaction types | | Risk-based approach | Controls calibrated to risk assessment findings | | Resource commitment | Adequate personnel, technology, budget |
| Element | Requirement | |---|---| | Qualifications | CAMS or equivalent; demonstrated BSA/AML expertise | | Reporting line | Direct to senior management; regular board access | | Independence | Evaluation tied to compliance effectiveness, not production | | Authority | Unrestricted access to all records, systems, personnel |
Core duties: Regulatory contact (FinCEN, regulators, law enforcement) · SAR/CTR/BSA filing oversight · risk assessment coordination · training management · independent testing oversight · program design and updates.
Per 31 CFR § 1020.220:
| Data Point | Individual | Legal Entity | |---|---|---| | Full legal name | Required | Required | | Date of birth | Required | N/A | | Address | Residential/business street | Principal place of business | | ID number | SSN/TIN or passport + country | EIN or equivalent |
Verification: Documentary (government ID / incorporation docs) · Non-documentary (consumer reporting, public databases) · Non-face-to-face (additional measures for remote channels).
Retention: 5 years after account closure.
Per 31 CFR § 1010.230:
Mandatory EDD triggers:
| Category | Examples | |---|---| | PEPs | Per FinCEN guidance | | High-risk geographies | FATF high-risk/monitored jurisdictions | | Complex ownership | Opaque structures obscuring beneficial ownership | | High-risk businesses | MSBs, virtual currency exchanges, cash-intensive | | Elevated risk rating | Multiple risk factors per internal methodology |
Requirements: Background investigation · senior management approval · enhanced monitoring (lower thresholds, more frequent reviews) · documented risk rating methodology (customer × geography × product × activity).
Per 31 CFR § 1020.320:
Per 31 CFR §§ 1010.310, 1020.310:
| Element | Requirement | |---|---| | Threshold | Currency transactions > $10,000 per person per business day | | Aggregation | Multiple transactions by/on behalf of same person in one day | | Filing deadline | 15 calendar days via BSA E-Filing | | Currency | Coin and paper money only (excludes cashier's checks, money orders) |
Exemptions (31 CFR § 1020.315): Banks, government entities, listed public companies, qualifying businesses. Require documentation, approval, biennial renewal, annual review.
| Trigger | Timing | |---|---| | Account opening | Before relationship established | | Existing customers | Minimum annually; risk-based frequency | | Transactions (wires, ACH) | Real-time or near real-time |
Lists: SDN, Consolidated Sanctions, country-based programs.
Actions:
Retention: All screening records ≥ 5 years.
| Dimension | Factors | |---|---| | Products/services | Velocity, geographic reach, anonymity, abuse susceptibility | | Customers | Type, occupation, geography, relationship characteristics | | Entities | Ownership structure, business purpose, formation jurisdiction | | Geography | Physical presence, customer concentrations, FATF/State Dept. flags |
Assess inherent (pre-controls) and residual (post-controls) risk. Conduct annually minimum or upon significant changes. Findings drive CDD intensity, monitoring sensitivity, and resource allocation.
| Audience | Timing | |---|---| | All employees/officers/directors | Annual minimum | | New hires | Within 30 days or before customer-facing duties | | High-risk positions | Role-specific schedule with specialized content |
Core curriculum: Institution AML policies · BSA/PATRIOT Act/FinCEN/OFAC · ML/TF typologies · red flags · CIP/CDD procedures · reporting obligations.
Documentation: Attendance records, completion certificates, comprehension assessments.
| Element | Standard | |---|---| | Independence | Personnel independent of AML function | | Frequency | 12–18 months; higher-risk more frequent | | Reporting | Findings to Compliance Officer, management, board |
Scope: Regulatory compliance · policy adequacy · risk assessment methodology · transaction monitoring effectiveness · training adequacy · SAR/CTR timeliness · CIP/CDD compliance · OFAC procedures.
Remediation: Management response required; action plans with timelines; follow-up verification.
Board duties: Approve program and updates · review risk assessment · receive quarterly compliance reports · review testing results · allocate resources.
Quarterly metrics: SAR/CTR activity, OFAC screening, CDD/EDD activities, training completion, testing findings, regulatory developments.
Change management: Document rationale → compliance + legal review → management/board approval → communicate to personnel → maintain version history.
| Record Type | Retention | |---|---| | SARs + supporting docs | 5 years from filing | | CTRs + supporting docs | 5 years from filing | | CIP/CDD/beneficial ownership | 5 years after account closure | | OFAC screening/blocking | 5 years minimum | | Risk assessments, testing, training | 5 years minimum |
Organized for prompt retrieval upon regulatory request. Security controls and audit trails for SAR-related records.
After delivering the draft, ask the user:
tools
Audits the complete in-scope medical-record universe in a litigation matter and produces an attorney-facing, Bates-cited analysis of treatment gaps, missing records or providers, baseline coverage, material billing or production mismatches, and complaint evolution. Use when asked to find missing medical records, analyze treatment gaps or first-care timing, identify absent providers, assess whether a production is complete, or prepare a records-request target list. Use medical-record-chronology instead when the primary request is a chronological clinical narrative.
development
Drafts a legally compliant Private Placement Memorandum for Regulation D offerings (Rule 506(b)/506(c)), covering full disclosure framework including risk factors, capitalization, securities terms, use of proceeds, and investor qualification requirements. Enforces SEC anti-fraud compliance under Section 10(b)/Rule 10b-5, blue sky law considerations, and accredited investor verification under Rule 501. Use this skill when drafting PPMs, offering memorandums, Reg D disclosure documents, or private offering circulars for issuers raising capital from sophisticated investors. Also trigger when the user mentions private placement disclosure, offering memorandum, Reg D fundraising, or accredited investor verification. Even if the user just says "PPM" or "draft our offering memo," use this skill.
data-ai
Generates structured privacy and data protection law briefings across US, EU, UK, and other jurisdictions. Organizes by jurisdiction with compliance deadlines, enforcement actions, and legislative changes. Use when preparing privacy law briefings, compliance updates, regulatory change summaries, or data protection landscape reviews.
testing
Generates structured summaries of prior art references for patent prosecution, validity analysis, and freedom-to-operate assessments. Maps disclosures to claim elements with precise citations. Use when summarizing prior art, analyzing patent landscapes, mapping references to claims, or preparing office action responses.