Three settings where the review comes up
AML due diligence usually means one of three things. For a financial institution, it is the work of knowing its own customers, including the people who ultimately own or control a business customer, and noticing when activity stops fitting the picture. For a company that depends on banks or payment processors, it is the questionnaire and document requests those partners send, which reflect obligations the partners carry themselves. In a merger or investment, it is a review of the target's program and history, because regulatory problems and gaps in records tend to follow the business after closing. Customers presenting higher risk, by geography, business type, or ownership structure, usually call for enhanced diligence rather than a single checklist.
Where diligence tends to break down
Problems often come from files that were opened properly and never revisited. Ownership changes, a customer's business shifts, or transaction volumes grow beyond what the original profile explained. Another frequent issue is screening that exists on paper but is not tied to how alerts are actually reviewed and closed out. Many banks and money transmitters regulated by New York's Department of Financial Services operate under state transaction monitoring and filtering requirements in addition to federal rules, and examiners look at whether the program works in practice, not only whether it is written down. For fintech and money services businesses, a gap in diligence can cost a banking relationship before any regulator acts. Keep your policies, the risk assessment behind them, and examples of how real cases were handled, because that record is what reviewers ask for.
Scoping the work with us
The first step is identifying who is asking and why, since a bank's onboarding request, a regulator's examination, and an acquisition review call for different responses. We look at the documents you have, the customer base and products involved, and any history of account closures, inquiries, or suspicious activity concerns. Suspicious activity reports are confidential by law, so certain questions about them cannot be answered by a bank and should not be asked of one. From there we decide whether you need a targeted response to a request, a gap review of an existing program, or diligence findings that feed into deal terms such as representations, indemnities, or conditions to closing.