Cherry Bekaert: Risk & Cybersecurity · Cherry Bekaert

Anti-Money Laundering – Part 2 Testing & Monitoring

·24 min·1 clip
Sam says banks should use alert dispositions to fine-tune thresholds and run incremental parameter changes.
1. Cherry Bekaert’s Risk and Accounting Advisory Podcast episode covers AML model testing, monitoring, and optimization. 2. Nate Regimbaugh hosts Sam Halaby and Dan Gallagher, who lead Cherry Bekaert’s Risk and Data Analytics practice and Information Assurance and Cybersecurity practice. 3. The episode asks how banks should test AML models, validate alerts, and keep monitoring current business activity. 4. Dan Gallagher says model testing has two phases: initial setup and model validation. 5. He says the initial setup should fit the institution’s specific risk profile, use the vendor closely, and compare manual monitoring with the AML model. 6. Dan recommends pre- and post-implementation reviews so the model and rules are set correctly from the beginning. 7. He says model validation is normally done around the six-month time frame and again after mergers, new product introductions, or system conversions. 8. Dan separates validation into data imported from core banking or feeder systems and the alert rule setup and output. 9. He says data validation should check transaction mapping, aggregate accuracy, and whether all relevant transactions are present. 10. Dan notes that some items such as fees or ACH pre-notifications may not be treated as true transactions in the mapping. 11. He says alert validation should confirm that the rule setup matches the institution’s size, risk, and fiscal aggregation. 12. Dan adds that reviewers should examine alert output over an extended period, sample alert reviews, case notes, and procedures for changing alerts. 13. Sam Halaby says ongoing monitoring has to reconfirm the model’s purpose against current business activity. 14. He uses cannabis banking as an example, saying higher cash transactions may be normal for those customers but abnormal for traditional customers. 15. Sam says many banks choose conservative settings, creating false positives that still need investigation and timely clearing. 16. He says some institutions have SLAs of a set number of days, and missing them can force account closure even when an alert is not suspicious. 17. Sam says periodic reviews should balance accurate detection with reduced false positives, then use statistical methods and alert dispositions to tune thresholds and parameters. 18. He explains that the episode’s tone is practical and technical, with Nate pressing for the “why,” “what,” and “how” of AML controls. 19. Banks, compliance teams, and risk leaders working on AML models would benefit most. 20. Listeners wanting entertainment or light general-business discussion may want to skip it.

As heard by us

A clear, practical look at AML model testing, with threshold tuning and governance kept in balance.

AML model testing is treated as a practical exercise in validation and optimization, with the work split between initial setup and model validation.

Read the full review in PlayNext →

Why you'd press play

Press play if you need a cleaner AML model test plan without losing alert quality.

Read the full recommendation in PlayNext →
Listen to the show on