Cherry Bekaert: Risk & Cybersecurity · Cherry Bekaert

Anti-Money Laundering Validation & Optimization – Part 1

·24 min·1 clip
Audrey McGinnis says AML models must be validated because vendor testing does not cover a bank’s own data and alerts.
1. Cherry Bekaert’s Risk & Cybersecurity episode on anti-money laundering model validation and optimization focuses on AML model validation, data governance, and tuning. 2. Nate Rudgenbaugh is the host and Digital Advisory Leader at Cherry Bekaert, and Audrey McGinnis, Dan Gallagher, and Alan Swan are named as AML authorities. 3. The episode is built around why financial institutions need validation and optimization methodology for AML models instead of relying only on vendor testing. 4. Audrey McGinnis says vendor testing checks the application itself, but institutions must confirm that their own data and alerts are working as intended. 5. Alan Swan describes methodology as a baseline process with documented standards and controls that supports transparency for external stakeholders. 6. The episode says AML validation typically covers transaction monitoring systems, OFAC sanction and watch list screening, customer risk scoring, and sometimes fraud monitoring. 7. The framework discussion cites OCC guidance that calls for conceptual soundness, ongoing monitoring, verification, benchmarking, outcome analysis, and backtesting. 8. Documentation comes up repeatedly, including decision theory, model logic, and master mapping documentation for accurate data input. 9. Alan Swan says institutions should define thresholds, model risk coverage, oversight responsibility, and AML risks tied to customer type, product type, geographic locations, and regulatory risk. 10. Audrey McGinnis explains that OCC 2011 guidance requires segregation of duties, which is difficult for small and mid-sized institutions with limited BSA, AML, IT, and data analytics staff. 11. The regulatory section names the FDIC, FRB, NCUA, and a 2021 Joint Federal Reserve, FDIC, and OCC release as additional guidance sources. 12. The episode also names NYDFS 504, which adds pre- and post-implementation reviews and IT general controls around the AML system environment. 13. Audrey says validation helps institutions avoid missing suspicious activity and avoid overburdening staff with false positives. 14. She also says heavy reliance on AML systems means missed suspicious activity can lead to fines or MRAs. 15. Dan Gallagher says data accuracy starts with capturing data that is relevant to the investigation process and aligned to the organization’s objectives. 16. Dan also says senior management must support data governance and resolve data issues that cannot be reconciled. 17. Alan Swan explains optimization through periodic calibration, data profiling, above-the-below line testing, threshold analysis, regression analysis, and back-testing. 18. The controls section says AML controls govern development, data population, monitoring, calibration, optimization, and validation across the model life cycle. 19. The episode’s style is a structured expert roundtable with short question-and-answer exchanges and practical compliance examples. 20. Listeners interested in bank compliance, AML operations, and model risk management would get the most value, while people looking for light entertainment would probably skip it.

As heard by us

A practical AML control conversation about validation, data governance, and keeping alerts useful.

It treats anti-money laundering model validation as a working control problem: making sure AML systems behave as intended, use relevant data, and stand up to regulatory scrutiny.

Read the full review in PlayNext →

Why you'd press play

If you need AML model validation and optimization guidance, start here.

Read the full recommendation in PlayNext →
Listen to the show on