An AML gap analysis compares a BSA/AML program as it actually runs against the standard it is required to meet: the program pillars, the FFIEC BSA/AML Examination Manual, and the regulations that apply to the institution. It rates each shortfall and orders what to fix. Its output is a prioritized remediation plan with named owners and dates. A gap analysis delivered as a standalone document, and not tied to a remediation plan that is tracked and updated, becomes inaccurate as the program changes.
An AML gap analysis is a structured comparison of a BSA/AML compliance program as it actually operates against the standard it should meet: the BSA program pillars at 31 CFR 1020.210 and 31 U.S.C. 5318(h), the FFIEC BSA/AML Examination Manual, and the regulations that apply to the institution. It identifies where the program falls short, rates the severity of each shortfall, and produces an ordered list of what to remediate.
This article sets out what a gap analysis is, when an institution needs one, what to measure against, the step-by-step method, how to score findings, and how findings become a remediation plan.
Definition and distinction from a risk assessment
A gap analysis is a structured comparison: current state (how the program operates today, in practice, not on paper) versus required state (what the law, guidance, and the institution's risk profile demand). The output is a list of gaps, each rated by severity, with a path to close it.
A gap analysis is distinct from a risk assessment. A risk assessment identifies what the institution is exposed to. A gap analysis identifies, given that exposure, where the program falls short of what is required. The risk assessment scopes the gap analysis: the analysis measures most closely where the institution is most exposed.
When a gap analysis is warranted
A gap analysis is overdue any time the program has materially changed since it was last assessed. The common triggers:
- Launching a new product or entering a new customer segment that changes the institution's risk profile.
- Preparing for an exam, or responding to one that produced findings.
- Onboarding with a sponsor bank that needs to see a defensible program before it will carry the institution.
- A merger or acquisition that joins two programs of different maturity.
- A new registration category (e.g., money transmitter licensing) with its own obligations.
- A regulatory change that shifts what's required.
- Time. A year has passed since the last assessment and existing practice has gone unexamined.
Benchmarks
A gap analysis is only as credible as its benchmark. The program is measured against three layers, in order:
| Benchmark | What it anchors |
|---|---|
| The BSA program pillars (31 CFR 1020.210; 31 U.S.C. 5318(h)) | Internal controls · a designated BSA officer · training · independent testing · customer due diligence and beneficial ownership. The foundational structure every program must have. |
| The FFIEC BSA/AML Examination Manual | How examiners evaluate each area. It is the interagency supervisory standard against which the program is examined. |
| The regulations that apply to the institution | The specific obligations for its products, customers, and jurisdictions, including OFAC sanctions-program expectations. Risk-based: depth follows actual exposure. |
Anchoring to these means a finding is not a matter of opinion. It points to a specific expectation the program does not yet meet.
Method
- Scope the analysis to the institution's risk. The risk assessment is the starting point. The most testing goes where the institution is most exposed, rather than equal effort across a low-risk corner and the highest-volume product.
- Gather the evidence. Policies, procedures (WSPs), training records, prior independent tests, system configurations, sample SARs and alerts. What the program does, not just what it says.
- Compare current against required state, area by area. Each pillar and each applicable obligation is walked. For each, the analysis records what is expected, what exists, and the delta.
- Test rather than read alone. Samples are pulled. A policy stating that alerts are reviewed in five days is a gap if the queue shows fifteen. Documented compliance and operating compliance are separate claims.
- Document each gap specifically. The expectation, the shortfall, the evidence, and the exposure are named. A finding reads "no role-specific training for the fintech partner's onboarding staff since Q3," rather than "training is weak."
- Score and prioritize. Each gap is rated on severity and likelihood (below), then sorted.
- Build the remediation plan. Every gap is assigned an owner, an action, and a date.
Scoring the gaps
Gaps are scored on two axes, and the score drives the sequence of remediation:
| Severity → Likelihood ↓ | Low severity | High severity |
|---|---|---|
| High likelihood | Schedule: fix in the normal cycle | Remediate first: material exposure, likely to surface |
| Low likelihood | Monitor: document and revisit | Plan: high impact if it lands, mitigate deliberately |
Where the data supports it, the exposure is priced in dollars: the cost of the likely enforcement outcome, the remediation, or the delayed launch. A gap rated "high" states a severity. A gap stated as "$400k of exposure and a blocked product launch" states the same severity in terms an executive can act on when allocating budget.
From findings to a remediation plan
Treating the analysis itself as the deliverable is a recurring failure mode. The operative deliverable is the remediation plan the analysis feeds: each gap mapped to an owner, an action, a due date, and a status tracked to closure. Open findings from the last cycle are among the first items an examiner reviews. A plan that closes its own gaps is itself evidence of a functioning program.
Common failure modes
- The analysis is a static document. Accurate the day it ships, inaccurate once a product launches or a rule changes.
- It scores against generic best practice instead of the institution's actual obligations and risk.
- It stops at findings and never becomes an owned, dated plan.
- It is never re-run. A gap analysis is a snapshot of a program that continues to change. Its value depends on repeating it when the program changes.
Pre-start checklist
- The scope is driven by a current risk assessment.
- The benchmark is explicit: pillars, FFIEC manual, applicable regulations.
- The analysis tests what the program does, not only what it says.
- Each gap is documented with the expectation, shortfall, evidence, and exposure.
- Gaps are scored on severity and likelihood, priced in dollars where possible.
- Every gap has an owner, an action, and a date.
- There is a plan to re-run the analysis when the program materially changes.