Skip to content
Reference

AML Look-Back Reviews: Transaction and SAR Look-Backs Explained

The short version

A look-back review is a retrospective examination of an institution's past transactions, alerts or suspicious activity decisions over a defined period, performed to find reportable activity that was missed or mishandled and to file or correct suspicious activity reports (SARs). Look-backs are usually required by a supervisory action or undertaken after a monitoring failure is discovered. The accepted method, reflected in OCC Bulletin 2013-33 and the FFIEC BSA/AML Examination Manual, sets the period and population from the failure, re-runs corrected monitoring logic or re-reviews past alerts (or both), uses a reviewer independent of the functions under review, and ends in a written report and any late SAR filings.

An AML look-back review is a retrospective review of a financial institution's historical transaction activity, monitoring alerts or SAR decisions over a defined past period, carried out to identify suspicious activity that should have been reported and was not, and to correct reports that were filed inaccurately. The term covers two related exercises: a transaction look-back, which re-examines the underlying activity, and a SAR look-back, which re-examines the institution's past decisions to file or not to file. The Office of the Comptroller of the Currency describes both in OCC Bulletin 2013-33, "Use and Review of Independent Consultants in Enforcement Actions," which notes that the OCC has required independent consultants to review transaction activity to determine whether SARs must be filed, whether filed SARs need to be corrected or amended, or whether additional SARs should be filed for continuing activity.

Legal basis

The obligation a look-back remediates is the SAR requirement. For banks, 31 CFR 1020.320 requires a SAR for reportable suspicious transactions and sets the filing deadline at no later than 30 calendar days after initial detection of facts that may constitute a basis for filing, extendable by up to 30 further days (60 days in total) when no suspect has been identified (31 CFR 1020.320(b)(3)). The same section requires retention of each SAR and its supporting documentation for five years from the date of filing (31 CFR 1020.320(d)). Parallel SAR rules apply to other institution types, such as money services businesses under 31 CFR 1022.320.

A look-back exists because an institution's monitoring, alert handling or decisioning failed to meet that obligation for some period. The underlying program duty is the requirement to maintain an anti-money laundering program with internal controls reasonably designed to assure compliance (31 U.S.C. 5318(h); 31 CFR 1020.210).

What triggers a look-back

Setting the scope and period

Scope is set from the failure being remediated. Where a look-back is required by an enforcement action, the order or the agency's review of the engagement letter usually fixes the period and population; OCC Bulletin 2013-33 states that the OCC reviews the engagement contract to determine whether the scope, resources and timeline are consistent with the enforcement action. Where the institution scopes the review itself, the accepted reasoning follows the defect:

The scope document records each of these decisions with its rationale, because the regulator reviewing the look-back will test whether the period and population match the failure.

Methods: re-running logic and re-reviewing alerts

Two methods are used, alone or together, depending on what failed.

MethodWhen it fitsWhat it involves
Re-running monitoring logicActivity was never monitored, or monitored with defective scenarios, thresholds or data.Correcting the data and scenario logic, running it against the historical population, and investigating the alerts it generates as if they had been produced at the time.
Re-reviewing alerts and casesAlerts were generated but closed inadequately, or SAR decisions were unsupported.Re-investigating past alerts and cases, fully or by sample, against the institution's own procedures and regulatory expectations, and recording a new decision for each.
Re-reviewing filed SARsSARs were late, incomplete or inaccurate.Testing filed SARs for timeliness and completeness, and filing corrected or amended reports where required.

Re-running logic requires the same data-quality discipline as a new monitoring implementation. New York's Part 504 rule, which applies to institutions regulated by the Department of Financial Services, requires end-to-end, pre- and post-implementation testing of a transaction monitoring program, including data mapping, transaction coding, detection scenario logic, model validation, data input and program output (3 NYCRR 504.3). Those elements are a practical checklist for a re-run, because a look-back run on incomplete data repeats the original defect.

Re-review of alerts is usually tested against the monitoring and investigation components the FFIEC manual describes in its suspicious activity reporting procedures and Appendix S, "Key Suspicious Activity Monitoring Components": identification of unusual activity, alert management, research, SAR decision-making, SAR completion and filing, and monitoring of continuing activity. Where the population is re-reviewed by sample rather than in full, the sampling method and the basis for any extrapolation are documented, following the approach in the reference on control testing methods.

Filing during the look-back

When a look-back identifies reportable activity, the institution files the SAR. FinCEN's SAR form includes fields for amended and corrected filings. The investigation record for a late filing documents when the activity occurred, when the look-back identified it, and the basis for the filing decision, since the 30-day clock in 31 CFR 1020.320(b)(3) runs from the date of initial detection. Where the look-back surfaces activity that requires immediate attention, such as an ongoing money laundering scheme, the same section requires the institution to notify an appropriate law enforcement authority by telephone in addition to filing a timely SAR.

Independence of the reviewer

A look-back tests work the institution already performed, so the reviewer is expected to be independent of that work. OCC Bulletin 2013-33 sets out the agency's expectations for independent consultants in enforcement actions:

The bulletin also states that using an independent consultant does not relieve the bank's management or board of responsibility for identifying and implementing the needed corrective actions. The same independence principle applies to voluntary look-backs: the staff whose alert decisions are under review do not grade their own decisions. The BSA/AML independent testing reference describes the parallel independence standard for the program's periodic review.

Deliverables

  1. Engagement letter and work plan: scope, period, population, methods, sampling approach, staffing and timeline.
  2. Population reconciliation: evidence that the reviewed population is complete against source systems.
  3. Case-level workpapers: for each alert or case, the evidence reviewed, the analysis, the decision and the reviewer.
  4. SAR filings: a log of SARs filed, corrected or amended as a result of the review, with filing dates.
  5. Findings on root cause: the control failures that allowed the missed activity, which feed the remediation plan.
  6. Final report: OCC Bulletin 2013-33 describes a final written report of findings and recommendations to the bank's board of directors, with supporting documentation available to the OCC.

A look-back addresses past activity; it does not by itself correct the monitoring or decisioning defect that caused it. The corrective actions it identifies are tracked to closure and validated, as described in the reference on compliance remediation and issue management.

Primary sources

Common questions

What is an AML look-back review?
It is a retrospective review of an institution's past transactions, alerts or suspicious activity decisions over a defined period, performed to find reportable activity that was missed or mishandled and to file or correct SARs. OCC Bulletin 2013-33 describes look-backs performed by independent consultants in enforcement actions.
What triggers a look-back?
Common triggers are a supervisory or enforcement action that requires one, discovery of a monitoring defect such as a missing data feed or misconfigured scenario, an alert backlog or unsupported alert closures, and specific events such as a law enforcement inquiry.
How is the look-back period set?
The period normally runs from the date the defect began to the date it was corrected, and the population covers the customers, products and transactions the defect affected. Where an enforcement action requires the look-back, the order or the agency's review of the engagement terms usually fixes the scope.
Who can perform a look-back?
A reviewer independent of the work under review, with the expertise and resources to complete it. In enforcement settings, OCC Bulletin 2013-33 sets expectations for independent consultants, including objectivity, disclosure of prior work for the bank, and agency access to workpapers.
Are SARs identified in a look-back filed late?
They are filed when identified, and the investigation record documents when the activity occurred and when it was detected. Under 31 CFR 1020.320(b)(3), the filing deadline is 30 calendar days after initial detection, extendable to 60 days where no suspect is identified.
About this library

This reference library is maintained by Rupture Labs. We perform BSA/AML independent testing and automated control testing against every record, with each requirement cited to its rule. Talk to a practitioner.