A look-back review is a retrospective examination of an institution's past transactions, alerts or suspicious activity decisions over a defined period, performed to find reportable activity that was missed or mishandled and to file or correct suspicious activity reports (SARs). Look-backs are usually required by a supervisory action or undertaken after a monitoring failure is discovered. The accepted method, reflected in OCC Bulletin 2013-33 and the FFIEC BSA/AML Examination Manual, sets the period and population from the failure, re-runs corrected monitoring logic or re-reviews past alerts (or both), uses a reviewer independent of the functions under review, and ends in a written report and any late SAR filings.
An AML look-back review is a retrospective review of a financial institution's historical transaction activity, monitoring alerts or SAR decisions over a defined past period, carried out to identify suspicious activity that should have been reported and was not, and to correct reports that were filed inaccurately. The term covers two related exercises: a transaction look-back, which re-examines the underlying activity, and a SAR look-back, which re-examines the institution's past decisions to file or not to file. The Office of the Comptroller of the Currency describes both in OCC Bulletin 2013-33, "Use and Review of Independent Consultants in Enforcement Actions," which notes that the OCC has required independent consultants to review transaction activity to determine whether SARs must be filed, whether filed SARs need to be corrected or amended, or whether additional SARs should be filed for continuing activity.
Legal basis
The obligation a look-back remediates is the SAR requirement. For banks, 31 CFR 1020.320 requires a SAR for reportable suspicious transactions and sets the filing deadline at no later than 30 calendar days after initial detection of facts that may constitute a basis for filing, extendable by up to 30 further days (60 days in total) when no suspect has been identified (31 CFR 1020.320(b)(3)). The same section requires retention of each SAR and its supporting documentation for five years from the date of filing (31 CFR 1020.320(d)). Parallel SAR rules apply to other institution types, such as money services businesses under 31 CFR 1022.320.
A look-back exists because an institution's monitoring, alert handling or decisioning failed to meet that obligation for some period. The underlying program duty is the requirement to maintain an anti-money laundering program with internal controls reasonably designed to assure compliance (31 U.S.C. 5318(h); 31 CFR 1020.210).
What triggers a look-back
- Supervisory or enforcement action. Formal agreements and consent orders issued by federal banking agencies and state regulators have required look-backs as a remedial article, often performed by an independent consultant whose engagement the agency reviews. OCC Bulletin 2013-33 describes the agency's review of the consultant's qualifications, independence and engagement terms in that setting.
- Discovery of a monitoring failure. An institution may find that transactions were not flowing into the monitoring system, that a product or customer segment was excluded, that a scenario was misconfigured, or that thresholds were set without support. Internal audit, independent testing, model validation or an examination may surface the defect.
- Alert-handling or decisioning failure. A backlog of unworked alerts, alerts closed without adequate investigation, or a pattern of unsupported no-file decisions calls the past decisions themselves into question.
- A specific event. A law enforcement inquiry, a subpoena, a correspondent bank's request, or adverse information about a customer can prompt a targeted look-back on the related customers and counterparties.
Setting the scope and period
Scope is set from the failure being remediated. Where a look-back is required by an enforcement action, the order or the agency's review of the engagement letter usually fixes the period and population; OCC Bulletin 2013-33 states that the OCC reviews the engagement contract to determine whether the scope, resources and timeline are consistent with the enforcement action. Where the institution scopes the review itself, the accepted reasoning follows the defect:
- Start date: the date the defect began, such as the date a data feed stopped, a product launched without coverage, or a scenario was changed.
- End date: the date the defect was corrected, so that the look-back closes the gap between failure and fix.
- Population: the customers, accounts, products, channels and transaction types affected by the defect, reconciled to source systems so that the population is complete.
- Risk weighting: where the population is large, a documented rationale for prioritizing higher-risk segments first, consistent with the risk-based approach of the FFIEC BSA/AML Examination Manual.
The scope document records each of these decisions with its rationale, because the regulator reviewing the look-back will test whether the period and population match the failure.
Methods: re-running logic and re-reviewing alerts
Two methods are used, alone or together, depending on what failed.
| Method | When it fits | What it involves |
|---|---|---|
| Re-running monitoring logic | Activity was never monitored, or monitored with defective scenarios, thresholds or data. | Correcting the data and scenario logic, running it against the historical population, and investigating the alerts it generates as if they had been produced at the time. |
| Re-reviewing alerts and cases | Alerts were generated but closed inadequately, or SAR decisions were unsupported. | Re-investigating past alerts and cases, fully or by sample, against the institution's own procedures and regulatory expectations, and recording a new decision for each. |
| Re-reviewing filed SARs | SARs were late, incomplete or inaccurate. | Testing filed SARs for timeliness and completeness, and filing corrected or amended reports where required. |
Re-running logic requires the same data-quality discipline as a new monitoring implementation. New York's Part 504 rule, which applies to institutions regulated by the Department of Financial Services, requires end-to-end, pre- and post-implementation testing of a transaction monitoring program, including data mapping, transaction coding, detection scenario logic, model validation, data input and program output (3 NYCRR 504.3). Those elements are a practical checklist for a re-run, because a look-back run on incomplete data repeats the original defect.
Re-review of alerts is usually tested against the monitoring and investigation components the FFIEC manual describes in its suspicious activity reporting procedures and Appendix S, "Key Suspicious Activity Monitoring Components": identification of unusual activity, alert management, research, SAR decision-making, SAR completion and filing, and monitoring of continuing activity. Where the population is re-reviewed by sample rather than in full, the sampling method and the basis for any extrapolation are documented, following the approach in the reference on control testing methods.
Filing during the look-back
When a look-back identifies reportable activity, the institution files the SAR. FinCEN's SAR form includes fields for amended and corrected filings. The investigation record for a late filing documents when the activity occurred, when the look-back identified it, and the basis for the filing decision, since the 30-day clock in 31 CFR 1020.320(b)(3) runs from the date of initial detection. Where the look-back surfaces activity that requires immediate attention, such as an ongoing money laundering scheme, the same section requires the institution to notify an appropriate law enforcement authority by telephone in addition to filing a timely SAR.
Independence of the reviewer
A look-back tests work the institution already performed, so the reviewer is expected to be independent of that work. OCC Bulletin 2013-33 sets out the agency's expectations for independent consultants in enforcement actions:
- The consultant has the expertise, capacity and resources to complete the engagement.
- The consultant is objective. The bulletin gives, as an example of a direct conflict, a consultant that previously reviewed the transactions to be evaluated in the current review.
- The bank discloses prior work the consultant performed for it, so conflicts can be assessed.
- The consultant's conclusions and recommendations rest on its own independent and expert judgment, although it may consider the bank's views.
- The OCC may examine the consultant's supporting documentation, analyses and workpapers, and material changes to the contract, work plan or staffing require OCC approval in writing.
The bulletin also states that using an independent consultant does not relieve the bank's management or board of responsibility for identifying and implementing the needed corrective actions. The same independence principle applies to voluntary look-backs: the staff whose alert decisions are under review do not grade their own decisions. The BSA/AML independent testing reference describes the parallel independence standard for the program's periodic review.
Deliverables
- Engagement letter and work plan: scope, period, population, methods, sampling approach, staffing and timeline.
- Population reconciliation: evidence that the reviewed population is complete against source systems.
- Case-level workpapers: for each alert or case, the evidence reviewed, the analysis, the decision and the reviewer.
- SAR filings: a log of SARs filed, corrected or amended as a result of the review, with filing dates.
- Findings on root cause: the control failures that allowed the missed activity, which feed the remediation plan.
- Final report: OCC Bulletin 2013-33 describes a final written report of findings and recommendations to the bank's board of directors, with supporting documentation available to the OCC.
A look-back addresses past activity; it does not by itself correct the monitoring or decisioning defect that caused it. The corrective actions it identifies are tracked to closure and validated, as described in the reference on compliance remediation and issue management.
Primary sources
- OCC Bulletin 2013-33, Use and Review of Independent Consultants in Enforcement Actions (November 12, 2013): OCC expectations for consultant qualifications, independence, engagement terms and workpaper access; describes SAR and transaction look-backs.
- 31 CFR 1020.320: SAR requirement for banks: filing within 30 days of initial detection (60 with no suspect identified), immediate notice for ongoing violations, five-year retention.
- 31 U.S.C. 5318(h) and 31 CFR 1020.210: The statutory and regulatory AML program requirement.
- FFIEC BSA/AML Examination Manual, Suspicious Activity Reporting: Examination procedures for monitoring, alert management, SAR decisioning and filing.
- FFIEC BSA/AML Examination Manual, Appendix S: Key Suspicious Activity Monitoring Components: The components of a suspicious activity monitoring and reporting process.
- 3 NYCRR Part 504 (NYDFS): Transaction monitoring and filtering program requirements, including end-to-end pre- and post-implementation testing (504.3) and annual certification (504.4).