A training needs assessment is the method for deciding who receives BSA/AML training, on what topics, and at what depth. 31 CFR 1020.210(b)(4) requires training for appropriate personnel, tied to the people whose duties require knowledge of the program, and the FFIEC exam procedure opens this pillar by asking whether every person whose duties require BSA/AML knowledge is covered by it. The assessment maps each role to the obligations, red flags, and procedures it touches, scores how much responsibility that role carries for each one, and uses the score to set both the training depth and the refresh cadence. Depth varies by role rather than being uniform across the institution. The scoping decision is recorded in its own document, which is the record an examiner reviews at this pillar.
A training needs assessment is the documented method by which an institution decides who receives BSA/AML training, on which topics, and at what depth. It maps each role to the obligations, red flags, and procedures that role's work intersects, scores the responsibility the role carries for each, and derives training depth and refresh frequency from that score. It is the scoping decision behind the training pillar rather than the training content itself.
The training procedure in the FFIEC BSA/AML Examination Manual does not open by asking whether training occurred. It opens by asking who was in scope to receive it and how that population was determined. A program with a matrix and a written rationale answers that question with evidence; a program with a completion headcount does not.
This guide sets out the method: the regulatory basis for scoping and the failure pattern examiners find first, how a role-to-obligation matrix is built, with a worked example, how the score sets proportional depth, when the assessment is redone, and how it is documented so the scoping is traceable at examination.
The regulatory basis for scoping, and the ad-hoc failure pattern
31 CFR 1020.210(b)(4) requires an anti-money-laundering program to provide training for appropriate personnel, and it ties that training to the persons whose duties require knowledge of the program. The regulation does not say train everyone the same amount. It says train the people whose duties require it, at the depth their duties require. The FFIEC BSA/AML Examination Manual's training procedures open with a scoping question: has the institution identified all personnel whose duties require knowledge of the BSA, and does the training reach them. That is the floor element, tested before the manual asks anything about content quality or delivery format.
Ad-hoc scoping has a recognizable shape. A new hire is assigned whatever course sits next to their job title in the learning system, a pairing chosen once by whoever set up that title and never revisited. A product launches and training gets added to the list of things nobody remembered to ask about. The board receives an annual briefing built the same way it was built three years ago, because nobody owns the question of whether it is still the right briefing. In each case the training occurred. What is absent is the reasoning for who was in scope and why, and that reasoning is what an examiner requests.
The corrective is a documented method for deciding who receives what, together with a rationale that a person other than its author can explain.
The role-to-obligation matrix method
The method begins from the job rather than the course catalog. For every role that touches the BSA/AML program, the assessment lists the obligations, red flags, and procedures that role's work intersects: the account-opening red flags a frontline analyst is positioned to see, the typology analysis an EDD investigator has to perform, the alert-handling procedures an operations lead executes, the AML risk a new product introduces before a product manager ships it, the oversight duties a board member is legally responsible for.
Each role is scored against each topic on a consistent scale rather than by estimate. A practical rubric scores seven dimensions of responsibility, from 0 (no exposure) to 4 (owns and teaches the procedure): does the role need basic knowledge that the obligation exists; does the role need to identify when a subject or transaction is in scope; does the role need to understand the process end to end; does the role take action on it directly; does the role escalate it; does the role write or maintain the procedure; and does the role train others on it. A frontline analyst who spots red flags and escalates them scores high on identification and escalation and low on procedure-writing. An EDD investigator who builds the typology playbook scores high across nearly every dimension. The rubric converts an impression that a role needs more training into a score that can be defended.
A worked example, scored on the representative topic each role is most exposed to:
| Role | Representative topic | Rubric score | Required depth | Refresh cadence |
|---|---|---|---|---|
| Frontline onboarding analyst | Red flags at account opening | 3 | Module + knowledge check + case study | Annual |
| EDD investigator | Typology analysis for escalated accounts | 4 | Module + case study + simulation + exam | Semi-annual |
| Operations team lead | Alert-queue procedures and escalation | 2 | Module + knowledge check | Annual |
| Product manager | New-product AML risk review | 2 | Module + knowledge check | Annual, plus on every launch |
| Board member | Program oversight and consequences of failure | 1 | Module only, briefing format | Annual |
The pattern across the rows carries as much information as the individual scores. The EDD investigator scores highest because that role identifies, acts on, escalates, and effectively writes the reasoning that supports a SAR, so the training has to demonstrate the role can perform all of it under exam conditions, which is what the simulation and exam test. The board scores lowest not because oversight is unimportant but because a board member's function is to exercise judgment on program-level information rather than to execute a procedure, so the training takes a briefing format rather than a workflow format. The operations lead and the product manager land in the middle for different reasons: one repeats a defined procedure often, the other touches AML risk only at discrete moments, and the matrix records both facts at the same numeric tier without treating the two roles as identical.
Proportional depth: how the score sets training format
The score sets the depth of the training and the frequency with which it repeats. A role that scores low on a topic receives the module: enough to recognize the obligation and identify the escalation point. A role that scores in the middle receives the module plus a knowledge check, which gives the program evidence that the material was absorbed rather than only opened. A role that scores high receives the module, a case study or applied content, and, in the highest-exposure roles, a simulation and an exam, in proportion to the consequences of an error by that role.
The logic mirrors the risk-based approach the training itself covers. A risk-based BSA/AML program does not apply identical controls to a low-risk retail customer and a high-risk correspondent relationship, and the same reasoning applies to a role that files SARs and a role that never touches one. Uniform training across every role functions as a flat control that ignores risk, and examiners assess it on that basis.
The failure mode runs in both directions. Under-scoping a high-exposure role leaves a genuine gap. Over-scoping every role to the deepest tier substitutes volume for risk differentiation and consumes hours a small compliance team has to allocate elsewhere.
Refresh triggers: calendar and event-driven
The cadence derives from the score as well. Annual refresh is a reasonable floor for most scored roles. Roles that score at the top of the rubric, the ones closest to filing and to the highest-risk typologies, are commonly placed on a semi-annual cycle, because the material they retain changes faster than a year allows.
The calendar alone does not capture every change. Three events trigger training outside the regular cycle regardless of where the annual calendar sits: a procedure change material enough to affect what the role does, an exam or audit finding that names a gap in a role's knowledge, and a new product or customer segment that introduces risk no one in that role has been trained on. The interval between a product launch and the next annual cycle can run for months, and it is a recurring source of findings. The rule that closes it is that a material change triggers training rather than waiting for the calendar.
Documenting the assessment
The matrix functions as evidence in its own right, not only as an input to evidence. The role list, the topics, the scores, the rationale behind each score, and the date the assessment was last run are held in a document that can be handed to an examiner or to a new BSA officer without reconstruction from memory. The document is versioned: where a role's score changes, or a role is added to or dropped from scope, the record notes the reason and the date.
- Full role inventory, every job function in scope, not just the ones that come to mind first.
- Topic-by-topic scores against the rubric, for each role, current as of the last run.
- The rationale behind each score, written in enough detail that someone who did not build the matrix can defend it.
- Resulting training depth and cadence mapped from the score, so the link between scope and content is traceable.
- A version history showing when scores changed and what triggered the change.
The record is what answers an examiner who asks why the frontline team receives less training than the investigations team, or why a role that appears high-risk is scored lower than expected. The answer is the rationale written at the time the scoping decision was made, held in the same file as the training records it supports.
The training needs assessment is the structural component of the training pillar: a document with an owner, a method, and a date, from which the delivered training derives. Training built on that basis is traceable to a stated reason for the scope it covers.