Compliance analyst screening questions: BSA/AML, KYC and SAR filings
On this page
- Which compliance seat: BSA/AML, broker-dealer, consumer compliance, or fintech
- Knockout questions
- BSA/AML and KYC questions
- Suspicious activity monitoring and SAR questions
- Regulators and exams
- CAMS and other credentials
- How compliance analyst experience gets overstated
- Scoring rubric and checklist
- Questions people ask
Compliance analyst screening questions need to establish which regulatory program the candidate actually worked in, what their day-to-day tasks were within it, and whether they can describe the mechanics, not just the acronyms. Ask for a specific alert they investigated or a specific report they filed, and what happened next. A resume that says "BSA/AML compliance" can mean reviewing automated transaction alerts under a senior analyst's supervision, or owning suspicious activity investigations from alert to filed report; the interview should make that difference clear.
This page is for financial services compliance roles centered on BSA/AML and KYC. If the order is for someone who independently tests whether the compliance program itself is working, rather than operating inside it day to day, use internal auditor screening questions. For the front-line role that a compliance analyst's monitoring often touches, see bank teller screening questions.
Which compliance seat: BSA/AML, broker-dealer, consumer compliance, or fintech
| Seat | Primary regulator(s) | A question that tests it |
|---|---|---|
| Bank BSA/AML | FinCEN sets the requirements; the OCC, Federal Reserve, FDIC or NCUA supervises depending on charter type | "Which regulator examined your BSA program, and what did an exam actually involve?" |
| Broker-dealer or investment adviser compliance | SEC and FINRA | "Have you worked with FINRA exam requests? What did they typically ask for?" |
| Consumer compliance | Varies by product; often the CFPB or a state regulator, alongside federal banking regulators | "Which consumer protection regulations were you responsible for monitoring?" |
| Fintech / money services business | FinCEN as an MSB, plus state money transmitter regulators | "Was your compliance program built for a bank charter, an MSB registration, or a partner bank relationship?" |
Knockout questions
| Question | What a strong answer sounds like | Red flags |
|---|---|---|
| This role covers [specific program, e.g. transaction monitoring for a community bank]. What has your scope actually included? | A direct, specific answer matched to the order, or an honest statement of a gap. | Claims broad compliance experience with no ability to describe a single specific task. |
| Have you filed SARs yourself, or supported someone else who made the filing decision? | An honest answer about their actual level of authority and experience. | Claims to have filed SARs but cannot describe the process or the 30-day timeline. |
| This role requires a background check and, in some cases, fingerprinting given the regulated environment. Are you comfortable with that? | A plain yes. | Hesitation or an unexplained concern. |
| What transaction monitoring or case management system have you used? | Names a specific system (Actimize, Verafin, NICE Actimize, SAS AML, or a similar platform) and describes a task in it. | Cannot name a system, for a role built around one. |
BSA/AML and KYC questions
The Bank Secrecy Act, administered by FinCEN, requires financial institutions to establish an AML program and file specific reports (as of September 2026). Know Your Customer work centers on the Customer Identification Program requirements at 31 CFR 1020.220: collecting a customer's name, date of birth, address and identification number, verifying identity within a reasonable time, and forming a reasonable belief about who the customer actually is.
-
"Walk me through onboarding a new customer under your CIP procedures."
- Strong answer: describes collecting the required identifying information, verifying it through documentary or non-documentary methods, and what happens when verification fails or raises a flag.
- Red flags: cannot describe what information is actually collected or why identity verification matters.
-
"What is the difference between customer due diligence and enhanced due diligence, and when does a customer move from one to the other?"
- Strong answer: describes standard due diligence as baseline risk assessment at onboarding, and enhanced due diligence as a deeper review triggered by risk factors (certain business types, geographies, or account activity), with ongoing monitoring for both.
- Red flags: treats the two as the same thing, or cannot name a single risk factor that would trigger enhanced review.
-
"Describe investigating a transaction monitoring alert. How do you decide it is a false positive versus something to escalate?"
- Strong answer: describes gathering context (account history, expected activity, prior alerts), comparing the transaction to the customer's known profile, and documenting the reasoning either way.
- Red flags: closes alerts without a documented reason, or escalates everything without triage.
Suspicious activity monitoring and SAR questions
For banks, 31 CFR 1020.320 requires a Suspicious Activity Report for transactions involving or aggregating at least $5,000 where the institution knows, suspects, or has reason to suspect the activity relates to a possible violation of law, filed within 30 calendar days of initial detection (as of September 2026; thresholds and filing rules differ by institution type, so confirm the specifics for the client's business). Ask a candidate to describe the mechanics, not just the acronym.
| Question | What a strong answer sounds like | Red flags |
|---|---|---|
| What is the filing deadline for a SAR once suspicious activity is detected? | 30 calendar days from initial detection, and awareness that the clock starts at detection, not at the transaction date. | No idea of a deadline at all, for a role that files SARs. |
| Describe a SAR narrative you wrote or contributed to. What made it clear to someone reading it later? | Describes writing a factual, specific narrative (who, what, when, how much, why it was suspicious) rather than a vague summary. | Cannot describe the structure or purpose of a SAR narrative. |
| What happens after a SAR is filed? Does the customer get told? | Knows that SAR confidentiality rules prohibit disclosing to the customer that a report was filed. | Suggests it would be fine to mention the filing to the customer. |
Regulators and exams
Ask which regulator actually examined the candidate's program, since the answer reveals both their institution type and how much direct exam exposure they have had. National banks are examined by the OCC, state member banks by the Federal Reserve, state non-member banks by the FDIC, and credit unions by the NCUA, while FinCEN sets BSA requirements across all of them; broker-dealers answer to the SEC and FINRA.
-
"Describe your role during your last regulatory exam. What did the examiners ask you directly?"
- Strong answer: describes being asked to produce specific evidence (a sample of alerts and their disposition, a policy document, training records) and being able to do so.
- Red flags: was never involved in an exam, for a role that clearly expects exam support.
-
"Has your institution ever received an exam finding or a consent order related to BSA/AML? What was your role in remediation, if any?"
- Strong answer: an honest, specific answer, including what changed in the program afterward if they were part of it.
- Red flags: evasive or unable to discuss the topic at all, at an institution where public information suggests it applies.
CAMS and other credentials
ACAMS' Certified Anti-Money Laundering Specialist (CAMS) is widely regarded in financial crime compliance as the field's benchmark credential, tested through a 120-question, 3.5-hour exam covering AML program requirements and practical scenarios (as of September 2026). It is not a legal requirement at most institutions, but it is a strong, checkable signal of depth. Ask whether the candidate holds it or is actively studying for it, and treat its absence as one data point among several rather than a disqualifier for a strong hands-on track record.
How compliance analyst experience gets overstated
- Alert review called investigation ownership. Clearing routine, low-risk alerts under supervision described as independently owning investigations.
- Acronyms without mechanics. BSA, AML, KYC and SAR named fluently with no ability to describe an actual process step.
- Exam presence called exam ownership. Being in the building during an exam described as directly answering examiner questions.
- Filing deadline and thresholds vague. No real number for the SAR filing window or dollar threshold, for a role that files them regularly.
- System listed without a task. A monitoring or case management platform named with no described workflow in it.
Scoring rubric and checklist
Knockouts are pass or fail. Score the rest 0 to 2 each.
Pass or fail
- Compliance seat (BSA/AML, broker-dealer, consumer, fintech) matches or is closely adjacent to the order.
- Can describe an honest, specific level of authority in filing decisions.
- Comfortable with a background check given the regulated environment.
- Has hands-on experience with the required monitoring or case management system.
Scored, 0 to 2 each (10 possible)
- KYC/CIP fluency: can describe real onboarding and due diligence mechanics.
- Investigation process: describes a real alert triage with documented reasoning.
- SAR mechanics: knows the filing deadline, narrative structure, and confidentiality rule.
- Exam exposure: a real, specific example of supporting a regulatory exam.
- Credential and currency: CAMS held or in progress, and current knowledge of the regulations involved.
Send the client a short analyst note with the submittal:
Analyst: [name]
Compliance seat: [BSA/AML / broker-dealer / consumer / fintech], [months], [how recent]
Regulator(s) worked under: [OCC / Fed / FDIC / NCUA / SEC / FINRA / state]
System used: [monitoring/case management platform]
Filing experience: [SARs filed independently / supported filing decisions]
Exam exposure: [described role in a real exam]
Credential: [CAMS - status] / [other]
Candidate's own gap: [e.g. "no enhanced due diligence experience, standard onboarding only"]
Available to start: [date]
A focused compliance screen covers program scope, one investigation story, SAR mechanics, and exam exposure; anything beyond that is worth a second conversation with the client's compliance officer. Interview Signal keeps the transcript on your computer during the call and ticks off each question as it is covered, so the analyst note above is built from what the candidate actually said.
Questions people ask
What is the difference between a compliance analyst and an internal auditor in a bank?
A compliance analyst works inside the ongoing BSA/AML or regulatory program, monitoring transactions, filing reports and keeping policies current. Internal audit independently tests, on a periodic cycle, whether that compliance program is actually working, usually reporting to an audit committee rather than to the compliance department itself. See internal auditor screening questions for that role.
What does KYC actually require a compliance analyst to do?
Know Your Customer work centers on the Customer Identification Program requirements in 31 CFR 1020.220: collecting a customer's name, date of birth, address and identification number, verifying identity within a reasonable time, and forming a reasonable belief about who the customer actually is. Ongoing due diligence adds monitoring the relationship for activity that does not match the customer's stated profile.
What is the dollar threshold for filing a Suspicious Activity Report?
For banks, 31 CFR 1020.320 sets the threshold at transactions involving or aggregating at least $5,000 where the institution knows, suspects, or has reason to suspect the activity is related to a possible violation of law, with a filing deadline of 30 calendar days after initial detection (as of September 2026). Thresholds and specifics can differ by institution type, so confirm against the current regulation for anything beyond a screening conversation.
Is a CAMS certification required for a BSA/AML compliance analyst role?
No, it is not required at most institutions, but ACAMS' Certified Anti-Money Laundering Specialist (CAMS) credential is widely regarded in the field as a strong, verifiable signal of AML knowledge. Ask whether the candidate holds it or is studying for it, without treating its absence as disqualifying for a strong track record.