Legal, Risk & Compliance

How to get hired as an AML analyst in 2026-27

The short answer

To get hired as an AML analyst in 2026-27, show that you have investigated something and written down a decision someone else could defend, use the vocabulary of the one seat you are applying to (transaction monitoring alert triage, sanctions screening adjudication, KYC and enhanced due diligence, or financial intelligence unit investigations), and be ready to pass a fingerprint background check, which is the real gate: no US state licenses AML analysts, but Section 19 of the Federal Deposit Insurance Act bars a person convicted of an offence involving dishonesty, breach of trust or money laundering from working at an FDIC-insured bank without FDIC consent, and federally insured credit unions apply an equivalent rule administered by the NCUA. Most AML analysts arrive from inside a regulated employer (teller or branch, deposit and wire operations, fraud and disputes, onboarding, collections) or from a contract look-back or KYC remediation project, and no law degree, accounting qualification or finance degree is expected. CAMS from ACAMS is the credential recruiters search for by name, and the realistic first credential while you build qualifying experience is a blockchain analytics certification from Chainalysis or TRM Labs, which has historically been free or low cost with no experience requirement. Expect two to four conversations with a BSA officer or financial intelligence unit manager, a timed case review or written narrative exercise that carries more weight than candidates expect, a few weeks of fingerprinting and background processing, and at least one question about what you verify before you put your name on an AI-drafted case narrative.

Licence requiredNone for the title. No US state licenses AML analysts and there is no mandatory exam. Two exceptions worth knowing: an AML seat inside a broker-dealer may require registration on Form U4 through FINRA, and an AML or compliance role at a commercial casino, card club or sportsbook usually requires a gaming registration or licence from the state gaming regulator, which is a real application with its own background investigation and its own timeline. Tribal gaming has a separate commission process.
The real gateThe background check, and it is stricter than most office jobs. Insured banks and credit unions fingerprint, many run credit, and Section 19 of the Federal Deposit Insurance Act prohibits a person convicted of a criminal offence involving dishonesty, breach of trust or money laundering, or who entered a pre-trial diversion for one, from participating in the affairs of an FDIC-insured institution without FDIC consent. Federally insured credit unions apply the parallel rule in Section 205(d) of the Federal Credit Union Act, with NCUA consent. Disclose honestly on the form: an undisclosed item ends the process faster than the item itself.
The credential recruiters search forCAMS, the Certified Anti-Money Laundering Specialist from ACAMS. It appears by name in a large share of postings, usually as preferred rather than required. Eligibility is scored on a points system combining education, work experience and other credentials, so check whether you qualify before you plan around it, and confirm the current eligibility rules, exam format and fees on the ACAMS site rather than from a forum post.
What you can get before you have hoursBlockchain analytics certifications from Chainalysis and TRM Labs are short, respected in financial crime hiring and have historically been free or low cost with no experience requirement. ACAMS also publishes shorter entry level certificates, and the CFCS from the Association of Certified Financial Crime Specialists is a reachable alternative to CAMS. Avoid unaccredited providers selling a generic AML certificate: hiring managers do not recognise them, and listing one signals you could not tell the difference.
DegreeMost postings ask for a bachelor's degree in any field. Criminal justice, finance, accounting, economics, international relations and languages are all common. Credit unions, money services businesses, casinos and crypto firms are the most willing to accept an associate degree plus relevant operations experience. Fluency in a second language, particularly Spanish, Mandarin, Russian, Arabic or Portuguese, is a genuine differentiator, because document review and adverse media searching happen in the customer's language.
Typical first seatLevel 1 transaction monitoring alert triage, or a KYC and customer due diligence analyst role, very often contract to hire through a staffing agency on a remediation or look-back programme. Both count as real financial crime experience, but only if the work includes dispositioning alerts and writing rationales rather than only chasing missing documents.
Realistic time to a first AML seatCommonly a few months to under a year if you already work for a regulated employer and can move internally, which is the fastest route by a wide margin. Roughly a year to eighteen months from cold, where the sequence that works is a contract remediation or KYC project first, a credential second, and a permanent investigations seat third.
PayUse the US Bureau of Labor Statistics Occupational Employment and Wage Statistics rather than any single quoted band. AML analysts are coded inconsistently, most often under SOC 13-1041 Compliance Officers and SOC 13-2054 Financial Risk Specialists, so look at both plus the Credit Intermediation and Related Activities industry rows. For live numbers, read postings in states with pay-transparency posting rules (Colorado, California, New York, Washington and a growing list of others) and ask agency recruiters for the hourly rate on contract roles, which they will tell you directly.

What an AML analyst actually does, and the four jobs hiding in the title

The unit of work is an alert or a case, and the output is a written decision. A system flags activity or a name, you gather the facts, you decide whether the activity is explained or suspicious, and you write down what you reviewed and why you concluded what you concluded. Somebody else samples that writing for quality. That loop is the job at every level: what changes as you move up is how ambiguous the cases are and how much of the write-up is yours to defend.

The title covers at least four distinct jobs, and applying to all of them with the same resume is the most common way to get filtered out. Transaction monitoring triage is queue work against a service level: dispositions per day, a close rationale on each, escalation of the small share that need a deeper look. Investigations, often inside a financial intelligence unit, is where escalated cases land, where enhanced due diligence memos get written and where Suspicious Activity Report narratives are drafted. Sanctions and screening adjudication is a different discipline again: deciding whether a fuzzy name match against the OFAC list is a true match, handling payment screening hits in real time against a payment cut-off, and knowing the difference between blocking and rejecting. KYC and customer due diligence covers onboarding reviews, periodic refresh, beneficial ownership collection and risk rating, and it is the highest-volume entry point.

Behind those four sit the second line and governance seats you should know exist, because they are where the career goes: quality assurance review of other analysts' dispositions, tuning and optimisation of the monitoring scenarios, model validation, and the designated BSA officer role, which is a named accountable position rather than a job title a company invents.

The artefacts are specific, and naming them correctly is most of what makes a candidate sound like an insider. An alert disposition with a documented rationale. A case file. A SAR narrative, structured as who, what, when, where, why and how. A Currency Transaction Report. A response to a 314(a) information request from FinCEN. A 314(b) voluntary information sharing request to another institution. A request for information to a relationship manager or the business. An enhanced due diligence memo on a high-risk customer. A blocked or rejected payment report. A quality assurance exception, and the rebuttal you write when you disagree with it.

The typologies are the vocabulary, and you can learn them from free public sources before anyone pays you. Structuring. Layering through accounts that move money in and straight out. Funnel accounts. Rapid movement of funds with no apparent business purpose. Cash-intensive businesses whose deposits do not match their stated model. Shell and front companies, and nominee or straw ownership. Trade-based money laundering with mispriced invoices. Money mules, including recruited students and romance scam victims. Pig butchering and other investment scams that end in crypto. Human trafficking indicators in third-party payments and hotel spending. Nested correspondent relationships. Elder financial exploitation. Being able to describe three of these in plain language, naming the account behaviour that reveals each one, is the difference between sounding like a reader and sounding like an analyst, because that is the language the interview is actually conducted in.

What actually gates the job

There is no licence, no bar exam and no required degree subject. The gate is the background check, and candidates underestimate it. An insured bank or credit union will fingerprint you and many will pull credit. The statute for banks is Section 19 of the Federal Deposit Insurance Act, which bars a person convicted of a criminal offence involving dishonesty, breach of trust or money laundering, or who has entered a pre-trial diversion for such an offence, from participating in the affairs of an FDIC-insured institution without FDIC consent. Credit unions are not covered by Section 19: the parallel provision is Section 205(d) of the Federal Credit Union Act, and consent comes from the NCUA rather than the FDIC. The FDIC rules set out which minor and older offences are treated as not requiring an application, and the Fair Hiring in Banking Act narrowed what the prohibition reaches, so if you have something on your record the right move is to read the current FDIC text and ask, not to assume you are excluded and not to hope nobody looks.

Credit checks are not about wealth. The concern is leverage: an analyst with unmanageable debt is exactly the person a launderer approaches. A thin file or a recovered history is usually fine. An undisclosed judgement is not, because the failure the employer cares about is the non-disclosure.

Honesty on the application is itself a screening test for this role. The job is attesting to facts in writing. A hiring manager who finds a gap you papered over has all the evidence they need about how you would handle an inconvenient fact in a case file.

Two adjacent licence regimes do exist. An AML role inside a broker-dealer may require registration via Form U4 with FINRA, which carries its own disclosure questions. An AML or compliance role at a commercial casino, card club or sportsbook usually requires a gaming licence or registration from the state regulator, which involves a financial disclosure and can take months, and which the employer will walk you through. Tribal gaming has its own commission process. If you are applying to gaming, ask in the first conversation how long licensing currently takes and whether you can start in a non-licensed capacity meanwhile, because the answer sets your start date.

Immigration status is normally not a barrier at a private institution. Work authorisation is required, but there is no citizenship requirement for a bank AML analyst. Roles supporting federal contracts or requiring a government clearance are a separate category and will say so in the posting.

What does not gate it: a law degree, a CPA, prior law enforcement service, or a finance degree. All four help in specific places and none is expected. The most common background among working AML analysts is internal promotion from somewhere else in the same institution.

The certifications banks screen for, and the order to take them

CAMS is the one that moves a resume. Recruiters type it into a search box, postings name it, and internal promotion cases are easier to make for a certified analyst. Eligibility is scored on a points system combining education, work experience and other credentials, which means a career changer with no financial services experience frequently cannot sit it yet. Check the current eligibility rules, exam format and fee with ACAMS directly, and note that many employers reimburse or pay for it after hire, which is a question to ask at offer stage rather than a bill to pay in advance.

If you cannot sit CAMS yet, the most effective thing you can do is a blockchain analytics certification. Chainalysis and TRM Labs both run certification programmes aimed at investigators that have historically been free or inexpensive, take days rather than months, and require no prior experience. They carry real weight, because crypto exposure is now a line item in most institutions' risk assessments and the supply of analysts who can read a blockchain tracing graph is still thin. Elliptic runs training too. Confirm current availability and cost on the vendor sites before planning around them.

Other credentials worth knowing, roughly in the order they become useful. CFCS from the Association of Certified Financial Crime Specialists is a broader financial crime certification and a reasonable CAMS alternative. CGSS from ACAMS is the sanctions specialisation and is genuinely differentiating if sanctions is your lane. CAMS-FCI and CAMS-Audit are advanced ACAMS credentials for investigators and auditors. The American Bankers Association's CAFP, its certified AML and fraud professional credential, suits people already inside a bank. CFE from the ACFE is the fraud equivalent and is points-gated like CAMS. The International Compliance Association diplomas carry weight outside the US and at international banks. CRCM is a wider bank regulatory compliance credential, not an AML one, so do not substitute it for CAMS on an AML application.

What to avoid: paid certificates from providers nobody in the industry has heard of. The test is whether the acronym appears in job postings. If you cannot find it in a posting, it will not be recognised in an interview.

A certification is not a substitute for a case you can talk about. The interview will move off your credential within two minutes and onto a fact pattern. Treat the certificate as the thing that gets your resume read and the case discussion as the thing that gets you hired.

One more credible signal: a booked exam date. "CAMS, exam scheduled for March" is concrete. "CAMS (in progress)" with no date is read as an intention, and intentions do not survive a recruiter screen.

Where the entry seats actually are in 2026-27

The fastest route into AML is an internal move, and it is not close. Institutions prefer to hire someone who already passed their background check, already knows the core banking system and already understands their products. If you work at a bank, credit union, payment company or insurer in any operational role, your job search starts with your own employer's internal postings and a conversation with the BSA officer.

The adjacent roles that convert well, in rough order of how short the jump is: fraud and disputes analyst, wire and payment operations, deposit operations, account onboarding and documentation, branch or teller roles that already file Currency Transaction Reports, call centre escalations, collections, trade finance operations, correspondent banking operations, underwriting, and insurance claims or special investigations. Each of those involves examining a transaction or a customer against a rule, which is the skill being bought.

From outside, the volume employer is the contract remediation or look-back programme. When an institution has a regulatory finding, it hires analysts in cohorts for six to eighteen months to re-review historic alerts or refresh KYC files. These run through staffing agencies that specialise in banking compliance and through the large consulting firms' financial crime practices, they pay hourly, and they are the most common way career changers get their first financial crime line on a resume. Find them by searching for "look-back", "remediation", "KYC refresh" and "quality control reviewer" rather than for "AML analyst", because that is how the postings are titled. Then use them deliberately: ask in the interview whether you will be dispositioning and writing rationales or only collecting documents, because the first is experience you can sell and the second is data entry with an AML job title.

Beyond banks, the sector is wider than most candidates realise and the smaller employers are less competitive. Credit unions, often with a compliance team of three or four, where you will see the whole programme. Money services businesses, money transmitters and check cashers. Payment processors, and the sponsor-bank oversight teams that supervise fintech programmes. Crypto exchanges and custodians, which hire aggressively for blockchain tracing skills and screen less on pedigree. Broker-dealers and wealth platforms. Life insurers and annuity providers. Casinos, card clubs, tribal gaming and online sportsbooks, which run real AML programmes and get a fraction of the applicants a bank does. Gaming and marketplace platforms. Trade finance. And the public sector: FinCEN, bank examiner tracks at the OCC, FDIC, Federal Reserve and NCUA, state banking and gaming regulators, and investigative support roles.

Vendors are an underrated destination. The companies selling monitoring, screening and blockchain analytics hire people who understand the work for implementation, customer success and investigations roles, and those jobs pay well and move people back into institutions at a higher level later.

Geography still matters for the large back-office programmes even in a partly remote market. Charlotte, Tampa, Jacksonville, Phoenix, Salt Lake City, Dallas, San Antonio, Wilmington, Sioux Falls, Columbus and the New York and New Jersey corridor all host big financial crime operations. Fully remote entry-level AML seats exist but are a smaller share than they were at the start of the decade, partly because large employers have broadly tightened return-to-office expectations and partly because supervision of new analysts and control of case data are easier on site.

One channel most candidates skip: agency recruiters who specialise in financial crime. Tell one of them exactly which seat you want, what you can evidence and what you will accept hourly, and they will put you in front of several employers at once. They are the main channel for the contract work and a significant one for permanent roles.

How hiring runs, and what the interview really tests

The screening order is recruiter, sometimes an assessment, then the hiring manager, then a panel, then background. The recruiter is matching strings: system names, typology words, credential acronyms, years, institution type. The hiring manager is a BSA officer, a financial intelligence unit manager or an AML operations manager, and that conversation decides. The panel usually includes a senior investigator and often someone from quality assurance, whose question is always whether your written work will survive sampling.

Size sets the timeline. A credit union or a small payments firm can run two conversations and decide inside a week. A large bank commonly takes four to six weeks across a screen, an assessment, a panel and a written exercise, and then adds a few more weeks of fingerprinting and background processing. Candidates routinely read that silence as rejection when the file is sitting with the screening vendor. Contract roles through agencies move fastest of all, sometimes a single interview and a start date inside a fortnight.

Assessments are common at high-volume alert triage seats: a timed case review where you are given transaction data and asked to decide, an attention-to-detail test, or a short English writing sample. Take the writing part seriously. The deliverable of this job is prose that a regulator may read years later, and managers weight it accordingly.

Shift reality, because this is not always a nine to five. Payment screening and crypto monitoring run against real-time payment windows, so some employers staff evenings, early mornings and weekends, and offer a shift differential. Alert backlogs produce overtime in bursts. Ask about coverage hours and current backlog in the first conversation rather than discovering them in week two.

Now the interview itself. It tests four things, roughly in this order: can you apply a red flag to a set of facts without jumping to a conclusion, do you escalate under a procedure rather than deciding alone, can you write it down, and will you hold your position when the business pushes back because the customer is profitable.

The fact pattern question is near certain. A customer deposits 9,500 dollars in cash on three consecutive days, just under the long-standing 10,000 dollar Currency Transaction Report threshold. The weak answer is "that is illegal" or "I would file a SAR". The strong answer separates indicator from conclusion: the pattern is consistent with structuring, so you review the customer profile and expected activity, check whether the business legitimately handles that much cash, look at where the money goes next, check for related accounts and prior alerts, document what you reviewed, and escalate for SAR consideration under your institution's procedure. Saying "under my institution's procedure" is not a hedge. The procedure governs, and an analyst who substitutes their memory of a regulation for the written procedure is the risk the function exists to manage.

A small set of facts function as pass or fail, and getting one wrong at the wrong moment ends an otherwise good interview. You never tell a customer that a report has been filed or that they are being reviewed; tipping off is prohibited. You personally do not file: the institution files, following internal escalation and review. SAR filing deadlines run from the date of initial detection of facts that may constitute a basis for filing, not from the date the alert was generated, which is why detection dates are recorded carefully. The long-standing rule gives a window of 30 calendar days, extendable to 60 where no subject has been identified, and the dollar thresholds that trigger a filing differ by institution type, so confirm both against your own procedure and FinCEN's current instructions rather than quoting a number from memory. A Currency Transaction Report is a mandatory report of cash transactions above the threshold and is not an accusation of anything; a SAR is suspicion-based and confidential. Confusing the two is the fastest tell that a candidate has read a blog rather than the FFIEC manual.

Sanctions questions discriminate hard, because the vocabulary is precise. Know that a screening hit is a potential match to be adjudicated, not a finding. Know that blocking and rejecting are different actions with different reporting consequences, and that blocked property must be reported to OFAC within the window set in its reporting regulations and again in an annual report, so look up the current requirement rather than guessing the deadline. Know that OFAC's 50 percent rule means an entity majority-owned by blocked persons is itself treated as blocked even when it is not named on the list. Know that you escalate a likely true match immediately rather than letting a payment settle while you research. If you can also explain why fuzzy matching produces so many false positives (transliteration, name order, common surnames, dates of birth missing from the record) you will sound like someone who has actually worked a screening queue.

The 314(a) versus 314(b) question is a favourite, because it cleanly separates people who have done the work. A 314(a) request comes from FinCEN on behalf of law enforcement, you search your records for the named subjects within the required period, and you report a match without closing the account or telling the customer. 314(b) is voluntary information sharing between enrolled financial institutions, with a safe harbour, used to see the other side of a transaction. Mixing them up is common and memorable.

Escalation questions are hunting two opposite failures: the analyst who sits on something because they are not certain, and the analyst who escalates everything and becomes noise. A good answer names a threshold. "Anything involving a politically exposed person, a possible sanctions nexus, law enforcement contact, an employee of the bank, a human trafficking or child exploitation indicator, or a pattern I cannot explain goes up the same day. Routine false positives I close with a documented rationale, and those are sampled in quality assurance."

Expect a pressure question: a relationship manager tells you the customer is important and the activity is fine, or your own manager tells you to close an alert you think is productive. The answer is not defiance and it is not compliance. You document the information the business gave you, you state your analysis in writing, and you escalate the disagreement through the procedure so that the decision and its owner are both on the record. Saying that out loud is the most senior-sounding thing an entry-level candidate can do.

Finally, ask questions that show you know the shape of the work: how many alerts does an analyst disposition per day, what is the quality assurance sampling rate and the accuracy target, does Level 1 write narratives or only disposition, who owns scenario thresholds and how often are they tuned, how big is the current backlog, and what is the most recent regulatory finding the team is remediating. The last one is sometimes answered carefully, and the way it is answered tells you a lot about the team you would join.

The resume that gets read, and what gets ignored

Put the lane in the top two lines. A resume that opens "transaction monitoring and sanctions alert investigation, SAR narrative drafting, CDD and EDD, Actimize and Fircosoft" gets read. One that opens "detail-oriented compliance professional seeking opportunities" is filtered by the keyword search and skimmed past by the human. Hiring managers are filling one specific seat and they are looking for the word that matches it.

Quantify the work, because volumes are how experience is compared in this field. Alerts dispositioned per day or per week. Cases escalated, and the escalation rate. Number of SAR referrals or narratives drafted. Quality assurance accuracy or pass rate, if you have it, and you should ask for your number before you leave a job. Backlog cleared on a remediation project. Languages used in document review. Average time to close. Four numbers do more than a page of duties.

Here is the hard constraint nobody tells career changers: do not put case content on a resume. SAR confidentiality is a statutory prohibition, not a company policy, and it extends to customer names, account numbers, transaction specifics, screenshots and anything that would reveal the existence of a filing. Write "drafted SAR narratives on suspected structuring and money mule activity in consumer deposit accounts" and stop. A hiring manager who sees a case detail on your resume will not be impressed by your experience, they will conclude you cannot be trusted with the next institution's data. Say the same thing in the interview: you can describe typologies and your method in full, and you decline to describe a specific filing.

Name systems exactly as the industry writes them, because this is what recruiter searches hit. Monitoring and case management: NICE Actimize, Verafin, Oracle Mantas and FCCM, SymphonyAI, Unit21, Hummingbird, Hawk, Feedzai, ThetaRay, Quantexa, Oscilar. Screening: LexisNexis Risk Solutions Firco (still widely called Fircosoft), LexisNexis Bridger, LSEG World-Check, Dow Jones Risk and Compliance, Silent Eight. Identity and onboarding: Alloy, Persona, Socure, Jumio, Sardine. Blockchain: Chainalysis Reactor, TRM Labs, Elliptic. Plus the ordinary tools: Excel at pivot table level, SQL if you have it, Power BI or Tableau, and the core banking or payments platform you used. List only what you actually touched: a panel will ask you what a particular screen in that tool looks like.

Translate non-AML experience into the same vocabulary rather than hoping someone makes the leap for you. A teller filed Currency Transaction Reports and spotted cash structuring at the counter. A fraud analyst investigated disputed transactions, built a timeline from account activity and wrote a disposition. An insurance special investigations clerk examined claims against policy terms and documented findings. A military or law enforcement analyst produced written intelligence products from fragmentary records. A collections agent verified identity and income documents. A paralegal did document review at volume against a defined standard. Each of those maps onto the loop of gather, assess against a rule, decide, document.

What gets ignored: adjectives, a skills section full of soft skills, a list of duties with no volumes, twenty regulations you cannot discuss, certifications in progress with no exam date, and a long early-career history irrelevant to financial crime. Two pages is acceptable in this field and one is better for a first seat.

A short cover note helps here more than in most roles, because the hiring manager is sorting candidates by lane. Three paragraphs: which seat you want and at which institution type, the single most relevant thing you have done, and the credential status with a date. If the institution has a recent public enforcement action, say you have read it and which part of the programme you understand to be under pressure. That lands.

Pay, hours, shift realities and the ladder

For pay, go to the source rather than a quoted range. In the US that means the Bureau of Labor Statistics Occupational Employment and Wage Statistics, where AML analysts are coded inconsistently across SOC 13-1041 Compliance Officers and SOC 13-2054 Financial Risk Specialists, and the Credit Intermediation and Related Activities industry rows are the relevant ones. Then read live postings in pay-transparency states, which show real bands by employer and level, and ask agency recruiters directly for the hourly rate on contract work, which they will quote without hesitation. The pattern worth knowing is the shape rather than the number: triage seats pay least, investigations more, sanctions and crypto specialisation more again, and tuning, optimisation and model validation more than general investigations. Contract hourly work often grosses more than the equivalent permanent salary and carries no benefits or stability, so compare total package, not rate.

Hours are mostly standard weeks with bursts. Month-end and quarter-end reporting, examination preparation and backlog clearance produce overtime, which at hourly contract rates is a real income consideration and at salaried level is not. Payment screening, crypto and card environments staff extended or weekend coverage against live payment windows, sometimes with a shift differential. Remote and hybrid both exist, and the share of fully remote triage seats has shrunk as return-to-office expectations tightened, so confirm the arrangement in writing rather than assuming.

The ladder is well defined, which is one of the better things about this field. Analyst I to Analyst II to Senior Analyst or Investigator. From there the branches are quality assurance and training, scenario tuning and optimisation, sanctions specialisation, crypto investigations, model validation in second line, and team lead to AML manager. Above that sit the deputy and designated BSA officer roles, which carry personal accountability, and then head of financial crime. Three to six years to a senior investigator seat is normal, and faster at a small institution where you see everything sooner.

The lateral moves are genuinely good. Financial crime experience transports into fraud strategy, sanctions and export controls, internal audit, consulting and advisory practices, examiner roles at the OCC, FDIC, Federal Reserve, NCUA or a state regulator, vendor roles at monitoring and blockchain analytics companies, and investigative support attached to law enforcement task forces. Few entry-level jobs open as many doors in as many directions.

The honest downside, since nobody says it in a job posting: queue work is repetitive, quality assurance scoring can feel punitive, and the backlog is sometimes a treadmill. Burnout at Level 1 is real, and turnover is high enough that large programmes hire in cohorts to replace it. The people who stay get out of the queue within a year or two by becoming the person who can write, who can handle sanctions, who can read a blockchain trace or who can defend a threshold. Make that your plan from the first week rather than the second year.

Starting from nothing: the next 90 days

Weeks one and two: pick a seat and write it down. Transaction monitoring triage, KYC and due diligence, sanctions screening, or investigations. Base the choice on what you can already evidence. Someone who has worked payments operations should aim at monitoring; someone who has done document review at volume should aim at KYC; someone with languages should say so loudly, because adverse media and document review happen in the customer's language.

Weeks one to four: read the primary sources, all of which are free and all of which the interview is drawn from. The FFIEC BSA/AML Examination Manual, which is the closest thing this field has to a textbook and which examiners actually use. FinCEN's advisories and alerts, which are short, current and typology-specific: read the ones on scams and pig butchering, on deepfake-enabled identity fraud, on human trafficking indicators and on elder exploitation. FinCEN's published national AML/CFT priorities. OFAC's FAQs and sanctions programme pages. FATF typology reports. Then read ten public enforcement actions and consent orders, and write a one-page summary of each covering what the institution did, which control failed, what the regulator ordered and what an analyst would have had to notice. That file teaches the vocabulary faster than any paid course and gives you specific examples to use in interviews.

Weeks two to five: take a blockchain analytics certification from Chainalysis or TRM Labs. It is the one credential a complete career changer can finish quickly, it is recognised, and it puts a skill on the resume that many incumbent analysts do not have. Check current cost and availability on the vendor site.

Weeks three to eight: build two artefacts, because almost no candidate brings any. First, three SAR-style narratives written from facts taken from public enforcement actions, each structured as who, what, when, where, why and how, each under a page, each containing no confidential information because the source is public. Second, a short alert-review write-up: take a public fact pattern, state the indicator, state what you reviewed, state what you concluded and state what you escalated and why. These convert "I think I could do this" into "here is me doing it", and they double as your answer when an interviewer asks for an example you do not yet have from work.

Weeks four to twelve: apply in two channels at once. Direct applications to credit unions, community banks, payment firms, crypto companies, insurers and casinos, which post on their own sites and get a fraction of the applicants. And one specialist financial crime agency recruiter, told precisely which seat you want, what you can evidence and what hourly rate you will accept, so they can run several contract and contract-to-hire options in parallel.

Running throughout, and the highest-value action on this list if it applies to you: if you already work for a regulated employer, ask your BSA or financial crime team for something real. Help with a 314(a) search. Take some KYC refresh files. Sit with an analyst for a morning. Six weeks of that plus an internal application beats a year of external applications, because you are already through the background check and already know the systems.

One habit to start now and keep: read every FinCEN alert and every enforcement action in the sector you are targeting, and be able to name the most recent one in an interview. A candidate who says "I read the consent order against that bank, and I understand the finding was about transaction monitoring coverage of a product line" is interviewing on a different level from everyone else in the queue, whatever their years of experience say.

Working with AI in this role

What an AML analyst needs to know about AI in 2026-27

Start with the honest calibration, because overstating this is the fastest way to sound uninformed in a financial crime interview. Statistical models have run transaction monitoring and sanctions screening for well over a decade: rules, customer segmentation, peer group comparisons and fuzzy name matching are not new, and a candidate who presents them as a 2026 breakthrough signals they have not been near the work. The core of the job has not been automated either, because the core is accountability. A model cannot be the designated BSA officer, cannot sign a filing, cannot be the person an examiner interviews, and cannot take responsibility for a closure rationale. What has genuinely changed is the volume of reading and typing between the alert and the decision.

The real tooling shift is case-level assistance, and you should be able to describe it precisely. Platforms now draft case narratives from the transaction record, extract and summarise identity and corporate documents during due diligence, summarise a customer's activity history, resolve and link entities across accounts to show networks rather than single accounts, cluster related alerts into one case, and score alerts so that the lowest-risk ones are suppressed, hibernated or auto-closed. On the screening side, tools now auto-adjudicate obvious false positive name matches and write the rationale. The practical effect on an analyst's day is a shift from assembling the facts to checking an assembled version of them, and from writing the first draft to editing and owning it. Say that in an interview and you sound current without overclaiming.

The effect on entry-level headcount is uneven and worth naming plainly. The shrinking part is bulk clerical work: document rekeying, routine KYC refresh of low-risk files, and the very large contract cohorts that used to absorb that work need fewer people per file. The parts that have grown are sanctions and export controls, scam and fraud typologies that move faster than any rulebook, crypto tracing, perpetual KYC design, and governance of the AI itself. Net effect: fewer purely clerical seats, steady demand for people who can decide and defend. Nobody is hiring an analyst to retype a passport number. Plenty of people are hiring an analyst who can explain why they closed an alert the model wanted escalated.

Auto-closure and alert suppression is the topic to have a real view on, because it is where supervisory attention sits. If a system suppresses alerts, someone must be able to show an examiner why that is defensible: how the model was validated, how thresholds were tuned, what sampling of suppressed alerts shows, how often a suppressed alert would have been productive, and who owns the threshold decision. Banks already have a framework for this through interagency model risk management guidance, commonly cited by its Federal Reserve supervisory letter number SR 11-7 and issued by the OCC as bulletin 2011-12. Knowing that an AI triage or screening model is a model under that framework, and therefore needs documented purpose and limitations, independent validation, ongoing monitoring and an accountable owner, is the most senior-sounding true thing an AML candidate can say. Knowing that the federal banking agencies have issued a joint statement encouraging innovative BSA/AML approaches, so that experimentation is not itself a supervisory problem, is the other half of the answer.

The failure mode you will be asked about, directly or indirectly, is signing an AI-drafted narrative you have not verified. Generated narratives go wrong in specific, checkable ways: an amount that does not reconcile to the transaction record, a date range that does not match the review period, a counterparty or account number that appears nowhere in the evidence, a typology label asserted without the behaviour that supports it, and a confident conclusion where the evidence only supports an unexplained pattern. The correct answer is a check routine, not an opinion about AI: trace every figure, date, account and counterparty to source, confirm the review period, confirm the stated typology matches the observed behaviour, and rewrite the conclusion in your own words so it reflects your judgement. Whoever submits it owns it, and a filing containing an unreconciled figure is a defect in a regulatory report rather than a typo.

Confidentiality has a new sharp edge. SAR confidentiality is a statutory prohibition, and customer data is protected by privacy law and by your institution's own policy. Pasting case facts, customer names, account numbers or narrative text into a consumer chatbot or an unapproved tool is a disclosure, and it is a disciplinary matter at every institution that has written a policy. Institutions now maintain an AI use policy, an inventory of approved tools and an intake process for new ones. Saying in an interview that you would check whether a tool is approved before using it on case data separates a careful candidate from a risky one.

The adversary side has changed more than the defence side, and this is the part worth sounding informed about. Generated media now shows up in onboarding: synthetic identity documents, manipulated selfies and video that defeats weak liveness checks, and voice cloning used against call centres and against payment approval controls in business email compromise. FinCEN has issued an alert on deepfake media in fraud schemes targeting financial institutions, and the detection signals it describes are the kind of concrete detail that lands in an interview: inconsistencies between a submitted image and other identity data, metadata and image anomalies, reverse image search hits, and accounts whose activity does not match the customer story. Scam networks also use generative tools to industrialise investment and romance scams, which means more mule accounts, faster funnel activity and more victims whose own accounts look like laundering. An analyst who can say what those patterns look like in the data is describing current, growing work rather than a trend piece.

On regulation, state the obligation and not the date. FinCEN has published national AML/CFT priorities, and the rulemaking implementing the effectiveness reforms in the Anti-Money Laundering Act has been revised more than once, including its compliance timing. The beneficial ownership reporting regime under the Corporate Transparency Act has been through litigation and rule changes that materially narrowed which companies must report. The EU AI Act imposes obligations on providers and deployers of high-risk systems covering data governance, documentation, logging and human oversight, and its application dates have been amended since it passed. Every one of those is exactly the kind of fact that is out of date in training data and in blog posts. Describe the obligation, name the source, and say you would confirm the current text and date before repeating it in a memo. That discipline is not a hedge in this profession. It is the job: an analyst who cites a stale effective date in a regulatory document is the specific failure the function exists to prevent.

Verifying an AI-drafted case narrative before you put your name on it

Case management platforms now generate narratives and activity summaries, and whoever submits one owns it. An unreconciled amount or a counterparty that appears nowhere in the evidence is a defect in a regulatory filing, not a typo, and it is the first thing a quality assurance reviewer finds.

Show it: Describe a check routine in order: trace every amount, date, account number and counterparty back to the source transaction record; confirm the review period matches; confirm the stated typology is supported by the observed behaviour rather than asserted; rewrite the conclusion in your own words. One resume line: "reviewed and reconciled system-generated case narratives against source transaction data before escalation".

Treating an AI triage or screening tool as a model under model risk management

Examiners already have a framework for models, and vendor AI does not sit outside it. Candidates who talk about AI only as a productivity gain sound junior. Candidates who ask who validated it and how often sound like second line.

Show it: Say that an alert scoring, suppression or auto-adjudication tool is a model under interagency model risk management guidance, commonly cited as SR 11-7, and name what that implies: documented purpose and limitations, independent validation, ongoing performance monitoring, change control and an accountable owner. Then ask the panel who validates theirs.

Above the line and below the line threshold testing

When a system suppresses or auto-closes more alerts, the only defensible evidence that nothing material is being missed is sampling of what was suppressed. It is a concrete, examinable artefact and very few junior candidates know it exists.

Show it: Explain the mechanic: pull a sample of alerts just above and just below the threshold, review them as if they had been generated, and measure how many below the line would have been productive. If you have done it, give the sample size and the outcome. If not, say you would propose it, how you would size the sample, and who would have to approve a threshold change.

Reading a blockchain tracing graph

Crypto exposure is a line item in most institutions' risk assessments, scam proceeds route through exchanges and mixers, and the supply of analysts who can follow funds on chain is still thin. It is the most accessible genuine differentiator available to a career changer.

Show it: Take a Chainalysis or TRM Labs certification and say what you can do with it: identify exchange, mixer, bridge, gambling and sanctioned-entity attributions, follow funds through hops, explain why an address cluster is attributed to one service, and state what you would put in a narrative about on-chain activity. Name the tool and the certification on the resume.

Spotting generated and manipulated identity evidence at onboarding

Synthetic documents, manipulated selfies and voice cloning now appear in real onboarding and call centre fraud, and FinCEN has issued an alert on deepfake media in schemes targeting financial institutions. KYC analysts are the control point, which makes this a current skill rather than a speculative one.

Show it: Name the detection signals: inconsistencies between a submitted document image and other identity data held, image and metadata anomalies, reverse image search hits, a document that is internally consistent but matches no verifiable record, and subsequent account activity that does not match the stated customer profile. Say which identity vendor tooling you have used and what you escalated.

Describing the AI use policy and tool intake process you would follow

SAR confidentiality is statutory and customer data is protected, so pasting case facts into an unapproved tool is a disclosure and a disciplinary matter. Interviewers are now screening for whether a candidate understands this before they are handed live data.

Show it: Say plainly that you check whether a tool is on the approved inventory before using it on case data, that you never paste customer identifiers or narrative text into a consumer chatbot, and that you know the institution maintains an AI use policy, an inventory and an intake process. If you have used an approved internal assistant, say what it was used for and what you still did manually.

Explaining what has not been automated, and why

The strongest answer to "is AI going to take this job" is a structural one, and it is also true. Accountability, escalation judgement, regulator-facing explanation and the conversation with the business cannot be delegated to a model, which is why headcount has shifted rather than vanished.

Show it: Name the parts that remain human: deciding when an explanation from the business is credible, escalating a case nobody wants escalated, defending a closure rationale to quality assurance and to an examiner, interviewing a relationship manager, handling a 314(a) search and a 314(b) exchange, and owning a filing. Then say which of those you have done or watched being done.

Enough data skill to work above the queue

Tuning, optimisation, quality assurance and typology work all need someone who can pull and shape data rather than only read a case screen. This is the most reliable route out of alert triage and it pays more.

Show it: Show Excel at pivot table and lookup level, SQL at the level of a select with joins and aggregation, and a dashboard tool if you have one. Describe one analysis you actually ran: a population you defined, a filter you applied, what the distribution showed and what you recommended. Keep it short and concrete.

What a screen is looking for

These are the terms that a resume screen, human or automated, is matching against for this role. Use the ones that are true of you, in the words the posting uses.

Mistakes that cost people this job

Sending the same resume to transaction monitoring, KYC, sanctions and investigations roles.

Pick one seat and put it in the first two lines. These are four different jobs with different vocabularies and different hiring managers. A resume that opens "sanctions screening adjudication, Fircosoft and World-Check, 50 percent rule analysis" gets read for a sanctions seat; "compliance professional" gets read for nothing.

Answering a suspicious activity fact pattern with "I would file a SAR".

You do not file. The institution files, after internal escalation and review. Describe what you would review (customer profile, expected activity, source and destination of funds, related accounts, prior alerts), what you would document, and that you would escalate for SAR consideration under your institution's procedure. Volunteering to file personally, or to call law enforcement yourself, signals you do not know how reporting works.

Putting case details, customer names or SAR content on a resume, or describing a specific filing in an interview to prove experience.

Describe typologies and method, never the case. SAR confidentiality is statutory, and a hiring manager who sees case content concludes you would leak theirs. Say "drafted narratives on suspected structuring and mule activity in consumer deposit accounts" and, in the interview, say explicitly that you cannot discuss specific filings. That answer gains you credibility rather than costing it.

Treating a screening hit as a sanctions match.

Say "potential match" until it is adjudicated. Explain why fuzzy matching over-alerts (transliteration, name order, common surnames, missing dates of birth), how you would resolve it against the available identifiers, and that blocking and rejecting are different actions with different reporting consequences. This single distinction separates candidates who have worked a screening queue from candidates who have read about one.

Confusing a Currency Transaction Report with a Suspicious Activity Report.

Learn the difference cold. A CTR is a mandatory report of cash transactions over the long-standing 10,000 dollar threshold and implies no suspicion; a SAR is suspicion-based and confidential, and telling the customer about it is prohibited. Mixing them up is a memorable interview failure, because the FFIEC manual covers it in the first pages anyone reads.

Quoting a SAR filing deadline, a threshold or a regulatory effective date from memory.

Name the obligation and the source, and say you would confirm the current text. SAR thresholds differ by institution type, filing clocks run from the date of initial detection rather than alert generation, and beneficial ownership and AI rules have all had dates amended. An analyst who cites a stale date in a memo is the exact failure the function exists to prevent, and interviewers know it.

Assuming Section 19 of the FDI Act is the rule everywhere, or assuming a record is automatically disqualifying.

Check which regime applies and read its current text. Section 19 covers FDIC-insured banks; federally insured credit unions fall under Section 205(d) of the Federal Credit Union Act with NCUA consent; broker-dealers run disclosure through Form U4 and casinos through a state gaming regulator. The Fair Hiring in Banking Act narrowed what Section 19 reaches. Then disclose on the application regardless, because non-disclosure ends the process faster than the item.

Taking a contract remediation role without checking what the work actually is.

Ask in the interview whether you will disposition alerts and write rationales or only collect missing documents. Both pay similarly; only one produces a resume you can move with. If the answer is document collection, take it if you need the income, but negotiate exposure to dispositioning and start applying internally the moment you are inside.

Listing twenty regulations and fifteen systems you cannot discuss.

List the four regulations and three systems you can talk about for five minutes each. The panel will pick from your list and ask you to apply it to a fact pattern, or ask you what a particular screen in that tool looks like. In a field whose entire product is written claims that survive checking, a bluff caught in the interview is disqualifying in a way it is not elsewhere.

Claiming AI has transformed transaction monitoring, or that it has changed nothing.

Say the precise thing: statistical monitoring and fuzzy screening are decades old, and what is new is case-level assistance (narrative drafting, document extraction, entity resolution, alert scoring and suppression, auto-adjudication of obvious false positives). Then say what you verify before signing a generated narrative. Precision here reads as experience.

Applying only to the large banks whose names you recognise.

Credit unions, money services businesses, payment processors, crypto firms, insurers, casinos and sportsbooks all run real AML programmes and receive a fraction of the applications. A compliance team of four will teach you the whole programme in a year, which is a better second job than three years of one alert type at a very large bank.

Questions people ask

Do I need CAMS to get an AML analyst job?

CAMS is not required to be hired as an AML analyst, and a large share of working analysts were hired without it and certified afterwards at the employer's expense. It is the credential recruiters search for by name, so it clearly helps an AML analyst resume get read, but ACAMS scores eligibility on a points system covering education, experience and other credentials, which means many career changers cannot sit it yet. If that is you, the sequence that works is a contract remediation or KYC role first, CAMS once you qualify, and in the meantime a blockchain analytics certification from Chainalysis or TRM Labs, which has historically required no experience and takes days rather than months. Ask at offer stage whether the employer funds certification, because many do.

Can I become an AML analyst with no banking experience?

An AML analyst job is reachable without banking experience, but it is much easier to reach from inside a regulated employer than from outside one. From cold, the realistic door is a contract look-back or KYC remediation programme through a staffing agency, where institutions hire in cohorts for six to eighteen months, or a smaller employer such as a credit union, money services business, crypto exchange, insurer or casino. What substitutes for banking experience is evidence of the same loop: gathering facts, assessing them against a rule and documenting a decision. Claims handling, fraud and disputes, document review, law enforcement or military intelligence work, collections and loss prevention all translate if you describe them in that structure.

What does alert investigation experience actually mean on an AML resume?

For an AML analyst it means you were given system-generated alerts, you gathered the facts around them and you recorded a decision with a written rationale that someone else sampled for quality. The credible version has numbers attached: alerts dispositioned per day or week, the share escalated, narratives or referrals drafted, and quality assurance accuracy. Collecting missing documents for a KYC file is not alert investigation, and hiring managers can tell the difference in one question, so if your contract role was document collection say so and describe what else you did. If you have never had access to a queue, the substitute is a written alert-review exercise built from a public enforcement action, which almost no candidate brings.

What questions are asked in an AML analyst interview?

An AML analyst interview is built around fact patterns and escalation. Expect a structuring scenario (cash deposits just under the 10,000 dollar reporting threshold on consecutive days) where the right answer separates indicator from conclusion and ends in escalation under the institution's procedure. Expect the difference between a Currency Transaction Report and a Suspicious Activity Report, the rule against tipping off, who actually files, the difference between 314(a) and 314(b), and on sanctions the difference between a potential match and a true match and between blocking and rejecting. Expect an escalation threshold question, a pressure question about a profitable customer the business wants left alone, and now a question about what you verify before signing an AI-drafted narrative. Many employers add a timed case review or a short written exercise.

How much does an AML analyst earn?

Rather than trust a quoted band, look up what AML analyst pay actually is in your market using the US Bureau of Labor Statistics Occupational Employment and Wage Statistics, where the role is coded inconsistently across SOC 13-1041 Compliance Officers and SOC 13-2054 Financial Risk Specialists, within the Credit Intermediation and Related Activities industry rows. Then read live postings in states with pay-transparency posting rules, such as Colorado, California, New York and Washington, which publish real bands by employer and level, and ask agency recruiters directly for hourly rates on contract work. The reliable pattern is the shape: triage pays least, investigations more, sanctions and crypto specialisation more again, and tuning, optimisation and model validation most.

Is AML still a good career if AI is automating alert review?

An AML analyst job has shifted rather than disappeared, and the shift is specific. Bulk clerical work such as document rekeying and routine refresh of low-risk files needs fewer people, so the very large contract cohorts are thinner. Demand has grown in sanctions and export controls, scam and mule typologies, crypto tracing, perpetual KYC design, and governance of the monitoring models themselves. Accountability is the part that cannot be automated: a model cannot be the designated BSA officer, cannot sign a filing and cannot be interviewed by an examiner. The analysts who do well in 2026-27 are the ones who can verify and own a machine-drafted narrative and defend a closure rationale, not the ones who were fastest at clearing a queue.

Can I get an AML analyst job with a criminal record?

An AML analyst faces a harder test here than most office roles, and the answer depends on the offence and the type of employer. Section 19 of the Federal Deposit Insurance Act bars a person convicted of a criminal offence involving dishonesty, breach of trust or money laundering, or who entered a pre-trial diversion for one, from participating in the affairs of an FDIC-insured bank without FDIC consent; federally insured credit unions apply the parallel rule in Section 205(d) of the Federal Credit Union Act, with NCUA consent. The FDIC rules set out which minor or older offences are treated as not requiring an application, and the Fair Hiring in Banking Act narrowed what the prohibition covers, so read the current text rather than assuming. Offences outside that category are often workable. In every case disclose on the application, because the non-disclosure ends the process faster than the conviction does.

What is the difference between an AML analyst, a KYC analyst, a sanctions analyst and a fraud analyst?

An AML analyst investigates whether activity suggests money laundering or another financial crime and documents a decision, usually starting from transaction monitoring alerts and ending in an escalation or a SAR referral. A KYC analyst works on who the customer is: onboarding documentation, beneficial ownership, risk rating and periodic refresh. A sanctions analyst adjudicates name and payment screening hits against lists such as OFAC's SDN list and deals with blocking, rejecting and reporting. A fraud analyst investigates loss to the institution or the customer, works in near real time and is measured on prevented loss. The four overlap heavily in practice, move between each other easily, and are often all housed in the same financial crime function.

Do AML analysts work remotely, and are the hours regular?

Both remote and on-site AML analyst seats exist, and the arrangement is worth getting in writing rather than assuming. Remote and hybrid roles are real but a smaller share than at the start of the decade, as return-to-office expectations tightened and because supervision of new analysts and control of case data are easier in a managed environment. Hours are mostly standard weeks punctuated by overtime around month end, examination preparation and backlog clearance. Payment screening, card and crypto environments are the exception and staff extended, early or weekend coverage against live payment windows, sometimes with a shift differential. Ask about coverage hours, backlog size and alerts per analyst in the first conversation.

How long does it take to get hired as an AML analyst?

An AML analyst hiring process usually runs about a week at a credit union or a small payments firm and four to six weeks at a large bank, plus a few more weeks for fingerprinting and background processing, which candidates often misread as rejection. Contract roles through specialist agencies can move from first call to start date inside a fortnight. Getting to the first seat at all commonly takes a few months to under a year if you can move internally at a regulated employer, and roughly a year to eighteen months from outside, where the pattern that works is a contract remediation or KYC project first, a credential second, and a permanent investigations seat third.

Put this on a resume in about a minute

Paste your history once and point it at the AML Analyst posting you are looking at. No account, no card.

Build my resume free More roles