AML compliance for small, regional firms – how deep do you really need to go?
Hey everyone, been lurking for a while, first post here. I'm with a smaller investment advisory firm, purely domestic clients, nothing exotic. We're looking at updating our AML policies and I'm honestly a bit overwhelmed by some of the guidance out there. It feels like a lot of it is geared towards massive, international banks dealing with high-risk clients and complex structures.
For a firm like ours, with maybe 200 clients, all vetted, nothing remotely suspicious in our history, how deep do we really need to go on things like enhanced due diligence on all beneficial owners, or really granular transaction monitoring beyond the obvious red flags? I know the rules are the rules, but I'm trying to figure out the practical application without drowning our compliance officer (me, mostly) in unnecessary paperwork. What's the sweet spot for a firm our size?