Founding Institution cohort now open.
AML/CFT Program

Your AML/CFT Program Needs to Be More Than a Policy Doc.

A living AML/CFT risk program for banks, fintechs, and MSBs. Risk-based analysis across customer, product, geography, and channel risk — mapped to FATF 40 and FFIEC BSA/AML.

Complete your initial assessment in about 2 hours. Self-paced — pause and resume anytime. No preparation required.

Tailored to your institution type, size, and operating geography — not a generic checklist.

ACFE • COSO ERM • FATF 40 • FFIEC BSA/AML • GDPR • PSD2 SCA

Built by practitioners

BSA Officers and risk professionals who've led programs through OCC, FDIC, and NCUA examinations

Secure by design

No names. No free-text. Nothing sensitive.

No AI agents

Auditable analysis. No autonomous actions. No black-box results.

When institutions come to us

The examination is coming up.

The OCC, FDIC, or NCUA is scheduled. The BSA Officer is pulling together documentation and realizing the risk assessment is two years old and doesn't reflect the current product mix. VeloRisk produces a current, examination-ready assessment in hours.

You're new to the role.

You inherited a BSA program from someone who left. You don't know what the examiners found last time, what's been remediated, or where the real gaps are. You need a baseline before the next examination tells you.

A peer institution just got hit.

A consent order or MRA was published — maybe against a bank your size, in your market. Your board is asking questions. You need to show them where your program stands and what's being done about it.

Get Started — from $7,499/yr

30-day satisfaction guarantee. No questions asked.

VeloRisk gives BSA Officers, compliance officers, and chief risk officers a living AML/CFT program — run it on demand, not just once a year. Risk-based analysis across customer, product, geography, and channel dimensions, with findings mapped to FATF 40 Recommendations, FFIEC BSA/AML, and other applicable regulatory frameworks.

Examination-ready documentation, always current. A program your regulators will recognize.

The Examination Standard

The FFIEC BSA/AML Examination Manual requires a documented, risk-based program — including a formal risk assessment. Examiners don't just review your controls. They review whether you understand your own risk profile.

Finding → Remediation

No documented assessment means no defensible posture

Examiners cite the absence of a current, documented risk assessment as a program deficiency. That finding becomes an MRA — and MRAs don't close until you fix them.

MRA → Consent Order

Unresolved findings escalate

Matters Requiring Attention that go unaddressed become Matters Requiring Immediate Attention. Serious program deficiencies result in consent orders, formal agreements, and restricted business activity.

Prevention vs. Remediation

Mandatory remediation costs far more than prevention

The consultants you'd bring in to remediate a consent order cost orders of magnitude more than the program that prevents the finding. And they arrive on the regulator's timeline, not yours.

How It Works

Self-paced Assessment

  • • Self-paced — no preparation or scheduling required
  • • No data collection needed in advance
  • • Guided survey adapted to your institution type and jurisdiction

Candor™ Analysis Engine

  • • AML/CFT risk dimensions analyzed across your institution's product, customer, and geographic profiles
  • • Risk-based approach aligned to FATF methodology
  • • Program gap identification with prioritized recommendations
  • • Findings validated against FATF 40, FFIEC BSA/AML, and other applicable frameworks

Examination-Ready Reports + Platform

  • • Executive Report (~25 pages) structured for examiner review, board briefings, and audit committee presentation
  • • Practitioner Report with full findings, risk ratings, gap analysis, and remediation priorities
  • • Both reports include an Assessment Comparison section on every re-run — documenting what changed since the prior assessment
  • • Interactive platform for ongoing access, KPI tracking, and remediations management

On-Demand Reassessment

  • • Re-run when business activity, risk exposure, or regulatory requirements change
  • • Aligned with FinCEN's proposed standard for dynamic, responsive risk assessments
  • • Compare results across runs with the Assessment Comparison Report
  • • Unlimited reassessments included with the Annual Program subscription

Will Your Regulators Accept This?

The FFIEC BSA/AML Examination Manual requires a documented, risk-based program assessment. VeloRisk produces exactly that documentation — structured to the format examiners recognize and mapped to the risk categories they evaluate.

Your BSA Officer reviews and attests to the output — the same role they'd play in a consultant-produced assessment.

Findings map to the FFIEC BSA/AML Examination Manual and FATF 40 Recommendations — the standards examiners cite in findings.

An accurate assessment that surfaces real gaps is a stronger examination position than a clean-looking document that doesn't reflect your program's reality.

The same documentation standard. The format regulators recognize. A fraction of the consulting cost.

See Your Program in Action

A living dashboard that evolves with your organization — not a PDF that ages on a shelf.

AML/CFT Program Dashboard — risk posture overview across all domains

Program Dashboard — risk posture at a glance

AML/CFT Program — Metrics view tracking control effectiveness over time

Metrics — control effectiveness over time

AML/CFT Assessment — domain-level risk scoring radar

Assessment — domain-level risk scoring

Built for Organizations That Can't Afford to Wait

VeloRisk's AML/CFT Program Assessment is built for BSA Officers, compliance leaders, and chief risk officers at financial institutions who need a current, documented AML/CFT Program Assessment—without the cost or timeline of a traditional engagement.

Common Use Cases

  • BSA/AML Program Assessment: Documenting your AML/CFT program's current risk profile and control effectiveness
  • Regulatory Examination Preparation: Producing examination-ready documentation ahead of OCC, FinCEN, FDIC, or state regulator reviews
  • FATF Alignment: Demonstrating risk-based approach consistent with FATF Recommendations
  • Board Reporting: Presenting AML/CFT risk posture and program gaps to the board or audit committee
  • New Product / Service Risk: Evaluating AML/CFT risk exposure from new products, customer segments, or geographies
  • M&A Due Diligence: Assessing AML/CFT program maturity in acquisition targets or merger partners

Your AML/CFT program, running in the platform today.

Get Started — from $7,499/yr

30-day satisfaction guarantee. No questions asked.

Start Your Program.

No hidden fees. No surprises.

Founding Institution pricing locks in your annual rate permanently — what you pay today is what you pay at every renewal. This tier is open for a limited time; standard pricing applies to new purchases after this window closes.

Founding Institution

Annual subscription — rate locked forever

$12,499/yr
$7,499 /yr
Tax included · Renews annually
  • Unlimited reassessments & re-runs for 12 months
  • Assessment Comparison Report (year-over-year)
  • Unlimited participants
  • Executive + Practitioner Reports (2 PDFs)
  • Interactive online platform
  • Rate locked forever — never increases at renewal
Get Started

Running multiple programs? See bundle pricing →

What to expect after purchase

1

Complete checkout

Takes about 2 minutes

2

Log in to your account

Access granted immediately

3

Start your assessment

No setup. Platform guides you through everything.

30-Day Satisfaction Guarantee

Not satisfied for any reason within 30 days? We'll refund 100% of your purchase — no back-and-forth. See full policy →

Mapped to the Frameworks That Matter

Findings Mapped to

  • ACFE Fraud Risk Management Guide
  • COSO ERM 2017
  • FATF 40 Recommendations
  • FFIEC Authentication Guidance
  • FFIEC BSA/AML Examination Manual
  • GDPR
  • ISO 27001:2022
  • NIST CSF 2.0
  • NIST SP 800-53
  • NIST SP 800-63
  • PSD2 Strong Customer Authentication
  • SOC 2

Security & Privacy

  • Data encrypted at rest and in transit
  • No data sharing with third parties
  • GDPR compliant
  • SOC 2 Type II in progress

Frequently Asked Questions

How long does the assessment take?

Most BSA Officers complete their initial AML/CFT assessment in about 2 hours. The assessment is self-paced — you can pause and resume at any time, so there's no need to block out a full session in advance. No data collection or preparation is required before you start; the platform guides you through everything it needs to know about your institution.

How thorough is the AML/CFT analysis?

VeloRisk evaluates your AML/CFT program across risk dimensions covering customer risk (CDD/EDD), product and service risk, geographic risk, channel risk, and program effectiveness (governance, controls, monitoring, reporting). Findings are mapped to FATF 40 Recommendations, FFIEC BSA/AML requirements, and other applicable frameworks—producing documentation that regulators and examiners recognize.

Is it tailored to my institution type?

Yes. The assessment adapts to your institution type—banks, credit unions, fintechs, money services businesses (MSBs), broker-dealers, and others face different AML/CFT risk profiles. VeloRisk accounts for your specific product set, customer segments, and geographic footprint.

What makes this a program, not just an assessment?

A one-time assessment reflects a moment in time. When your customer mix changes, a new product launches, or a new typology emerges, that assessment is out of date. VeloRisk lets you re-evaluate on demand — unlimited reassessments are included with the annual program. Your AML/CFT documentation stays current between examination cycles, not just when an examiner asks for it.

Who should complete the assessment?

The assessment is designed for the BSA Officer or Chief Compliance Officer—the person who owns the AML/CFT program. Involve as many participants as needed — compliance, operations, legal, and other relevant functions are all welcome contributors.

What does the report include?

The AML/CFT Program Assessment produces a single comprehensive report containing: inherent risk ratings by risk category (customer, product, geography, channel), residual risk ratings reflecting control effectiveness, program gap analysis with prioritized recommendations, and compliance mappings to FATF 40, FFIEC BSA/AML, ACFE, COSO, GDPR, and other applicable frameworks. The report is structured to satisfy examination documentation requirements and to present to your board or audit committee.

Will regulators accept this as documentation of our AML/CFT Program Assessment?

Examiners look for a documented, risk-based assessment of your institution's AML/CFT risk profile — current, comprehensive, and specific to your products, customers, geographies, and channels. VeloRisk produces exactly that documentation, structured to the FFIEC BSA/AML Examination Manual and FATF 40 requirements. The format is one regulators recognize.

Your BSA Officer reviews the output and attests to its accuracy — the same role they'd play with a consultant-produced assessment. The documentation doesn't replace judgment; it structures and surfaces it.

What the assessment reveals about your program is up to your program. VeloRisk doesn't hide gaps — it finds them. Going into an examination with a current, accurate assessment that identifies real gaps is a stronger position than going in with a clean-looking document that doesn't reflect reality.

Is my data secure?

Absolutely. All data is encrypted at rest and in transit, hosted on Google Cloud Platform with SOC 2 controls. We never share your data with third parties. You retain full ownership of all assessment data and reports.

Do you offer volume discounts or enterprise pricing?

Yes. Contact us for custom enterprise packages.

Your AML/CFT Program, Always Current.

Start today. No preparation required. Examination-ready documentation from day one.

Have questions? Contact us and we'll help you get started.