100 AML Interview Questions for Experienced Professionals
100 AML Interview Questions for Experienced Professionals
Senior AML interviews are not knowledge tests. Interviewers assume you know what layering is. What they want to know is whether you can defend an escalation decision, tune a scenario without weakening detection, explain a control gap to a regulator, and hold a position when the business pushes back.
These AML interview questions for experienced professionals cover investigations, monitoring and model governance, SAR quality, programme design, regulatory examination and the leadership questions that decide senior hires.
What senior interviewers are listening for
Whether you think in terms of control effectiveness rather than task completion. Junior answers describe what was done; senior answers explain what risk the control addresses, how you know it works, and what you would do if it did not. Enforcement actions almost never cite a single missed case — they cite systemic weakness.
Your experience and track record (Q1–12)
1Walk me through your AML experience.
Structure by scope — products and customer types monitored, alert types and volumes, whether you investigated, escalated, drafted SARs, tuned scenarios or owned governance. Say what you decided yourself versus what you referred upward.
2Describe the most complex investigation you have run.
Choose one with genuine difficulty — a network across multiple accounts, trade-based laundering, or a case where the explanation was superficially plausible. Explain how you unpicked it, what evidence changed your view, and the outcome. This question carries the most weight in the interview.
3What alert volumes and case types have you handled?
Give real figures with context — daily alert throughput, escalation rate, SAR conversion rate. Ratios are more informative than raw volume and show you understand your own effectiveness.
4What monitoring systems have you worked with?
Name them and describe what you actually did — investigating alerts, writing case narratives, running queries, contributing to tuning, testing scenarios. Overstating system depth is exposed immediately by follow-up questions.
5Have you drafted SARs, and how many?
Say honestly whether you drafted, contributed to, or escalated for drafting. Quality of narrative matters more than volume, so be ready to describe what makes a strong one.
6Have you been involved in scenario tuning or model validation?
Describe your role precisely — providing outcome data, testing thresholds, below-the-line sampling, or owning the change. Even contributing analysis is relevant if you can explain the reasoning.
7Have you supported a regulatory examination or lookback?
This is valuable experience. Explain the trigger, your role, and what you learned about how files are actually assessed under scrutiny.
8What is your SAR conversion rate and what does it tell you?
Give the figure with interpretation. A very low rate may indicate poorly tuned scenarios generating noise; a very high one may suggest under-detection or over-reporting. The point is that you monitor and interpret it.
9Have you specialised in any typology or sector?
Name it — trade-based laundering, crypto, correspondent banking, fraud-linked laundering, sanctions-adjacent activity. Depth in one area is more marketable than shallow coverage of everything.
10Tell me about a case you got wrong.
Have a real example — a closure later reopened, or a missed connection. Describe how it surfaced, what you did, and what changed in your approach. Denying any error is not credible at senior level.
11Why are you leaving your current role?
Give a forward-looking reason — greater complexity, ownership of a control, specialisation, or leadership. Avoid criticising your current employer.
12What are you looking for in your next role?
Be specific about scope and ownership — running investigations end to end, owning tuning, managing a team, or moving toward MLRO. Clear direction reads as considered.
Practise the delivery, not just the content
Senior interviews probe your reasoning with follow-up questions, which is where prepared answers usually break down. Practise a live AI voice and video interview on AGZIT tailored to your target role:
- A real spoken interview that follows up on what you say
- A 10-competency scorecard showing where your reasoning is thin
- A free ATS-friendly resume builder once you register
- Your first AI interview is free
Complex investigations (Q13–30)
13How do you structure a complex investigation?
Establish the customer baseline, define the question the alert actually raises, map the flow of funds and counterparties, test the most plausible legitimate explanation, then test alternatives. Document as you go so the reasoning is visible, not reconstructed afterwards.
14How do you avoid confirmation bias?
By actively testing the innocent explanation as rigorously as the suspicious one, and by asking what evidence would change my conclusion. If nothing would, I am not investigating — I am justifying a position already taken.
15How do you investigate a network rather than a single account?
Link accounts by shared counterparties, addresses, devices, timing patterns and transaction structure. Individually unremarkable alerts often form a clear picture collectively, so I aggregate before concluding on any one.
16What is link analysis and when do you use it?
Mapping relationships between entities to reveal structures not visible transaction by transaction. It is most useful for mule networks, layering chains and cases where the same beneficiary appears behind multiple customers.
17How do you investigate trade-based money laundering?
Compare invoice values against market prices, check whether goods, volumes and routes are commercially coherent, look for repeated invoicing and mismatches between documents, and assess whether the counterparties plausibly trade in those goods.
18What makes trade-based laundering hard to detect?
The transactions look commercial, documentation is paper-based and easy to falsify, banks often see only the payment leg, and pricing anomalies require sector knowledge to spot. Detection usually depends on documentary inconsistency rather than transaction patterns.
19How do you investigate suspected mule activity?
Look at the profile mismatch first — credits from multiple unrelated senders inconsistent with income or age — then the speed of onward movement, the withdrawal method, and whether the same beneficiaries appear across other accounts.
20How do you approach crypto-linked investigations?
Focus on the fiat legs you can see, use blockchain analytics for wallet exposure and clustering, assess whether counterparty exchanges are regulated, and check whether declared activity matches observed volumes. Pseudonymity is a limit, not a dead end.
21How do you handle a case where the explanation is plausible but unverifiable?
Unverified is not verified. I document the explanation, note the evidence gap, and weigh it against the rest of the risk picture. A plausible story with no corroboration on a material point supports escalation rather than closure.
22How much weight do you give a customer's explanation?
It is evidence, not a conclusion. I assess whether it is internally consistent, consistent with the account history and profile, and supported by anything independent. A rehearsed or shifting explanation is itself informative.
23What sources do you use beyond internal data?
Corporate registries, adverse media, court and enforcement records, sanctions and PEP data, blockchain analytics where relevant, and open-source research. Internal data alone rarely explains why funds are moving.
24How do you decide when an investigation is complete?
When I can either explain the activity with evidence, or articulate clearly why it cannot be explained. Completeness is about reaching a defensible position, not exhausting every possible line of enquiry.
25How do you handle historical activity discovered mid-investigation?
Expand the review period rather than restricting to the alerted transactions. If the pattern predates the alert, the scope should follow the conduct, and any prior closures on the same pattern need revisiting.
26What do you do when data you need is missing?
Request it internally, note the limitation explicitly in the case, and assess whether the gap is systemic. Recurring data gaps are a control issue that should be escalated rather than worked around case by case.
27How do you assess whether a business rationale is genuine?
Test it against observable reality — does the counterparty exist and trade, do volumes match the stated business, is the routing commercially sensible, does the pricing hold up. Rationales collapse quickly when checked against third-party data.
28How do you handle an investigation involving a colleague or internal party?
Declare any conflict, follow the internal fraud or whistleblowing route rather than the standard path, and restrict information sharing. Internal cases have different confidentiality requirements.
29What is your approach to prioritising a case queue?
Risk-weighted rather than first in first out — customer risk rating, value, sanctions adjacency, and regulatory deadlines. I also track ageing, because unmanaged backlogs are themselves a finding.
30How do you know your investigation quality is good?
Through QA outcomes, whether escalations are upheld, whether reopened cases trace back to my closures, and feedback from the MLRO on narrative quality. Self-assessment alone is not evidence.
Monitoring systems and tuning (Q31–48)
31How do you approach scenario tuning?
Start from outcome data — which scenarios produce escalations and which produce almost none. Then segment customers so thresholds reflect expected behaviour, test proposed changes against historical data, and validate with below-the-line sampling before implementing.
32What is below-the-line testing and why does it matter?
Sampling transactions that fell just below a threshold and did not alert, to check whether risk is being missed. It is the primary evidence that thresholds are not set too high, and regulators expect to see it.
33How would you reduce false positives without weakening detection?
Improve customer segmentation and data quality first, since most noise comes from applying one threshold to dissimilar customers. Then refine scenario logic. Raising thresholds across the board reduces alerts and detection equally.
34What is customer segmentation in monitoring?
Grouping customers with similar expected behaviour so thresholds reflect their normal activity. Without it, a rule calibrated for salaried individuals will misfire constantly on trading businesses and miss risk on high-turnover accounts.
35How do you demonstrate scenario coverage is adequate?
Map scenarios against the risks identified in the enterprise risk assessment and show that each material typology has detection logic. Gaps in that mapping are exactly what examiners look for.
36What is model validation and who should perform it?
Independent testing that the system works as intended — rules fire correctly, data is complete, coverage matches risk. It must be performed by a party independent of the model owner, periodically and on material change.
37What are the risks of incomplete data feeds?
Silent failure. Missing transaction types or counterparty fields mean scenarios never trigger and no alert is generated to reveal the gap. Data completeness testing is therefore a control in its own right.
38How would you identify a detection gap?
Compare typologies in the risk assessment against active scenarios, review SARs generated by other routes such as staff referrals, examine cases identified externally, and run below-the-line testing. Gaps rarely announce themselves.
39What is your view on machine learning in monitoring?
Useful for alert prioritisation, anomaly detection and reducing false positives, but it must be explainable and validated. Most firms run it alongside rules rather than replacing them, because rules are transparent to regulators.
40What are the governance requirements for a machine learning model?
Documented development, explainability of outputs, bias and drift monitoring, independent validation, ongoing performance testing, and a fallback if the model degrades. "The model decided" is not a defensible answer to an examiner.
41How do you handle a scenario producing almost entirely false positives?
Analyse why before switching it off — it may be poor segmentation rather than a bad scenario. If it genuinely addresses no live risk, retire it through change governance with documented rationale, not informally.
42Who should approve a tuning change?
It should go through documented model change governance with second-line review and, for material changes, senior approval. Analysts should never adjust thresholds unilaterally.
43How do you manage an alert backlog?
Triage by risk rather than age, add resource to the highest-risk population, report the position transparently and address the cause — usually tuning or capacity. Concealing a backlog turns an operational issue into a regulatory one.
44What management information would you use to run a monitoring function?
Alert volumes by scenario, escalation and SAR conversion rates by scenario, ageing and backlog, QA pass rates, data completeness metrics and tuning change history. Scenario-level outcome data is the most actionable.
45How do real-time and post-event controls complement each other?
Real-time prevents prohibited payments — principally sanctions — while post-event detects behavioural patterns that only emerge over time. Neither substitutes for the other, and instant payments increase reliance on real-time.
46What monitoring challenges do instant payments create?
Irrevocable settlement means post-event detection cannot recover funds, compressing the intervention window. It shifts weight to real-time controls, behavioural profiling and mule detection at onboarding.
47How do you monitor correspondent banking activity?
Through payment pattern analysis on the respondent's flows, watching for nesting, unexpected jurisdictions and volumes inconsistent with the respondent's stated business — since you cannot see their underlying customers.
48How would you build monitoring for a new product?
Start from a risk assessment of how the product could be abused, define typologies, design scenarios against them, ensure the data required is actually captured, then test before launch. Retrofitting monitoring after launch is the common and expensive failure.
SAR quality and escalation (Q49–62)
49What makes a high-quality SAR narrative?
A clear account of who, what, when, how much and why it is suspicious — with the reasoning explicit. Investigators need to understand the concern, not reconstruct it from a transaction list. Facts first, conclusion supported by them.
50What are common weaknesses in SAR narratives?
Transaction dumps with no analysis, jargon without explanation, conclusions without supporting facts, omitting what was ruled out, and failing to state clearly what the suspected activity actually is.
51What is the threshold for reporting?
Reasonable suspicion — a reasonable basis to suspect, not evidence or certainty. Over-reporting to be safe is its own problem, because it degrades the intelligence value of the regime.
52What is defensive reporting and why is it a problem?
Filing to protect the institution rather than because suspicion genuinely exists. It floods FIUs with low-value reports, obscures real intelligence, and regulators have criticised it. The answer is better analysis, not more filings.
53How do you decide between closing and escalating a borderline case?
Whether the activity has an evidenced explanation consistent with what is known. Where genuinely balanced, I escalate with my reasoning and let the MLRO decide — that is what the escalation route exists for.
54What is continuing activity reporting?
Filing further reports where suspicious activity persists after an initial SAR, on a defined cycle. It ensures the FIU sees the ongoing picture rather than a single snapshot.
55How do you handle the relationship after filing?
Maintain strict confidentiality, avoid tipping off, continue servicing normally where required, and follow any guidance on account restrictions. Exit is a separate decision taken at senior level.
56When would you recommend exiting a customer after a SAR?
Where risk is unmanageable, cooperation has broken down, or the pattern is persistent. But exit can prejudice an investigation, so it should be considered with the MLRO rather than triggered automatically.
57What is a consent or DAML request?
A request to the FIU for permission to proceed with a transaction that would otherwise risk a money laundering offence. Terminology and process differ by jurisdiction, and timing obligations are strict.
58How do you handle a request for information from law enforcement?
Route it through the proper legal and compliance channel, verify authenticity and legal basis, provide only what is properly requested, and maintain confidentiality. Analysts should not respond directly.
59What is tipping off and where do people go wrong?
Disclosing that a report has been made or is contemplated. People go wrong by improvising explanations to customers about delays, or discussing cases internally with staff who have no need to know.
60How do you measure SAR quality?
Through internal QA against a defined standard, MLRO feedback, any FIU feedback available, and whether reports contain the elements investigators need. Volume is not a quality measure.
61What would you do if the MLRO declined to file on a case you believed warranted it?
Present the evidence and reasoning clearly, and if they still declined, accept the decision while ensuring my analysis is documented. The MLRO owns the decision, but my position should be on record.
62How do you ensure consistency in escalation decisions across a team?
Documented criteria, worked examples, calibration sessions on borderline cases, and QA feedback loops. Without shared standards, escalation becomes a function of individual risk tolerance.
Programme, governance and audit (Q63–78)
63What are the components of an effective AML programme?
Senior management commitment, a documented risk assessment, policies and internal controls, customer due diligence, monitoring and reporting, independent testing, and training — with governance connecting them.
64What goes into an enterprise-wide risk assessment?
Inherent risk by customer type, product, geography and channel; the controls mitigating each; and the resulting residual risk. It should drive control design and resourcing rather than sit as a document.
65How does the risk assessment connect to monitoring?
Scenario coverage should map directly to the typologies identified as material. If the risk assessment names a risk with no corresponding detection, that is a documented gap.
66What is the three lines of defence model in practice?
First line owns and operates the controls, second line sets policy and challenges, third line provides independent assurance. The common failure is second line acting as an extension of operations rather than genuinely challenging.
67What does effective independent testing look like?
Testing whether controls actually work, not whether procedures exist — sampling decisions for quality, testing system coverage and data completeness, and validating that identified issues were genuinely remediated.
68How would you respond to an audit finding you disagreed with?
Understand it precisely, provide evidence if I believe it is factually wrong, and accept it if the point is valid. Disputing findings without evidence damages credibility more than accepting them.
69What is a lookback review and when is it required?
A retrospective review of historical activity to identify what was missed, usually triggered by a control failure or regulatory finding. They are costly, which is why detecting gaps internally matters.
70How do you approach remediation of a known control gap?
Contain the immediate risk, assess the population affected, define the remediation scope and timeline, fix the root cause rather than the symptom, and evidence the fix through testing. Regulators judge firms on how they respond to known issues.
71What management information should reach the board?
Risk assessment outcomes, SAR volumes and trends, alert backlogs, control testing results, open regulatory or audit findings, and resourcing pressure. Board reporting should surface problems, not present a clean picture.
72How do you design effective AML training?
Role-specific and case-based rather than generic. Front-line staff need to recognise and escalate; analysts need investigative technique; senior management need to understand what they are accountable for.
73How do you build a culture where staff actually escalate?
Make escalation safe and expected — respond constructively to referrals even when they close, avoid punishing false alarms, and visibly support staff who hold a position under commercial pressure.
74How do you resolve disagreement between compliance and the business?
State the risk and the regulatory basis clearly, distinguish requirement from preference, and use the governance forum where genuine disagreement persists. Escalation is a legitimate route, not a failure of relationship.
75How do you assess whether the function is adequately resourced?
Through alert throughput against capacity, backlog trends, quality outcomes under load, and overdue reviews. Deteriorating quality under stable volume is usually the first sign.
76What is your view on outsourcing AML operations?
Execution can be outsourced; accountability cannot. It requires clear standards, quality oversight, testing and the ability to demonstrate the outsourced work meets the same standard as in-house.
77What are the AML risks of a new business initiative?
New products, channels or markets change the risk profile. The failure mode is launching before the risk assessment, monitoring coverage and data capture are in place — retrofitting is far more expensive.
78How do you keep the programme current?
Regular risk assessment refresh, horizon scanning on regulation and typologies, learning from enforcement actions against peers, and testing whether controls still address how criminals are actually operating.
Regulatory examination and enforcement (Q79–88)
79What do examiners focus on?
Control effectiveness rather than documentation existence — whether alerts are properly investigated, whether coverage matches assessed risk, whether known issues were remediated, and whether decisions are evidenced.
80What are the most common enforcement findings?
Inadequate scenario coverage, untuned thresholds, alert backlogs, weak investigation documentation, failure to act on internally identified deficiencies, and insufficient resourcing. Almost never a single missed transaction.
81Why does failure to remediate a known issue attract heavier penalties?
Because it shows the firm knew and did not act, which moves the conduct from oversight toward recklessness. Regulators consistently treat known-and-unaddressed as an aggravating factor.
82How would you prepare for an examination?
Know your own weaknesses before they do — review file quality, backlogs, coverage mapping and open findings, and be ready to explain what you are doing about each. Being able to articulate a known gap and its remediation plan lands far better than being surprised by it.
83How should staff handle examiner questions?
Answer accurately and within their knowledge, avoid speculation, and refer questions beyond their scope rather than guessing. Inconsistent answers across staff cause more damage than an acknowledged gap.
84What is a monitorship?
An independent monitor imposed under a settlement to oversee remediation and report to the authority. They are intrusive, lengthy and expensive, which is why avoiding one drives remediation urgency.
85What personal liability exists in AML?
Several regimes provide for action against individuals — particularly MLROs and senior managers — including fines, prohibition orders and in serious cases criminal liability. Accountability regimes have sharpened this considerably.
86What lessons do you take from recent enforcement actions?
Have specific examples ready. The recurring themes are known gaps left unaddressed, growth outpacing control investment, and monitoring coverage that never kept up with new products or markets.
87How do you evidence that a control is effective, not just present?
Through testing outcomes — coverage tests, below-the-line sampling, QA results, and whether the control has actually detected anything. A documented procedure with no outcome data proves nothing.
88How do FATF mutual evaluations affect firms?
They assess national regimes, and poor outcomes drive regulatory tightening, listing risk and heavier supervision. Firms feel them through changed expectations and higher scrutiny of exposure to affected jurisdictions.
Scenario questions (Q89–95)
89You discover a scenario has not been generating alerts for six months due to a data feed failure. What do you do?
Contain first — confirm the scope and get the feed fixed. Then assess the population of transactions that went unmonitored, run a retrospective review over that period, and escalate to compliance leadership. A silent detection gap of that length is a reportable control failure, not an IT ticket.
90Alert volumes have tripled after a tuning change and the team cannot cope. How do you respond?
Do not quietly revert or let alerts age unreviewed. I would triage by risk to protect coverage, analyse whether the increase reflects genuine detection or poor calibration, and take a proposal back through change governance with evidence. Meanwhile the backlog gets reported, not hidden.
91A senior executive asks you to close an investigation into a major client. How do you handle it?
Complete the investigation on its merits and document the request. Commercial standing does not change the analysis, and the approach itself is a compliance concern I would escalate to the MLRO. I would not close it and I would ensure my position is on record.
92You identify a pattern across twelve unrelated customers suggesting an organised network. What now?
Escalate as a linked case rather than twelve separate ones, because the collective picture is the finding. I would map the connections, brief the MLRO on the network, and flag it for scenario review since the pattern evidently evaded existing detection.
93An internal audit finds 30 percent of your team's closed alerts lack adequate documentation. How do you respond?
Accept the finding and treat it as systemic rather than individual. I would review whether the standard is clearly defined, whether time pressure is driving it, and whether QA was catching it. Then remediate the affected population and fix the cause — retraining alone rarely resolves a documentation failure at that rate.
94The business wants to launch a product in a high-risk market in six weeks. Compliance readiness is not there. What do you say?
Set out precisely what is missing — risk assessment, scenario coverage, data capture, resourcing — and what the exposure is if launched without it. Offer a phased approach with restricted scope if timing is fixed. What I would not do is agree and hope to retrofit.
95You inherit a function with a 4,000-alert backlog. What are your first three actions?
Triage by risk so the highest-exposure alerts are worked first; establish the true cause — tuning, capacity or data — since the fix differs entirely; and report the position honestly to senior management with a remediation plan. Working through it chronologically without addressing the cause just recreates it.
Leadership and closing (Q96–100)
96How do you build and develop an AML team?
Teach reasoning rather than process, review real cases together, give specific feedback, and create space for people to raise concerns. Describe something you have actually done rather than a philosophy.
97Tell me about a time you changed your mind on a case.
Use a real example where new evidence shifted your assessment. It demonstrates you follow evidence rather than defending your first conclusion — the trait senior reviewers value most.
98How do you balance detection effectiveness against operational cost?
By measuring where detection actually comes from — scenario-level outcome data — and directing effort there, rather than treating all controls as equally valuable. Efficiency should come from better targeting, not from lower standards.
99Do you want to become an MLRO?
Answer honestly. If yes, show you understand what the role carries — personal accountability, regulator-facing responsibility, ownership of reporting decisions. If not, be clear about the specialism you want instead.
100What questions do you have for us?
Ask about scenario coverage and tuning governance, backlog position, how escalation disagreements are resolved, what the last audit or examination found, and how compliance and the business work together. These reveal whether the function is genuinely supported.
Test your answers under pressure
Senior interviews probe with follow-up questions, which is where rehearsed answers break down. Practise a live AI voice and video interview on AGZIT, get a 10-competency scorecard, and build a free ATS-friendly resume when you register.
Deepen your technical edge
Senior AML roles reward demonstrable depth in investigations, due diligence and monitoring practice. eStraLux training covers end-to-end workflows with real tool access and case-based walkthroughs.
leave your comment