AML Instructor
About us
beCloudReady delivers cloud, data, and AI training to engineers and enterprise teams. TorontoAI is Canada's most active applied AI community, 10K+ members, events across Toronto and beyond.
Learn more about TorontoAI →The role
You'll teach a graduate cohort headed into entry-level financial-crime analyst roles at banking clients, covering the actual regime and workflows they'll be dropped into on day one, not generic compliance theory.
Curriculum
Course 1: AML & Financial Crime Foundations (5 days)
- AML Foundations
- Know Your Customer: KYC, CDD & EDD
- Sanctions, Watchlists & Screening
- Regulatory Reporting & Recordkeeping
- Applied Work (Lab)
AML Foundations
- The three stages of money laundering: placement, layering, and integration.
- The purpose of an AML program: prevent, detect, investigate, escalate, report, and retain records.
- Core program pillars: internal controls, independent testing, a designated officer, training, and risk-based due diligence.
- Risk-based thinking: customer, product, channel, geography, transaction activity, and expected versus actual behaviour.
Know Your Customer: KYC, CDD & EDD
- Customer identification: information collected at onboarding and how identity is verified.
- Customer due diligence, beneficial ownership, and establishing expected activity as the baseline for later monitoring.
- Customer risk rating: geography, product, channel, occupation, business purpose, and activity as rating inputs.
- Enhanced due diligence: what triggers it, and source of funds versus source of wealth.
- Risk indicators and red flags: customer profile mismatch, unusual transaction velocity, cash structuring, third-party activity, high-risk geographies, unexplained source of funds, and activity inconsistent with stated occupation or business purpose.
Sanctions, Watchlists & Screening
- Why sanctions screening is separate from AML but connected to financial-crime operations.
- Customer and payment screening: real-time screening, batch screening, false positives, possible true matches, and escalation.
- Name-matching concepts: aliases, transliteration, fuzzy matching, common names, and documentation of the disposition rationale.
Regulatory Reporting & Recordkeeping
- Suspicious activity escalation: facts, red flags, reasonable suspicion, reviewer expectations, and prohibition on tipping off.
- Currency transaction and large cash transaction concepts: thresholds, aggregation, documentation, and why analysts never coach customers around reporting limits.
- Writing an escalation or STR-style narrative: customer profile, transaction facts, red flags, evidence, inference, rationale, and recommendation.
Applied Work (Lab) — Course 1
- Complete a customer risk-rating file for four synthetic retail customers, with written rationale for each.
- Disposition a set of synthetic sanctions and watchlist alerts, scored on accuracy and documentation quality.
- Draft a suspicious activity escalation memo using a supplied customer profile and transaction package.
- Build an enhanced due diligence file from a supplied customer package.
Course 2: Retail Banking AML — Typologies, Alerts & Investigations
- Retail Banking & Payments Context
- Retail AML Typologies
- The Alert Lifecycle
- Investigation Toolkit
- Applied Work (Lab)
Retail Banking & Payments Context
- Retail products: personal deposit accounts, cards, lending products, and small-business accounts.
- Payment channels: branch cash, ATM, cheque and remote deposit, ACH or EFT, wires, cards, person-to-person payments, bill payments, and remittances.
- Normal versus unusual activity: payroll, benefits, rent, seasonal spending, customer occupation, business purpose, source of funds, counterparties, and geography.
Retail AML Typologies
- Cash structuring across branches, days, ATMs, and accounts.
- Money mules and funnel accounts: recruitment patterns, account behaviour, and network indicators.
- Rapid movement of funds, pass-through activity, third-party deposits, unusual wires, and transactions lacking clear economic purpose.
- Retail fraud patterns that may create AML concerns: account takeover, synthetic identity, scams, elder financial exploitation, and unusual account funding.
The Alert Lifecycle
- How rules and scenarios generate transaction-monitoring alerts.
- Triage, investigation, disposition, escalation, case creation, closure, and the evidence each state requires.
- Queue management: aging, service levels, prioritization, and when to stop investigating and escalate.
- Quality assurance: reviewer comments, four-eyes review, correction cycles, and documenting work to audit standard.
Investigation Toolkit
- The investigation lifecycle: understand the alert, verify the customer profile, review transaction history, gather evidence, document findings, make a disposition decision, and escalate when the facts support reasonable suspicion.
- Timeline construction, entity resolution, counterparty review, source-of-funds indicators, and separating observed facts from inference.
- Open-source research boundaries: legal and ethical sources, what is off-limits, and how to document external evidence.
Applied Work (Lab) — Course 2
- Work twelve simulated transaction-monitoring alerts end to end under a queue-management time constraint, dispositioning each with written rationale.
- Build a complete case file for one escalated alert: transaction timeline, customer-risk summary, key red flags, evidence log, disposition decision, and escalation narrative.
- Complete a routing exercise: assign six mixed intake items to fraud, AML, or disputes, and justify each routing decision.
Capstone Project: AML Case Study (5 days)
- Day 1, Profile, clean, reconcile: load the three files, profile every column (shape, completeness, cardinality, types), fix date/amount/whitespace problems in Power Query rather than by hand, deduplicate with a stated rule, join transactions to customers and report how many fail to join and why. Deliverable: a validation log, every defect found, the rule applied, and rows affected.
- Day 2, Exploratory analysis: distributions of amount and volume, outlier identification, activity by jurisdiction and payment type, time-series view (velocity, bursts, dormancy followed by sudden activity), segment customers by behavior against their assigned risk rating. Deliverable: an EDA findings pack, five findings, each with the evidence and chart that supports it.
Curriculum delivery
- Teach the BSA/FinCEN regime, KYC/CDD/EDD, and OFAC and watchlist screening
- Teach CTR/SAR reporting requirements and the alert lifecycle end to end
- Cover retail typologies: structuring, mules, check fraud, elder exploitation, and scams
- Teach SAR narrative writing, with real practice, not just format review
Format
- Deliver live, workshop-style sessions across the two-week block
- Curriculum outline and material available to work from
What we're looking for
- Practitioner experience: has actually worked alert queues and written SARs, practitioner background over certifications
- Prior training or mentoring experience is a plus
- Comfort working with transaction data in Excel is a plus
AML certification (e.g. CAMS) or equivalent professional credential. Experience training teams in fintech or banking specifically — a plus, not required. No technical background needed.
What you'll learn
You'll shape how a graduate cohort enters the financial-crime analyst pipeline at banking clients, delivering inside a training company already active in regulated-industry engagements.
Apply for this role
Upload your resume and tell us why you're a fit.