All roles
beCloudReady / TorontoAIContract, two-week block

AML Instructor

Remote Contract, two-week block beCloudReady / TorontoAI

About us

beCloudReady delivers cloud, data, and AI training to engineers and enterprise teams. TorontoAI is Canada's most active applied AI community, 10K+ members, events across Toronto and beyond.

Learn more about TorontoAI

The role

You'll teach a graduate cohort headed into entry-level financial-crime analyst roles at banking clients, covering the actual regime and workflows they'll be dropped into on day one, not generic compliance theory.

Curriculum

Course 1: AML & Financial Crime Foundations (5 days)

  • AML Foundations
  • Know Your Customer: KYC, CDD & EDD
  • Sanctions, Watchlists & Screening
  • Regulatory Reporting & Recordkeeping
  • Applied Work (Lab)

AML Foundations

  • The three stages of money laundering: placement, layering, and integration.
  • The purpose of an AML program: prevent, detect, investigate, escalate, report, and retain records.
  • Core program pillars: internal controls, independent testing, a designated officer, training, and risk-based due diligence.
  • Risk-based thinking: customer, product, channel, geography, transaction activity, and expected versus actual behaviour.

Know Your Customer: KYC, CDD & EDD

  • Customer identification: information collected at onboarding and how identity is verified.
  • Customer due diligence, beneficial ownership, and establishing expected activity as the baseline for later monitoring.
  • Customer risk rating: geography, product, channel, occupation, business purpose, and activity as rating inputs.
  • Enhanced due diligence: what triggers it, and source of funds versus source of wealth.
  • Risk indicators and red flags: customer profile mismatch, unusual transaction velocity, cash structuring, third-party activity, high-risk geographies, unexplained source of funds, and activity inconsistent with stated occupation or business purpose.

Sanctions, Watchlists & Screening

  • Why sanctions screening is separate from AML but connected to financial-crime operations.
  • Customer and payment screening: real-time screening, batch screening, false positives, possible true matches, and escalation.
  • Name-matching concepts: aliases, transliteration, fuzzy matching, common names, and documentation of the disposition rationale.

Regulatory Reporting & Recordkeeping

  • Suspicious activity escalation: facts, red flags, reasonable suspicion, reviewer expectations, and prohibition on tipping off.
  • Currency transaction and large cash transaction concepts: thresholds, aggregation, documentation, and why analysts never coach customers around reporting limits.
  • Writing an escalation or STR-style narrative: customer profile, transaction facts, red flags, evidence, inference, rationale, and recommendation.

Applied Work (Lab) — Course 1

  • Complete a customer risk-rating file for four synthetic retail customers, with written rationale for each.
  • Disposition a set of synthetic sanctions and watchlist alerts, scored on accuracy and documentation quality.
  • Draft a suspicious activity escalation memo using a supplied customer profile and transaction package.
  • Build an enhanced due diligence file from a supplied customer package.

Course 2: Retail Banking AML — Typologies, Alerts & Investigations

  • Retail Banking & Payments Context
  • Retail AML Typologies
  • The Alert Lifecycle
  • Investigation Toolkit
  • Applied Work (Lab)

Retail Banking & Payments Context

  • Retail products: personal deposit accounts, cards, lending products, and small-business accounts.
  • Payment channels: branch cash, ATM, cheque and remote deposit, ACH or EFT, wires, cards, person-to-person payments, bill payments, and remittances.
  • Normal versus unusual activity: payroll, benefits, rent, seasonal spending, customer occupation, business purpose, source of funds, counterparties, and geography.

Retail AML Typologies

  • Cash structuring across branches, days, ATMs, and accounts.
  • Money mules and funnel accounts: recruitment patterns, account behaviour, and network indicators.
  • Rapid movement of funds, pass-through activity, third-party deposits, unusual wires, and transactions lacking clear economic purpose.
  • Retail fraud patterns that may create AML concerns: account takeover, synthetic identity, scams, elder financial exploitation, and unusual account funding.

The Alert Lifecycle

  • How rules and scenarios generate transaction-monitoring alerts.
  • Triage, investigation, disposition, escalation, case creation, closure, and the evidence each state requires.
  • Queue management: aging, service levels, prioritization, and when to stop investigating and escalate.
  • Quality assurance: reviewer comments, four-eyes review, correction cycles, and documenting work to audit standard.

Investigation Toolkit

  • The investigation lifecycle: understand the alert, verify the customer profile, review transaction history, gather evidence, document findings, make a disposition decision, and escalate when the facts support reasonable suspicion.
  • Timeline construction, entity resolution, counterparty review, source-of-funds indicators, and separating observed facts from inference.
  • Open-source research boundaries: legal and ethical sources, what is off-limits, and how to document external evidence.

Applied Work (Lab) — Course 2

  • Work twelve simulated transaction-monitoring alerts end to end under a queue-management time constraint, dispositioning each with written rationale.
  • Build a complete case file for one escalated alert: transaction timeline, customer-risk summary, key red flags, evidence log, disposition decision, and escalation narrative.
  • Complete a routing exercise: assign six mixed intake items to fraud, AML, or disputes, and justify each routing decision.

Capstone Project: AML Case Study (5 days)

  • Day 1, Profile, clean, reconcile: load the three files, profile every column (shape, completeness, cardinality, types), fix date/amount/whitespace problems in Power Query rather than by hand, deduplicate with a stated rule, join transactions to customers and report how many fail to join and why. Deliverable: a validation log, every defect found, the rule applied, and rows affected.
  • Day 2, Exploratory analysis: distributions of amount and volume, outlier identification, activity by jurisdiction and payment type, time-series view (velocity, bursts, dormancy followed by sudden activity), segment customers by behavior against their assigned risk rating. Deliverable: an EDA findings pack, five findings, each with the evidence and chart that supports it.

Curriculum delivery

  • Teach the BSA/FinCEN regime, KYC/CDD/EDD, and OFAC and watchlist screening
  • Teach CTR/SAR reporting requirements and the alert lifecycle end to end
  • Cover retail typologies: structuring, mules, check fraud, elder exploitation, and scams
  • Teach SAR narrative writing, with real practice, not just format review

Format

  • Deliver live, workshop-style sessions across the two-week block
  • Curriculum outline and material available to work from

What we're looking for

  • Practitioner experience: has actually worked alert queues and written SARs, practitioner background over certifications
  • Prior training or mentoring experience is a plus
  • Comfort working with transaction data in Excel is a plus

AML certification (e.g. CAMS) or equivalent professional credential. Experience training teams in fintech or banking specifically — a plus, not required. No technical background needed.

What you'll learn

You'll shape how a graduate cohort enters the financial-crime analyst pipeline at banking clients, delivering inside a training company already active in regulated-industry engagements.

Apply for this role

Upload your resume and tell us why you're a fit.

Click to upload your resume

We'll only use your information to review your application.