Skip to content
KnowledgeCity

By Maryam Hintzen

How a Learning Library Helps Banks Keep Annual Compliance Refresher Training on Track

16 min read

How a Learning Library Helps Banks Keep Annual Compliance Refresher Training on Track

Key Takeaways

  • US banks are required to train appropriate personnel on multiple federal compliance obligations, including BSA/AML, OFAC sanctions, information security, funds availability, identity theft red flags, and bank protection. Annual refreshers are common industry practice even where the underlying regulation says ongoing.
  • A learning library moves the work of keeping course content current, for the topics it covers, from the bank's internal team to the content vendor. That maintenance is where most banks lose time when they build compliance courses themselves.
  • A strong bank learning library delivers pre-built courses for the topics that recur every year, tracks completion with examiner-ready records, and is maintained by the provider as rules and guidance move.
  • Evaluating a learning library for banking compliance requires looking beyond course counts to how content is kept current, LMS integration, reporting that stands up at examination, and role-based curriculum design.

Every US bank runs an annual compliance training cycle that touches almost every employee. The FDIC's own examination manual spells out the reach: at a minimum, a bank's training program must cover all operational personnel whose duties may require knowledge of the BSA, naming tellers, new accounts personnel, lending personnel, bookkeeping personnel, wire room personnel, international department personnel, and information technology personnel.

Layer the consumer and operational rules on top and the picture widens further. Frontline tellers train on BSA/AML, funds availability, and red flag identification. Lending staff train on TILA, RESPA, ECOA, Fair Lending, and UDAAP. IT and operations staff train on GLBA information security and physical bank protection. Directors and officers train on their governance responsibilities across the full compliance stack.

The Regulatory Foundation at a Glance

Multiple federal regulations require banks to train appropriate personnel on specific compliance obligations. The core citations behind the annual training calendar are as follows.

BSA/AML training pillar:

  • 31 U.S.C. 5318(h)(1)(C): Statutory basis for the ongoing employee training program in a financial institution's AML program.
  • 31 CFR 1020.210(a)(2)(iv): Requires banks to provide training for appropriate personnel as one of the pillars of a BSA/AML compliance program. The parallel requirement for banks that lack a Federal functional regulator sits at 31 CFR 1020.210(b)(2)(iv).
  • 12 CFR 208.63(c)(4) (Federal Reserve), 12 CFR 326.8(c)(4) (FDIC), and 12 CFR 21.21(d)(4) (OCC): Parallel agency rules, each requiring banks to provide training for appropriate personnel. Customer Identification Program obligations at 31 CFR 1020.220 sit inside the same BSA/AML program, and 12 CFR 21.21(c)(2) says so directly, requiring the CIP to be implemented as part of the BSA compliance program. CIP therefore belongs on the same training calendar.

Examiner expectation for BSA/AML frequency:

  • FDIC Risk Management Manual of Examination Policies, Section 8.1: Lists ongoing employee training programs among the required elements of a BSA compliance program, and states that training should be comprehensive, conducted regularly, and clearly documented.
  • FFIEC BSA/AML Examination Manual: Training should incorporate current developments and changes to regulatory requirements, supervisory guidance, internal policies, and the bank's products and customer base.

OFAC sanctions training:

  • OFAC's Framework for Compliance Commitments (May 2, 2019): Training should be provided to all appropriate employees and personnel on a periodic basis and, in OFAC's own words, at a minimum annually.

Information security and customer data:

  • 12 CFR Part 30, Appendix B (Interagency Guidelines Establishing Information Security Standards): Directs banks to train staff to implement the information security program. Parallel guidelines apply at the other banking agencies.

Operational compliance training:

  • 12 CFR 229.19(f) (Regulation CC funds availability): Titled Employee training and compliance, it requires each bank to establish compliance procedures and give every affected employee a statement of the procedures that apply to their duties.
  • FCRA Identity Theft Red Flags: The program must train staff, as necessary, to implement it effectively. The citation depends on the bank's regulator: 12 CFR 222.90(e)(3) for Federal Reserve member banks other than national banks, 12 CFR 41.90(e)(3) for national banks, and 12 CFR 334.90(e)(3) for state nonmember banks.
  • 12 CFR 21.3(a)(3) (OCC) and 12 CFR 208.61(c)(1)(iii) (Federal Reserve) under the Bank Protection Act: Both require initial and periodic training of employees in their responsibilities under the security program.

Consumer compliance guidance:

  • Federal Reserve Consumer Compliance Outlook, First Issue 2019, Enhancing Your Compliance Training Program: Positions training as a core control for Community Reinvestment Act, fair lending, and UDAP risk.

What Is Changing in 2026

The citations above are current law. 2 rulemakings published in April 2026 would change several of them, and a separate change is already in force.

FinCEN published a proposed rule on April 10, 2026 that would reform how financial institutions build and run their AML/CFT programs. The OCC, FDIC, and NCUA published a companion proposal the same day, announced in OCC Bulletin 2026-11 on April 7, 2026, that would amend the BSA compliance program rules each agency issues for the banks it supervises, including a risk assessment process that takes account of FinCEN's national AML/CFT priorities. Comments on both closed on June 9, 2026. Neither has been finalized, so 31 CFR 1020.210, 12 CFR 208.63, 12 CFR 326.8, and 12 CFR 21.21 stand as written. A bank should track both without teaching them as settled law.

One change has already taken effect. FinCEN order FIN-2026-R001, issued February 13, 2026, removed the requirement to identify and verify a legal entity customer's beneficial owners at every new account opening. Institutions now collect that information when the customer first opens an account and update it when their risk-based procedures call for it. That changes what front-line staff should be taught about a returning business customer, which makes it a training-content change as much as a procedural one.

Building and maintaining all of this in-house every year is a substantial workload for a bank's L&D and compliance teams. A learning library changes the economics for the topics it covers by moving that maintenance to the content vendor. This blog walks through what a bank annual training calendar contains, why the calendar falls behind without library-backed content, and how to evaluate a learning library for banking compliance use.

The Compliance Training Environment Banks Face Every Year

The annual training calendar at a US bank is not a single event. It is a rolling program of role-based courses delivered across the calendar year, each tied to a specific regulatory obligation or examiner expectation. Understanding the scope is the first step toward evaluating whether a learning library covers the calendar the bank needs to run.

BSA/AML, OFAC, and Sanctions Training

BSA/AML training is the most visible pillar of the bank annual compliance calendar. 31 CFR 1020.210(a)(2)(iv) and 31 U.S.C. 5318(h)(1)(C) require the training program as part of a bank's AML compliance program. Related agency regulations at 12 CFR 208.63(c)(4), 12 CFR 326.8(c)(4), and 12 CFR 21.21(d)(4) impose parallel training requirements. OFAC's 2019 Framework expects sanctions training at a minimum annually for appropriate employees. FinCEN and the federal banking agencies both examine BSA/AML training as part of routine supervision.

Information Security, GLBA, and Customer Data Protection

The Interagency Guidelines Establishing Information Security Standards, at 12 CFR Part 30, Appendix B for national banks and in parallel form at the other agencies, direct banks to train staff to implement the information security program. In practice, banks deliver GLBA and information security awareness training annually to all employees who handle customer data.

Consumer Financial Protection Training

The consumer financial protection layer of the annual calendar covers TILA, RESPA, ECOA, Fair Lending, FCRA, UDAAP, and Community Reinvestment Act obligations. No single regulation imposes an explicit annual training mandate across all of them, but Federal Reserve Consumer Compliance Outlook identifies CRA, fair lending, and UDAP as topics strong programs cover periodically, and industry practice runs these as annual refreshers for staff whose duties involve consumer-facing products.

Operational Compliance Training

Beyond BSA/AML and consumer protection, banks train on Regulation CC funds availability, FCRA Identity Theft Red Flags, and Bank Protection Act physical security. Each of these rules specifies training for staff whose duties involve the covered activities, and each is a standard element of the bank annual training calendar.

Why Annual Refresher Training Falls Behind Without a Learning Library

The compliance training calendar is stable in its scope but dynamic in its content. Regulations change. Interagency guidance updates. Examiner expectations shift. The gap between what the bank trained on last year and what the current regulatory environment requires is where most compliance training programs quietly fall behind.

Regulatory Refresh Burden on Internal Teams

Banks that build compliance training themselves carry the update work on their own team. When a new FinCEN geographic targeting order lands, an FFIEC BSA/AML Examination Manual section is revised, an OFAC program changes, or a state UDAP interpretation shifts, the bank's compliance and L&D team has to identify the change, update the course content, review the update, republish, and track re-completion. Training that was defensible on January 1 can be out of date by March if a regulatory update lands early in the year and the internal team has not caught up.

Content Development Cost and Timeline

Custom course production carries a real cost in staff time before any vendor invoice appears. A subject matter expert has to draft the content, compliance has to review it for regulatory accuracy, an instructional designer has to build it, and somebody has to version and republish it every time the underlying rule moves. Multiply that by a calendar covering BSA/AML, OFAC, GLBA, Regulation CC, Red Flags, Fair Lending, UDAAP, CRA, and the operational topics, and the maintenance alone becomes a standing commitment. The library alternative moves course production and upkeep for the covered topics to the vendor.

Examiner Documentation Gaps

Federal banking examiners who evaluate compliance training expect to see current course content, completion records tied to specific employees, evidence of periodic refresh, and documentation of the training needs analysis that justified the calendar. Banks running custom content often have solid completion records but struggle with the currency and refresh documentation, because internal content updates lag regulatory changes. This is the operational failure pattern behind the question of whether your banking LMS is examination-ready, where the system holds the completion data but does not demonstrate the regulatory currency examiners expect.

WHO KEEPS BANK COMPLIANCE COURSES CURRENT Bank builds its own An internal team rewrites courses each year Library carries them The provider updates the recurring topics Topics that recur BSA/AML, OFAC, GLBA, consumer protection What to evaluate How the content is kept current Ask who updates the course, not how many courses there are

What a Bank-Ready Learning Library Provides

A learning library that works for banking compliance covers a specific set of capabilities that distinguish it from a general-purpose corporate training catalog. Understanding what bank-ready means at the library level is the second step in evaluating whether a library fits the annual training calendar.

Pre-Built Coverage of the Annual Compliance Calendar

The value of a library is that the recurring topics are already built, so the compliance team is not drafting core course content from scratch each year. The practical step is to look at the catalog alongside the bank's own calendar and see how much of the year it already carries, and where the bank would prefer to add its own material.

Regulatory Refresh Cadence Written Into the Product

Content that sits still goes stale, so it matters that someone other than the bank is responsible for keeping courses current as rules and guidance move. A vendor-maintained catalog puts that work on the provider, which is the difference between a library and a folder of files the bank has to revisit itself.

Examiner-Ready Completion Records

The library needs to produce completion records that hold up when an examiner asks for them. That means per-employee course completion dates, the version of the course completed, evidence that the version was current for the regulatory period, and reporting that aggregates completion by department and role. This is what turns training from a compliance activity into examinable evidence.

Role-Based Curriculum Design

Bank employees do not all need the same training. A teller does not need the same course content as a mortgage lender or an IT security engineer. The library should support role-based curricula that assign the right courses to the right employees, with assignment triggered automatically by role, department, or job code from the HRIS. This is what makes the library a working operational tool rather than a catalog the compliance team assigns by hand every year.

How to Evaluate a Learning Library for Banking Compliance

Evaluating a learning library for bank compliance training involves criteria that go beyond course counts. Banks that select on features alone often end up with a library that looks strong on paper and produces gaps at examination time.

Content Coverage Checklist

Put the catalog next to the bank's own training calendar and see how the 2 line up. The goal is a clear picture of what is already built and what the bank would rather shape itself, so the year is planned rather than assembled in pieces.

Regulatory Update Commitment

Ask how content is kept current and who owns that work. What helps is that maintaining and refreshing the catalog sits with the provider rather than with the compliance team, so the calendar does not depend on internal capacity in a busy quarter.

LMS Integration and Assignment Automation

The library needs to integrate with the bank's LMS so that assignments, completion tracking, and reporting flow through one system. If the library requires manual assignment, or produces completion data that has to be reconciled to the LMS by hand, the operational load shifts back to the compliance team.

Examiner Documentation Reporting

Test the library's reporting against a hypothetical examiner request. The vendor should be able to show reports covering which employees completed which course version on which date, what the course covered, and what regulatory guidance it reflects. If those reports require manual assembly, the work lands back on the compliance team at the worst moment.

Role-Based Curriculum Alignment

Confirm that the library supports role-based curriculum assignment and that the roles map to the bank's actual job codes and departments. A library that supports only a default all-employee and all-manager curriculum leaves the bank building role-specific assignments manually.

Put Your Training Calendar Next to the Catalog

Walk through your annual topics with a KnowledgeCity specialist and see what is already built, what you would shape yourself, and how the year would run.

Explore KC Library

How KC Library and KC LMS Support Bank Annual Compliance Training

KnowledgeCity's Learn suite splits the work across 2 solutions: KC Library holds the content, and KC LMS runs the assignment, completion, and reporting.

What KC Library Provides for Bank Compliance Content

KC Library is a maintained catalog of 50,000+ training videos in multiple languages, with new content added monthly and delivery on any system through SCORM, xAPI, or API. It is recognized by PMI, SHRM, HRCI, and IIBA for professional recertification credits.

For a bank, the relevant material sits in the Finance and Compliance categories. Finance covers filing suspicious activity reports to anti-money laundering standards, detecting fraud in bank transactions from behavioral warning signs, and retail banking operations. Compliance covers global compliance essentials and legal and ethics training. Alongside the catalog, KC LMS lets a bank build and publish its own courses, so institution-specific material sits in the same catalog, assigns through the same engine, and lands on the same employee record as library content.

What KC LMS Provides for Assignment, Completion, and Reporting

KC LMS handles the assignment engine, completion tracking, and reporting that connect course content to the individual employee record.

  • Compliance and Assignment Engine: Rule-based recurring assignments with an audit-ready trail, so role-specific training assigns automatically by role, department, location, and hire date.
  • Learning Paths and Curricula: Sequenced courses, prerequisites, and path-level certificates that run the annual compliance curriculum by role.
  • Course Delivery and Assessments: SCORM, xAPI, AICC, video, quizzes, and question banks, with knowledge checks that produce completion evidence.
  • Certification and Recertification: Automatic certificate issuance with expiry-driven recertification that tracks the annual cycle.
  • Bulk Assignment With Exclusions: Assign to everyone matching a filter in one step, with exclusions for staff who have already completed the current cycle.
  • Reporting and Integrations: A dashboard carrying the live compliance picture, reports built on the dimensions you need including org unit, course, status, and date range, with one-click export, plus SSO, SCIM, HRIS, and webhook integrations.

What the Combination Produces

Together, KC Library and KC LMS make the annual compliance calendar a managed workflow rather than an internal content project. The library holds the courses it covers. The LMS assigns them, tracks completion, and produces reports. The compliance officer sees completion status by role and department in one view. The examiner sees a current record of what the bank trained on and who completed which version.

Frequently Asked Questions

1. What compliance training do banks need every year?

US banks train appropriate personnel on BSA/AML, OFAC sanctions, GLBA information security, Regulation CC funds availability, FCRA identity theft red flags, and Bank Protection Act physical security. Federal Reserve guidance adds CRA, fair lending, and UDAP. Each rule names the staff whose duties require the knowledge, so the calendar is role-based rather than one course for everyone.

2. Is BSA/AML training required every year?

No, not by the regulation itself. Federal rules require training for appropriate personnel without naming a frequency. The exception is OFAC sanctions training, where the 2019 Framework expects it at a minimum annually. Most banks run the whole calendar as annual refreshers and document each round.

3. Why use a learning library for compliance training?

It moves course upkeep to the content vendor for the topics the catalog covers. When a rule or a piece of guidance changes, the vendor updates the affected courses. A bank building training itself has to catch the change, revise the content, review it, republish, and chase re-completion.

4. How do you choose a compliance training library?

Check 5 things: how much of the recurring calendar the catalog already carries, who keeps content current, LMS integration with automated role-based assignment, completion reporting that ties employees to specific course versions, and curricula that map to the bank's real roles and departments.

5. What does KnowledgeCity offer banks for compliance training?

KC Library supplies the courses, including suspicious activity reporting, fraud detection in bank transactions, retail banking operations, and general compliance and ethics. KC LMS assigns training by role, tracks completion, produces the reports, and lets the bank publish its own courses alongside the catalog. Both sit in the Learn suite.

References

  1. United States Code, Office of the Law Revision Counsel. 31 U.S.C. 5318, Compliance, exemptions, and summons authority.
  2. Electronic Code of Federal Regulations. 31 CFR 1020.210, Anti-money laundering program requirements for banks.
  3. Electronic Code of Federal Regulations. 31 CFR 1020.220, Customer identification program requirements for banks.
  4. Electronic Code of Federal Regulations. 12 CFR 208.63, Procedures for monitoring Bank Secrecy Act compliance.
  5. Electronic Code of Federal Regulations. 12 CFR 326.8, Bank Secrecy Act compliance.
  6. Electronic Code of Federal Regulations. 12 CFR 21.21, Procedures for monitoring Bank Secrecy Act (BSA) compliance.
  7. Electronic Code of Federal Regulations. 12 CFR 229.19, Miscellaneous.
  8. Electronic Code of Federal Regulations. 12 CFR 222.90, Duties regarding the detection, prevention, and mitigation of identity theft.
  9. Electronic Code of Federal Regulations. 12 CFR 41.90, Duties regarding the detection, prevention, and mitigation of identity theft.
  10. Electronic Code of Federal Regulations. 12 CFR 334.90, Duties regarding the detection, prevention, and mitigation of identity theft.
  11. Electronic Code of Federal Regulations. 12 CFR 21.3, Security program.
  12. Electronic Code of Federal Regulations. 12 CFR 208.61, Bank security procedures.
  13. Electronic Code of Federal Regulations. 12 CFR Part 30, Appendix B, Interagency Guidelines Establishing Information Security Standards.
  14. Federal Financial Institutions Examination Council. BSA/AML Examination Manual, BSA/AML Training.
  15. Federal Deposit Insurance Corporation. Risk Management Manual of Examination Policies, Section 8.1.
  16. Office of Foreign Assets Control. A Framework for OFAC Compliance Commitments. , May 2, 2019.
  17. Financial Crimes Enforcement Network. Anti-Money Laundering and Countering the Financing of Terrorism Programs, Notice of Proposed Rulemaking. , April 10, 2026.
  18. Office of the Comptroller of the Currency, Federal Deposit Insurance Corporation, and National Credit Union Administration. Anti-Money Laundering and Countering the Financing of Terrorism Programs, Notice of Proposed Rulemaking. , April 10, 2026.
  19. Office of the Comptroller of the Currency. Bulletin 2026-11, Anti-Money Laundering and Countering the Financing of Terrorism Program Requirements. , April 7, 2026.
  20. Financial Crimes Enforcement Network. Exceptive Relief from Requirement to Identify and Verify Beneficial Owners, FIN-2026-R001. , February 13, 2026.
  21. Federal Reserve. Consumer Compliance Outlook, Enhancing Your Compliance Training Program. , First Issue 2019.

Everything your workforce needs, on one platform.

A quick walkthrough tailored to your team — learning, compliance, skills, and performance in one place.