Skip to main content
Category: Enforcement and Penalties

Look-Back Review

Also known as: Lookback Review, Look-Back, Historical Transaction Review, Retrospective Transaction Review
Simply put

A look-back review is an exercise in which a financial institution re-examines its past transactions and customer activity over a defined earlier period to find suspicious activity that should have been detected or reported at the time but was not. It is typically carried out to fix gaps discovered in the institution's monitoring or reporting, and can result in additional suspicious activity filings for the historical period. It is generally a corrective or remediation measure rather than a routine, ongoing control.

Formal definition

A look-back review (also styled 'lookback' or 'historical transaction review') is a retrospective examination of a defined prior time window of transactions, alerts, customer relationships, or reporting decisions, conducted to identify potentially suspicious activity that was missed, mis-dispositioned, or unreported due to deficiencies in an institution's transaction monitoring, screening, or suspicious activity reporting processes. Such reviews are typically triggered by the discovery of a control failure, whether identified internally (for example, through audit, self-testing, or a system change), by regulatory examination, or pursuant to a supervisory or enforcement action. In the United States, look-backs are frequently required or agreed as part of consent orders or other enforcement actions issued by prudential regulators such as the OCC, FDIC, or Federal Reserve, and may be coordinated with FinCEN expectations under the Bank Secrecy Act framework; in the United Kingdom, comparable retrospective work may arise through a Skilled Person review commissioned under section 166 of the Financial Services and Markets Act 2000, or through remediation undertaken in response to FCA supervisory action. The exact scope, look-back period, customer or product population, and monitoring scenarios covered, is generally defined by reference to the nature and extent of the identified deficiency and is often negotiated with, or dictated by, the relevant authority; a risk-based approach may be applied to prioritize higher-risk segments, though regulators may require broader coverage. Outputs commonly include remediation findings, model or scenario tuning changes, and, where warranted, the filing of suspicious activity reports (SARs) or suspicious transaction reports (STRs) for the historical period, subject to applicable jurisdictional reporting rules. A look-back is a remediation and detection exercise: identifying, filing on, or escalating historical activity does not itself establish that any underlying criminal conduct occurred. Specific triggers, mandated scope, timeframes, and any associated penalties vary by regime and matter and should be confirmed against the applicable regulation, order, or engagement terms.

Why it matters

Look-back reviews sit at the intersection of remediation and regulatory accountability. When an institution discovers, or is told by a supervisor, that its transaction monitoring, screening, or suspicious activity reporting processes were deficient for a period of time, the gap is not merely forward-looking. Activity that should have been detected or reported during the affected window may have gone unexamined, meaning the institution's historical reporting record is potentially incomplete. A look-back is the mechanism through which an institution re-examines that earlier period to identify and, where warranted, report activity it missed at the time. This matters because unaddressed historical gaps can compound regulatory concerns, and because timely, complete suspicious activity reporting is a core expectation under frameworks such as the US Bank Secrecy Act and comparable regimes elsewhere.

Who it's relevant to

AML Compliance Officers and BSA Officers
Compliance leaders are typically responsible for scoping, executing, and documenting look-back reviews, whether triggered internally through audit and self-testing or externally through supervisory or enforcement action. They must ensure the review addresses the identified deficiency, coordinate any resulting historical SAR or STR filings under the applicable reporting framework, and evidence that remediation, such as scenario tuning or process changes, has been implemented.
Financial Intelligence and Investigations Analysts
Analysts often perform the hands-on re-examination of historical alerts, transactions, and customer relationships within the defined look-back period. They apply monitoring scenarios retrospectively, re-assess prior dispositions, and prepare the analysis supporting any historical filings, while recognizing that a historical filing does not by itself establish wrongdoing.
Legal, Risk, and Enforcement Response Teams
Where a look-back arises from a consent order, other enforcement action, or a section 166 engagement, legal and risk professionals manage the institution's obligations to the relevant authority, for example the OCC, FDIC, or Federal Reserve in the US, or the FCA in the UK. They negotiate or interpret mandated scope, timeframes, and deliverables, and confirm requirements against the specific order or engagement terms.
Internal Audit and Independent Testing Functions
Audit and independent testing teams frequently surface the control failures that prompt look-backs and may later assess whether a completed review adequately covered the deficiency and its historical impact. Their findings can both trigger a look-back and validate its sufficiency.

Inside Look-Back Review

Retrospective Transactional Focus
The core of the review is a backward-looking examination of historical transactions, alerts, or relationships over a defined period, rather than prospective or real-time monitoring. Its purpose is to identify activity that may have warranted a SAR/STR filing or that revealed a control gap not previously detected.
Defined Scope and Look-Back Period
A look-back review is bounded by parameters such as the date range covered, the customer segments, products, or risk typologies in scope, and the detection standards applied. Because scope is typically set on a risk-based basis, some activity may fall outside the review, and the exact boundaries should be documented and justified.
Triggers
Reviews are commonly initiated by a regulatory order or enforcement action, by internal discovery of a control weakness or system failure, or by findings from audit or examination. The trigger frequently determines the required scope, period, and level of independent oversight.
Jurisdictional Context
The framework and expectations differ by regime. In the US, look-backs often stem from consent orders issued by agencies such as the OCC or FDIC or from Bank Secrecy Act/FinCEN deficiencies; in the UK they may form part of an FCA skilled person review under section 166. Requirements, terminology, and standards are not uniform across jurisdictions.
Remediation Outcomes
Findings may include the filing of previously missed SARs/STRs, correction of CDD deficiencies, and identification of systemic control failures requiring remediation. The review is a measure to detect and address past gaps, not a guarantee that all missed activity is captured or that wrongdoing occurred.

Common questions

Answers to the questions practitioners most commonly ask about Look-Back Review.

Is a look-back review the same thing as an enforcement penalty or fine?
No. A look-back review is primarily a remediation and compliance exercise, not a penalty in itself. It is a retrospective examination of historical transactions and activity intended to identify suspicious activity that may not have been detected or reported at the time. While a look-back is frequently required as part of an enforcement outcome, such as a consent order or a directed review, the review itself is a corrective and detective measure rather than a sanction. Any monetary penalties are typically imposed separately under the applicable enforcement framework, and the two should not be treated as interchangeable.
Does conducting a look-back review mean the institution has committed a crime or that suspicious transactions found are proven wrongdoing?
No. A look-back review is generally triggered by a regulatory order, an internal discovery of a control gap, or an enforcement action, and its existence does not by itself establish that any offence has occurred. When the review identifies potentially suspicious transactions, those findings may support the filing of reports (such as a SAR or STR, depending on the jurisdiction), but a filing or an alert does not establish that a customer or the institution engaged in criminal conduct. The compliance obligation to detect and report is separate from any criminal-law determination of wrongdoing, which rests with the relevant authorities and courts.
What typically triggers a look-back review?
Triggers generally fall into three broad categories: a regulatory directive or enforcement outcome (for example, a consent order from a US federal banking regulator such as the OCC or FDIC, or a Skilled Person review under section 166 of the UK Financial Services and Markets Act 2000); an internal discovery of a control failure, monitoring gap, or misconfigured detection scenario; and the identification of a specific issue during examination or audit. The precise mechanisms and terminology vary by jurisdiction and by the supervisory body involved, and the applicable order or regulation should be consulted to confirm the specific requirement.
How is the scope and time period of a look-back review typically determined?
Scope is generally set on a risk-based basis and may be defined by the triggering order, by agreement with the supervisor, or by the institution's own assessment of where the deficiency likely had impact. Relevant factors typically include the nature of the control failure, the customer segments, products, or transaction types affected, and the period during which the deficiency was present. Some reviews are bounded by a specified date range in a consent order or directed review, while others require the institution to justify a proportionate window. Exact periods and thresholds vary and should be confirmed against the applicable order or regulatory framework.
Who typically performs a look-back review, and what role does independence play?
A look-back may be conducted by internal teams, by an external third party such as a consultancy or law firm, or by an independent party specified in a regulatory order. In certain regimes, an independent reviewer is required, for example, a Skilled Person appointed under section 166 in the UK, or an independent consultant named in a US consent order. The degree of independence expected generally depends on the severity of the underlying issue and the direction of the supervisor. Where the review is conducted internally, institutions typically need to demonstrate sufficient independence, competence, and resourcing to make the findings credible.
What are common practical outputs and deliverables of a look-back review?
Typical outputs include documentation of the methodology and scope, a population of transactions or accounts reviewed, alerts or cases generated and their dispositions, and any resulting regulatory reports filed under the applicable regime. Institutions generally also produce a report to management and, where required, to the supervisor, along with remediation recommendations addressing the root-cause control weaknesses that prompted the review. Maintaining a clear audit trail of decisions and rationale is generally important, both to support the reliability of the review and to evidence the institution's response to the triggering issue.
How does a look-back review relate to ongoing transaction monitoring and remediation?
A look-back is a retrospective, point-in-time exercise addressing historical activity, whereas transaction monitoring is a forward-looking, ongoing control. The two are complementary: findings from a look-back often inform improvements to monitoring rules, thresholds, and detection scenarios as part of broader remediation. A look-back is generally intended to address activity that ongoing monitoring may have missed during a period of deficiency, but completing one does not guarantee that all suspicious activity has been captured, nor does it eliminate financial crime risk. It should be understood as one measure to detect and mitigate risk within a wider risk-based program.

Common misconceptions

A look-back review is a form of enforcement penalty.
A look-back review is primarily a remediation and compliance exercise. While it is often mandated in connection with or following enforcement action, such as a consent order, the review itself is investigative and corrective in nature, not a punitive sanction.
Identifying activity during a look-back proves that money laundering or wrongdoing occurred.
A look-back may lead to the filing of previously missed SARs or STRs, but a filing reflects suspicion of activity, not established criminal conduct. Findings indicate potential control gaps or reportable activity, and do not by themselves establish that any customer committed an offence.
A look-back review must cover all of an institution's historical activity.
The scope, period, and population are typically defined on a risk-based basis and are often shaped by the trigger and, where applicable, regulatory expectations. Activity outside the defined scope generally falls out of the review, so boundaries should be clearly documented and justified.

Best practices

Clearly document the scope, look-back period, in-scope customer segments, products, and risk typologies, along with the rationale for any activity excluded, so the boundaries of the review are transparent and defensible.
Align the methodology and detection standards to the specific trigger, whether a regulatory order, internal discovery, or enforcement action, and to the expectations of the applicable jurisdiction and supervisory body.
Where a review arises from a consent order or a skilled person requirement, confirm the mandated scope, timeframe, and independence expectations against the specific instrument rather than assuming a universal standard.
Ensure that any previously missed SARs or STRs identified are assessed and filed in line with the obligations of the relevant regime, while treating filings as reflecting suspicion rather than proof of wrongdoing.
Use findings to identify and remediate underlying control failures, treating the review as a measure to detect and address past gaps rather than a one-time exercise that eliminates future risk.
Maintain a clear audit trail of decisions, dispositions, and remediation steps so the review's conclusions can be reviewed by auditors, examiners, or an independent third party.