Why pre-screen AML data scientists before the technical panel and MLRO interview
Pre-screening AML data scientists protects the scarcest calendar in the building: the MLRO's. Applicants arrive from three different pools (general data science, bank operations analytics, and vendor or consultancy work), and a resume listing Python, SQL and "transaction monitoring" cannot tell you which. A ten minute screen surfaces whether they have actually tuned thresholds against a live alert queue, whether they can name FATF typologies and SAR timelines unprompted, and whether they explain a model in language an investigator would accept.
What actually matters when screening Anti-Money Laundering (AML) Data Scientist candidates
- 01
Technical proficiency
Probe modelling depth on heavily imbalanced data, plus command of typologies and the sanctions and reporting rules the models serve.
- 02
Systems and trade-offs
Test how they balance detection against alert volume, given every false positive costs an investigator's day.
- 03
Evidence and rigour
Check how they validate models when true labels are late, rare, and partly unknowable.
- 04
Collaboration and communication
Assess how they explain and defend a model to investigators, MLROs, and regulators who need to justify decisions.
Pre-screening questions to ask Anti-Money Laundering (AML) Data Scientist candidates
12 questions grouped by what they test. Ask the same set in every screen and score answers on a consistent scale, or send them as an async video screen and compare answers side by side.
AML domain knowledge
4 questions01How would you describe the job of a data scientist inside an AML programme, as opposed to general analytics?
Listen forThey tie models to obligations: transaction monitoring scenarios, alert triage, SAR quality, sanctions screening tuning, and evidence a validation team or regulator will inspect.
They describe generic fraud or churn modelling and never mention reporting obligations, investigators, or model governance.
02What is your understanding of KYC and EDD requirements, and how do they show up in the data you model?
Listen forThey connect onboarding fields (beneficial ownership, PEP status, source of funds, expected activity) to risk ratings and to features that drive monitoring thresholds.
They define KYC in one textbook line and cannot say which customer attributes ever reached their models.
03How familiar are you with FinCEN rules, the FATF recommendations, and the Basel AML Index, and where have they constrained your work?
Listen forThey cite specifics: FATF typologies or the forty recommendations, FinCEN reporting thresholds and CTR or SAR filing, country risk scoring drawn from Basel or similar indices.
They recognise the acronyms but cannot name a single rule that changed a feature, threshold, or filing decision.
04Explain what a SAR is, and how suspicious activity you surfaced in analysis actually reached a filing.
Listen forThey describe the chain end to end: alert, investigator narrative, escalation to the MLRO, filing deadline, and the feedback loop back into model labels.
They think the data scientist files the SAR, or cannot describe any handoff to an investigations team.
Modelling and rigour
3 questions05Which machine learning algorithms have you used to identify suspicious activity, and how did you handle the class imbalance?
Listen forNamed methods (gradient boosting, isolation forest, graph or network features, entity resolution) plus concrete handling of imbalance: sampling, class weights, precision at k, PR curves.
They quote overall accuracy, or propose deep learning with no answer for a base rate under one percent.
06How do you use Python or R day to day, and which libraries do you reach for on transaction data?
Listen forFluent, unrehearsed detail: pandas or data.table, scikit-learn, XGBoost or LightGBM, networkx or graph tooling, plus version control and reproducible pipelines.
Library names come out vague or dated, and they cannot describe how a model of theirs got into production.
07Walk me through the most complex SQL you have written against transaction data.
Listen forWindow functions, self joins for counterparty pairs, rolling aggregates over customer accounts, and awareness of data volume, partitioning, and query cost.
They only ever consumed extracts prepared by someone else and cannot describe a join beyond simple filters.
Detection trade-offs
3 questions08Describe a scenario where predictive modelling reduced an AML risk, and tell me what it did to alert volume.
Listen forNumbers on both sides: alerts before and after, false positive rate, investigator hours freed, and what they accepted losing in recall to get there.
They report only detection gains and treat rising alert volume as somebody else's operational problem.
09Have you developed or improved a transaction monitoring system, and how did you prove the change was safe to ship?
Listen forAbove-the-line and below-the-line testing, champion challenger runs, retired or retuned scenarios, documentation for model validation, and sign-off from the MLRO or audit.
They changed thresholds with no backtesting, no documentation, and no independent validation before go-live.
10Pick one complicated AML problem you solved with data science and walk me through it as if I were the MLRO.
Listen forA clear narrative for a non-technical decision maker: the typology suspected, features used, limits of the model, and why the output can be defended to a regulator.
They retreat into model internals and jargon, unable to state the business decision the model supported.
Background and logistics
2 questions11How many years have you worked inside financial crime compliance, and in which sectors?
Listen forSpecific settings (retail bank, payments, crypto exchange, correspondent banking) with the regulator involved and the size of the customer or transaction base.
All exposure is a short vendor project or coursework with no ownership of a live monitoring or screening process.
12Do you hold any AML or data science certifications, and are there any restrictions on background screening or start date we should know about?
Listen forStraight answers on CAMS, ICA, CFCS or cloud and ML credentials, plus clarity on notice period, vetting or fingerprinting history, and location or onsite constraints.
Evasiveness about background checks or previously failed vetting, or an inflated certification they cannot date.
How to score responses
Score every candidate on the same four criteria immediately after the screen. At this stage you are shortlisting for panel interviews, not making the final call.
Technical proficiency
35%5Strong on imbalanced-data modelling and fluent in the typologies and reporting rules the models exist to serve.
Systems and trade-offs
25%5Reasons explicitly about detection versus investigator capacity, and names the threshold trade-off they chose.
Evidence and rigour
25%5Validates rigorously despite late and incomplete labels, and can describe a model failure they caught themselves.
Collaboration and communication
15%5Explains and defends models to investigators and regulators in terms that support a documented decision.
Async video shows you the part that matters most here: whether they can walk an MLRO through a threshold decision out loud, without jargon, and sound credible defending it to a regulator.
Try it on HirevireScreening FAQ
Process basics
What should an AML data scientist screen cover in ten minutes?
Cover four things: one domain check (SARs, KYC or EDD, sanctions screening), one modelling check on imbalanced data, one question about alert volume and false positives, and one on how they explained a model to compliance. Skip generic data cleaning questions; the panel can test those on a live dataset later.
Do AML data scientists need a CAMS certification?
No, CAMS or ICA certification is useful signal but not a requirement for a modelling seat. What matters more is time inside a monitoring stack (Actimize, Verafin, Oracle Mantas, Hawk or an in-house engine) and familiarity with FinCEN, FATF and local reporting rules. Treat certification as a tiebreaker, not a filter.
Evaluating answers
How do you tell real transaction monitoring experience from vendor-adjacent experience?
Ask what happened after deployment. Real experience produces numbers and friction: alert volume before and after, false positive rate, how many investigators worked the queue, which scenario they retired, what the model validation team or auditor challenged. Vendor-adjacent answers stay at the level of tools, pipelines and dashboards.
What is a red flag when an AML data scientist talks about model accuracy?
Quoting accuracy at all is the red flag. With money laundering base rates below a fraction of a percent, accuracy is meaningless; strong candidates talk precision at a given alert budget, recall against confirmed SARs, and the label lag between an alert and a confirmed outcome months later.
























