Federal anti-money laundering compliance program requirements come from the Bank Secrecy Act and FinCEN’s implementing regulations, and at their core they require every covered financial institution to build a written program with five specific elements, file two types of reports on strict deadlines, keep records for five years, and screen against U.S. sanctions lists. The consequences for failing run from civil penalties measured per violation to criminal prison terms of up to ten years.1Office of the Law Revision Counsel. 31 US Code 5322 – Criminal Penalties
Which Businesses Are Covered
The Bank Secrecy Act’s definition of “financial institution” reaches well past banks. The statutory list includes credit unions, insurance companies, broker-dealers, casinos with more than $1 million in annual gaming revenue, dealers in precious metals and jewels, money services businesses, loan companies, pawnbrokers, vehicle dealers, and persons involved in real estate closings. Treasury can add other business types whose cash transactions are useful in criminal or tax investigations.2Office of the Law Revision Counsel. 31 US Code 5312 – Definitions and Application
Money services businesses have an extra step before anything else. Any company that qualifies as an MSB must file FinCEN Form 107 within 180 days of beginning operations, and operating as an unregistered MSB is itself a federal crime.3Financial Crimes Enforcement Network. Money Services Business (MSB) Registration Businesses that transmit money, cash checks, exchange currency, or sell prepaid access should confirm their status before designing anything else.
The Five Pillars of an AML Program
Under 31 U.S.C. § 5318(h), every covered institution must maintain an anti-money laundering and counter-terrorism financing program that includes, at minimum, four statutory elements.4Office of the Law Revision Counsel. 31 USC 5318 – Compliance, Exemptions, and Summons Authority FinCEN’s Customer Due Diligence rule added a fifth. Together they define what a compliant program looks like on paper.
Written Policies, Procedures, and Controls
The written program has to address the specific products, services, customer types, and geographies the business actually handles. A wire transfer desk and a retail branch face different risks, and the procedures need to reflect that. Off-the-shelf policies are a common reason programs fail their first audit.
A Designated Compliance Officer
The statute requires a named individual responsible for day-to-day operation of the program and serving as the primary point of contact for regulators and law enforcement. The role only functions if that person has genuine authority: direct access to senior management, an adequate budget, and the ability to implement changes without being overruled by revenue-generating business lines.
Ongoing Employee Training
Every staff member who touches transactions or interacts with customers needs role-specific training. A teller needs to understand structuring indicators. A relationship manager needs to recognize suspicious account activity over time. Training has to be updated as regulations change, and the business should document attendance and test comprehension.
Independent Testing
An independent audit function must evaluate whether the program actually works. No regulation sets a fixed frequency, but a cycle of every 12 to 18 months is widely accepted for institutions with a moderate risk profile.5FFIEC BSA/AML InfoBase. FFIEC BSA/AML Assessing the BSA/AML Compliance Program – BSA/AML Independent Testing Qualified internal staff who sit outside the compliance function can perform the review, or a third-party firm can. Either way, the auditors test whether the institution follows its own policies and whether those policies satisfy current law.
Customer Due Diligence
The fifth pillar, added by FinCEN regulation at 31 C.F.R. § 1010.230, requires written procedures for identifying and verifying the beneficial owners of legal entity customers.6eCFR. 31 CFR 1010.230 – Beneficial Ownership Requirements for Legal Entity Customers When a legal entity opens an account, the institution must identify every individual who directly or indirectly owns 25 percent or more of the entity’s equity interests, plus at least one individual with significant management control such as a CEO or managing member. The rule also requires ongoing monitoring: when a customer’s transaction patterns shift substantially from their established profile, the institution has to investigate and, when warranted, file a Suspicious Activity Report.7Financial Crimes Enforcement Network. About FinCEN
For individual customers, the baseline information collected at account opening is legal name, physical address, date of birth, and an identification number such as a Social Security number or taxpayer identification number. For corporate clients, the institution collects the entity’s legal name, tax identification number, formation documents, and beneficial ownership information. That baseline becomes the reference point for every monitoring decision that follows.
The Two Reports You Have to File
Two filings carry most of the compliance workload: Currency Transaction Reports and Suspicious Activity Reports. Filing failures are among the most common triggers for enforcement actions, so the thresholds and deadlines deserve careful attention.
Currency Transaction Reports
A CTR is required for any transaction in currency exceeding $10,000, covering deposits, withdrawals, exchanges, and other payments.8eCFR. 31 CFR 1010.311 Transactions must be aggregated: if the institution knows multiple transactions on the same business day are by or on behalf of the same person and the total exceeds $10,000, a CTR is required. The filing deadline is 15 calendar days after the transaction date.9Financial Crimes Enforcement Network. FinCEN Currency Transaction Report (FinCEN CTR) Electronic Filing Requirements
Suspicious Activity Reports
SAR thresholds shift with the circumstances:
- Any known or suspected criminal violation involving a director, officer, employee, or other institution-affiliated party must be reported regardless of the dollar amount.
- When the institution has a substantial basis for identifying a suspect, a SAR is required for transactions of $5,000 or more.
- When no suspect can be identified, the threshold rises to $25,000 or more.
- Any transaction of $5,000 or more that the institution knows or suspects involves illegal funds, is designed to evade BSA requirements, or lacks any apparent lawful purpose triggers a mandatory SAR filing.10eCFR. 12 CFR 208.62 – Suspicious Activity Reports
The SAR must be filed within 30 calendar days of the date the institution first detects facts that could support a filing. If no suspect has been identified by then, the institution may take an additional 30 days to identify one, but reporting cannot be delayed beyond 60 calendar days total from initial detection. Situations that need immediate attention, such as active money laundering schemes, also require a phone call to law enforcement.11eCFR. 31 CFR 1020.320 – Reports by Banks of Suspicious Transactions
Both CTRs and SARs must be filed electronically through FinCEN’s BSA E-Filing System. Paper forms are no longer accepted.12Financial Crimes Enforcement Network. Bank Secrecy Act Filing Information The system requires user registration and role-based access for personnel authorized to submit reports, and FinCEN publishes detailed filing instructions for each report type.13Financial Crimes Enforcement Network. FinCEN Suspicious Activity Report (FinCEN SAR) Electronic Filing Instructions
Recordkeeping and the Travel Rule
All records required under the BSA must be retained for five years and stored so they can be produced within a reasonable period.14eCFR. 31 CFR 1010.430 – Nature of Records and Retention Period That covers CTR and SAR filings, customer identification records, transaction logs, and confirmation receipts from the E-Filing System. An institution that cannot produce its records invites enforcement even when the underlying filings were correct.
The Travel Rule adds a recordkeeping layer for funds transfers of $3,000 or more. The transmittal order must include the sender’s name, address, and account number; the transfer amount and date; the recipient’s financial institution; and as much information about the recipient as the sender provides.15FFIEC BSA/AML InfoBase. Funds Transfers Recordkeeping Intermediary institutions that handle the transfer in transit must pass that information to the next institution in the chain, so law enforcement can trace funds from origin to destination.
Sanctions Screening and OFAC
A compliance program that ignores sanctions screening is incomplete. Every U.S. person and business with access to the U.S. financial system is legally prohibited from transacting with parties on OFAC’s lists, whether or not the organization has a formal screening program.
OFAC does not technically require a written sanctions compliance program, but it strongly encourages one and treats the absence of a program as an aggravating factor when assessing penalties.16U.S. Department of the Treasury. A Framework for OFAC Compliance Commitments In practice, any institution subject to BSA obligations should integrate sanctions screening into its AML framework, screening customers and counterparties at onboarding and on an ongoing basis against OFAC’s Specially Designated Nationals list and other sanctions lists.
Civil penalties for sanctions violations under the International Emergency Economic Powers Act can reach $377,700 per violation, and criminal penalties for willful violations can include up to 20 years in prison.17Federal Register. Inflation Adjustment of Civil Monetary Penalties OFAC launched a voluntary self-disclosure portal in February 2026 for organizations that discover potential violations internally, and self-disclosure is treated as a significant mitigating factor in penalty calculations.18Office of Foreign Assets Control. Launch of Voluntary Self-Disclosure Portal
Enhanced Due Diligence for Higher-Risk Relationships
Federal guidance emphasizes that no category of customer is automatically high risk, and regulators do not expect institutions to refuse entire classes of business. The expectation is a risk-based approach where the depth of review matches the risk the relationship actually presents.19FFIEC BSA/AML InfoBase. Risks Associated with Money Laundering and Terrorist Financing – Introduction
Examiners nonetheless look closely at relationships involving politically exposed persons (foreign individuals entrusted with prominent public functions, along with immediate family and close associates), non-bank financial institutions, cash-intensive businesses, third-party payment processors, correspondent accounts, and entities tied to jurisdictions with weak AML controls.20FFIEC BSA/AML InfoBase. Politically Exposed Persons For these relationships, enhanced due diligence typically means collecting additional information about the source of funds, the customer’s government responsibilities or business activities, the geographies involved, and the expected volume and nature of transactions. Documenting the reasoning matters as much as the analysis itself.
Structuring and Why Staff Need to Spot It
Federal law makes it illegal to break up transactions to evade BSA reporting. This practice, called structuring, carries criminal penalties of up to five years in prison. When it occurs while violating another federal law or as part of a pattern involving more than $100,000 over 12 months, the maximum rises to ten years.21Office of the Law Revision Counsel. 31 US Code 5324 – Structuring Transactions to Evade Reporting Requirement Prohibited
Program design has to account for it. Staff need to recognize the patterns in real time. A customer who makes four $2,800 cash deposits across different branches on the same day is almost certainly trying to stay below the $10,000 CTR threshold. Training should cover common structuring indicators, and monitoring systems should flag transactions that look designed to avoid the reporting trigger. The institution itself can face liability for failing to detect and report structuring even when the criminal act is the customer’s.
What Non-Compliance Costs
Civil Penalties
An institution or its personnel that willfully violates the BSA faces a civil penalty of up to $25,000 per violation or the amount involved in the transaction (capped at $100,000), whichever is greater.22Office of the Law Revision Counsel. 31 USC 5321 – Civil Penalties For certain recordkeeping failures, each day the violation continues counts as a separate violation. Negligent violations carry a lower penalty of up to $500 per occurrence, but a pattern of negligent violations can trigger an additional penalty of up to $50,000. These base statutory amounts are subject to periodic inflation adjustments.
Criminal Penalties
Willful BSA violations can result in fines up to $250,000 and imprisonment for up to five years. When the violation occurs alongside another federal crime or as part of a pattern of illegal activity exceeding $100,000 in a 12-month period, the maximum fine doubles to $500,000 and the prison term rises to ten years.23Office of the Law Revision Counsel. 31 USC 5322 – Criminal Penalties Courts may also order convicted individuals to disgorge profits gained from the violation and, if the person was an officer or employee of the institution, repay any bonus received during the calendar year of the violation.
FinCEN maintains a public list of its enforcement actions, and the pattern is clear: the largest penalties tend to involve institutions that had no real program, ignored deficiencies flagged in prior examinations, or allowed suspicious activity to continue long after it should have been reported.24Financial Crimes Enforcement Network. Enforcement Actions A documented, functioning program that the institution actually follows is the single best defense.
Building the Program in Practice
A compliance program exists on paper and in practice. The written component starts with a risk assessment that evaluates the institution’s products, services, customer base, and geographic exposure. That assessment drives the depth of customer due diligence, the frequency of transaction monitoring, the sensitivity of automated alert thresholds, and the topics covered in employee training. A program that treats every customer and product line identically wastes resources on low-risk areas and leaves high-risk areas exposed.
Organize the data your program will rely on before it goes live. For individuals, that means legal name, address, date of birth, and identification numbers. For entities, add formation documents and beneficial ownership information. Map your transaction data to the fields you will need for CTR and SAR filings, including amounts, dates, methods, and parties. FinCEN’s electronic filing instructions specify the exact data format expected for each report type, and building your data collection around those formats from the start saves considerable time later.
Categorize customers and products into risk tiers. Higher-risk categories generally include customers in jurisdictions with weak AML oversight, cash-intensive businesses, and relationships involving complex corporate structures. The risk tier determines monitoring frequency, with higher-risk relationships warranting more frequent and more detailed reviews. Revisit the risk assessment annually, or sooner if the business model changes.
Management should review the overall program at least once a year, separate from the independent audit. That annual review confirms monitoring technology is functioning, staffing is adequate, training is current, and the institution has responded to regulatory changes. The independent audit on a 12-to-18-month cycle then provides an external check. A clear audit trail of decisions, escalations, and filings is what demonstrates to regulators that the program operates as designed.