A BSA/AML compliance program is the written system a financial institution uses to detect and report money laundering, and federal law requires every covered institution to build one around four mandatory pillars: internal policies and controls, a designated compliance officer, ongoing employee training, and independent testing.1Office of the Law Revision Counsel. 31 USC 5318 – Compliance, Exemptions, and Summons Authority On top of those pillars sit customer identification and due diligence rules, a documented risk assessment, transaction reporting duties, sanctions screening, and recordkeeping obligations that all have to work together. Miss a piece and the penalties escalate quickly, from per-instance civil fines into criminal exposure for the institution and the individuals running it.
“Financial institution” under the Bank Secrecy Act is a broad category. Banks, credit unions, thrifts, and SEC-registered broker-dealers are the obvious names, but the statute also reaches insurance companies, casinos above $1 million in annual gaming revenue, money services businesses, dealers in precious metals and jewels, loan and finance companies, and others.2Office of the Law Revision Counsel. 31 USC 5312 – Definitions and Application of This Subchapter If your organization is covered, you need a written program, and the requirements below apply.
The Four Pillars
Written Policies, Procedures, and Internal Controls
The institution needs written policies that tell employees how to handle transactions, flag unusual patterns, escalate concerns, verify customer identities, monitor activity, and file required reports. Generic boilerplate will not pass an examination. Policies have to address each product and service the institution actually offers, reflect its real risk profile, and be reviewed and approved by management on a regular cadence.
A Designated Compliance Officer
One named individual has to own the program’s day-to-day operation. That person needs real authority, real resources, and direct access to the board, and serves as the primary contact for examiners and law enforcement. At smaller institutions the compliance officer often wears other hats, which is fine, but the role cannot be ceremonial. Examiners look for evidence the officer can actually make decisions and implement policy independently.
Ongoing Employee Training
Every employee who handles customer interactions or processes transactions has to understand their role in detecting and reporting suspicious activity. Training must happen at least annually and whenever significant policy changes are adopted, and it has to be tailored to the job. A teller’s training is not what a wire transfer specialist needs. Keep a log of dates, topics, and attendees; that log is what examiners will ask to see.
Independent Testing
The program has to be tested by a third party or by qualified internal staff who are not part of compliance operations. The audit evaluates whether controls actually work, whether reports are filed accurately and on time, and whether previous deficiencies were corrected.3FFIEC BSA/AML InfoBase. BSA/AML Independent Testing Testing should be risk-based, covering the risk assessment itself, customer identification procedures, the accuracy and timeliness of SAR and CTR filings, the transaction monitoring systems, and management’s response to prior findings. Most institutions schedule testing annually; higher-risk operations need it more often. Results go directly to the board.
Customer Identification and Due Diligence
The customer-facing requirements come in three layers: identifying who the customer is, understanding the relationship, and identifying who owns or controls legal entity customers.
Customer Identification Program (CIP)
Before opening any account, a bank must collect four pieces of information from each customer: name, date of birth (for individuals), address, and an identification number such as a Social Security number or taxpayer ID. Non-U.S. persons can substitute a passport number, alien identification card number, or other government-issued identification.4eCFR. 31 CFR 1020.220 – Customer Identification Program Requirements for Banks The institution then verifies the information through documentary or non-documentary methods within a reasonable time after account opening.
Customer Due Diligence and Beneficial Ownership
Beyond basic ID, the institution has to understand the purpose of each account and build a profile of expected activity. For legal entity customers, it must identify every individual who owns 25 percent or more of the entity’s equity, plus at least one person with significant managerial control such as a CEO, CFO, or managing member.5eCFR. 31 CFR 1010.230 – Beneficial Ownership Requirements for Legal Entity Customers Name, date of birth, address, and identification number are collected for each beneficial owner on a certification form signed by the person opening the account.6Financial Crimes Enforcement Network. Certification Regarding Beneficial Owners of Legal Entity Customers
A boundary worth flagging: the CDD rule for financial institutions is separate from the Corporate Transparency Act’s beneficial ownership information (BOI) reporting. As of March 2025, FinCEN exempted all U.S.-formed entities from BOI reporting and narrowed that obligation to foreign entities registered to do business in the United States.7Financial Crimes Enforcement Network. Beneficial Ownership Information Reporting The CDD rule is fully in effect regardless. Institutions still must collect and verify beneficial ownership information from legal entity customers at account opening.
Risk Assessment
The risk assessment is the backbone of the program. Every policy decision, staffing choice, and monitoring threshold flows from it, and examiners will trace those choices back to the assessment. A good one evaluates three categories.
Products and services come first. International wire transfers, private banking, correspondent accounts, and cash-intensive services carry higher inherent risk. The institution has to map how each offering could be exploited and calibrate monitoring accordingly. A community bank that does no international business faces a very different profile from one handling cross-border payments daily.
Geography matters at both the institutional and customer levels. Operations in or near High Intensity Financial Crime Areas (HIFCAs) or High Intensity Drug Trafficking Areas (HIDTAs) draw greater scrutiny.8Financial Crimes Enforcement Network. HIFCA Customers with ties to countries identified as high risk by FinCEN or the Financial Action Task Force get heightened monitoring as well.
Customer type is the third axis. Politically exposed persons, foreign entities, cash-intensive businesses, and non-bank financial institutions like money services businesses all warrant enhanced due diligence. The final risk profile determines whether the institution applies standard or enhanced procedures and how often it refreshes customer information.
Currency Transaction Reports
Any transaction in currency exceeding $10,000 triggers a Currency Transaction Report (CTR) on FinCEN Form 112.9eCFR. 31 CFR 1010.311 – Filing Obligations for Reports of Transactions in Currency “Currency” means physical cash and coin; checks and wire transfers do not count toward the threshold on their own. The report captures the customer’s full legal name, SSN or taxpayer ID, physical address, the identification presented, and details of the transaction.
CTRs are due within 15 days after the day the reportable transaction occurred.10eCFR. 31 CFR 1010.306 – Filing of Reports Institutions also have to aggregate multiple cash transactions by or on behalf of the same person on the same business day. If the total exceeds $10,000, a CTR is required even if no single transaction crossed the line.
Not every large cash transaction needs a CTR. Phase I exemptions apply automatically to five customer categories that pose minimal risk: other domestic banks, government agencies, entities exercising governmental authority, companies listed on major U.S. stock exchanges, and majority-owned subsidiaries of those listed companies.11FFIEC BSA/AML InfoBase. Transactions of Exempt Persons Phase II covers non-listed businesses and payroll customers that meet specific criteria, though certain industries such as car dealerships, law and accounting firms, pawnbrokers, gaming operations, and real estate brokers are ineligible. Using either exemption requires filing a Designation of Exempt Person (DOEP) on FinCEN Form 110 within 30 days after the first transaction the bank wants to exempt, plus an annual review.12Financial Crimes Enforcement Network. FinCEN DOEP Electronic Filing Instructions
Suspicious Activity Reports
When a transaction appears to have no lawful purpose, involves funds that may come from illegal activity, or is designed to evade BSA reporting, the institution files a Suspicious Activity Report (SAR) on FinCEN Form 111. The SAR requires a detailed written narrative explaining why the activity looks suspicious, plus dates, amounts, account numbers, and identifying information about the subjects.
For banks, the filing deadline is 30 calendar days after the bank first detects facts that may warrant a SAR. If no suspect has been identified by that detection date, the bank gets an additional 30 days, but filing cannot be delayed beyond 60 days from initial detection under any circumstances.13eCFR. 31 CFR 1020.320 – Reports by Banks of Suspicious Transactions
SAR confidentiality is strict. Federal law prohibits anyone involved in filing a SAR from telling the subject of the report, or anyone else outside the reporting chain, that a report was filed. This applies to the institution and to every director, officer, employee, and agent, including former employees.1Office of the Law Revision Counsel. 31 USC 5318 – Compliance, Exemptions, and Summons Authority In exchange, the statute provides a broad safe harbor: institutions and their personnel cannot be sued for filing a SAR or for failing to notify the subject. The protection covers federal law, state law, and private contracts including arbitration agreements.
The Travel Rule
For funds transfers of $3,000 or more, the sending institution must pass specific identifying information along with the payment so any institution in the chain can trace it back to the originator.14eCFR. 31 CFR 1010.410 – Records to Be Made and Retained by Financial Institutions The required data includes the sender’s name and account number, the sender’s address, the transfer amount and date, the receiving institution’s identity, and any recipient information the sender has. Intermediary institutions pass along what they receive but have no duty to obtain information that was never provided to them.
When either the sender or the recipient is not an established customer, the institution has to verify their identity in person by reviewing a government-issued ID and recording the document type, number, name, address, and taxpayer ID. Coded names and pseudonyms are not allowed; trade names and abbreviated business names are.15FFIEC BSA/AML InfoBase. Funds Transfers Recordkeeping
OFAC Sanctions Screening
A BSA/AML program does not operate alone. The Treasury Department’s Office of Foreign Assets Control (OFAC) administers a separate but overlapping set of obligations requiring institutions to screen customers and transactions against sanctions lists, most importantly the Specially Designated Nationals (SDN) list. Processing a payment to or from a sanctioned person or entity carries severe penalties regardless of how strong the BSA/AML program is otherwise.
OFAC’s compliance framework expects five elements: management commitment, a risk assessment, internal controls, testing and auditing, and training.16U.S. Department of the Treasury. A Framework for OFAC Compliance Commitments When an institution blocks a transaction or rejects a prohibited payment, it must report the action to OFAC within 10 business days.17eCFR. 31 CFR Part 501 – Reporting, Procedures and Penalties Regulations Entities owned 50 percent or more by a blocked person are themselves considered blocked, even without appearing on the SDN list by name.
PATRIOT Act Information Sharing
Section 314 of the USA PATRIOT Act creates two channels that intersect with the compliance program’s daily work.
Under Section 314(a), FinCEN periodically posts lists of subjects involved in terrorism or money laundering investigations through a secure portal. Institutions must search their records for any accounts maintained by the named subjects within the past 12 months and any non-account transactions within the past 6 months. Positive matches must be reported through the portal within two weeks of the posting date; if the search finds nothing, the institution simply does not respond.18Financial Crimes Enforcement Network. Section 314(a) Fact Sheet A positive match gives law enforcement a lead, not the account records themselves. Investigators still need a subpoena or other legal process to obtain documents.
Section 314(b) is voluntary sharing between institutions to identify and report potential money laundering or terrorist financing. To qualify for the liability safe harbor, institutions must register with FinCEN’s Secure Information Sharing System, verify that the other institution is also a registered participant, and maintain procedures to keep shared information confidential.19Financial Crimes Enforcement Network. Section 314(b) Fact Sheet Shared information may only be used for identifying reportable activity, deciding whether to open or maintain an account, or complying with AML requirements. A reasonable basis to believe the information relates to potential money laundering or terrorism is enough; conclusive proof is not required. Section 314(b) does not authorize sharing a SAR itself or revealing that a SAR exists.
Filing, Deadlines, and Recordkeeping
All BSA reports are filed electronically through the FinCEN BSA E-Filing System, which returns an acknowledgment and tracking number for each submission. Save those receipts. Incomplete or inaccurate filings can trigger regulatory inquiries and, in some cases, are themselves violations.
The core deadlines:
- CTRs: 15 days after the day of the reportable transaction.10eCFR. 31 CFR 1010.306 – Filing of Reports
- SARs: 30 days from initial detection, or 60 days if no suspect has been identified.13eCFR. 31 CFR 1020.320 – Reports by Banks of Suspicious Transactions
- DOEPs: 30 days after the first transaction the institution wants to exempt.12Financial Crimes Enforcement Network. FinCEN DOEP Electronic Filing Instructions
- OFAC blocked property and rejected transaction reports: 10 business days.17eCFR. 31 CFR Part 501 – Reporting, Procedures and Penalties Regulations
All records required by the BSA must be retained for five years. That includes filed CTRs and SARs, supporting documentation, customer identification records, beneficial ownership certifications, and funds transfer records.20eCFR. 31 CFR 1010.430 – Nature of Records and Retention Period Records have to be accessible within a reasonable time. For checks and other monetary instruments, retain copies of both the front and back. If a record is not created in the ordinary course of business but the BSA requires it, the institution must prepare one in writing. The five-year clock runs from the report filing date or the transaction date, depending on the record type.
Penalties for Getting It Wrong
Civil penalties depend on whether the violation was negligent or willful. A single negligent violation carries a penalty of up to $500; a pattern of negligent violations jumps to $50,000. Willful violations face up to the greater of $25,000 or the amount involved in the transaction, capped at $100,000.21Office of the Law Revision Counsel. 31 USC 5321 – Civil Penalties These base amounts are adjusted annually for inflation. As of the adjustment published in January 2024, the inflation-adjusted ceiling for a willful violation ranged from roughly $69,700 to $278,900, and a pattern of negligent activity could reach approximately $108,500.22Federal Register. Financial Crimes Enforcement Network – Inflation Adjustment of Civil Monetary Penalties Penalties are assessed per violation, so a single examination finding multiple unfiled CTRs can produce staggering totals.
Criminal penalties are steeper. A willful violation can result in a fine of up to $250,000 and up to five years in federal prison.23Office of the Law Revision Counsel. 31 USC 5322 – Criminal Penalties If the violation occurs while the person is breaking another federal law, or is part of a pattern of illegal activity involving more than $100,000 within a 12-month period, the maximum fine doubles to $500,000 and the prison term rises to 10 years. Individual officers and employees can be charged personally.
Keeping the Program Current
A program that passed examination three years ago will not necessarily pass today. Guidance changes, and the institution’s own risk profile shifts as it adds products, enters new markets, or takes on new customer segments.
The Anti-Money Laundering Act of 2020 brought several changes that programs need to account for. FinCEN published government-wide AML/CFT priorities identifying eight threat categories: corruption, cybercrime (including virtual currency), terrorist financing, fraud, transnational criminal organizations, drug trafficking, human trafficking and smuggling, and proliferation financing.24Financial Crimes Enforcement Network. AML/CFT Priorities Institutions are expected to incorporate these priorities into their risk assessments and internal controls. The same legislation also created a BSA whistleblower program, with FinCEN proposing implementing rules in early 2026.25Financial Crimes Enforcement Network. The Anti-Money Laundering Act of 2020
Independent testing should occur at least every 12 to 18 months, and higher-risk institutions may need annual reviews. Each cycle should evaluate whether the risk assessment still matches reality, whether monitoring systems catch what they are supposed to catch, and whether prior deficiencies were actually fixed.3FFIEC BSA/AML InfoBase. BSA/AML Independent Testing Training should happen at least annually, plus whenever the institution makes significant policy changes. A detailed log of dates, topics, and attendees is the concrete evidence examiners want to see.