BSA Compliance and Monitoring for Wire Transfers: CTRs, SARs, and OFAC

BSA compliance for wire transfers requires a financial institution to identify its customers and their beneficial owners, attach specified sender information to every transmittal order of $3,000 or more, screen all parties against OFAC’s sanctions list, monitor account activity for suspicious patterns, file the reports the Bank Secrecy Act mandates, and keep the underlying records for five years. The obligations run from account opening through the moment funds leave the building, and they sit on top of a written anti-money-laundering program with internal controls, a designated compliance officer, employee training, and independent testing.1Financial Crimes Enforcement Network. USA PATRIOT Act Compliance failures carry civil penalties into six figures per violation and criminal exposure of up to ten years, so none of this is decorative.

Who Has to Comply

The BSA’s definition of “financial institution” reaches well beyond traditional banks. The regulations list more than a dozen categories, including broker-dealers, money services businesses, mutual funds, futures commission merchants, casinos, and card clubs, alongside every federally or state-supervised bank and credit union.2FFIEC BSA/AML InfoBase. FFIEC BSA/AML General Definitions If your business transmits funds on behalf of customers, expect the wire-transfer rules below to apply.

Identifying the Customer Before the Wire Moves

A bank cannot process a wire for a customer it hasn’t identified. The Customer Identification Program regulation sets the minimum data the bank must gather when opening an account.3eCFR. 31 CFR 1020.220 – Customer Identification Program Requirements for Banks

For an individual, that means four items:

  • Full legal name
  • Date of birth
  • A residential or business street address. A standard P.O. box does not satisfy this requirement, though an APO or FPO box is acceptable for individuals who lack a street address.
  • An identification number: a taxpayer identification number such as an SSN for U.S. persons, or a passport number, alien identification card number, or other government-issued document number showing nationality or residence for non-U.S. persons.

The bank then verifies identity within a reasonable time using documents, non-documentary methods, or both. An unexpired government-issued photo ID such as a driver’s license or passport is the usual documentary route for individuals.

When the customer is a legal entity, verification shifts to the entity’s existence. Acceptable documents include certified articles of incorporation, a government-issued business license, a partnership agreement, or a trust instrument. Non-documentary alternatives include public database checks, direct contact with the customer, or references from other financial institutions. If neither approach confirms the entity, the bank must collect information about the individuals who control the account before proceeding.

Beneficial Owners of Business Customers

For legal entity customers, identifying the entity is only half the job. Under the Customer Due Diligence Rule, a bank must also identify each individual who directly or indirectly owns 25 percent or more of the entity’s equity, plus at least one individual who exercises significant managerial control, even if that person owns no equity.4eCFR. 31 CFR 1010.230 – Beneficial Ownership Requirements for Legal Entity Customers

The rule covers corporations, LLCs, general partnerships, and similar entities formed by filing with a secretary of state or equivalent office, including foreign-jurisdiction equivalents that register to do business in the United States. Several categories of entities are exempt from beneficial-ownership collection, including banks and credit unions regulated by a federal functional regulator, SEC-registered public companies, registered investment companies, registered investment advisers, and state-regulated insurance companies.

One boundary worth flagging: the separate Corporate Transparency Act filing regime is not a substitute for CDD collection. As of March 2025, FinCEN exempted all domestic reporting companies and their U.S.-person beneficial owners from the CTA filing obligation, leaving only foreign entities registered in a U.S. state or tribal jurisdiction subject to it.5Financial Crimes Enforcement Network. Beneficial Ownership Information Reporting Banks still must collect beneficial ownership information from legal entity customers at account opening regardless of whether those customers owe any filing to FinCEN.

The Travel Rule at $3,000

Once a wire is $3,000 or more, a defined set of identifying information has to travel with the payment as it moves bank to bank. The purpose is twofold: every institution in the chain can evaluate the transaction for risk in real time, and investigators can reconstruct the full path of funds later.6eCFR. 31 CFR 1010.410 – Records to Be Made and Retained by Financial Institutions

At a minimum, the originating bank must include in the transmittal order:

  • The sender’s name and account number
  • The sender’s address
  • The dollar amount and execution date
  • Any payment instructions from the sender
  • The identity of the recipient’s financial institution

Intermediary banks between the originator and beneficiary bank must pass these fields to the next institution in the chain. Dropping or stripping any of them creates a compliance gap examiners treat seriously.

Records related to these transfers must be kept for five years, and the retention obligation applies equally to the originating bank, any intermediary, and the receiving bank.7eCFR. 31 CFR 1010.430 – Nature of Records and Retention Period Storage must allow retrieval within a reasonable time when law enforcement or examiners ask.

When Cash Enters the Picture: CTRs

A standard electronic wire does not, by itself, trigger a Currency Transaction Report, because no physical currency changes hands. The CTR obligation attaches to any transaction involving more than $10,000 in coin or paper money, and it becomes relevant to wires when cash is part of the funding chain โ€” a customer walks in with cash and immediately wires the funds out, for example.8eCFR. 31 CFR 1010.311 – Filing Obligations for Reports of Transactions in Currency Multiple cash transactions that individually fall below $10,000 but aggregate above the threshold during a single business day count as a single transaction.

CTRs must be filed electronically through FinCEN’s BSA E-Filing System within 15 calendar days of the transaction.9Financial Crimes Enforcement Network. Frequently Asked Questions Regarding the FinCEN Currency Transaction Report (CTR) Banks may designate certain customers as “exempt persons” to avoid repeat filings for the same predictable activity, with the exemption categories and eligibility conditions set out in the regulation.10eCFR. 31 CFR 1020.315 – Transactions of Exempt Persons

Suspicious Activity Reporting

A CTR is mechanical. A Suspicious Activity Report is a judgment call. A bank must file a SAR when a transaction of $5,000 or more runs through the bank and the bank knows, suspects, or has reason to suspect one of three things: that the funds come from illegal activity, that the transaction is designed to evade BSA requirements, or that the transaction has no apparent business purpose and no reasonable explanation surfaces after review.11eCFR. 31 CFR 1020.320 – Reports by Banks of Suspicious Transactions

Wire transfers are one of the most common SAR triggers. Patterns that draw scrutiny include rapid movement of funds through multiple accounts with no clear commercial purpose, transfers to or from high-risk jurisdictions, round-dollar amounts that don’t match the customer’s normal activity, and transactions that appear structured to sit just below reporting or recordkeeping thresholds.

Structuring

Structuring deserves special attention because customers sometimes attempt it without realizing it’s a standalone federal crime. Breaking a $15,000 cash deposit into three $4,900 deposits at different branches to duck the CTR threshold violates 31 U.S.C. ยง 5324, which carries up to five years in prison and a $250,000 fine. The maximum doubles to ten years if the structuring is part of a pattern involving more than $100,000 in illegal activity over twelve months.12Office of the Law Revision Counsel. 31 U.S. Code 5324 – Structuring Transactions to Evade Reporting Requirement Institutions that spot structuring behavior must file a SAR regardless of whether they believe the underlying funds are legitimate.

Filing Deadlines

A SAR must be filed electronically within 30 calendar days from the date the institution first detects facts that may warrant a report. The clock does not start when a monitoring system fires an alert; it starts when a human reviewer looks at the alert and concludes the activity looks suspicious. If no suspect can be identified, the deadline extends to 60 calendar days.13FFIEC BSA/AML InfoBase. Suspicious Activity Reporting – Overview

Confidentiality

The SAR process is strictly confidential. Federal law prohibits the institution, its officers, employees, and agents from telling the customer or anyone else involved in the transaction that a report has been filed. Current and former government employees who learn about a SAR filing are equally prohibited from disclosing it.14Office of the Law Revision Counsel. 31 U.S. Code 5318 – Compliance, Exemptions, and Summons Authority A single conversation can create serious legal exposure for the person who speaks.

OFAC Sanctions Screening

Before a wire is released or incoming funds are credited, the institution must screen every party against the Specially Designated Nationals and Blocked Persons list maintained by the Treasury Department’s Office of Foreign Assets Control.15FFIEC BSA/AML InfoBase. Office of Foreign Assets Control The SDN list includes individuals, companies, and organizations linked to sanctioned countries, terrorist groups, narcotics traffickers, and other targeted threats. Most institutions run automated screening that flags exact matches and phonetic near-matches; a compliance analyst then works through each hit to sort genuine matches from false positives.

Block or Reject

A confirmed match does not always produce the same result. If a person on the SDN list has a present, future, or contingent interest in the funds, the institution must block the transaction: the money moves into an interest-bearing account on the institution’s books, and only OFAC-authorized debits are permitted. If the transaction is prohibited by sanctions regulations but no SDN or blocked person has an interest in the funds, the institution rejects the transfer and returns it to the originator.16U.S. Department of the Treasury. Frequently Asked Questions – OFAC Both blocked and rejected transactions must be reported to OFAC within 10 business days.17eCFR. 31 CFR 501.603 – Reports on Blocked and Unblocked Property Getting the distinction wrong โ€” blocking what should have been rejected, or rejecting what should have been frozen โ€” draws examiner attention.

Ongoing Monitoring and Independent Testing

BSA compliance is not a one-time setup. Banks must conduct ongoing monitoring to identify and report suspicious transactions and, on a risk basis, to maintain and update customer information over time.18eCFR. 31 CFR 1020.210 – Anti-Money Laundering Program Requirements for Banks Effective monitoring looks at account behavior across weeks and months rather than evaluating each wire in isolation, so layering schemes and gradual shifts in transaction patterns actually surface.

Independent testing of the BSA/AML program is a core component of the framework. No regulation prescribes a fixed testing frequency, but examination guidance recommends intervals proportionate to risk, often every 12 to 18 months. More frequent testing is appropriate after identified deficiencies, significant changes to transaction-monitoring systems, or compliance staff turnover.19FFIEC BSA/AML InfoBase. BSA/AML Independent Testing Testing must be conducted by someone with no responsibility for running the compliance program. Smaller institutions that can’t create genuine independence internally typically hire an outside firm.

What Violations Cost

Penalties escalate sharply based on whether the violation was negligent, willful, or part of a broader criminal scheme.

For negligent violations, the statutory base civil penalty is up to $500 per violation, plus up to $50,000 if the negligence forms a pattern.20Office of the Law Revision Counsel. 31 U.S. Code 5321 – Civil Penalties Willful violations carry a base civil penalty of the greater of $25,000 or the transaction amount, up to $100,000. These figures are adjusted annually for inflation under the Federal Civil Penalties Inflation Adjustment Act. For 2026, the 2025 adjusted amounts remain in effect because the Office of Management and Budget canceled the 2026 inflation adjustment due to missing CPI data.

Criminal exposure is more serious. A person who willfully violates the BSA or its implementing regulations faces a criminal fine of up to $250,000, imprisonment of up to five years, or both. If the violation occurs alongside another federal crime or as part of a pattern of illegal activity involving more than $100,000 within a 12-month period, the maximum fine rises to $500,000 and the maximum sentence to ten years.21Office of the Law Revision Counsel. 31 U.S. Code 5322 – Criminal Penalties A convicted individual who was an officer, director, or employee of a financial institution at the time of the violation must also forfeit any bonus received during the calendar year of the violation or the following year.