BSA Independent Testing: Auditor, Coverage, and Penalties

BSA independent testing is the audit function every anti-money laundering program must include: a qualified reviewer who did not build or run the compliance program evaluates whether that program actually works, tests a sample of the institution’s BSA-related activity, and reports the findings straight to the board. It is one of the four mandatory pillars of an AML program under the Bank Secrecy Act, alongside internal controls, a designated compliance officer, and ongoing training.1Office of the Law Revision Counsel. 31 USC 5318 – Compliance, Exemptions, and Summons Authority The Anti-Money Laundering Act of 2020 added that these programs must be risk-based, which shapes how the testing itself is scoped and scheduled.

For banks, 31 CFR § 1020.210 implements the statutory requirement and specifies that testing may be conducted by bank personnel or an outside party.2eCFR. 31 CFR 1020.210 – Anti-Money Laundering Program Requirements for Banks National banks and savings associations have a parallel rule at 12 CFR § 21.21 with nearly identical language.3eCFR. 12 CFR 21.21 – Procedures for Monitoring Bank Secrecy Act Compliance The point across all of these is the same: someone who didn’t build the program has to evaluate it.

Who Can Perform the Testing

The FFIEC BSA/AML Examination Manual recognizes four categories of acceptable reviewers: the institution’s internal audit department, outside auditors, consultants, and other qualified independent parties.4FFIEC BSA/AML InfoBase. BSA/AML Independent Testing An institution without an internal audit department or the budget for an outside firm can use qualified staff, provided those employees have no role in the compliance functions they are testing.

Independence is the piece that trips institutions up most often. The reviewer cannot be the designated compliance officer and cannot report to the compliance officer.5Financial Crimes Enforcement Network. Frequently Asked Questions Conducting Independent Reviews of Money Services Business Anti-Money Laundering Programs If you bring in an outside firm, confirm it is not also writing your policies, running your training, or performing other BSA-related work that would compromise its objectivity. Hiring the same consultants who designed your compliance program to grade it defeats the purpose of the requirement.

Reporting Line

Whoever performs the testing must report directly to the board of directors or to a designated board committee composed primarily or entirely of outside directors.4FFIEC BSA/AML InfoBase. BSA/AML Independent Testing Findings routed through the compliance officer or a line manager first tend to arrive at the board softer than they started. The reporting line exists to prevent that filtering.

Qualifications

Examiners look at the reviewer’s subject matter expertise.4FFIEC BSA/AML InfoBase. BSA/AML Independent Testing The person needs to know BSA regulatory requirements well enough to catch technical deficiencies and to understand the risks tied to your specific products, customers, and geography. Credentials like the Certified Anti-Money Laundering Specialist (CAMS) or Certified Global Sanctions Specialist (CGSS) signal relevant training, though no regulation requires a specific certification.

What the Testing Has to Cover

The scope must be risk-based and broad enough to evaluate risk management across the institution’s significant operations. The FFIEC manual sets a minimum checklist:4FFIEC BSA/AML InfoBase. BSA/AML Independent Testing

  • Whether the BSA risk assessment reflects the institution’s actual customer base, products, and geographic footprint.
  • Whether the institution follows its own written compliance policies and procedures.
  • Whether it meets recordkeeping and reporting requirements for customer identification, customer due diligence, beneficial ownership, SARs, CTRs, CTR exemptions, and information-sharing requests.
  • Whether the overall process for identifying and reporting suspicious activity is adequate.
  • Whether the technology systems supporting compliance are complete and accurate.
  • Whether training is tailored to job functions and documented.
  • Whether management addressed prior testing and examination deficiencies in a timely way.

Examiners weigh that last item heavily. Repeat findings that haven’t been corrected mark a program as stagnant, and unresolved prior deficiencies can escalate the severity of the regulatory response on their own.

SAR and CTR Filing Review

Transaction testing for suspicious activity reporting sits at the core of the scope. A SAR must be filed within 30 calendar days of initial detection of facts that could warrant one; if no suspect has been identified at detection, the institution gets another 30 days to identify one, and filing cannot be delayed more than 60 days from initial detection.6eCFR. 12 CFR 208.62 – Suspicious Activity Reports The reviewer pulls a sample of filed SARs to verify these deadlines and check the quality of narratives and supporting documentation.

No-file decisions matter just as much. When monitoring flags suspicious activity and the compliance team decides not to submit a report, the reasoning must be documented and defensible. Poorly justified no-file decisions are one of the fastest routes to enforcement.

Beneficial Ownership Verification

Under 31 CFR § 1010.230, covered institutions must identify and verify the beneficial owners of legal entity customers at account opening.7eCFR. 31 CFR 1010.230 – Beneficial Ownership Requirements for Legal Entity Customers Testing should sample new legal-entity accounts to confirm the institution collected the required information for each beneficial owner (name, date of birth, address, identification number) and verified enough of it to form a reasonable belief as to true identity.8FFIEC BSA/AML InfoBase. Beneficial Ownership Requirements for Legal Entity Customers The reviewer should also confirm risk-based procedures exist for updating beneficial ownership information and that verification records are retained.

OFAC Sanctions

The FFIEC manual requires an objective, comprehensive evaluation of OFAC policies, procedures, and processes, with scope broad enough to assess sanctions risk across the organization.9FFIEC BSA/AML InfoBase. Office of Foreign Assets Control Check whether screening lists and country criteria are current, whether procedures distinguish real matches from false hits, and whether blocked or rejected items are tracked properly, including amounts, ownership information, and interest paid.

Automated Transaction Monitoring

The monitoring system’s programming and effectiveness need independent validation to confirm the models are actually detecting potentially suspicious activity.10FFIEC BSA/AML InfoBase. Suspicious Activity Reporting – Overview Test specific parameters and alert thresholds against the institution’s risk profile. Evaluate whether staffing is adequate to work the alert volume being generated. A system that produces thousands of alerts nobody has time to review is functionally the same as no system at all.

How Often to Test

No regulation fixes a testing frequency.4FFIEC BSA/AML InfoBase. BSA/AML Independent Testing The interval must be proportional to the institution’s risk profile and overall risk management strategy. The FFIEC manual offers 12 to 18 months as an example of a periodic cycle, but treating that as a safe harbor is a mistake. Higher-risk profiles, complex product lines, and significant international exposure can call for more frequent testing.

Certain events should prompt testing outside the normal schedule. Launching new products such as cryptocurrency services, expanding into higher-risk geographies, replacing monitoring software, or losing key compliance staff all change the risk profile the last review measured against. Waiting for the next scheduled cycle while operating under materially different conditions is the kind of passive posture examiners criticize.

Documentation and Reporting

The reviewer must document the scope, procedures performed, transaction testing completed, and every finding. Violations, policy exceptions, and other deficiencies get reported to the board or designated board committee in a timely manner.4FFIEC BSA/AML InfoBase. BSA/AML Independent Testing The final report should include an explicit statement on the institution’s overall BSA compliance and enough detail that a board member, compliance officer, or examiner reading it can reach an independent conclusion about program adequacy.

The board and appropriate staff have to track deficiencies and document progress on corrective action.4FFIEC BSA/AML InfoBase. BSA/AML Independent Testing All testing documentation and workpapers should be retained and produced for examiners on request. A clean audit report sitting in a drawer while findings go unaddressed satisfies no one.

Non-Bank Institutions

The testing requirement is not limited to banks. Money services businesses must provide for an independent review under 31 CFR § 1022.210(d)(4), with scope and frequency proportional to the risk of the services provided.11eCFR. 31 CFR Part 1022 – Rules for Money Services Businesses An officer or employee can conduct it, so long as that person is not the designated day-to-day compliance officer. FinCEN has confirmed that MSBs do not need to hire a CPA or outside consultant; the requirement is for an independent review, not a formal audit.5Financial Crimes Enforcement Network. Frequently Asked Questions Conducting Independent Reviews of Money Services Business Anti-Money Laundering Programs

Casinos face a similar requirement under 31 CFR § 1021.210, again with scope and frequency proportional to their risk profile.12eCFR. 31 CFR 1021.210 – Anti-Money Laundering Program Requirements for Casinos The independence and risk-based-scope principles carry over; the specific risks (cash intensity, rapid funds movement through gaming, high-value chip transactions) look different from a bank’s.

What Happens When Testing Fails

When examiners find that testing was inadequate or that the institution ignored its results, the response escalates along a defined path. The Federal Reserve classifies supervisory findings into two tiers. Matters Requiring Attention (MRA) are issues the institution must correct within a reasonable timeframe. Matters Requiring Immediate Attention (MRIA) involve significant safety-and-soundness risks or significant noncompliance and demand immediate action.13Federal Reserve. Supervisory Considerations for the Communication of Supervisory Findings (SR 13-13) A repeat criticism that wasn’t fixed the first time can move from MRA to MRIA purely because it wasn’t addressed.

When deficiencies persist or are severe, regulators move to formal enforcement. The OCC has issued cease and desist orders citing specific breakdowns in “internal controls, BSA Officer, independent testing, and training components” of the compliance program, along with transaction monitoring and SAR process failures.14Office of the Comptroller of the Currency. Consent Order (AA-ENF-2024-56) These consent orders typically require a revised audit program, qualified new personnel, and enhanced supervisory oversight until the regulator is satisfied.

Civil and Criminal Penalties

Under 31 U.S.C. § 5321, a willful violation of BSA requirements carries a civil penalty of up to the greater of the amount involved in the transaction (capped at $100,000) or $25,000 per violation.15Office of the Law Revision Counsel. 31 USC 5321 – Civil Penalties Negligent violations carry up to $500 per violation, with steeper consequences for a pattern. Systemic failures produce much larger numbers in practice: FinCEN assessed a record $1.3 billion penalty against TD Bank for willfully failing to file SARs on thousands of suspicious transactions totaling roughly $1.5 billion.16Financial Crimes Enforcement Network. FinCEN Assesses Record $1.3 Billion Penalty Against TD Bank

Criminal exposure exists too. A willful violation of the BSA or its regulations carries up to $250,000 in fines and five years in prison. If the violation occurs while breaking another federal law or as part of a pattern of illegal activity involving more than $100,000 in a twelve-month period, the maximums rise to $500,000 and ten years.17Office of the Law Revision Counsel. 31 USC 5322 – Criminal Penalties These criminal provisions apply to individuals as well as institutions, which is worth remembering for compliance officers and board members who might treat testing findings as optional reading.