Continuous Transaction Monitoring: AML Program, SARs, and Penalties

Continuous transaction monitoring is the automated, around-the-clock surveillance of every transaction moving through a financial institution to detect patterns that suggest money laundering, structuring, sanctions evasion, or other financial crime. Federal law requires banks, credit unions, money service businesses, and other covered institutions to run these programs, review the alerts they generate, and report suspicious activity to the Treasury. The obligation is not optional. An institution that fails to maintain an effective program can face civil penalties reaching $1,000,000 for certain violations, and the officers responsible can face criminal prosecution.

The Legal Basis for the Obligation

The Bank Secrecy Act, at 31 U.S.C. § 5311, is the source of every transaction monitoring duty in the United States. Its stated purpose is to require financial institutions to keep records and file reports that are “highly useful” in criminal, tax, and regulatory investigations, and to prevent money laundering and terrorism financing through “reasonably designed risk-based programs.”1Office of the Law Revision Counsel. 31 USC 5311 – Declaration of Purpose FinCEN, the Financial Crimes Enforcement Network within the Treasury Department, administers and enforces the BSA.2Internal Revenue Service. Internal Revenue Manual – Bank Secrecy Act Penalties

The USA PATRIOT Act of 2001 expanded the BSA by adding customer identification rules, broadening the definition of covered institutions, and strengthening suspicious activity reporting. The Anti-Money Laundering Act of 2020 pushed the framework further, toward what FinCEN describes as a shift from procedural compliance to operational effectiveness, and authorized a SAR Sharing Pilot Program allowing institutions to share suspicious activity information with foreign branches and affiliates.3FinCEN. The Anti-Money Laundering Act of 2020

FinCEN has also published eight national AML/CFT priorities that institutions must factor into their programs: corruption, cybercrime (including virtual currency), terrorism financing, fraud, transnational criminal organization activity, drug trafficking, human trafficking and smuggling, and proliferation financing.4FinCEN. AML/CFT Priorities These priorities shape how each institution calibrates its rules. A bank with heavy international correspondent exposure weights proliferation and transnational crime indicators more heavily than a community credit union focused on consumer lending.

What an AML Program Must Contain

Federal regulations require every covered bank to maintain an AML program built on four minimum components: a system of internal controls to ensure ongoing compliance; independent testing, done either by bank personnel outside the compliance department or by an outside party; a designated individual or team responsible for day-to-day compliance; and training for appropriate personnel on BSA requirements and the institution’s own policies.5eCFR. 31 CFR 1020.210 – Anti-Money Laundering Program

Continuous transaction monitoring lives inside the internal controls pillar, but it depends on the other three. Independent testing verifies that the monitoring rules are catching what they should without drowning investigators in false positives. The designated compliance officer oversees the rule tuning. Training ensures that front-line staff know what to escalate when something slips past the automated system.

How a Monitoring System Actually Works

A monitoring system typically rests on three layers working together.

Threshold rules are the simplest. They flag any single event that hits a defined dollar amount, the most obvious being the $10,000 currency transaction trigger.6FinCEN. Bank Secrecy Act Effective systems go well beyond that single number, watching for transactions just below reporting thresholds, rapid sequences of smaller transactions, and unusual patterns in wire transfers, ACH payments, and foreign exchange activity.

Behavioral profiling compares a customer’s current activity against their own historical pattern. If a small retail business that normally deposits $8,000 to $15,000 per month in cash suddenly starts depositing $90,000, the system flags the deviation. This layer only works once the institution has collected enough baseline data to define “normal” for each customer segment.

Historical data integration ties the first two layers together. Storing years of past transaction detail lets the system tell a one-off spike (a business owner selling equipment) from a sustained change with no obvious explanation. Algorithms process thousands of data entries per second to detect relationships between accounts, identify networks of related entities, and spot patterns no human reviewer could catch across a portfolio of millions of accounts.

Rule calibration is where these systems succeed or fail. Overly sensitive rules flood investigators with false positives and bury genuine threats. Rules that are too loose let real suspicious activity pass. Independent testing exists partly to check whether the calibration still matches the institution’s actual risk profile.

What the System Has to Report

Two federal reports drive most of what a monitoring program produces: Currency Transaction Reports and Suspicious Activity Reports.

Currency Transaction Reports

A financial institution must file a CTR for any cash transaction exceeding $10,000 in a single business day. The rule covers deposits, withdrawals, exchanges, and transfers, and it applies when multiple cash transactions by or on behalf of the same person aggregate above $10,000 in a single day, even across different branches of the same institution.6FinCEN. Bank Secrecy Act CTRs are filed electronically through the BSA E-Filing System within 15 calendar days of the transaction.

Suspicious Activity Reports

SARs work differently. There is no single dollar figure that automatically requires one. A bank must file when a transaction involves at least $5,000 and the bank knows or suspects the funds come from illegal activity, the transaction is designed to evade BSA requirements, or it has no apparent lawful purpose the bank can identify after examining the facts.7Federal Reserve. 31 CFR 1020.320 – Reports by Banks of Suspicious Transactions For criminal violations involving insider abuse, there is no dollar minimum. For criminal violations where no suspect can be identified, the threshold is $25,000.8FFIEC BSA/AML InfoBase. Assessing Compliance with BSA Regulatory Requirements – Suspicious Activity Reporting

A SAR must be filed within 30 calendar days of detecting the suspicious activity. If no suspect has been identified within that window, the institution gets an additional 30 days to try to identify one, but the filing cannot be delayed beyond 60 days from initial detection.7Federal Reserve. 31 CFR 1020.320 – Reports by Banks of Suspicious Transactions

Structuring

Structuring, sometimes called smurfing, is the deliberate breaking of transactions into smaller amounts to avoid a CTR filing. Under 31 U.S.C. § 5324, no person may structure or assist in structuring any transaction with a financial institution for the purpose of evading BSA reporting requirements.9Office of the Law Revision Counsel. 31 USC 5324 – Structuring Transactions to Evade Reporting Requirement Prohibited Federal law makes structuring a crime on its own, separate from any underlying offense. Monitoring algorithms look for transactions just below the $10,000 threshold, deposits spread across multiple branches on the same day, and round-dollar amounts that don’t fit the customer’s usual activity. When the system detects a structuring pattern, the institution must file a SAR regardless of whether any individual transaction hit the CTR threshold.

The Alert Resolution Workflow

When the monitoring system flags a transaction, the clock starts. An investigator examines the alert against internal records, the customer’s stated business purpose, and the transaction’s context. Most alerts resolve here. A flagged wire turns out to be a scheduled vendor payment, or a cash spike matches a seasonal pattern the customer documented during onboarding.

When the investigator cannot find a legitimate explanation, the case escalates to a senior compliance officer who decides whether the activity meets the SAR filing standard. If it does, the institution files electronically through the BSA E-Filing System within the deadline.10Financial Crimes Enforcement Network. FinCEN Suspicious Activity Report Electronic Filing Instructions Every step is documented: the timestamp of the original alert, the identity of each reviewer, the evidence examined, and the rationale for the final decision. Federal examiners audit these records and question any gaps. An institution that generates alerts but cannot show how it resolved them is nearly as exposed as one that doesn’t monitor at all.

SAR Confidentiality and Safe Harbor

Once a SAR is filed, its existence is confidential. Federal law prohibits the institution, its directors, officers, employees, former employees, and contractors from telling anyone involved in the transaction that a SAR was filed or revealing information that would disclose its existence.11Office of the Law Revision Counsel. 31 USC 5318 – Compliance, Exemptions, and Summons Unauthorized disclosure can carry civil penalties of up to $100,000 per violation and criminal penalties of up to $250,000 in fines and five years in prison.12FinCEN. SAR Confidentiality Reminder for Internal and External Counsel of Financial Institutions

In return, the BSA provides a safe harbor. An institution that files a SAR in good faith, whether voluntarily or as required, cannot be held liable under any federal or state law for making the disclosure. The protection extends to individual directors, officers, and employees who took part in the filing decision.11Office of the Law Revision Counsel. 31 USC 5318 – Compliance, Exemptions, and Summons The two rules work together: customers never learn that a report was filed, and the institution files without exposure to a defamation suit from the customer.

Recordkeeping

The BSA imposes a five-year retention requirement on most records. Transaction monitoring alerts, investigation files, SAR filings, CTR records, and customer identification documents must all be kept for at least five years.13eCFR. 31 CFR 1010.430 – Nature of Records and Retention Period Records tied to a customer’s identity must be kept for five years after the account is closed, not five years from when the record was created.14FFIEC BSA/AML InfoBase. Appendix P – BSA Record Retention Requirements

Institutions can store records in any format, including paper, microfilm, electronic files, or reproductions, as long as the records remain accessible within a reasonable period.13eCFR. 31 CFR 1010.430 – Nature of Records and Retention Period For checks, drafts, and similar instruments, the institution must retain a copy of both the front and back. Law enforcement or a Treasury order can require retention beyond five years on a case-by-case basis.

Penalties for Getting It Wrong

Consequences run along two tracks: civil and criminal.

Civil Penalties

A financial institution or individual who willfully violates the BSA faces a civil penalty of up to the greater of $100,000 (capped at the amount involved in the transaction) or $25,000 per violation. Violations of certain provisions, particularly those tied to correspondent accounts and special measures under sections 5318(i), 5318(j), and 5318A, carry heavier civil penalties of not less than two times the transaction amount, up to $1,000,000. Repeat offenders can be assessed additional penalties of up to three times the profit gained or loss avoided, or two times the maximum penalty for the violation, whichever is greater.15Office of the Law Revision Counsel. 31 USC 5321 – Civil Penalties

Criminal Penalties

Willful BSA violations carry criminal fines of up to $250,000 and imprisonment of up to five years. When the violation occurs alongside another federal crime or as part of a pattern of illegal activity involving more than $100,000 in a 12-month period, the maximums rise to $500,000 and 10 years.16Office of the Law Revision Counsel. 31 USC 5322 – Criminal Penalties The AMLA 2020 added a further consequence: a convicted individual who was a partner, director, officer, or employee of a financial institution at the time of the violation must forfeit any profit from the violation and repay any bonus received during the calendar year of the violation or the year after.

These penalties reach individuals as well as institutions. A compliance officer who knows the monitoring system is broken and does nothing about it faces personal criminal exposure, not a bad performance review. That personal liability is what gives BSA enforcement its teeth.