Patriot Act Compliance: AML Program, SARs, and Penalties

PATRIOT Act compliance requirements obligate every covered financial institution to maintain a written anti-money laundering program with four specific components, verify the identity of every customer, apply enhanced scrutiny to high-risk foreign accounts, file Currency Transaction Reports and Suspicious Activity Reports on strict deadlines, respond to government information requests, and retain the underlying records for five years. Title III of the Act expanded the Bank Secrecy Act to create this framework, and willful failure to meet any of these obligations can trigger fines up to $250,000 and five years in prison per offense, doubling to $500,000 and ten years when the conduct is tied to other illegal activity.

Which Businesses Are Covered

The BSA defines “financial institution” broadly, and the definition catches businesses that don’t always think of themselves that way. Covered institutions include banks and credit unions (including domestic branches), SEC-registered broker-dealers, money services businesses (money transmitters, check cashers, currency dealers, and sellers of money orders or prepaid access), casinos and card clubs above the applicable gross annual gaming revenue threshold, futures commission merchants and introducing brokers registered with the CFTC, and SEC-registered mutual funds.1FFIEC BSA/AML InfoBase. FFIEC BSA/AML General Definitions

If your business fits any of these categories, every requirement below applies to you in full.

The Four-Part Anti-Money Laundering Program

Federal law requires every covered institution to establish and maintain a written AML program built on four minimum components.2Office of the Law Revision Counsel. 31 US Code 5318 – Compliance, Exemptions, and Summons Authority

  • Written internal policies, procedures, and controls covering how the institution detects, prevents, and reports suspicious activity across every line of business.
  • A designated compliance officer who runs the program day to day, tracks regulatory changes, and coordinates with examiners and law enforcement.
  • Ongoing employee training tailored to each role, so that staff at every level recognize red flags and follow internal escalation procedures.
  • Independent testing, performed by internal staff outside the compliance function or by an outside firm, that evaluates whether the program actually works.

Independent testing is where most weaknesses surface. Auditors are expected to check whether the risk assessment matches actual risk, whether staff follow the written procedures, whether SARs and CTRs are accurate and timely, whether prior findings were addressed, and whether the technology generating alerts produces complete and accurate results.3FFIEC BSA/AML InfoBase. Assessing the BSA/AML Compliance Program – BSA/AML Independent Testing

Customer Identification and Due Diligence

Every institution must implement a written Customer Identification Program. Before opening an account, you must collect the customer’s name, date of birth (for individuals), a street address (residential or business for individuals; a physical location for entities), and an identification number (a taxpayer identification number for U.S. persons, or a passport number and country of issuance or comparable government-issued document for non-U.S. persons).4eCFR. 31 CFR 1020.220 – Customer Identification Program Requirements for Banks

The collected information must then be verified through documentary methods (an unexpired government-issued photo ID, or formation documents for entities), non-documentary methods (cross-referencing against a consumer reporting agency, public database, or other reliable source), or both.4eCFR. 31 CFR 1020.220 – Customer Identification Program Requirements for Banks

FinCEN also requires four explicit customer due diligence elements in every AML program: identifying and verifying customers, identifying and verifying the beneficial owners of legal entity customers, understanding the nature and purpose of each customer relationship to build a risk profile, and ongoing monitoring to spot suspicious activity and refresh customer information on a risk basis.5Federal Register. Customer Due Diligence Requirements for Financial Institutions

For legal entity customers, “beneficial owner” means every individual who owns or controls at least 25 percent of the entity and every individual exercising substantial control, such as senior officers or anyone with authority to appoint or remove directors. This applies at account opening and must be kept current on a risk basis.5Federal Register. Customer Due Diligence Requirements for Financial Institutions

Enhanced Due Diligence for High-Risk Accounts

Section 312 of the PATRIOT Act requires heightened scrutiny for two categories of accounts: correspondent accounts for foreign financial institutions and private banking accounts for non-U.S. persons.6Financial Crimes Enforcement Network. FACT SHEET for Section 312 of the USA PATRIOT Act Final Regulation and Notice of Proposed Rulemaking

For correspondent accounts, you must adopt risk-based due diligence policies to detect and report money laundering, including determining the foreign bank’s ownership and evaluating its AML controls. Enhanced due diligence is triggered when the foreign bank operates under an offshore license, in a jurisdiction designated as non-cooperative with international AML standards, or in a jurisdiction identified as a primary money laundering concern under Section 311.6Financial Crimes Enforcement Network. FACT SHEET for Section 312 of the USA PATRIOT Act Final Regulation and Notice of Proposed Rulemaking

Correspondent accounts for foreign shell banks (foreign banks with no physical presence in any country) are flatly prohibited. Your institution must also take reasonable steps to make sure the foreign banks you do serve aren’t providing indirect access to shell banks.7Financial Crimes Enforcement Network. USA PATRIOT Act

A private banking account under the Act is one held for a non-U.S. person, requiring a minimum deposit of at least $1,000,000, and assigned to a dedicated bank employee acting as the client’s liaison. For these accounts, you must identify all beneficial owners, determine the source of deposited funds, understand the account’s expected purpose and use, and monitor activity for consistency with that profile. Accounts held for senior foreign political figures, their family members, and known close associates require an additional layer of scrutiny.6Financial Crimes Enforcement Network. FACT SHEET for Section 312 of the USA PATRIOT Act Final Regulation and Notice of Proposed Rulemaking

Currency Transaction Reports and the Structuring Trap

Any cash transaction over $10,000, whether a deposit, withdrawal, currency exchange, or other cash transfer, triggers a mandatory Currency Transaction Report. Multiple cash transactions by the same customer on the same business day that together exceed $10,000 must be aggregated and reported on a single CTR.8FFIEC BSA/AML InfoBase. Assessing Compliance with BSA Regulatory Requirements – Currency Transaction Reports

The related risk is structuring. Structuring means breaking transactions into smaller amounts to stay below the $10,000 threshold. A customer depositing $9,500 in the morning and $9,500 in the afternoon at different branches is structuring. The individual transactions never need to exceed $10,000 for the conduct to be illegal; the crime is the intent to evade reporting. Structuring carries penalties of up to five years in prison, or up to ten years if it’s connected to other illegal activity involving more than $100,000 in a twelve-month period.9Office of the Law Revision Counsel. 31 US Code 5324 – Structuring Transactions to Evade Reporting Requirement Prohibited

Frontline staff should be trained to recognize structuring patterns and escalate them via SAR. Your obligation to report the pattern exists whether or not you can prove the customer’s intent.

Suspicious Activity Reports

Beyond the mechanical CTR threshold, institutions must continuously monitor customer activity and file a Suspicious Activity Report when something doesn’t add up. A SAR is required when a transaction involves at least $5,000 in funds and you know, suspect, or have reason to suspect that it involves proceeds of illegal activity, is designed to evade BSA reporting, or has no apparent lawful purpose consistent with the customer’s normal behavior.10eCFR. 31 CFR 1020.320 – Reports by Banks of Suspicious Transactions

The deadline is 30 calendar days from the date the institution first detects facts that may warrant filing. If no suspect has been identified by then, you get an additional 30 days, but reporting cannot be delayed beyond 60 calendar days total. When the activity involves an ongoing scheme needing immediate attention, notify law enforcement by telephone in addition to filing the SAR.10eCFR. 31 CFR 1020.320 – Reports by Banks of Suspicious Transactions

Confidentiality and Tipping Off

SAR information is strictly confidential. The institution, its officers, employees, and agents are prohibited from telling anyone involved in the transaction that a report was filed or from disclosing any information that would reveal the report’s existence. The prohibition survives an employee’s departure from the institution. Government employees with knowledge of a filing face the same restriction. A narrow exception permits including SAR-related information in employment references under the Federal Deposit Insurance Act’s safe harbor for sharing termination information between financial institutions, but even then you cannot reveal that a SAR was filed.2Office of the Law Revision Counsel. 31 US Code 5318 – Compliance, Exemptions, and Summons Authority

Information Sharing Under Section 314

Section 314(a) creates a mandatory channel from the government to institutions. When FinCEN sends a 314(a) request, you must search your records for any account or transaction involving the named individual or entity. The search covers current accounts, accounts maintained within the preceding twelve months, reportable transactions from the preceding six months, and funds transfers from the preceding six months. Positive matches must be reported back within 14 days of the request or within the timeframe the request specifies.11FFIEC BSA/AML InfoBase. Assessing Compliance with BSA Regulatory Requirements – Special Information Sharing Procedures

Section 314(b) creates a voluntary channel between institutions. Financial institutions may share information with each other about individuals or entities suspected of money laundering or terrorist financing after filing a notice with FinCEN, which stays effective for one year. Institutions that share under 314(b) receive a safe harbor from liability for the disclosure.11FFIEC BSA/AML InfoBase. Assessing Compliance with BSA Regulatory Requirements – Special Information Sharing Procedures

OFAC Sanctions Screening

OFAC compliance sits under a separate legal framework from the BSA, but no compliance program is complete without it. The Office of Foreign Assets Control maintains the Specially Designated Nationals and Blocked Persons list, and U.S. persons are generally prohibited from transacting with anyone on it. New accounts should be screened against OFAC lists at or shortly after opening, such as during nightly processing. Existing customers should be rescreened whenever the OFAC list is updated, with frequency driven by risk. Wire transfers, letters of credit, and similar transactions should be checked before execution. How far you screen beyond the accountholder (beneficiaries, guarantors, signatories) depends on your risk assessment and available technology.12FFIEC BSA/AML InfoBase. Office of Foreign Assets Control

Recordkeeping

The BSA imposes a general five-year retention period for all records required under its regulations, including CTRs, SARs, CIP documentation, CDD records, and your written AML program materials.13eCFR. 31 CFR 1010.430 – Nature of Records and Retention Period

For CIP records, the identifying information must be kept for five years after the account is closed, and records of the verification methods used must be retained for five years after the record is made. Where verification occurred early in a long-standing customer relationship, the second clock can push retention well past the account closure date.4eCFR. 31 CFR 1020.220 – Customer Identification Program Requirements for Banks

Recordkeeping failures are among the most common examination findings. Build retention schedules into your document management systems rather than tracking them manually.

Penalties for Non-Compliance

Enforcement runs on parallel civil and criminal tracks. On the civil side, a negligent violation of any BSA provision can bring a penalty of up to $500 per occurrence, escalating to up to $50,000 when a pattern of negligent violations is established. Willful violations carry a civil penalty of up to the greater of $25,000 or the amount involved in the transaction, capped at $100,000. Violations of the enhanced due diligence and correspondent account provisions carry a distinct range, from two times the transaction amount up to $1,000,000.14Office of the Law Revision Counsel. 31 US Code 5321 – Civil Penalties

On the criminal side, willful BSA violations are federal crimes. The baseline penalty is a fine of up to $250,000, up to five years in prison, or both. When the violation occurs alongside another federal crime or as part of a pattern of illegal activity exceeding $100,000 in a twelve-month period, the maximums double to $500,000 and ten years.15Office of the Law Revision Counsel. 31 US Code 5322 – Criminal Penalties

Penalties apply to the institution and to individual officers, directors, and employees. FinCEN has pursued enforcement actions against compliance officers personally, not only the banks that employed them. The designated compliance officer role carries real legal exposure.16Financial Crimes Enforcement Network. Enforcement Actions

Safe Harbor for Good-Faith Reporting

Any financial institution that voluntarily or mandatorily reports suspicious activity to a government agency is shielded from civil liability for the disclosure. The protection extends to directors, officers, employees, and agents. No person can sue the institution under federal law, state law, or any contract for filing a SAR or for failing to notify the subject of the report.2Office of the Law Revision Counsel. 31 US Code 5318 – Compliance, Exemptions, and Summons Authority

That safe harbor shapes how the filing decision should be made. Filing when unsure carries no legal downside. Failing to file a report you should have filed can trigger institutional penalties and personal liability for the compliance officer who made the call.