AML/BSA: Anti-Money Laundering and Bank Secrecy Act Guide
The Bank Secrecy Act (BSA), enacted in 1970 and significantly strengthened by the USA PATRIOT Act and the 2021 Anti-Money Laundering Act, forms the foundation of the United States' anti-money laundering (AML) regulatory regime. It requires financial institutions to assist government agencies in detecting and preventing money laundering, terrorist financing, and other financial crimes. Recent enforcement actions exceeding $1 billion in penalties demonstrate that regulators treat AML failures with extraordinary seriousness.
What AML/BSA Is and Who Issues It
The BSA was enacted on October 26, 1970 as the Currency and Foreign Transactions Reporting Act. It established the first systemic framework for financial institution reporting to government agencies. Subsequent legislation — including the Money Laundering Control Act (1986), the USA PATRIOT Act (2001), and the Anti-Money Laundering Act of 2020 (passed as part of the National Defense Authorization Act for FY2021) — dramatically expanded BSA's scope and requirements.
Primary enforcement authority rests with the Financial Crimes Enforcement Network (FinCEN), a bureau of the US Department of the Treasury. Banking regulators (OCC, Federal Reserve, FDIC, NCUA) enforce BSA requirements during safety-and-soundness examinations for their respective institutions. The Department of Justice and FBI conduct criminal investigations of AML failures. The 2021 AML Act strengthened FinCEN's authority, introduced national AML priorities, and created the beneficial ownership registry that companies began filing into in January 2024.
Who Must Comply
BSA/AML requirements apply broadly across the financial sector. The following institution types are covered:
- Banks, credit unions, and savings associations
- Broker-dealers and securities firms
- Mutual funds and investment advisers (certain)
- Money services businesses (MSBs): money transmitters, currency exchangers, check cashers, prepaid access providers, and dealers in foreign exchange
- Casinos and card clubs
- Insurance companies (for certain products)
- Loan or finance companies
- Housing government-sponsored enterprises
- Operators of credit card systems
- Virtual currency businesses and digital asset service providers
Fintech companies providing money transmission services — including payment apps, digital wallets, and crypto exchanges — face full BSA/AML obligations as MSBs. The definition of "financial institution" under the BSA has expanded through regulatory rulemaking and will continue to evolve as new financial products emerge.
The Five Pillars of BSA/AML Compliance
FinCEN regulations require financial institutions to implement an AML program built on five pillars:
Pillar 1: Internal Controls
Internal controls are the policies, procedures, and processes that identify, detect, and manage money laundering and terrorist financing risks. They must cover all products, services, customers, and geographic footprints of the institution. Key internal controls include transaction monitoring rules and thresholds, KYC procedures, SAR investigation workflows, and staff accountability for AML functions.
Pillar 2: Independent Testing
BSA/AML programs require independent testing — typically by internal audit or an external firm — conducted at least annually. Testing assesses the adequacy and effectiveness of the AML program, including the calibration of transaction monitoring systems, the quality of SAR filings, and adherence to KYC procedures. Regulators review independent testing reports during examinations and expect institutions to remediate identified weaknesses promptly.
Pillar 3: BSA/AML Officer
Every covered institution must designate a BSA/AML Officer responsible for implementing and managing the compliance program. The BSA/AML Officer must have sufficient authority, resources, and expertise to carry out this role. At large institutions, this is a senior executive with a dedicated team. At smaller institutions, the role may be combined with other responsibilities but must remain substantive.
Pillar 4: Training
All personnel with relevant AML responsibilities must receive training commensurate with their roles. This includes frontline staff who identify suspicious activity, compliance personnel who investigate and file SARs, senior management who oversee the program, and board members who provide governance oversight. Training must be documented and updated as requirements change.
Pillar 5: Customer Due Diligence (CDD)
Added as an explicit fifth pillar through FinCEN's 2016 CDD Rule, this pillar requires covered financial institutions to implement risk-based procedures for:
- Identifying and verifying the identity of customers through a Customer Identification Program (CIP)
- Identifying and verifying the identity of beneficial owners of legal entity customers — individuals who own 25% or more of the entity or who exercise control
- Understanding the nature and purpose of customer relationships to develop customer risk profiles
- Conducting ongoing monitoring to identify and report suspicious transactions and maintain accurate customer information
Enhanced Due Diligence (EDD) applies to higher-risk customers such as politically exposed persons (PEPs), customers from high-risk jurisdictions, and customers in business lines with elevated money laundering risk.
Reporting Requirements
Suspicious Activity Reports (SARs)
Financial institutions must file a SAR with FinCEN within 30 days of detecting a known or suspected violation of federal law, including money laundering, terrorist financing, or fraud. The report must include: the type of suspicious activity, the amount involved, the suspect's identifying information where available, and a narrative explaining why the activity is suspicious. SAR filings are confidential and may not be disclosed to the subject of the report. Institutions must maintain records of filed SARs for five years.
Currency Transaction Reports (CTRs)
Institutions must file a CTR for any cash transaction exceeding $10,000, whether a single transaction or multiple transactions that aggregate to $10,000 within a single business day by or for a single person. CTRs must be filed with FinCEN within 15 days of the transaction. Structuring — breaking up transactions to avoid the $10,000 threshold — is itself a federal crime.
Other Reporting
Suspicious activity, international wire transfers, and foreign bank account relationships generate additional reporting obligations under FBAR (Foreign Bank Account Report) requirements and other specialized rules.
Audit and Assessment Process
Independent testing of the BSA/AML program typically covers:
| Testing Area | Frequency | Key Questions |
|---|---|---|
| Transaction monitoring calibration | Annual | Are rules detecting the right patterns? Are false-positive rates reasonable? |
| SAR quality review | Annual | Are SARs filed timely? Are narratives complete and accurate? |
| CIP/CDD file review | Annual | Are customer files complete? Are EDD files adequate for high-risk customers? |
| Training effectiveness | Annual | Is training current? Is completion documented? |
| Policy and procedure review | Annual | Are policies current with regulatory guidance? |
Regulatory examinations take a risk-based approach, devoting more scrutiny to institutions with higher-risk products, customers, or geographies, or with prior examination findings.
Costs and Timeline
| Institution Type | Typical Timeline | Annual Compliance Cost |
|---|---|---|
| Small community bank | 6–9 months initial build | $50,000–$200,000 |
| Mid-sized regional bank | 9–12 months | $200,000–$1,000,000 |
| Large national bank | 12–18 months | $1,000,000–$3,000,000+ |
| MSB or fintech | 6–12 months | $50,000–$500,000 |
Transaction monitoring technology is a major cost driver, with enterprise platforms ranging from $100,000 to $1 million or more annually. The 2021 AML Act's innovation provisions encourage investment in new technologies — including AI-based transaction monitoring — that can improve detection while reducing false-positive burden.
Comparison with Related Frameworks
- FATF Recommendations: 75% overlap. FATF's 40 Recommendations establish the global standard that US BSA/AML requirements implement. Institutions operating internationally must align with both US requirements and FATF-derived local laws. See the FATF guide.
- GLBA: About 30% overlap, primarily around customer information protection and record-keeping. Financial institutions subject to both must integrate AML CIP/CDD with GLBA customer data management. See the GLBA guide.
- Dodd-Frank: Overlapping governance and risk management requirements for large financial institutions. See the Dodd-Frank guide.
- PCI DSS: Limited overlap, but financial institutions processing card payments must simultaneously manage PCI DSS compliance alongside AML/BSA. Shared access control and audit logging requirements reduce duplicate effort.
How Automation Helps
AML compliance is one of the most technology-intensive areas of financial regulation. Transaction monitoring, KYC verification, and SAR case management all depend on specialized technology. Compliance automation tools address the broader program management burden:
- Policy and procedure management ensures AML program documentation stays current with FinCEN guidance and examination expectations
- Training tracking verifies that all required personnel complete AML training and documents completion for examiner review
- Vendor management modules track the AML compliance posture of correspondent banks, payment processors, and other critical third parties
- Risk assessment workflows formalize the annual AML risk assessment process with documentation suitable for regulatory review
LowerPlane supports AML program management components including policy management, training tracking, and risk assessment documentation across 50-plus compliance frameworks. At $4,000 per year entry pricing (with a free tier available) and a 9.4/10 AuditXYZ rating, LowerPlane provides fintech companies and financial institutions with a unified compliance platform. For fintech-specific regulatory guidance, see /for/fintech. Compare automation platforms at /compare/best-compliance-automation-platforms.
Frequently Asked Questions
What is the difference between AML and BSA?
The Bank Secrecy Act (BSA) is the US federal statute that establishes the legal framework for anti-money laundering (AML) compliance. "AML" refers broadly to the practices and programs that institutions implement to detect and prevent money laundering. In practice, the terms are often used interchangeably, and the combined abbreviation BSA/AML refers to the regulatory compliance program that US financial institutions must maintain.
What happens if a financial institution fails to file a SAR?
Failure to file required SARs is a serious AML violation. Regulators can impose civil monetary penalties, require independent monitoring at the institution's expense, and — for the most egregious failures — refer matters for criminal prosecution. Several major banks have entered deferred prosecution agreements or paid multi-billion dollar penalties for systemic SAR filing failures. Regulators take a dim view of institutions that detect suspicious activity but fail to report it.
Do cryptocurrency exchanges need BSA/AML compliance?
Yes. FinCEN has determined that virtual currency exchanges, convertible virtual currency administrators, and certain other digital asset businesses qualify as money services businesses (MSBs) under the BSA. They must register with FinCEN as MSBs, implement AML programs with the five pillars, file SARs and CTRs, and conduct CIP/CDD for their customers. This applies to centralized exchanges; the treatment of decentralized finance (DeFi) protocols continues to evolve through FinCEN rulemaking.
What is beneficial ownership and why does it matter?
Beneficial ownership refers to the natural persons who ultimately own or control a legal entity. Money launderers often use shell companies and complex corporate structures to obscure the true owners of criminal proceeds. FinCEN's CDD Rule requires covered financial institutions to identify and verify individuals who own 25% or more of a legal entity customer, plus the individual who controls the entity. The 2021 AML Act's Corporate Transparency Act provisions established a national beneficial ownership registry, which FinCEN began administering in January 2024, creating a complementary resource for due diligence.
How often should we recalibrate our transaction monitoring system?
FinCEN and banking regulators expect institutions to conduct periodic reviews of transaction monitoring system calibration — at least annually and whenever significant changes occur in the institution's products, services, or customer base. Calibration reviews should assess whether alert thresholds are appropriate (not generating excessive false positives while still detecting suspicious patterns), whether alert rules are current with emerging typologies, and whether alert investigation and disposition processes are operating as intended. Regulators have imposed significant penalties on institutions where transaction monitoring systems were poorly calibrated or tuning reviews were not documented.