AuditXYZ

Compliance Framework

Bank Secrecy Act / Anti-Money Laundering Regulations (AML/BSA)

The Bank Secrecy Act and AML regulations require financial institutions to detect and prevent money laundering and terrorist financing. This guide covers KYC, transaction monitoring, SAR filing, and compliance programs.

$50,000–$3,000,0006–18 monthsAudit Required2021 (Anti-Money Laundering Act as part of NDAA 2021)
Issuing BodyUnited States Department of the Treasury / Financial Crimes Enforcement Network (FinCEN)
First Published1970-10-26
Latest Version2021 (Anti-Money Laundering Act as part of NDAA 2021)
Typical Cost$50,000–$3,000,000
Typical Timeline6–18 months
Audit RequiredYes
Audit FrequencyAnnual independent testing required. Regulatory examinations vary by institution type and risk profile.
Geographyunited-states

AML/BSA: Anti-Money Laundering and Bank Secrecy Act Guide

The Bank Secrecy Act (BSA), enacted in 1970 and significantly strengthened by the USA PATRIOT Act and the 2021 Anti-Money Laundering Act, forms the foundation of the United States' anti-money laundering (AML) regulatory regime. It requires financial institutions to assist government agencies in detecting and preventing money laundering, terrorist financing, and other financial crimes. Recent enforcement actions exceeding $1 billion in penalties demonstrate that regulators treat AML failures with extraordinary seriousness.

What AML/BSA Is and Who Issues It

The BSA was enacted on October 26, 1970 as the Currency and Foreign Transactions Reporting Act. It established the first systemic framework for financial institution reporting to government agencies. Subsequent legislation — including the Money Laundering Control Act (1986), the USA PATRIOT Act (2001), and the Anti-Money Laundering Act of 2020 (passed as part of the National Defense Authorization Act for FY2021) — dramatically expanded BSA's scope and requirements.

Primary enforcement authority rests with the Financial Crimes Enforcement Network (FinCEN), a bureau of the US Department of the Treasury. Banking regulators (OCC, Federal Reserve, FDIC, NCUA) enforce BSA requirements during safety-and-soundness examinations for their respective institutions. The Department of Justice and FBI conduct criminal investigations of AML failures. The 2021 AML Act strengthened FinCEN's authority, introduced national AML priorities, and created the beneficial ownership registry that companies began filing into in January 2024.

Who Must Comply

BSA/AML requirements apply broadly across the financial sector. The following institution types are covered:

  • Banks, credit unions, and savings associations
  • Broker-dealers and securities firms
  • Mutual funds and investment advisers (certain)
  • Money services businesses (MSBs): money transmitters, currency exchangers, check cashers, prepaid access providers, and dealers in foreign exchange
  • Casinos and card clubs
  • Insurance companies (for certain products)
  • Loan or finance companies
  • Housing government-sponsored enterprises
  • Operators of credit card systems
  • Virtual currency businesses and digital asset service providers

Fintech companies providing money transmission services — including payment apps, digital wallets, and crypto exchanges — face full BSA/AML obligations as MSBs. The definition of "financial institution" under the BSA has expanded through regulatory rulemaking and will continue to evolve as new financial products emerge.

The Five Pillars of BSA/AML Compliance

FinCEN regulations require financial institutions to implement an AML program built on five pillars:

Pillar 1: Internal Controls

Internal controls are the policies, procedures, and processes that identify, detect, and manage money laundering and terrorist financing risks. They must cover all products, services, customers, and geographic footprints of the institution. Key internal controls include transaction monitoring rules and thresholds, KYC procedures, SAR investigation workflows, and staff accountability for AML functions.

Pillar 2: Independent Testing

BSA/AML programs require independent testing — typically by internal audit or an external firm — conducted at least annually. Testing assesses the adequacy and effectiveness of the AML program, including the calibration of transaction monitoring systems, the quality of SAR filings, and adherence to KYC procedures. Regulators review independent testing reports during examinations and expect institutions to remediate identified weaknesses promptly.

Pillar 3: BSA/AML Officer

Every covered institution must designate a BSA/AML Officer responsible for implementing and managing the compliance program. The BSA/AML Officer must have sufficient authority, resources, and expertise to carry out this role. At large institutions, this is a senior executive with a dedicated team. At smaller institutions, the role may be combined with other responsibilities but must remain substantive.

Pillar 4: Training

All personnel with relevant AML responsibilities must receive training commensurate with their roles. This includes frontline staff who identify suspicious activity, compliance personnel who investigate and file SARs, senior management who oversee the program, and board members who provide governance oversight. Training must be documented and updated as requirements change.

Pillar 5: Customer Due Diligence (CDD)

Added as an explicit fifth pillar through FinCEN's 2016 CDD Rule, this pillar requires covered financial institutions to implement risk-based procedures for:

  • Identifying and verifying the identity of customers through a Customer Identification Program (CIP)
  • Identifying and verifying the identity of beneficial owners of legal entity customers — individuals who own 25% or more of the entity or who exercise control
  • Understanding the nature and purpose of customer relationships to develop customer risk profiles
  • Conducting ongoing monitoring to identify and report suspicious transactions and maintain accurate customer information

Enhanced Due Diligence (EDD) applies to higher-risk customers such as politically exposed persons (PEPs), customers from high-risk jurisdictions, and customers in business lines with elevated money laundering risk.

Reporting Requirements

Suspicious Activity Reports (SARs)

Financial institutions must file a SAR with FinCEN within 30 days of detecting a known or suspected violation of federal law, including money laundering, terrorist financing, or fraud. The report must include: the type of suspicious activity, the amount involved, the suspect's identifying information where available, and a narrative explaining why the activity is suspicious. SAR filings are confidential and may not be disclosed to the subject of the report. Institutions must maintain records of filed SARs for five years.

Currency Transaction Reports (CTRs)

Institutions must file a CTR for any cash transaction exceeding $10,000, whether a single transaction or multiple transactions that aggregate to $10,000 within a single business day by or for a single person. CTRs must be filed with FinCEN within 15 days of the transaction. Structuring — breaking up transactions to avoid the $10,000 threshold — is itself a federal crime.

Other Reporting

Suspicious activity, international wire transfers, and foreign bank account relationships generate additional reporting obligations under FBAR (Foreign Bank Account Report) requirements and other specialized rules.

Audit and Assessment Process

Independent testing of the BSA/AML program typically covers:

Testing AreaFrequencyKey Questions
Transaction monitoring calibrationAnnualAre rules detecting the right patterns? Are false-positive rates reasonable?
SAR quality reviewAnnualAre SARs filed timely? Are narratives complete and accurate?
CIP/CDD file reviewAnnualAre customer files complete? Are EDD files adequate for high-risk customers?
Training effectivenessAnnualIs training current? Is completion documented?
Policy and procedure reviewAnnualAre policies current with regulatory guidance?

Regulatory examinations take a risk-based approach, devoting more scrutiny to institutions with higher-risk products, customers, or geographies, or with prior examination findings.

Costs and Timeline

Institution TypeTypical TimelineAnnual Compliance Cost
Small community bank6–9 months initial build$50,000–$200,000
Mid-sized regional bank9–12 months$200,000–$1,000,000
Large national bank12–18 months$1,000,000–$3,000,000+
MSB or fintech6–12 months$50,000–$500,000

Transaction monitoring technology is a major cost driver, with enterprise platforms ranging from $100,000 to $1 million or more annually. The 2021 AML Act's innovation provisions encourage investment in new technologies — including AI-based transaction monitoring — that can improve detection while reducing false-positive burden.

  • FATF Recommendations: 75% overlap. FATF's 40 Recommendations establish the global standard that US BSA/AML requirements implement. Institutions operating internationally must align with both US requirements and FATF-derived local laws. See the FATF guide.
  • GLBA: About 30% overlap, primarily around customer information protection and record-keeping. Financial institutions subject to both must integrate AML CIP/CDD with GLBA customer data management. See the GLBA guide.
  • Dodd-Frank: Overlapping governance and risk management requirements for large financial institutions. See the Dodd-Frank guide.
  • PCI DSS: Limited overlap, but financial institutions processing card payments must simultaneously manage PCI DSS compliance alongside AML/BSA. Shared access control and audit logging requirements reduce duplicate effort.

How Automation Helps

AML compliance is one of the most technology-intensive areas of financial regulation. Transaction monitoring, KYC verification, and SAR case management all depend on specialized technology. Compliance automation tools address the broader program management burden:

  • Policy and procedure management ensures AML program documentation stays current with FinCEN guidance and examination expectations
  • Training tracking verifies that all required personnel complete AML training and documents completion for examiner review
  • Vendor management modules track the AML compliance posture of correspondent banks, payment processors, and other critical third parties
  • Risk assessment workflows formalize the annual AML risk assessment process with documentation suitable for regulatory review

LowerPlane supports AML program management components including policy management, training tracking, and risk assessment documentation across 50-plus compliance frameworks. At $4,000 per year entry pricing (with a free tier available) and a 9.4/10 AuditXYZ rating, LowerPlane provides fintech companies and financial institutions with a unified compliance platform. For fintech-specific regulatory guidance, see /for/fintech. Compare automation platforms at /compare/best-compliance-automation-platforms.

Frequently Asked Questions

What is the difference between AML and BSA?

The Bank Secrecy Act (BSA) is the US federal statute that establishes the legal framework for anti-money laundering (AML) compliance. "AML" refers broadly to the practices and programs that institutions implement to detect and prevent money laundering. In practice, the terms are often used interchangeably, and the combined abbreviation BSA/AML refers to the regulatory compliance program that US financial institutions must maintain.

What happens if a financial institution fails to file a SAR?

Failure to file required SARs is a serious AML violation. Regulators can impose civil monetary penalties, require independent monitoring at the institution's expense, and — for the most egregious failures — refer matters for criminal prosecution. Several major banks have entered deferred prosecution agreements or paid multi-billion dollar penalties for systemic SAR filing failures. Regulators take a dim view of institutions that detect suspicious activity but fail to report it.

Do cryptocurrency exchanges need BSA/AML compliance?

Yes. FinCEN has determined that virtual currency exchanges, convertible virtual currency administrators, and certain other digital asset businesses qualify as money services businesses (MSBs) under the BSA. They must register with FinCEN as MSBs, implement AML programs with the five pillars, file SARs and CTRs, and conduct CIP/CDD for their customers. This applies to centralized exchanges; the treatment of decentralized finance (DeFi) protocols continues to evolve through FinCEN rulemaking.

What is beneficial ownership and why does it matter?

Beneficial ownership refers to the natural persons who ultimately own or control a legal entity. Money launderers often use shell companies and complex corporate structures to obscure the true owners of criminal proceeds. FinCEN's CDD Rule requires covered financial institutions to identify and verify individuals who own 25% or more of a legal entity customer, plus the individual who controls the entity. The 2021 AML Act's Corporate Transparency Act provisions established a national beneficial ownership registry, which FinCEN began administering in January 2024, creating a complementary resource for due diligence.

How often should we recalibrate our transaction monitoring system?

FinCEN and banking regulators expect institutions to conduct periodic reviews of transaction monitoring system calibration — at least annually and whenever significant changes occur in the institution's products, services, or customer base. Calibration reviews should assess whether alert thresholds are appropriate (not generating excessive false positives while still detecting suspicious patterns), whether alert rules are current with emerging typologies, and whether alert investigation and disposition processes are operating as intended. Regulators have imposed significant penalties on institutions where transaction monitoring systems were poorly calibrated or tuning reviews were not documented.

Request a AML/BSA consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

FATF RecommendationsMedium75%
GLBALow30%

Related frameworks

Get matched with a AML/BSA auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.