Bank Secrecy Act (BSA)
The Bank Secrecy Act is the 1970 United States statute, heavily amended since, that requires banks, money services businesses and other financial institutions to keep records, register where applicable, report large cash transactions and suspicious activity, and maintain an anti-money-laundering program.
Also called: BSA/AML · 31 CFR Chapter X
The name is misleading: the Bank Secrecy Act is about disclosure, not secrecy. Passed in 1970 and amended repeatedly — most heavily by the USA PATRIOT Act in 2001 and the Anti-Money Laundering Act of 2020 — it is the foundation of United States anti-money-laundering law. The operative detail lives in the regulations beneath it, at 31 CFR Chapter X, written and administered by FinCEN.
The core obligations are recordkeeping, reporting, and having a program. Cash above a set dollar amount is reported on a Currency Transaction Report. Activity that may involve criminal proceeds is reported on a Suspicious Activity Report — in the United States, filed with FinCEN, which is a different instrument from the report of the same abbreviation that a UK firm sends to the National Crime Agency. Funds-transfer records must be kept and passed along the chain. A money services business must also register with FinCEN, and every covered institution must maintain an AML program.
Who examines for compliance depends on the institution. Federal banking agencies examine banks. The IRS examines money services businesses on FinCEN’s behalf. State regulators apply their own requirements on top, and a state examination of a licensed money transmitter will normally look at BSA compliance as well as the state’s own conditions.
In practice
The Bank Secrecy Act applies to money services businesses as well as banks, but the specific obligations are not identical between them. Check what attaches to the particular institution type rather than reading a bank’s compliance manual and assuming it fits.
Example
A licensed US money transmitter and its sponsor bank both file suspicious activity reports with FinCEN under the same statute. Only the transmitter must register with FinCEN as a money services business. Only the bank operates under the customer identification program rule written for banks. One Act, two very different obligation sets.
Commonly confused with
| Term | How it differs |
|---|---|
| FinCEN | FinCEN is the bureau that writes, administers and receives filings under the rules; the Bank Secrecy Act is the statute those rules sit beneath. |
| FinCEN Registration | Registration is one BSA obligation for money services businesses, and completing it satisfies none of the others. |
See also
- FinCENThe bureau of the US Treasury that administers the Bank Secrecy Act. FinCEN writes the anti-money-laundering rules applying to financial institutions, receives suspicious activity and currency transaction reports, and maintains the federal register of money services businesses.
- Suspicious Activity ReportA suspicious activity report is a confidential filing made to FinCEN when a US financial institution knows, suspects, or has reason to suspect that a transaction above a set dollar floor involves illicit funds, has no apparent lawful purpose, or is designed to evade reporting rules. It is filed without telling the customer.
- Money Services BusinessA money services business is a category in US federal law under the Bank Secrecy Act, covering seven capacities: dealer in foreign exchange, check casher, issuer or seller of money orders or traveler’s checks, provider of prepaid access, seller of prepaid access, money transmitter, and the US Postal Service.
- Currency Transaction ReportA Currency Transaction Report, or CTR, is a report a United States financial institution files with FinCEN when currency transactions by or on behalf of one person exceed USD 10,000 in a single business day. It is triggered by an amount of cash, not by anything suspicious.
- AML ProgramAn AML program is the documented set of controls a regulated firm must maintain to detect and deter money laundering. In the United States it is conventionally described as four pillars: written policies and procedures, a designated compliance officer, staff training, and independent review. Other regimes frame the same components differently.
