AML / BSA Programs

AML BSA Programs: Building Compliant Anti-Money Laundering Programs for Financial Businesses

AML BSA programs are the foundational compliance infrastructure that every money services business, bank, fintech operator, and crypto business in the United States is legally required to maintain. The Bank Secrecy Act (BSA) establishes the framework: every covered financial institution must build and maintain a written anti-money laundering program, designate a compliance officer, train employees, conduct independent testing, and apply customer due diligence procedures. The quality of that program determines whether a business can maintain banking relationships, pass regulatory examination, and operate without enforcement action from FinCEN, the OCC, or state regulators. Faisal Khan LLC advises MSBs, fintechs, and crypto businesses on AML BSA program design and remediation, and connects them to compliance officers, AML auditors, and BSA/AML software providers.


The Bank Secrecy Act: The Foundation of US AML Compliance

The Bank Secrecy Act (BSA) of 1970, as amended by the USA PATRIOT Act and subsequent legislation, is the primary US federal law governing anti-money laundering and financial intelligence. Administered by the Financial Crimes Enforcement Network (FinCEN), the BSA imposes reporting, recordkeeping, and program requirements on a broad range of financial institutions, including banks, credit unions, broker-dealers, insurance companies, casinos, and money services businesses.

For money services businesses, the BSA's core obligations include: registration with FinCEN as an MSB (required for businesses that transmit money, exchange currency, issue or redeem money orders and traveler's checks, or deal in convertible virtual currency); maintenance of a written AML program; filing of Currency Transaction Reports (CTRs) for cash transactions over USD 10,000; filing of Suspicious Activity Reports (SARs) when the business detects or suspects money laundering, fraud, or other suspicious activity; recordkeeping for certain transactions; and compliance with OFAC sanctions obligations.

Failure to maintain a compliant AML/BSA program can result in FinCEN civil money penalties, criminal prosecution, debarment from the financial system, and loss of banking relationships. The most common enforcement actions against MSBs involve failure to file SARs, inadequate customer due diligence, and failure to conduct independent testing.


The Five Pillars of an AML/BSA Program

FinCEN's regulations require that every covered financial institution's AML program be "reasonably designed" to prevent the institution from being used for money laundering or terrorist financing. The five pillars of an adequate AML program are:

1. Written policies, procedures, and controls: The program must be documented in writing. Policies must address the specific risks of the business model, products, customers, channels, and geographies. Generic policies that do not reflect the actual business are routinely cited as deficiencies.

2. Designated compliance officer: A qualified individual must be designated to administer the AML program. The compliance officer must have sufficient authority, resources, and independence to be effective. For MSBs, the compliance officer does not need to be full-time or on-site, but must be accessible and accountable.

3. Employee training: All employees who are relevant to AML compliance (customer-facing staff, supervisors, management) must receive regular training on the institution's AML obligations, red flags, SAR filing procedures, and their specific responsibilities. Training must be documented.

4. Independent testing: The AML program must be reviewed by an independent party (not the compliance officer or a party under their supervision) at least once every 12 to 18 months. The independent test evaluates whether the program is functioning as designed and identifies gaps. For smaller MSBs, independent testing is often conducted by an external AML audit firm.

5. Customer due diligence (CDD): The CDD rule requires covered financial institutions to identify and verify the identity of customers, identify and verify the identity of beneficial owners of legal entity customers (individuals with 25% or more ownership), understand the nature and purpose of customer relationships, and conduct ongoing monitoring.


BSA Reporting Obligations

The BSA imposes specific reporting obligations that require prompt and accurate compliance:

Currency Transaction Reports (CTRs): A CTR must be filed with FinCEN within 15 days for any cash transaction (or series of related transactions) exceeding USD 10,000 in a single business day. CTRs are filed electronically through FinCEN's BSA E-Filing System. Structuring transactions specifically to avoid the USD 10,000 threshold is itself a federal crime (31 U.S.C. 5324) and a common AML red flag.

Suspicious Activity Reports (SARs): A SAR must be filed within 30 days of the date the suspicious activity is detected (60 days if the subject cannot be identified on the date of detection). SAR filing is mandatory when the institution knows, suspects, or has reason to suspect that a transaction involves funds derived from illegal activity, is designed to evade reporting requirements, lacks a lawful purpose, or involves the use of the institution for criminal purposes. SARs are confidential; disclosing that a SAR has been filed is a federal violation.

314(a) and 314(b) information sharing: FinCEN's 314(a) program allows law enforcement to request that financial institutions search their records for accounts or transactions matching a named subject. 314(b) is voluntary and allows financial institutions to share information with each other about suspected money laundering or terrorist financing.


AML Programs for MSBs and Crypto Businesses

MSB-specific AML programs must address the particular risk characteristics of money services: high transaction volumes, cash-intensive operations (for remittance and currency exchange businesses), diverse and sometimes anonymous customer bases, agent network risks, and corridor-specific geographic risks.

Crypto and stablecoin businesses face additional AML complexities: pseudonymous wallet addresses, cross-chain transaction flows, exposure to high-risk exchanges and DeFi protocols, and Travel Rule obligations for VASP-to-VASP transfers. FinCEN has issued extensive guidance confirming that businesses dealing in convertible virtual currency are MSBs subject to all BSA obligations, including those that apply specifically to money transmitters.

The most common AML program deficiencies that cause banking rejections and enforcement actions include: a risk assessment that predates the current business model, a compliance officer without adequate authority or resources, inadequate SAR investigation and filing procedures, missing or nominal independent testing, and transaction monitoring that generates alerts but where the investigation process is not documented.


Frequently Asked Questions

Who is required to have an AML/BSA program? In the US, covered financial institutions under the BSA include banks, credit unions, broker-dealers, insurance companies, casinos, and money services businesses. MSBs are defined broadly to include businesses that provide money transmission, currency exchange, check cashing, money order issuance and redemption, traveler's check issuance and redemption, and prepaid access, as well as businesses dealing in convertible virtual currency. If your business transmits money or exchanges currency (including crypto), you are almost certainly an MSB with full BSA obligations.

Can a small MSB have a minimal AML program? The BSA requires a program that is "reasonably designed" based on the institution's size, activities, and risks. A small MSB with limited transaction volumes and a simple business model can have a leaner program than a large bank, but the five pillars are required regardless of size. "Minimal" should not be confused with incomplete; the program must address the actual risks of the business, not simply exist on paper.

How often must the AML program be updated? The program must be reviewed and updated whenever the business model changes (new products, new corridors, new customer segments), when new regulatory guidance is issued that affects the business, and at a minimum annually. An outdated program that does not reflect current operations is a common deficiency finding.

What does FinCEN look for when it examines an MSB's AML program? FinCEN examinations (typically conducted by state examiners or the IRS as FinCEN's examination delegate for MSBs) evaluate: whether the program is written and tailored to the business's risks, whether the compliance officer has adequate authority and qualifications, whether training is documented and current, whether independent testing has occurred and findings have been addressed, and whether the CDD and SAR filing procedures are functioning and documented. We advise on examination preparation.


Build an AML BSA Program That Passes the Test

AML BSA programs that are built properly from the start prevent the enforcement actions, banking rejections, and compliance remediation costs that plague MSBs and fintechs that treat compliance as an afterthought. Faisal Khan LLC advises businesses on AML BSA program design, helps identify and remediate gaps in existing programs, connects businesses to qualified compliance officers, independent AML auditors, and BSA/AML software providers suited to the business's size and transaction profile, and helps prepare businesses for banking partner due diligence and regulatory examination. If your AML BSA program needs to be built from scratch or is overdue for a serious upgrade, we can help.

Share
Page Last Updated: 29/Jun/2026 (4616057)