search

FAQs About BSA And AML

BSA and AML Compliance FAQs

What is the BSA?

The Bank Secrecy Act (BSA) is a U.S. federal law designed to prevent and detect money laundering, terrorist financing, and other financial crimes. It establishes recordkeeping, reporting, customer identification, and compliance-program requirements for covered financial institutions.

What does AML mean?

AML stands for Anti-Money Laundering. An AML program consists of policies, procedures, controls, monitoring, investigations, reporting, and training designed to identify and mitigate money-laundering and related financial-crime risks.

Who is responsible for BSA/AML compliance?

BSA/AML compliance is an enterprise-wide responsibility. The board and senior management provide oversight, while the BSA Officer and compliance personnel administer the program. Business units and employees are responsible for following applicable procedures and escalating suspicious activity.

What are the basic elements of a BSA/AML program?

A typical program includes:

  • Internal controls and written policies and procedures
  • A designated BSA/AML compliance officer
  • Independent testing
  • Employee training
  • Customer identification and risk-based customer due diligence
  • Transaction monitoring and suspicious-activity processes
  • Applicable regulatory reporting and recordkeeping

What are the pillars of a BSA/AML compliance program?

Four longstanding pillars are a system of internal controls, independent testing, a designated BSA compliance officer, and training for appropriate personnel. Customer due diligence, including beneficial ownership identification for legal entity customers, was added as a fifth pillar effective in 2018. Examiners assess each pillar separately, and a weakness in any one of them can support a program criticism.

What is a Customer Identification Program (CIP)?

CIP is the process used to establish and verify a customer's identity when an account is opened, consistent with applicable regulatory requirements.

What is Customer Due Diligence (CDD)?

CDD involves understanding who the customer is, the nature and purpose of the relationship, and the customer's expected activity so that the institution can appropriately assess and manage financial-crime risk.

What is Enhanced Due Diligence (EDD)?

EDD is additional investigation or monitoring applied to customers or relationships presenting higher risk. The specific measures should be proportionate to the identified risk.

What is a beneficial owner?

For covered legal-entity customers, beneficial ownership requirements generally require identifying individuals who meet applicable ownership or control criteria. The exact requirements depend on the applicable regulation and circumstances.

What is transaction monitoring?

Transaction monitoring involves reviewing customer activity for patterns or transactions that may be inconsistent with the customer's known profile or may indicate money laundering, fraud, or other illicit activity.

What is OFAC screening?

OFAC screening is the process of identifying potential matches to sanctions administered by the U.S. Department of the Treasury's Office of Foreign Assets Control. BSA/AML compliance and sanctions compliance are related but distinct regulatory disciplines.

What should an employee do if they notice potentially suspicious activity?

Employees should follow the institution's escalation procedures and promptly report the concern to the designated compliance/BSA personnel. They should not independently confront the customer or disclose confidential investigative or SAR information.

What are common red flags for suspicious activity?

Examples can include:

  • Activity inconsistent with a customer's stated business or expected behavior
  • Unexplained rapid movement of funds
  • Unusual transaction patterns
  • Structuring
  • Use of multiple accounts without an apparent legitimate purpose
  • Transactions involving higher-risk jurisdictions or counterparties

What is a Suspicious Activity Report (SAR)?

A SAR is a regulatory report used by covered financial institutions to report transactions or patterns of activity that meet applicable suspicious-activity reporting requirements.

Does every unusual transaction require a SAR?

No. An unusual transaction is not automatically suspicious. Institutions should investigate activity based on their risk-based procedures and applicable reporting thresholds and determine whether the facts and circumstances warrant reporting.

Who must receive BSA/AML training?

Appropriate personnel, which examiners interpret functionally rather than by job title. In practice this means anyone who opens accounts, handles transactions, makes lending decisions, monitors activity, or supervises those who do, plus the board, which needs enough understanding to exercise oversight. Training should be tailored to role: a teller and a commercial lender do not need the same course.

How often is BSA/AML training required?

The regulation does not specify a frequency. The expectation, well established in examination practice, is at least annually for most staff, with additional training when the person's role changes, when regulations change, or when testing reveals a gap. Institutions should document who was trained, when, on what content, and that the board received its own training.

What does independent testing require?

A review of the BSA/AML program by someone independent of the function being tested, such as internal audit, a qualified consultant, or, in smaller institutions, a knowledgeable employee outside the BSA function. Testing should cover the adequacy of the program, transaction testing, and the effectiveness of monitoring. Frequency is risk-based, with annual being the common practice.

What is a risk assessment, and how often should it be updated?

A risk assessment is a documented analysis of the institution's exposure to money laundering and terrorist financing across products, services, customers, and geographies, which then drives the design of controls. It should be refreshed when the risk profile changes, such as with new products, new markets, or a merger, and reviewed at least annually.

When must a Currency Transaction Report be filed?

For each transaction in currency of more than $10,000 by, through, or to the institution in one business day by or on behalf of the same person. Multiple transactions must be aggregated when the institution knows they are by or on behalf of the same person. CTRs are filed with FinCEN, and the deadline is 15 days after the transaction.

What is structuring, and what should staff do if they see it?

Structuring is breaking transactions into amounts below the reporting threshold, or otherwise arranging them, to evade the CTR requirement. It is a federal crime regardless of whether the underlying funds are legitimate. Staff must never advise a customer how to avoid triggering a CTR; the correct response is to complete the transaction as presented and escalate for suspicious activity review.

When must a Suspicious Activity Report be filed?

When the institution knows, suspects, or has reason to suspect that a transaction involves funds from illegal activity, is designed to evade BSA requirements, has no business or apparent lawful purpose, or involves use of the institution to facilitate criminal activity. The applicable dollar thresholds depend on the circumstances and institution.

What is the SAR filing deadline?

The applicable deadline is generally 30 calendar days after initial detection of facts that may constitute a basis for filing. If no suspect has been identified on the date of detection, applicable rules may permit additional time. Institutions should document the date of initial detection and follow current regulatory requirements.

Can we tell a customer that we filed a SAR?

No. SAR information is subject to strict confidentiality requirements. Employees should not disclose the existence of a SAR, or information that would reveal its existence, to the subject or to any unauthorized person. Staff should escalate questions to the appropriate BSA/AML or legal personnel.

Do we have to close an account after filing a SAR?

No. Filing a SAR does not automatically require the institution to exit the relationship. Decisions to continue or terminate a relationship should be deliberate, documented, and based on applicable risk-management, compliance, legal, and business considerations.

What is a 314(b) information request?

A 314(b) information-sharing mechanism under the USA PATRIOT Act allows participating financial institutions to share information with each other about suspected money laundering or terrorist financing, subject to applicable requirements and protections.

What is CDD, and how does it differ from CIP?

The Customer Identification Program is the account-opening requirement to establish and verify identity. Customer due diligence is broader and ongoing: understanding the nature and purpose of the relationship, developing a customer risk profile, and monitoring for activity inconsistent with it. CIP occurs at account opening, while CDD continues throughout the relationship.

What is enhanced due diligence, and who gets it?

Enhanced due diligence involves additional scrutiny applied to higher-risk relationships, such as obtaining additional information at onboarding, conducting more frequent reviews, and applying closer monitoring. Institutions should determine appropriate EDD measures based on their risk assessment and applicable requirements.

What is OFAC screening, and how is it different from BSA?

OFAC administers economic sanctions and maintains lists of blocked persons and other sanctions-related information. OFAC compliance is a separate legal regime from BSA/AML. Institutions must follow applicable sanctions screening, blocking or rejection, reporting, and recordkeeping requirements.

What are the consequences of a weak BSA/AML program?

Consequences can include examination criticism, matters requiring attention, formal enforcement actions, civil money penalties, and other corrective measures. Serious deficiencies can also result in individual accountability, criminal referrals, restrictions on activities, or other significant regulatory consequences.

Most-Used Training Courses:

Recommended Online Training Courses

BankTrainingCenter.com 9715 Rod Road Suite A Alpharetta, GA 30022 1-770-410-1219 support@BankTrainingCenter.com
Certifications Webinars Seminars
Stay Up To Date
Need Training Or Resources In Other Areas? Try Our Other Training Center Sites:
HR Accounting Financial Services Insurance Mortgage Payroll Real Estate Safety
Training By Delivery Format & Subjects Covered:
Special Promotions Online Training Resource Materials Seminars Webinars All Banking Subjects
Facebook Copyright BankTrainingCenter.com 2026