The Bank Secrecy Act is the oldest and broadest compliance obligation most bankers will ever work under, and it is also the one most often explained badly. New compliance staff are handed a list of forms and thresholds — file a CTR over $10,000, file a SAR when something looks wrong — without ever being shown how the pieces connect or why the statute is built the way it is.
This guide fixes that. It walks through what the BSA actually requires, how five decades of amendments layered on top of it, who enforces which part, and what an examiner opens the file looking for. It is written for someone who has to own or support the program, not for someone memorizing thresholds for a quiz.
The BSA was enacted in 1970 as the Currency and Foreign Transactions Reporting Act, codified principally at 31 U.S.C. 5311 and following, with implementing regulations at 31 CFR Chapter X. Its stated purpose is to require financial institutions to keep records and file reports that have a high degree of usefulness in criminal, tax, and regulatory investigations and proceedings.
That phrase — "a high degree of usefulness" — is worth pausing on, because it explains the entire structure of the statute. The BSA does not ask banks to prevent crime. It asks them to generate a paper trail that investigators can follow later. Everything else in the regime is downstream of that purpose: the reports exist to be searched, the records exist to be subpoenaed, and the monitoring exists to surface what should be reported.
The nickname is misleading. "Bank Secrecy Act" describes the problem the law addressed — bank secrecy being used to hide criminal proceeds — rather than what the law does. The BSA is an anti-secrecy statute.
The statute in force today is the accumulation of several major expansions:
Reading the statute as a stack rather than a single rule explains why the obligations sometimes feel duplicative. Beneficial ownership appears in two different places — the CDD rule, which obligates banks, and the Corporate Transparency Act, which obligates companies — because they were enacted twenty years apart to solve related problems from opposite directions.
Three layers of authority operate at once, and confusing them is a common source of error when responding to an inquiry.
FinCEN — the Financial Crimes Enforcement Network, a bureau of the Treasury Department — is the administrator of the BSA. It writes the regulations, receives the reports, and has civil enforcement authority. It is not, however, the agency that shows up to examine most banks.
The federal banking agencies — the OCC, Federal Reserve, FDIC, and NCUA — examine institutions for BSA compliance under authority delegated by FinCEN, and they use their own enforcement powers to act on deficiencies. Section 8(s) of the Federal Deposit Insurance Act requires the agencies to issue a cease and desist order when an institution fails to establish and maintain a reasonably designed BSA program or fails to correct previously reported problems. That is a mandatory consequence, not a discretionary one, which is why program-level findings are treated so seriously.
The Department of Justice prosecutes criminal violations, including willful failures to file and money laundering itself.
Examination is conducted against the FFIEC BSA/AML Examination Manual, which is publicly available. Any institution serious about exam readiness should be reading the same manual the examiners are working from — it sets out the procedures, the expectations, and the language findings will be written in. Our Bank Secrecy Act training courses are structured around those same expectations.
Every covered financial institution must maintain a written AML program, approved by the board and reasonably designed to achieve compliance. The program has four longstanding pillars, with a fifth added by the CDD rule:
Two things about the pillars are consistently misunderstood.
First, the pillars are assessed individually. A bank with excellent monitoring technology and no independent testing has a program deficiency, regardless of how good the monitoring is. Examiners work through the pillars one at a time.
Second, "reasonably designed" is measured against the institution's own risk profile. There is no universal program. A community bank with a retail deposit base and no international activity should not have the same program as an institution with correspondent relationships and money services business customers — and if it does, one of the two programs is wrong.
The document that connects the institution's risk to its controls is the BSA/AML risk assessment. It should identify the specific risks presented by products, services, customers, and geographies, analyze them, and support the design of the control environment.
Examiners frequently begin here, because the risk assessment is where a program either coheres or does not. If the risk assessment identifies significant cash-intensive business exposure but the monitoring rules were never tuned for it, the gap is visible immediately and it is documented in the institution's own words.
A CTR is required for each transaction in currency of more than $10,000 conducted by, through, or to the institution in one business day by or on behalf of the same person. Multiple transactions must be aggregated when the institution knows they are by or on behalf of the same person. CTRs are filed on FinCEN Form 112 within 15 days.
The exemption system is underused. Phase I exemptions cover other banks, government agencies and entities, and listed public companies and their subsidiaries. Phase II exemptions cover eligible non-listed businesses and payroll customers meeting specified conditions, and require a designation filing and periodic review. For a bank serving several high-volume cash businesses, properly designating exemptions eliminates a substantial volume of low-value filings — but the annual review obligation must be honored, or the exemption becomes its own finding.
A SAR is required when the institution knows, suspects, or has reason to suspect that a transaction involves funds derived from illegal activity, is designed to evade BSA requirements, has no business or apparent lawful purpose, or involves use of the institution to facilitate criminal activity. The thresholds are generally $5,000 where a suspect can be identified and $25,000 regardless of whether one can be.
Filing is due within 30 calendar days of initial detection of facts that may constitute a basis for filing, extendable to 60 days when no suspect has been identified. The date of initial detection is a defined moment and should be documented, because it is both the start of the clock and the first thing an examiner reconciles against the filing date.
Two rules around SARs are absolute. Confidentiality: disclosing the existence of a SAR, or information that would reveal it, to the subject or any unauthorized person is prohibited by statute. Safe harbor: an institution that files is protected from civil liability for the disclosure, which removes any incentive to hesitate over a marginal filing.
For the mechanics of writing and filing, see our dedicated guide to suspicious activity reporting.
Institutions also file Reports of Foreign Bank and Financial Accounts where applicable, Reports of Cash Payments Over $10,000 Received in a Trade or Business in relevant circumstances, and Designation of Exempt Person filings for CTR exemptions.
Reporting gets the attention; recordkeeping generates as many findings.
The funds transfer rules require institutions to collect and retain specified information for transmittals of funds at or above the applicable threshold, and the travel rule requires certain of that information to move with the transfer to the next institution in the chain. The monetary instrument log requires records for cash purchases of monetary instruments such as cashier's checks and money orders in the specified range. CIP records, beneficial ownership records, and records supporting CTR exemptions each carry their own retention requirements.
The general BSA retention period is five years, which is longer than several other banking retention requirements — a mismatch that catches institutions applying a single blanket policy across all records.
The Customer Identification Program requires, at minimum, collecting name, date of birth, address, and identification number before opening an account, and verifying identity within a reasonable time through documentary or non-documentary means. The program must be written, board-approved, and include procedures for responding when identity cannot be verified.
Customer due diligence goes further and continues for the life of the relationship: understanding the nature and purpose of the relationship in order to develop a customer risk profile, and conducting ongoing monitoring to identify and report suspicious transactions and to keep customer information current. For legal entity customers, the institution must identify and verify beneficial owners — individuals owning 25 percent or more, plus one individual with significant managerial control.
Enhanced due diligence applies to higher-risk relationships. The institution defines the categories in its own procedures, and common ones include foreign correspondent accounts, private banking for non-U.S. persons, politically exposed persons, cash-intensive businesses, and money services businesses.
Two provisions of the USA PATRIOT Act govern sharing, and they work differently.
Section 314(a) allows federal law enforcement, through FinCEN, to request that institutions search their records for named subjects. Responding is mandatory, requests arrive on a recurring schedule, and a positive match requires a response to FinCEN — but it does not automatically require a SAR, though it frequently prompts a review that leads to one.
Section 314(b) permits institutions to share information with each other voluntarily regarding suspected money laundering or terrorist financing, with a safe harbor from liability. Participation requires annual notice to FinCEN and verification that the counterparty is also registered.
The findings that recur across enforcement actions cluster in a small number of places:
Consequences escalate from examination criticism through matters requiring attention to formal enforcement actions, civil money penalties against both institutions and individuals, and in severe cases criminal referral. There is also a strategic cost that is easy to overlook: an institution operating under a BSA-related enforcement action generally cannot complete acquisitions or open branches until it is lifted.
BSA knowledge decays because the rules move. Beneficial ownership requirements, sanctions programs, and FinCEN priorities all shift on their own schedules, and a program that was well designed three years ago can be materially out of date without anyone having done anything wrong.
The practical response is structured, recurring education rather than an annual slide deck. For staff who own or support the program, a full Certificate in BSA and AML Compliance covers the framework end to end, and targeted courses on OFAC and SARs and information sharing fill the specific gaps that examinations tend to expose.
It is the U.S. law requiring financial institutions to keep records and file reports that help investigators detect and trace money laundering, terrorist financing, tax evasion, and other financial crimes. It obligates banks to know who their customers are, to report large currency transactions and suspicious activity, and to maintain a written program ensuring they actually do so.
Far more than banks. Credit unions, broker-dealers, mutual funds, money services businesses, casinos, insurance companies, and certain other financial institutions are covered, with requirements varying by industry. Within a bank, compliance is not confined to the BSA department — tellers, lenders, operations, and management all perform parts of it.
A CTR is objective and threshold-driven: currency transactions over $10,000 in one business day for the same person, filed within 15 days, no judgment required. A SAR is subjective and suspicion-driven: filed when activity is suspected of involving illegal funds or evading reporting, generally within 30 days of initial detection, and confidential from the subject. A single transaction can require both.
Internal controls, independent testing, a designated BSA compliance officer, training for appropriate personnel, and customer due diligence including beneficial ownership identification. The first four come from the original program requirement; the fifth was added by the CDD rule effective in 2018.
The regulation does not state a frequency. Examination practice has settled on at least annually for most staff, with role-specific content, additional training when duties or regulations change, and separate training for the board. Institutions should retain records of who was trained, when, and on what.
They range from examination criticism and mandatory cease and desist orders for program failures, through substantial civil money penalties against institutions and against responsible individuals, to criminal prosecution for willful violations. Penalties have been assessed against compliance officers personally, which is why individual accountability is now a standing theme in enforcement.


