Most bankers encounter the FFIEC BSA/AML Examination Manual indirectly: an examiner cites it, a consultant references it, or a vendor's training mentions it. Comparatively few have read the sections that apply to their own institution, which is a missed opportunity — it is the closest thing available to the examiner's own working document.
The manual is issued by the Federal Financial Institutions Examination Council and provides examination procedures for assessing BSA/AML compliance. It is used by examiners from the OCC, Federal Reserve, FDIC, and NCUA.
It is not regulation. This is the single most important thing to understand about it, and the point institutions most often get wrong. The FFIEC has stated explicitly, in releases accompanying section updates, that manual revisions do not establish new requirements — the requirements live in the Bank Secrecy Act and its implementing regulations. The manual describes how examiners assess compliance with those existing requirements.
The practical consequence is that an institution reading a manual update should ask "does this change how we will be examined?" rather than "what new obligation did we just acquire." Institutions that treat every manual revision as a new requirement generate unnecessary work; institutions that ignore revisions are surprised by the questions they get asked.
Introductory sections covering the regulatory framework, the risk-focused examination approach, assessing the BSA/AML compliance program, and developing conclusions and finalizing the examination.
Core examination procedures organized by topic — the compliance program elements, customer identification, customer due diligence, beneficial ownership, currency transaction reporting and exemptions, suspicious activity reporting, information sharing, and recordkeeping requirements including funds transfers and monetary instruments.
Expanded examination procedures for higher-risk products, services, customers, and geographies — correspondent accounts, private banking, money services businesses, cash-intensive businesses, trade finance, electronic banking, and others. These are applied based on the institution's risk profile rather than universally.
Appendices with reference material, including forms, tables, and quantity-of-risk matrices that examiners use in practice.
The structure itself carries information. The core procedures apply to every institution; the expanded procedures apply only where the institution has the relevant exposure. An institution that reads only the core sections has read what will definitely be examined.
The manual's framing emphasizes that examinations are risk-focused: scope and depth are tailored to the institution's own risk profile rather than applied uniformly.
Two implications for a bank.
Your risk assessment shapes your examination. Examiners use the institution's own risk assessment as a starting point for scoping. A risk assessment that understates exposure invites an examiner to develop their own view, and a risk assessment that does not reconcile to the institution's actual controls is the fastest route to a program finding.
Low risk is a legitimate conclusion. Where an institution genuinely has limited exposure in an area, a proportionally limited control is appropriate — provided the assessment supporting that conclusion is documented. The manual does not expect a community bank with no international activity to build correspondent banking controls.
Read the sections applicable to your institution, not the whole manual. The core sections plus the expanded sections matching your products and customer base is a realistic reading list.
Self-assess against the procedures. The manual states what an examiner will look for. Working through the relevant procedures on your own program, and documenting the result, is both the cheapest gap analysis available and evidence of self-identification.
Use it to write your own documentation. Where the manual describes what examiners assess, an institution can structure its program documentation to answer those questions directly. This is not gaming the examination; it is making the evidence findable.
Give it to new compliance staff. A new BSA officer who has read the applicable sections understands the shape of the job faster than one working from institutional memory.
Track section updates through the FFIEC's own release page rather than through secondary coverage, and record the applicability assessment for each in the regulatory change log.
Certain themes are stable across manual versions and are worth knowing independently of any particular update.
The risk assessment is foundational. Examiners begin there, and a program that does not trace to it is not risk-based whatever it says.
Pillars are assessed individually. Strong monitoring does not compensate for absent independent testing.
Evidence matters more than intent. A control that operated without a record is treated as a control that did not operate.
Timeliness is testable. SAR filing from initial detection, CTR filing within fifteen days, exemption reviews annually — these are date arithmetic, and examiners do the arithmetic.
Repeat findings escalate. Recurrence of a previously identified issue is assessed as a governance failure rather than a process failure.
The officer's competence is examined. Not through a test, but through conversation. An officer who cannot explain their own risk assessment or monitoring logic is a finding in themselves.
Structured coverage is available through our BSA training and AML training catalogs and the Certificate in BSA and AML Compliance.
The most useful exercise an institution can run before a BSA examination takes a day and uses nothing but the manual and its own files.
Pick the applicable sections — core, plus expanded sections matching the institution's actual exposure.
Work through each procedure as though you were the examiner. For each item, ask what document you would produce and where it is. Anything you cannot locate in ten minutes is a finding waiting to happen, regardless of whether the underlying work was done.
Note the gaps in two columns — genuine control gaps, and evidence gaps where the work occurred but was never recorded. They require different remediation and, in most institutions, the second column is longer.
Fix the evidence gaps first, because they are cheap and they change the examination materially. A control performed and documented is a satisfactory finding; the same control performed and undocumented is a criticism.
Give the resulting document to the board, because it demonstrates self-identification — which is the distinction examiners draw most sharply between institutions with the same underlying weakness.
Institutions that do this consistently report a specific benefit beyond the examination result: the exercise surfaces which procedures nobody in the institution can explain, and that is usually a more accurate map of the program's weak points than any self-assessment questionnaire produces.
One structural feature of the manual repays understanding, because it explains why two institutions with identical control sets can receive different assessments.
Examiners assess quantity of risk — what exposure the institution actually has, given its products, customers, geographies, and channels — and separately quality of risk management, meaning whether the controls are adequate to that exposure. The conclusion is a function of both, and the manual's appendices include matrices that make the relationship explicit.
Three consequences follow.
High risk is not a criticism. An institution serving money services businesses, operating near a border, or offering international wires has high inherent risk in those areas, and that is a business decision rather than a deficiency. What is assessed is whether management is adequate to it. Institutions that argue about their risk rating rather than about their control adequacy are having the wrong conversation.
Growing risk without growing controls is the pattern that produces findings. An institution that added a higher-risk customer segment, entered a new market, or launched a payments product, without corresponding changes to monitoring, training, and testing, has moved along one axis and not the other. This is the single most common way a previously satisfactory program becomes deficient, and it is visible in advance to anyone comparing the risk assessment's revision history against the control set's.
Reducing risk is a legitimate remediation option. Where controls cannot practically be brought up to the exposure — a product the institution cannot monitor adequately, a customer segment it cannot resource — exiting or limiting the activity is a valid response, and one examiners accept. It is frequently a better answer than committing to controls the institution will not build.
For a compliance officer, the useful translation is that the examination conversation is about the relationship between two things the institution controls separately. Management can change the exposure, or change the controls, and the program is adequate when they match. Framing it that way also gives the board a decision it can actually make.
A last note for institutions that use a consultant for BSA independent testing or examination readiness. The manual is public, and a consultant working from it is applying a document the institution could read itself. That is not an argument against engaging one — an independent perspective and specialist experience have real value — but it does change what to ask for. A report that recites the manual's procedures back to you is worth considerably less than one that identifies where this institution's evidence would not survive the procedure, and the difference is visible in whether findings cite your documents or the manual's language. Institutions that read the applicable sections before commissioning the work get better work, because they can tell which it is.
One further practical point about scope. Institutions sometimes assume that because examinations are risk-focused, a low-risk profile produces a short examination. The relationship is not that direct: a genuinely low-risk institution with well-documented controls does get a narrower examination, but a low-risk institution whose documentation is thin invites more testing precisely because the examiner cannot verify the claim quickly. The scope narrows in response to evidence, not to assertion, which is another reason the self-assessment exercise pays for itself.
No. It provides examination procedures used by the federal banking agencies to assess compliance, and the FFIEC has stated explicitly that manual revisions do not establish new requirements. The requirements come from the Bank Secrecy Act and its implementing regulations; the manual describes how examiners assess compliance with them.
By asking whether it changes how the institution will be examined, not what new obligation it created. Record the applicability assessment in the regulatory change log, adjust documentation or self-assessment where the examination approach shifted, and resist generating new controls in response to a document that did not create new requirements.
The introductory sections and the core examination procedures, which apply to every institution, plus only those expanded procedures matching the bank's actual products, customers, and geographies. An institution with no international activity does not need to work through correspondent banking procedures.
That examination scope and depth are tailored to the institution's own risk profile rather than applied uniformly, using the institution's risk assessment as a starting point for scoping. A limited control in a genuinely low-risk area is appropriate provided the assessment supporting that conclusion is documented.
As a self-assessment tool. Work through the applicable procedures as an examiner would, asking for each item what document you would produce and where it is. Separate genuine control gaps from evidence gaps — the latter are cheaper to fix and change the examination outcome materially, since an undocumented control is treated as one that did not operate.
Through the FFIEC's own release page rather than secondary coverage, which lags and occasionally mischaracterizes revisions. Each update should receive a recorded applicability assessment in the institution's regulatory change log, the same treatment given to any other regulatory development.


