AML Basics
- The Bank Secrecy Act is the foundation of US AML. FinCEN enforces it.
- CIP means verifying identity at account opening. Name, DOB, address, ID number.
- CDD means knowing what the relationship is for, and watching it afterwards.
- SARs go in within 30 days of detection. $5K+ with a suspect, $25K+ without.
- CTRs are required for cash over $10,000 in a business day. You get 15 days to file.
- Most merchants aren't directly covered by any of this. Your bank and your processor are. That's why their questions feel disproportionate to your size.
If you're a merchant, BSA/AML probably doesn't bind you. It binds banks, money services businesses, and the fintechs on top of them. You'll still collide with it constantly. The onboarding questionnaire. The reserve. The beneficial-ownership form nobody explained. The account frozen without warning. All of it traces back to somebody else's AML program. Knowing what that program has to do makes the questions predictable instead of arbitrary.
What Is AML?
Anti-money laundering is machinery that financial institutions are required to run. The job is to stop criminals pushing dirty money through the payment system and having it come out clean. In the US it's called BSA/AML. Add the counter-terrorist-financing piece and it's AML/CFT.
The obligations land on regulated institutions, not their customers. But institutions push the work downstream. Your bank has to document what your business does. So you fill in the form.
Key Regulatory Bodies
| Agency | Role |
|---|---|
| FinCEN | Primary BSA enforcement (Treasury Department) |
| OCC, FDIC, Federal Reserve | Bank regulators with BSA examination authority |
| CFPB | Consumer-facing enforcement |
| DOJ | Criminal prosecution |
The Bank Secrecy Act Framework
The Bank Secrecy Act (1970) and its amendments establish requirements for:
- Recordkeeping of certain transactions
- Reporting suspicious and large cash transactions
- Compliance programs at financial institutions
- Customer identification and due diligence
Key BSA Amendments
| Legislation | Year | Key Additions |
|---|---|---|
| Money Laundering Control Act | 1986 | Made money laundering a federal crime |
| USA PATRIOT Act | 2001 | Enhanced CIP/KYC, expanded covered entities |
| CDD Final Rule | 2016/2018 | Beneficial ownership for legal entities |
| Anti-Money Laundering Act | 2020 | Modernization, beneficial ownership to FinCEN |
| Corporate Transparency Act | 2024 | Beneficial ownership reporting to FinCEN (domestic companies exempted in 2025) |
Know Your Customer (KYC)
KYC is proving who the customer is. Then working out what they'll use the account for. It's the first line against synthetic identity fraud and application fraud. It's also why you got asked for a utility bill. See identity verification for how it's implemented.
Customer Identification Program (CIP)
Required information at account opening:
| Individual | Legal Entity |
|---|---|
| Full legal name | Legal name |
| Date of birth | Formation date/jurisdiction |
| Residential address | Principal place of business |
| ID number (SSN for US persons) | EIN or equivalent |
| Government-issued ID | Formation documents |
Verification methods:
- Documentary: Government-issued ID, passport, articles of incorporation
- Non-documentary: Third-party databases, credit bureaus, public records
CIP has to be finished at or before account opening. Some institutions grant risk-based temporary access while verification finishes. That comes with extra controls attached. It's usually why a new account can take payments but can't yet withdraw.
Customer Due Diligence (CDD)
Beyond basic identification:
- Understand the nature and purpose of the relationship
- Assign a risk rating based on customer profile
- Collect beneficial ownership information (25%+ ownership or control)
- Conduct ongoing monitoring of transactions
Beneficial Ownership Requirements
For legal entity customers, identify and verify:
- Beneficial owners: Individuals with 25%+ ownership
- Control person: CEO, CFO, managing member, general partner, or equivalent
Required information for each:
- Full legal name
- Date of birth
- Address
- ID number (SSN or passport)
Exemptions:
- Regulated financial institutions
- SEC-registered investment companies
- Public companies (US exchanges)
- Government entities
- Certain pooled investment vehicles
Corporate Transparency Act Impact
The CTA took effect in 2024. It originally made companies report beneficial ownership straight to FinCEN. In March 2025 FinCEN exempted domestic companies. The rule now reaches foreign entities only. Filed a BOI report in 2024 as a US LLC? That's why the follow-up never came.
It didn't get your bank off the hook. Institutions have their own CDD obligations. They can't lean on the FinCEN database alone. So they'll keep asking you for ownership information, whatever the CTA requires this year.
Enhanced Due Diligence (EDD)
Some customers get a heavier version of the same process. If you're in one of the categories below, expect onboarding to take weeks, not days. Expect to be asked where the money came from:
- More thorough background research
- Senior management approval for relationship
- More frequent review and monitoring
- Source of funds/wealth documentation
Higher-risk categories:
- Politically Exposed Persons (PEPs)
- High-risk jurisdictions (FATF grey/black lists)
- Cash-intensive businesses
- Non-resident accounts
- Correspondent banking relationships
- Private banking
- Virtual currency businesses
Transaction Monitoring
What to Monitor
| Category | Examples |
|---|---|
| Amounts/frequency | Unusual transaction sizes, sudden volume changes |
| Geographic patterns | High-risk countries, unexpected jurisdictions |
| Behavior changes | Deviation from established patterns |
| Structuring | Multiple transactions avoiding $10K threshold |
| Round-dollar transactions | $9,999, $9,900 repeatedly |
| Rapid fund movement | Money in and out quickly |
Network-Specific Requirements
Mastercard monitoring (Rules Section 1.2.1.1):
- Cross-border activity
- Cardholder and merchant monitoring based on risk
- High-risk MCCs
- Products facilitating fund movement (crypto, transfers, cash-out)
- Activity changes over time
Mastercard ATM monitoring:
- Out-of-pattern withdrawal volume
- Sequential high-volume withdrawals
- Excessive at-limit transactions
- Out-of-pattern deposits
Card-Specific Red Flags
| Pattern | What It May Indicate |
|---|---|
| Bust-out | Rapid credit build-up → max out → disappear |
| Card testing | Multiple small transactions → large purchases |
| Cash-advance concentration | Unusual reliance on cash advances |
| Geographic anomalies | Transactions in unlikely locations |
| Velocity anomalies | Too many transactions in short time |
Building Effective Monitoring Rules
A rule that fires on every third customer isn't a control. It's a queue nobody works. Design for a caseload your team can clear.
Rule design principles:
- Start from baseline behavior per customer segment, not from a round number.
- Use statistical thresholds. "$9,500" is a guess. Two standard deviations off that segment's mean isn't.
- Combine velocity and volume triggers.
- Fire on combinations. One red flag shouldn't open a case on its own.
- Tune on outcomes, quarterly. Write down what you changed.
Rule categories:
| Type | Example |
|---|---|
| Threshold-based | Cash out >$5K in 24 hours |
| Pattern-based | Round-dollar transactions repeatedly |
| Behavioral | Deviation from 6-month average |
| Peer-based | Activity unusual vs. similar customers |
| List-based | Match against known bad actors |
Alert Investigation Process
Alert generated
↓
L1 review (triage)
↓
L2 review (detailed)
↓
Case escalation
↓
SAR decision
Suspicious Activity Reports (SARs)
When to File
For banks (thresholds vary by institution type):
| Situation | Threshold |
|---|---|
| Suspected violation with identifiable suspect | $5,000+ |
| Suspected violation without identifiable suspect | $25,000+ |
| Insider abuse | Any amount |
| Money laundering or BSA violation | $5,000+ |
Note: Money Services Businesses (MSBs) may have $2,000 threshold.
SAR Filing Timeline
| Event | Deadline |
|---|---|
| Detection | Start 30-day clock |
| Initial SAR | 30 calendar days from detection |
| Extension (if investigating) | Up to 60 days total |
| Continuing activity | Risk-based follow-up |
Continuing Activity SARs: the old convention was ~90 days. Current FinCEN guidance asks for risk-based timing instead of a fixed cadence. Plenty of institutions still run ~90 days as the default. It's defensible in an exam.
SAR Confidentiality
- Cannot disclose SAR filing to the subject
- No tipping off the subject of investigation
- Safe harbor for good-faith filings
A bank closes your account and offers nothing beyond "a business decision." That's usually not evasion. It's the law. Nobody there is allowed to tell you a SAR exists. Pushing harder won't produce an answer. It won't get the account back either.
What Goes in a SAR
- Subject information (name, address, DOB, SSN, account numbers)
- Suspicious activity description
- Dates and amounts involved
- Account information
- Narrative explaining why activity is suspicious
- Documentation references
Currency Transaction Reports (CTRs)
Requirement
File a CTR for cash transactions exceeding $10,000 in a single business day.
Key Points
- Aggregate multiple transactions by the same person.
- Structuring means splitting deposits to stay under $10,000. It's a federal crime on its own. Clean money doesn't save you.
- 15-day filing deadline.
- Applies to deposits, withdrawals, exchanges.
A CTR isn't an accusation. It isn't a SAR either. It's a routine filing on a routine deposit. Deposit $12,000 of legitimate cash and one gets filed. Nothing happens to you. Splitting that deposit into two $6,000 trips is what creates the problem.
Exemptions
Certain customers may be exempt from CTR filing:
- Domestic banks
- Government entities
- Listed public companies
- Eligible non-listed businesses (requires risk assessment and documentation)
AML Program Requirements
Five Pillars
Every covered institution has to run a program with all five. Four out of five is a finding. The one usually missing is independent testing:
- Written policies and procedures
- Designated compliance officer (BSA Officer with authority and resources)
- Ongoing training for relevant personnel
- Independent testing (regular audits)
- Risk assessment (periodic evaluation)
Mastercard Requirements (Rules Section 1.2)
- Client identification and due diligence
- Controls, resources, and monitoring systems
- Regulatory recordkeeping and reporting
- Risk assessment incorporating all products
- Training for AML personnel
- Independent audit processes
Visa Requirements
Visa's rules focus on data protection and risk, requiring members to:
- Investigate suspected compromise, fraud, or money laundering
- Report to Visa
- Maintain security
- Cooperate with investigations
Sanctions Compliance
Key Lists
| List | Maintained By |
|---|---|
| SDN List | OFAC (US Treasury) |
| Restrictive Measures | European Union |
| Consolidated List | UN Security Council |
Mastercard Requirements (Rules Section 1.2.2)
- Issuers: Screen cardholders, service providers, agents
- Acquirers: Screen merchants, service providers, agents
- Screening at onboarding and ongoing
- No activity with sanctioned persons, entities, or jurisdictions
Recordkeeping Requirements
| Record Type | Retention Period |
|---|---|
| Customer identification records | 5 years after account closure |
| Transaction records | 5 years from transaction |
| SAR filings and documentation | 5 years from filing |
| CTR filings | 5 years from filing |
| AML training records | 5 years |
Consequences of Non-Compliance
| Violation | Potential Consequence |
|---|---|
| Failure to file SARs | Up to $1M civil penalty, criminal penalties |
| Failure to maintain AML program | Enforcement actions, consent orders |
| Willful BSA violations | Criminal prosecution, $250K fines, 5 years (up to $500K/10 years if combined with other violations) |
| Repeat violations | License revocation, processing restrictions |
| Network non-compliance | License suspension, termination |
Recent Enforcement Examples
| Institution | Year | Penalty | Issue |
|---|---|---|---|
| TD Bank | 2024 | $3B | BSA/AML failures |
| Wells Fargo | 2023 | $97.8M | Sanctions compliance failures |
| Bittrex | 2022 | $29M | Crypto SAR filing failures |
| HSBC | 2012 | $1.9B | Insufficient AML controls |
Practical Implementation Guidance
Building an AML Program from Scratch
Phase 1 (Foundation):
- Appoint BSA Officer
- Draft policies and procedures
- Implement basic CIP/KYC
- Establish CTR filing process
Phase 2 (Monitoring):
- Deploy transaction monitoring
- Define initial rules based on product risk
- Establish alert investigation workflows
- Implement SAR process
Phase 3 (Optimization):
- Tune rules based on outcomes
- Conduct first independent audit
- Formalize training program
- Establish ongoing risk assessment
Common Implementation Mistakes
- Leaning on the automated system without human review. Then in an exam, nobody can explain a single decision.
- Investigators who were never trained on the typologies they're screening for.
- Static rule sets that don't evolve.
- Fraud and AML in separate silos, chasing the same customer from two directions.
- Decisions made well and documented badly. In an exam that looks identical to decisions made badly.
Coordinating AML with Fraud Prevention
Fraud and AML look at the same transactions with different questions. Fraud asks whether the money is leaving the wrong way. AML asks where it came from. They investigate the same behavior. Both can close an account. At most companies they don't talk to each other.
Integration opportunities:
- Shared case management systems
- Combined alerts for cross-functional review
- Joint training on overlapping typologies
- Coordinated customer communication
Next Steps
Building an AML program?
- Start with CIP/KYC - Foundation requirements
- Define risk ratings - Segment customers
- Set up transaction monitoring - Build initial rules
Improving existing program?
- Tune monitoring rules - Reduce false positives
- Coordinate with fraud team - Share insights
- Prepare for independent testing - Audit readiness
Handling a suspicious activity case?
- Review SAR requirements - Know thresholds
- Follow investigation process - Document thoroughly
- Maintain confidentiality - No tipping off
See Also
- KYC & KYB for Fraud Prevention - When merchants should verify identity (even without regulatory obligations)
- Why Issuers Decline and Dispute - Understanding issuer behavior
- Synthetic Identity - Fabricated identities
- Application Fraud - Origination-stage fraud
- Fraud Rings - Organized fraud attacks
- Identity Verification - Document and biometric checks
- PCI DSS Compliance - Payment security standards
- Dispute Monitoring Programs - Network requirements
- Regulation E - Consumer protections