Skip to main content

AML Basics

TL;DR
  • The Bank Secrecy Act is the foundation of US AML. FinCEN enforces it.
  • CIP means verifying identity at account opening. Name, DOB, address, ID number.
  • CDD means knowing what the relationship is for, and watching it afterwards.
  • SARs go in within 30 days of detection. $5K+ with a suspect, $25K+ without.
  • CTRs are required for cash over $10,000 in a business day. You get 15 days to file.
  • Most merchants aren't directly covered by any of this. Your bank and your processor are. That's why their questions feel disproportionate to your size.

If you're a merchant, BSA/AML probably doesn't bind you. It binds banks, money services businesses, and the fintechs on top of them. You'll still collide with it constantly. The onboarding questionnaire. The reserve. The beneficial-ownership form nobody explained. The account frozen without warning. All of it traces back to somebody else's AML program. Knowing what that program has to do makes the questions predictable instead of arbitrary.

What Is AML?

Anti-money laundering is machinery that financial institutions are required to run. The job is to stop criminals pushing dirty money through the payment system and having it come out clean. In the US it's called BSA/AML. Add the counter-terrorist-financing piece and it's AML/CFT.

The obligations land on regulated institutions, not their customers. But institutions push the work downstream. Your bank has to document what your business does. So you fill in the form.

Key Regulatory Bodies

AgencyRole
FinCENPrimary BSA enforcement (Treasury Department)
OCC, FDIC, Federal ReserveBank regulators with BSA examination authority
CFPBConsumer-facing enforcement
DOJCriminal prosecution

The Bank Secrecy Act Framework

The Bank Secrecy Act (1970) and its amendments establish requirements for:

  • Recordkeeping of certain transactions
  • Reporting suspicious and large cash transactions
  • Compliance programs at financial institutions
  • Customer identification and due diligence

Key BSA Amendments

LegislationYearKey Additions
Money Laundering Control Act1986Made money laundering a federal crime
USA PATRIOT Act2001Enhanced CIP/KYC, expanded covered entities
CDD Final Rule2016/2018Beneficial ownership for legal entities
Anti-Money Laundering Act2020Modernization, beneficial ownership to FinCEN
Corporate Transparency Act2024Beneficial ownership reporting to FinCEN (domestic companies exempted in 2025)

Know Your Customer (KYC)

KYC is proving who the customer is. Then working out what they'll use the account for. It's the first line against synthetic identity fraud and application fraud. It's also why you got asked for a utility bill. See identity verification for how it's implemented.

Customer Identification Program (CIP)

Required information at account opening:

IndividualLegal Entity
Full legal nameLegal name
Date of birthFormation date/jurisdiction
Residential addressPrincipal place of business
ID number (SSN for US persons)EIN or equivalent
Government-issued IDFormation documents

Verification methods:

  • Documentary: Government-issued ID, passport, articles of incorporation
  • Non-documentary: Third-party databases, credit bureaus, public records
Timing

CIP has to be finished at or before account opening. Some institutions grant risk-based temporary access while verification finishes. That comes with extra controls attached. It's usually why a new account can take payments but can't yet withdraw.

Customer Due Diligence (CDD)

Beyond basic identification:

  • Understand the nature and purpose of the relationship
  • Assign a risk rating based on customer profile
  • Collect beneficial ownership information (25%+ ownership or control)
  • Conduct ongoing monitoring of transactions

Beneficial Ownership Requirements

For legal entity customers, identify and verify:

  • Beneficial owners: Individuals with 25%+ ownership
  • Control person: CEO, CFO, managing member, general partner, or equivalent

Required information for each:

  • Full legal name
  • Date of birth
  • Address
  • ID number (SSN or passport)

Exemptions:

  • Regulated financial institutions
  • SEC-registered investment companies
  • Public companies (US exchanges)
  • Government entities
  • Certain pooled investment vehicles

Corporate Transparency Act Impact

The CTA took effect in 2024. It originally made companies report beneficial ownership straight to FinCEN. In March 2025 FinCEN exempted domestic companies. The rule now reaches foreign entities only. Filed a BOI report in 2024 as a US LLC? That's why the follow-up never came.

It didn't get your bank off the hook. Institutions have their own CDD obligations. They can't lean on the FinCEN database alone. So they'll keep asking you for ownership information, whatever the CTA requires this year.

Enhanced Due Diligence (EDD)

Some customers get a heavier version of the same process. If you're in one of the categories below, expect onboarding to take weeks, not days. Expect to be asked where the money came from:

  • More thorough background research
  • Senior management approval for relationship
  • More frequent review and monitoring
  • Source of funds/wealth documentation

Higher-risk categories:

  • Politically Exposed Persons (PEPs)
  • High-risk jurisdictions (FATF grey/black lists)
  • Cash-intensive businesses
  • Non-resident accounts
  • Correspondent banking relationships
  • Private banking
  • Virtual currency businesses

Transaction Monitoring

What to Monitor

CategoryExamples
Amounts/frequencyUnusual transaction sizes, sudden volume changes
Geographic patternsHigh-risk countries, unexpected jurisdictions
Behavior changesDeviation from established patterns
StructuringMultiple transactions avoiding $10K threshold
Round-dollar transactions$9,999, $9,900 repeatedly
Rapid fund movementMoney in and out quickly

Network-Specific Requirements

Mastercard monitoring (Rules Section 1.2.1.1):

  • Cross-border activity
  • Cardholder and merchant monitoring based on risk
  • High-risk MCCs
  • Products facilitating fund movement (crypto, transfers, cash-out)
  • Activity changes over time

Mastercard ATM monitoring:

  • Out-of-pattern withdrawal volume
  • Sequential high-volume withdrawals
  • Excessive at-limit transactions
  • Out-of-pattern deposits

Card-Specific Red Flags

PatternWhat It May Indicate
Bust-outRapid credit build-up → max out → disappear
Card testingMultiple small transactions → large purchases
Cash-advance concentrationUnusual reliance on cash advances
Geographic anomaliesTransactions in unlikely locations
Velocity anomaliesToo many transactions in short time

Building Effective Monitoring Rules

A rule that fires on every third customer isn't a control. It's a queue nobody works. Design for a caseload your team can clear.

Rule design principles:

  • Start from baseline behavior per customer segment, not from a round number.
  • Use statistical thresholds. "$9,500" is a guess. Two standard deviations off that segment's mean isn't.
  • Combine velocity and volume triggers.
  • Fire on combinations. One red flag shouldn't open a case on its own.
  • Tune on outcomes, quarterly. Write down what you changed.

Rule categories:

TypeExample
Threshold-basedCash out >$5K in 24 hours
Pattern-basedRound-dollar transactions repeatedly
BehavioralDeviation from 6-month average
Peer-basedActivity unusual vs. similar customers
List-basedMatch against known bad actors

Alert Investigation Process

Alert generated

L1 review (triage)

L2 review (detailed)

Case escalation

SAR decision

Suspicious Activity Reports (SARs)

When to File

For banks (thresholds vary by institution type):

SituationThreshold
Suspected violation with identifiable suspect$5,000+
Suspected violation without identifiable suspect$25,000+
Insider abuseAny amount
Money laundering or BSA violation$5,000+

Note: Money Services Businesses (MSBs) may have $2,000 threshold.

SAR Filing Timeline

EventDeadline
DetectionStart 30-day clock
Initial SAR30 calendar days from detection
Extension (if investigating)Up to 60 days total
Continuing activityRisk-based follow-up

Continuing Activity SARs: the old convention was ~90 days. Current FinCEN guidance asks for risk-based timing instead of a fixed cadence. Plenty of institutions still run ~90 days as the default. It's defensible in an exam.

SAR Confidentiality

  • Cannot disclose SAR filing to the subject
  • No tipping off the subject of investigation
  • Safe harbor for good-faith filings

A bank closes your account and offers nothing beyond "a business decision." That's usually not evasion. It's the law. Nobody there is allowed to tell you a SAR exists. Pushing harder won't produce an answer. It won't get the account back either.

What Goes in a SAR

  • Subject information (name, address, DOB, SSN, account numbers)
  • Suspicious activity description
  • Dates and amounts involved
  • Account information
  • Narrative explaining why activity is suspicious
  • Documentation references

Currency Transaction Reports (CTRs)

Requirement

File a CTR for cash transactions exceeding $10,000 in a single business day.

Key Points

  • Aggregate multiple transactions by the same person.
  • Structuring means splitting deposits to stay under $10,000. It's a federal crime on its own. Clean money doesn't save you.
  • 15-day filing deadline.
  • Applies to deposits, withdrawals, exchanges.

A CTR isn't an accusation. It isn't a SAR either. It's a routine filing on a routine deposit. Deposit $12,000 of legitimate cash and one gets filed. Nothing happens to you. Splitting that deposit into two $6,000 trips is what creates the problem.

Exemptions

Certain customers may be exempt from CTR filing:

  • Domestic banks
  • Government entities
  • Listed public companies
  • Eligible non-listed businesses (requires risk assessment and documentation)

AML Program Requirements

Five Pillars

Every covered institution has to run a program with all five. Four out of five is a finding. The one usually missing is independent testing:

  1. Written policies and procedures
  2. Designated compliance officer (BSA Officer with authority and resources)
  3. Ongoing training for relevant personnel
  4. Independent testing (regular audits)
  5. Risk assessment (periodic evaluation)

Mastercard Requirements (Rules Section 1.2)

  • Client identification and due diligence
  • Controls, resources, and monitoring systems
  • Regulatory recordkeeping and reporting
  • Risk assessment incorporating all products
  • Training for AML personnel
  • Independent audit processes

Visa Requirements

Visa's rules focus on data protection and risk, requiring members to:

  • Investigate suspected compromise, fraud, or money laundering
  • Report to Visa
  • Maintain security
  • Cooperate with investigations

Sanctions Compliance

Key Lists

ListMaintained By
SDN ListOFAC (US Treasury)
Restrictive MeasuresEuropean Union
Consolidated ListUN Security Council

Mastercard Requirements (Rules Section 1.2.2)

  • Issuers: Screen cardholders, service providers, agents
  • Acquirers: Screen merchants, service providers, agents
  • Screening at onboarding and ongoing
  • No activity with sanctioned persons, entities, or jurisdictions

Recordkeeping Requirements

Record TypeRetention Period
Customer identification records5 years after account closure
Transaction records5 years from transaction
SAR filings and documentation5 years from filing
CTR filings5 years from filing
AML training records5 years

Consequences of Non-Compliance

ViolationPotential Consequence
Failure to file SARsUp to $1M civil penalty, criminal penalties
Failure to maintain AML programEnforcement actions, consent orders
Willful BSA violationsCriminal prosecution, $250K fines, 5 years (up to $500K/10 years if combined with other violations)
Repeat violationsLicense revocation, processing restrictions
Network non-complianceLicense suspension, termination

Recent Enforcement Examples

InstitutionYearPenaltyIssue
TD Bank2024$3BBSA/AML failures
Wells Fargo2023$97.8MSanctions compliance failures
Bittrex2022$29MCrypto SAR filing failures
HSBC2012$1.9BInsufficient AML controls

Practical Implementation Guidance

Building an AML Program from Scratch

Phase 1 (Foundation):

  • Appoint BSA Officer
  • Draft policies and procedures
  • Implement basic CIP/KYC
  • Establish CTR filing process

Phase 2 (Monitoring):

  • Deploy transaction monitoring
  • Define initial rules based on product risk
  • Establish alert investigation workflows
  • Implement SAR process

Phase 3 (Optimization):

  • Tune rules based on outcomes
  • Conduct first independent audit
  • Formalize training program
  • Establish ongoing risk assessment

Common Implementation Mistakes

  • Leaning on the automated system without human review. Then in an exam, nobody can explain a single decision.
  • Investigators who were never trained on the typologies they're screening for.
  • Static rule sets that don't evolve.
  • Fraud and AML in separate silos, chasing the same customer from two directions.
  • Decisions made well and documented badly. In an exam that looks identical to decisions made badly.

Coordinating AML with Fraud Prevention

Fraud and AML look at the same transactions with different questions. Fraud asks whether the money is leaving the wrong way. AML asks where it came from. They investigate the same behavior. Both can close an account. At most companies they don't talk to each other.

Integration opportunities:

  • Shared case management systems
  • Combined alerts for cross-functional review
  • Joint training on overlapping typologies
  • Coordinated customer communication

Next Steps

Building an AML program?

  1. Start with CIP/KYC - Foundation requirements
  2. Define risk ratings - Segment customers
  3. Set up transaction monitoring - Build initial rules

Improving existing program?

  1. Tune monitoring rules - Reduce false positives
  2. Coordinate with fraud team - Share insights
  3. Prepare for independent testing - Audit readiness

Handling a suspicious activity case?

  1. Review SAR requirements - Know thresholds
  2. Follow investigation process - Document thoroughly
  3. Maintain confidentiality - No tipping off

See Also