AML Scenario Gap Finder
Regime

Bank Secrecy Act and its regulations (31 CFR Chapter X): what it asks of a monitoring programme

The United States rule set a bank examiner reads a monitoring programme against: suspicious activity and currency transaction reporting, funds-transfer records, customer due diligence and the programme pillars. Where the same obligation is held twice, the statute-shaped row is quoted and the other is left out.

Shown when United States is ticked.

One row per obligation

which row is quoted
ObligationQuotedLeft out, and why
Suspicious activity reportsBSA-AML-09BSA-SAR-1, BSA-SAR-2: the statute-shaped rows are flagged as shared evidence in the export
Currency transaction reportsBSA-AML-10BSA-CTR-1, BSA-CTR-2: the statute-shaped rows are flagged as shared evidence
Funds-transfer recordsBSA-REC-1BSA-AML-13: statute-shaped row preferred
Monetary instrument recordsBSA-AML-12BSA-REC-2: the statute-shaped row is flagged as shared evidence
Customer identification programmeBSA-CIP-1BSA-AML-05: statute-shaped row preferred
Customer due diligence and risk profileBSA-CDD-3BSA-AML-06: statute-shaped row preferred
Beneficial ownershipBSA-AML-07BSA-CDD-1, BSA-CDD-2: the statute-shaped rows carry the same evidence block as BSA-CDD-4 in the export, and the library shows every evidence block once
Enhanced due diligenceBSA-CDD-4BSA-AML-08: statute-shaped row preferred
StructuringBSA-AML-10BSA-ENF-1: the prohibition row is flagged as shared evidence; the CTR row carries the figure

Named, not quoted, beside it: the FinCEN AML programme rule, the FFIEC BSA/AML examination manual, and NYDFS Part 504 for New York regulated institutions.

Typologies anchored here

50
TypologyObligation
Cash structuring below the reporting thresholdBSA BSA-AML-15 · BSA BSA-AML-10
Large cash deposits and withdrawalsBSA BSA-AML-15 · BSA BSA-AML-10
Cash-intensive business out of lineBSA BSA-AML-15 · BSA BSA-CDD-3
Cash bought into monetary instrumentsBSA BSA-AML-15 · BSA BSA-AML-12
Cash withdrawn abroadBSA BSA-AML-15
Rapid movement of fundsBSA BSA-AML-15
Transfers between related accountsBSA BSA-AML-15 · BSA BSA-CDD-3
Internal and suspense accountsBSA BSA-AML-15
Loan paid down from unexplained fundsBSA BSA-AML-15 · BSA BSA-CDD-3
Funnel accountsBSA BSA-AML-15
Third-party depositsBSA BSA-AML-15 · BSA BSA-CDD-3
Money mulesBSA BSA-AML-15
Many-to-one and one-to-manyBSA BSA-AML-15
Shell and front companiesBSA BSA-AML-15 · BSA BSA-AML-07
High-risk jurisdictionsBSA BSA-AML-15 · BSA BSA-AML-23
Cross-border activity out of profileBSA BSA-AML-15
Over and under invoicingBSA BSA-AML-15 · BSA BSA-CDD-3
Letter of credit and document anomaliesBSA BSA-AML-15 · BSA BSA-CDD-3
Trade paid by an unrelated partyBSA BSA-AML-15
Politically exposed personsBSA BSA-AML-15 · BSA BSA-CDD-4
Correspondent and nested activityBSA BSA-AML-15 · BSA BSA-AML-17
Private banking and high net worthBSA BSA-AML-15 · BSA BSA-AML-18
Money services business customersBSA BSA-AML-15
High-risk customer segmentBSA BSA-AML-15 · BSA BSA-CDD-4
Charities and non-profitsBSA BSA-AML-15
Dormant account reactivationBSA BSA-AML-15 · BSA BSA-CDD-3
Activity above the expected profileBSA BSA-AML-15 · BSA BSA-CDD-3
New accounts with outsized activityBSA BSA-AML-15 · BSA BSA-CIP-1
Round amountsBSA BSA-AML-15
VelocityBSA BSA-AML-15
Structuring below the funds-transfer recordkeeping lineBSA BSA-AML-15 · BSA BSA-REC-1
Sanctions name screeningBSA BSA-AML-14
Sanctioned ownership and controlBSA BSA-AML-07
Comprehensively sanctioned geographiesBSA BSA-AML-14
Sectoral sanctionsBSA BSA-AML-14
Missing originator or beneficiary informationBSA BSA-AML-15 · BSA BSA-REC-1
Beneficiary name does not match the accountBSA BSA-AML-15
Check kiting and returned itemsBSA BSA-AML-15
Remote deposit duplicatesBSA BSA-AML-15
Exploitation of older customersBSA BSA-AML-15 · BSA BSA-CDD-3
Account takeoverBSA BSA-AML-15
Scam payments by the customerBSA BSA-AML-15
Business email compromiseBSA BSA-AML-15
Prepaid loading and card cash-outBSA BSA-AML-15
Transaction laundering through merchantsBSA BSA-AML-15
Human trafficking red flagsBSA BSA-AML-15 · BSA BSA-AML-09
Drug trafficking proceedsBSA BSA-AML-15 · BSA BSA-AML-09
Terrorist financing indicatorsBSA BSA-AML-15 · BSA BSA-AML-09
Proliferation financingBSA BSA-AML-15
Bribery and corruption proceedsBSA BSA-AML-15 · BSA BSA-CDD-4

Every obligation cited, quoted

16 of the 44 held

The requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim. Rows the export flags as shared evidence are never shown.

BSA BSA-AML-02 BSA Compliance Officer

A qualified individual shall be designated as BSA Compliance Officer with authority, independence and resources to administer the AML programme.

What an examiner asks to see: BSA Officer appointment letter; Job description; Reporting line to board/committee
Where programmes usually fall short: BSA Officer reports to business line; No documented authority
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-AML-03 Independent Testing

The AML programme shall be subject to independent testing by qualified internal or external parties on a risk-based cadence.

What an examiner asks to see: Independent AML audit reports; Audit charter; Remediation tracker
Where programmes usually fall short: Testing performed by AML function itself; Findings unresolved
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-AML-07 Beneficial Ownership Identification

For legal entity customers, institutions shall identify and verify beneficial owners (25 percent ownership) and one control person.

What an examiner asks to see: Beneficial ownership certification forms; UBO verification records; Renewal procedures on trigger events
Where programmes usually fall short: Old customers not back-filled; Verification only documentary
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-AML-09 Suspicious Activity Reporting (SAR)

Institutions shall file SARs with FinCEN within 30 days of detection (or 60 if no subject identified) for transactions meeting reporting thresholds and indicia.

What an examiner asks to see: SAR filing logs; Investigation case files; SAR decisioning memos; Continuing activity reviews
Where programmes usually fall short: Late filings; No documented no-file rationale
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-AML-10 Currency Transaction Reporting (CTR)

Cash transactions over USD 10,000 in a single business day involving the same person shall be reported on FinCEN Form 112 within 15 days.

What an examiner asks to see: CTR filing logs; Aggregation logic documentation; Sample filed forms
Where programmes usually fall short: No aggregation across branches; Late filings
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-AML-12 Monetary Instrument Recordkeeping

Records of sales of monetary instruments (e.g., money orders, cashier checks) between USD 3,000 and USD 10,000 shall be retained.

What an examiner asks to see: MI sale logs; ID verification records
Where programmes usually fall short: Incomplete records; Aggregation across products missing
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-AML-14 OFAC Sanctions Screening

Institutions shall screen customers, beneficial owners, counterparties and transactions against OFAC and other applicable sanctions lists in real time.

What an examiner asks to see: Screening engine config; List update cadence; Blocked/rejected transaction reports; OFAC annual reports
Where programmes usually fall short: List updates lag; No fuzzy matching tuning
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-AML-15 Transaction Monitoring

Automated and manual transaction monitoring shall identify unusual or suspicious activity using risk-based scenarios and thresholds.

What an examiner asks to see: TM scenario inventory; Threshold tuning documentation; Above-the-line/below-the-line testing; Model validation reports
Where programmes usually fall short: No model validation; Scenarios not aligned to risk assessment
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-AML-16 AML Risk Assessment

An institution-wide AML risk assessment shall consider products, services, customers, geographies and delivery channels and inform programme calibration.

What an examiner asks to see: Enterprise AML risk assessment; Inherent and residual risk ratings; Refresh cadence
Where programmes usually fall short: Outdated assessment; Not linked to TM scenarios
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-AML-17 Correspondent Account Due Diligence

Foreign correspondent accounts shall undergo enhanced due diligence including assessing AML controls of the respondent bank.

What an examiner asks to see: Wolfsberg questionnaires; Respondent AML programme reviews; Senior approval
Where programmes usually fall short: No annual refresh; Nested relationships not identified
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-AML-18 Private Banking Due Diligence

Private banking accounts for non-US persons shall be subject to enhanced scrutiny including source of funds and PEP determination.

What an examiner asks to see: Source of wealth/funds documentation; PEP screening; Relationship manager attestations
Where programmes usually fall short: Source of wealth not corroborated; PEP refresh missed
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-AML-23 Section 311 Special Measures

Institutions shall implement FinCEN Section 311 special measures against jurisdictions, institutions or transactions of primary money laundering concern.

What an examiner asks to see: 311 designations register; Account/transaction restrictions evidence
Where programmes usually fall short: No process to ingest new 311 measures; Restrictions not enforced
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-CDD-3 Customer Risk Profiling

Financial institutions must develop a customer risk profile for each customer, understanding the nature and purpose of the customer relationship. Risk profiles guide ongoing monitoring.

What an examiner asks to see: Registration certificate copies; Filing submission evidence; Renewal calendar; Public register screenshots; Registration fee payment records
Where programmes usually fall short: Renewals tracked informally; Filings missed on minor updates
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-CDD-4 Enhanced Due Diligence (EDD)

Higher-risk customers (PEPs, foreign correspondents, private banking) require enhanced due diligence including additional information collection, source of funds/wealth, senior management approval, and enhanced ongoing monitoring (31 U.S.C. 5318(i), 31 CFR 1010.610, 1010.620).

What an examiner asks to see: AML program documentation; KYC and CDD records; Transaction monitoring scenarios and tuning; SAR/STR filing register; Independent AML audit reports
Where programmes usually fall short: Beneficial ownership data incomplete; Monitoring scenarios not tuned to risk
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-CIP-1 Customer Identification Program (CIP)

Banks must implement a written CIP appropriate for their size and type, which must include procedures for obtaining minimum identifying information from each customer opening an account: name, date of birth, address, and identification number (SSN or TIN) (31 CFR 1020.220).

What an examiner asks to see: Policy referencing the control; Documented procedure; Evidence of operating effectiveness; Monitoring or review reports; Roles and responsibilities mapping
Where programmes usually fall short: Policy not aligned to control statement; Procedure undocumented
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-REC-1 Funds Transfer Recordkeeping (Travel Rule)

Banks must collect, retain, and transmit certain information relating to funds transfers of $3,000 or more, including originator name, address, account number, and amount (31 CFR 1010.410(e)).

What an examiner asks to see: Transfer impact assessment documents; Standard contractual clauses register; Binding corporate rules approval; Adequacy decision references; Vendor transfer mapping
Where programmes usually fall short: No transfer impact assessment performed; SCCs not updated to current versions
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)