Bank Secrecy Act and its regulations (31 CFR Chapter X): what it asks of a monitoring programme
The United States rule set a bank examiner reads a monitoring programme against: suspicious activity and currency transaction reporting, funds-transfer records, customer due diligence and the programme pillars. Where the same obligation is held twice, the statute-shaped row is quoted and the other is left out.
Shown when United States is ticked.
One row per obligation
which row is quoted| Obligation | Quoted | Left out, and why |
|---|---|---|
| Suspicious activity reports | BSA-AML-09 | BSA-SAR-1, BSA-SAR-2: the statute-shaped rows are flagged as shared evidence in the export |
| Currency transaction reports | BSA-AML-10 | BSA-CTR-1, BSA-CTR-2: the statute-shaped rows are flagged as shared evidence |
| Funds-transfer records | BSA-REC-1 | BSA-AML-13: statute-shaped row preferred |
| Monetary instrument records | BSA-AML-12 | BSA-REC-2: the statute-shaped row is flagged as shared evidence |
| Customer identification programme | BSA-CIP-1 | BSA-AML-05: statute-shaped row preferred |
| Customer due diligence and risk profile | BSA-CDD-3 | BSA-AML-06: statute-shaped row preferred |
| Beneficial ownership | BSA-AML-07 | BSA-CDD-1, BSA-CDD-2: the statute-shaped rows carry the same evidence block as BSA-CDD-4 in the export, and the library shows every evidence block once |
| Enhanced due diligence | BSA-CDD-4 | BSA-AML-08: statute-shaped row preferred |
| Structuring | BSA-AML-10 | BSA-ENF-1: the prohibition row is flagged as shared evidence; the CTR row carries the figure |
Named, not quoted, beside it: the FinCEN AML programme rule, the FFIEC BSA/AML examination manual, and NYDFS Part 504 for New York regulated institutions.
Typologies anchored here
50Every obligation cited, quoted
16 of the 44 heldThe requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim. Rows the export flags as shared evidence are never shown.
BSA BSA-AML-02 BSA Compliance OfficerA qualified individual shall be designated as BSA Compliance Officer with authority, independence and resources to administer the AML programme.
Where programmes usually fall short: BSA Officer reports to business line; No documented authority
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-AML-03 Independent TestingThe AML programme shall be subject to independent testing by qualified internal or external parties on a risk-based cadence.
Where programmes usually fall short: Testing performed by AML function itself; Findings unresolved
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-AML-07 Beneficial Ownership IdentificationFor legal entity customers, institutions shall identify and verify beneficial owners (25 percent ownership) and one control person.
Where programmes usually fall short: Old customers not back-filled; Verification only documentary
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-AML-09 Suspicious Activity Reporting (SAR)Institutions shall file SARs with FinCEN within 30 days of detection (or 60 if no subject identified) for transactions meeting reporting thresholds and indicia.
Where programmes usually fall short: Late filings; No documented no-file rationale
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-AML-10 Currency Transaction Reporting (CTR)Cash transactions over USD 10,000 in a single business day involving the same person shall be reported on FinCEN Form 112 within 15 days.
Where programmes usually fall short: No aggregation across branches; Late filings
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-AML-12 Monetary Instrument RecordkeepingRecords of sales of monetary instruments (e.g., money orders, cashier checks) between USD 3,000 and USD 10,000 shall be retained.
Where programmes usually fall short: Incomplete records; Aggregation across products missing
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-AML-14 OFAC Sanctions ScreeningInstitutions shall screen customers, beneficial owners, counterparties and transactions against OFAC and other applicable sanctions lists in real time.
Where programmes usually fall short: List updates lag; No fuzzy matching tuning
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-AML-15 Transaction MonitoringAutomated and manual transaction monitoring shall identify unusual or suspicious activity using risk-based scenarios and thresholds.
Where programmes usually fall short: No model validation; Scenarios not aligned to risk assessment
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-AML-16 AML Risk AssessmentAn institution-wide AML risk assessment shall consider products, services, customers, geographies and delivery channels and inform programme calibration.
Where programmes usually fall short: Outdated assessment; Not linked to TM scenarios
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-AML-17 Correspondent Account Due DiligenceForeign correspondent accounts shall undergo enhanced due diligence including assessing AML controls of the respondent bank.
Where programmes usually fall short: No annual refresh; Nested relationships not identified
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-AML-18 Private Banking Due DiligencePrivate banking accounts for non-US persons shall be subject to enhanced scrutiny including source of funds and PEP determination.
Where programmes usually fall short: Source of wealth not corroborated; PEP refresh missed
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-AML-23 Section 311 Special MeasuresInstitutions shall implement FinCEN Section 311 special measures against jurisdictions, institutions or transactions of primary money laundering concern.
Where programmes usually fall short: No process to ingest new 311 measures; Restrictions not enforced
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-CDD-3 Customer Risk ProfilingFinancial institutions must develop a customer risk profile for each customer, understanding the nature and purpose of the customer relationship. Risk profiles guide ongoing monitoring.
Where programmes usually fall short: Renewals tracked informally; Filings missed on minor updates
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-CDD-4 Enhanced Due Diligence (EDD)Higher-risk customers (PEPs, foreign correspondents, private banking) require enhanced due diligence including additional information collection, source of funds/wealth, senior management approval, and enhanced ongoing monitoring (31 U.S.C. 5318(i), 31 CFR 1010.610, 1010.620).
Where programmes usually fall short: Beneficial ownership data incomplete; Monitoring scenarios not tuned to risk
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-CIP-1 Customer Identification Program (CIP)Banks must implement a written CIP appropriate for their size and type, which must include procedures for obtaining minimum identifying information from each customer opening an account: name, date of birth, address, and identification number (SSN or TIN) (31 CFR 1020.220).
Where programmes usually fall short: Policy not aligned to control statement; Procedure undocumented
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-REC-1 Funds Transfer Recordkeeping (Travel Rule)Banks must collect, retain, and transmit certain information relating to funds transfers of $3,000 or more, including originator name, address, account number, and amount (31 CFR 1010.410(e)).
Where programmes usually fall short: No transfer impact assessment performed; SCCs not updated to current versions
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)