BSA/AML,explained
BSA/AML is the US anti-money-laundering regime: the Bank Secrecy Act (31 U.S.C. 5311 and following) and its implementing rules in 31 CFR Chapter X. Covered institutions must run a written AML programme with a designated officer, internal controls, training and independent testing, verify who their customers are, monitor transactions, and report suspicious and large cash activity.
What BSA/AML is
The Bank Secrecy Act is US law, administered by FinCEN and examined by the federal banking agencies and other functional regulators. It is not a certification and there is no certificate to hang on the wall. What you are judged on is whether you run a programme that works, and whether you can evidence it when an examiner asks.
People often say "BSA" and "AML" as if they were two things. In practice BSA is the statute and the rules under it, and the AML programme is what those rules require you to build and operate.
Who it applies to
The definition of a financial institution under the BSA is much wider than "a bank". It covers banks and credit unions, broker-dealers, money services businesses (including many payments and crypto firms), casinos, mutual funds, futures commission merchants, insurance companies for certain products, and more. If you move money or hold customer accounts in the US, assume you are in scope until someone qualified tells you otherwise.
If you are a technology vendor to those institutions rather than a regulated institution yourself, the obligations reach you through your customers. Their examiners expect them to oversee you, so their requirements land in your contracts and their diligence questionnaires.
The AML programme pillars
A compliant programme rests on five pillars. Four come from the original rule and the fifth was added by the customer due diligence rule.
- A designated BSA/AML compliance officer, qualified for the role, with real authority and access to the board.
- Written internal controls, policies and procedures, approved and overseen by senior management.
- Ongoing training for the staff whose work touches the risk, sized to their role.
- Independent testing on a risk-based schedule, by qualified internal or external people who did not build the thing they are testing.
- Risk-based customer due diligence, including understanding the nature and purpose of the customer relationship.
Customer due diligence and beneficial ownership
A Customer Identification Program (31 CFR 1020.220) requires you to identify and verify customers at onboarding and to retain the identifying information. On top of that, the CDD rule (31 CFR 1010.230) requires covered institutions to identify the beneficial owners of legal-entity customers and to maintain a risk-based, ongoing understanding of the relationship.
The word that carries the weight is "ongoing". A file that was accurate at onboarding and never revisited is a common examination finding, because the risk picture moves and the file does not.
Monitoring, reporting and recordkeeping
- Transaction monitoring: monitor on a risk basis for activity that is unusual or potentially indicative of money laundering, and investigate and disposition the alerts you raise.
- Suspicious Activity Reports: file with FinCEN within the required timeline once you have identified suspicious activity, keep the supporting documentation, and keep the filing confidential. Telling the subject is itself an offence.
- Currency Transaction Reports: aggregate and report cash transactions above the reporting threshold.
- Recordkeeping: retain BSA records for the required period and keep them retrievable for examination.
The recurring examination theme is not the tooling, it is the paper trail. If you cannot show why an alert was closed, the decision effectively did not happen.
How it relates to security frameworks
A lot of BSA/AML overlaps an information-security programme more than people expect. Governance and a named accountable owner, written policy, role-based training, independent assurance, logging and monitoring, and records retention all have direct analogues in ISO 27001 and SOC 2. If you already run one of those, that control work carries a meaningful part of the load, and BSA/AML adds the financial-crime specifics: customer identification, beneficial ownership, alert handling, and the reporting obligations.
Frequently asked questions
Is BSA/AML a certification?
No. It is US law administered by FinCEN and enforced through examination by the federal banking agencies and other functional regulators. There is no certificate. What matters is whether the programme is written, operating, and evidenced well enough to survive an examination.
What are the five pillars of an AML programme?
A designated BSA/AML compliance officer, written internal controls and policies, ongoing training, independent testing, and risk-based customer due diligence. The first four come from the original programme rule; customer due diligence was added as the fifth by the CDD rule.
Does BSA/AML overlap ISO 27001 or SOC 2?
Substantially, on the governance side. Named ownership, written policy, training, independent assurance, monitoring and logging, and records retention all map across. What does not carry over is the financial-crime substance: customer identification, beneficial ownership, transaction monitoring, and the SAR and CTR reporting obligations.
Do this in a fraction of the time
Diligio centralises your approved answers, drafts each response grounded in your sources, and independently verifies it before you review. RFPs, DDQs, and security questionnaires, answered from one knowledge base.
Related guides
What is a DDQ (due-diligence questionnaire)?
Due diligenceDDQ vs RFP: what is the difference?
RFPsRFP vs RFI vs RFQ: what is the difference?
RFPsThe RFP response process: a step-by-step guide
RFPsHow to build an RFP content library
RFPsThe bid/no-bid decision: when to respond to an RFP
Security questionnairesHow to respond to security questionnaires faster
Security questionnairesSIG vs CAIQ vs VSAQ: the security questionnaires explained
Security questionnairesVendor security assessment checklist
ComplianceSOC 2 vs ISO 27001: what is the difference?
ComplianceISO 27001 readiness checklist: how to prepare for certification
ComplianceSOC 2 for startups: a practical guide
ComplianceGDPR compliance for SaaS: a practical guide
ComplianceHIPAA compliance for software vendors
CompliancePCI DSS compliance, explained
ComplianceThe NIST Cybersecurity Framework, explained
ComplianceISO 42001, the AI management standard, explained
ComplianceISO 27017 and ISO 27018: cloud security and privacy, explained
ComplianceISO 22301 and business continuity, explained
ComplianceDORA, explained
ComplianceCyber Essentials, explained
ComplianceThe CCPA and CPRA, explained
ComplianceNIST 800-53, explained
ComplianceNIST 800-171 and CMMC, explained
ComplianceFedRAMP, explained
ComplianceHITRUST CSF, explained
Financial regulationThe FATF 40 Recommendations, explained
Financial regulationMiFID II and MAR, explained
Financial regulationConsumer credit and fair lending, explained
Due diligenceThird-party risk management (TPRM): a practical guide
Putting BSA/AML into practice? See Diligio Compliance for BSA/AML.