Scope
This guide examines the tension in your AML/CFT framework between effective law enforcement collaboration and procedural compliance. You'll find requirement breakdowns, guidance for risk-based resource allocation, and strategies for shifting from information-sharing to box-checking.
This isn't just about compliance. It's about ensuring your compliance generates intelligence that law enforcement can use.
Key Concepts and Definitions
Bank Secrecy Act (BSA): The 1970 statute requiring financial institutions to maintain records and file reports to detect money laundering, tax evasion, and other financial crimes.
Title III of the USA Patriot Act: The 2001 amendment that expanded BSA compliance to include ongoing customer identification, verification, and monitoring.
Customer Identification Program (CIP): The requirement to obtain, verify, and record identifying information for every person opening an account, including tax IDs, birth dates, and addresses.
Beneficial Owner Identification: Identifying natural persons who own or control legal entities. The Corporate Transparency Act created a centralized registry in 2024, but FinCEN's final rule (effective August 14, 2024) eliminated reporting requirements for U.S. companies, leaving only foreign entities registered in the U.S. subject to reporting.
Risk-Based Allocation: Directing Customer Due Diligence and monitoring resources toward higher-risk customers and transactions instead of a uniform approach.
Requirements Breakdown
Core BSA/AML/CFT Framework Components
Your AML/CFT framework must include:
Customer Identification Program (31 CFR § 1020.220)
- Obtain identifying information at account opening.
- Verify identity using documents or non-documentary methods.
- Maintain records for five years after account closure.
- Compare customer names against OFAC lists.
Ongoing Due Diligence (31 CFR § 1010.610)
- Understand the nature and purpose of customer relationships.
- Monitor transactions to identify and report suspicious activity.
- Update customer information based on risk.
Suspicious Activity Report Filing (31 CFR § 1020.320)
- File FinCEN SAR (Form 111) within 30 days of detection.
- File within 60 days if no suspect is identified.
- Maintain SAR confidentiality.
Currency Transaction Report Filing (31 CFR § 1010.310)
- Report currency transactions over $10,000.
- File through the BSA E-Filing System.
What Changed Under the Corporate Transparency Act Reversal
Before August 2024, U.S. companies had to report beneficial ownership to FinCEN. The final rule eliminated this requirement for domestic entities.
Current state: Only foreign entities registered in the U.S. must report beneficial ownership. U.S. LLCs and corporations have no federal beneficial ownership reporting obligation.
Practical impact: You can't rely on a centralized registry for domestic entity ownership. Collect this information yourself during Customer Due Diligence if your risk assessment requires it.
Implementation Guidance
Shift From Uniform to Risk-Based Coverage
Your examination schedule and SAR obligations remain unchanged. What's shifted is the regulatory emphasis on resource concentration.
Start here: Map your current Customer Due Diligence by customer segment. What percentage of your team's time goes to low-risk retail accounts versus high-risk correspondent banking or cash-intensive businesses?
If you're applying the same verification depth to a payroll account and a shell company, you're misallocating resources.
Rebuild Beneficial Ownership Collection
Without a federal registry for U.S. entities, collect beneficial ownership information directly during account opening and periodic review.
For higher-risk legal entities:
- Obtain ownership structure documentation.
- Identify natural persons with 25% or greater ownership.
- Identify natural persons with significant control.
- Verify identities using the same standards as individual CIP.
- Document the information in the customer file.
For lower-risk entities: Identify beneficial owners, but scale verification depth with risk. A local nonprofit with transparent governance doesn't require the same scrutiny as a newly formed LLC with opaque ownership.
Refocus Transaction Monitoring Rules
Your transaction monitoring should generate alerts that lead to actionable intelligence, not just SAR volume.
Review your tuning:
- What percentage of alerts become SARs?
- What percentage of SARs reference specific offenses versus generic "unusual activity"?
- How often does law enforcement follow up on your filings?
If you're filing SARs because the rules generated an alert, not because you identified suspicious activity, you're performing compliance theater.
Strengthen Law Enforcement Information Sharing
The BSA's original purpose was to provide information useful to criminal and tax investigations. That purpose is lost when compliance becomes procedural.
Practical steps:
- Attend local FBI or FinCEN working group meetings.
- Request feedback on SAR quality from your FinCEN analyst.
- Document specific typologies in your SAR narratives, not just account activity summaries.
- Use the Continuing Activity SAR designation for ongoing schemes.
Common Pitfalls
Pitfall 1: Treating All Customers as Equal Risk
You can't perform the same due diligence depth on every customer. Risk-based allocation means higher scrutiny for higher risk, not uniform scrutiny everywhere.
Pitfall 2: Assuming the Government Has Better Information
Post-9/11 regulations shifted information-gathering responsibility to banks. You're expected to investigate and make judgments about customer activity. Law enforcement often has less transaction-level visibility than you do.
Pitfall 3: Ignoring the Shell Company Gap
Eliminating beneficial ownership reporting for U.S. entities means bad actors can avoid the requirement by forming a domestic LLC. If you bank business entities, you need compensating controls in your Customer Due Diligence process.
Pitfall 4: Filing SARs to Satisfy Metrics
SAR volume isn't a success metric. Actionable intelligence is. If your compliance team measures success by SAR count rather than quality, you've lost the original purpose.
Pitfall 5: Waiting for Regulatory Clarity on Risk-Based Approaches
Your regulator expects you to apply risk-based principles. Waiting for explicit permission to reduce scrutiny on low-risk segments means you're over-investing in low-value activity.
Quick Reference Table
| Requirement | Citation | Key Obligation | Record Retention |
|---|---|---|---|
| Customer Identification Program | 31 CFR § 1020.220 | Obtain and verify identifying information at account opening | 5 years after account closure |
| Beneficial Ownership (foreign entities only) | 31 CFR § 1010.230 | Identify natural persons owning 25%+ or with significant control | 5 years after account closure |
| Suspicious Activity Report | 31 CFR § 1020.320 | File within 30 days of detection (60 if no suspect) | 5 years from filing date |
| Currency Transaction Report | 31 CFR § 1010.310 | Report currency transactions over $10,000 | 5 years from filing date |
| AML/CFT Framework | 31 CFR § 1020.210 | Maintain written program with internal controls, independent testing, training, and designated officer | Current version plus 5 years |
| Ongoing Due Diligence | 31 CFR § 1010.610 | Conduct risk-based monitoring and update customer information | Duration of relationship plus 5 years |
Bottom line: Your AML/CFT framework should produce intelligence, not just documentation. The regulatory environment now expects risk-based resource allocation. Direct your scrutiny where the risk is, collect beneficial ownership information yourself, and measure success by whether law enforcement can act on what you report.



