Skip to main content
BSA/AML Field Guide: When Compliance Stops Being IntelligenceBeneficial Ownership
5 min readFor MLROs

BSA/AML Field Guide: When Compliance Stops Being Intelligence

Scope

This guide examines the tension in your AML/CFT framework between effective law enforcement collaboration and procedural compliance. You'll find requirement breakdowns, guidance for risk-based resource allocation, and strategies for shifting from information-sharing to box-checking.

This isn't just about compliance. It's about ensuring your compliance generates intelligence that law enforcement can use.

Key Concepts and Definitions

Bank Secrecy Act (BSA): The 1970 statute requiring financial institutions to maintain records and file reports to detect money laundering, tax evasion, and other financial crimes.

Title III of the USA Patriot Act: The 2001 amendment that expanded BSA compliance to include ongoing customer identification, verification, and monitoring.

Customer Identification Program (CIP): The requirement to obtain, verify, and record identifying information for every person opening an account, including tax IDs, birth dates, and addresses.

Beneficial Owner Identification: Identifying natural persons who own or control legal entities. The Corporate Transparency Act created a centralized registry in 2024, but FinCEN's final rule (effective August 14, 2024) eliminated reporting requirements for U.S. companies, leaving only foreign entities registered in the U.S. subject to reporting.

Risk-Based Allocation: Directing Customer Due Diligence and monitoring resources toward higher-risk customers and transactions instead of a uniform approach.

Requirements Breakdown

Core BSA/AML/CFT Framework Components

Your AML/CFT framework must include:

  1. Customer Identification Program (31 CFR § 1020.220)

    • Obtain identifying information at account opening.
    • Verify identity using documents or non-documentary methods.
    • Maintain records for five years after account closure.
    • Compare customer names against OFAC lists.
  2. Ongoing Due Diligence (31 CFR § 1010.610)

    • Understand the nature and purpose of customer relationships.
    • Monitor transactions to identify and report suspicious activity.
    • Update customer information based on risk.
  3. Suspicious Activity Report Filing (31 CFR § 1020.320)

  4. Currency Transaction Report Filing (31 CFR § 1010.310)

What Changed Under the Corporate Transparency Act Reversal

Before August 2024, U.S. companies had to report beneficial ownership to FinCEN. The final rule eliminated this requirement for domestic entities.

Current state: Only foreign entities registered in the U.S. must report beneficial ownership. U.S. LLCs and corporations have no federal beneficial ownership reporting obligation.

Practical impact: You can't rely on a centralized registry for domestic entity ownership. Collect this information yourself during Customer Due Diligence if your risk assessment requires it.

Implementation Guidance

Shift From Uniform to Risk-Based Coverage

Your examination schedule and SAR obligations remain unchanged. What's shifted is the regulatory emphasis on resource concentration.

Start here: Map your current Customer Due Diligence by customer segment. What percentage of your team's time goes to low-risk retail accounts versus high-risk correspondent banking or cash-intensive businesses?

If you're applying the same verification depth to a payroll account and a shell company, you're misallocating resources.

Rebuild Beneficial Ownership Collection

Without a federal registry for U.S. entities, collect beneficial ownership information directly during account opening and periodic review.

For higher-risk legal entities:

  • Obtain ownership structure documentation.
  • Identify natural persons with 25% or greater ownership.
  • Identify natural persons with significant control.
  • Verify identities using the same standards as individual CIP.
  • Document the information in the customer file.

For lower-risk entities: Identify beneficial owners, but scale verification depth with risk. A local nonprofit with transparent governance doesn't require the same scrutiny as a newly formed LLC with opaque ownership.

Refocus Transaction Monitoring Rules

Your transaction monitoring should generate alerts that lead to actionable intelligence, not just SAR volume.

Review your tuning:

  • What percentage of alerts become SARs?
  • What percentage of SARs reference specific offenses versus generic "unusual activity"?
  • How often does law enforcement follow up on your filings?

If you're filing SARs because the rules generated an alert, not because you identified suspicious activity, you're performing compliance theater.

Strengthen Law Enforcement Information Sharing

The BSA's original purpose was to provide information useful to criminal and tax investigations. That purpose is lost when compliance becomes procedural.

Practical steps:

  • Attend local FBI or FinCEN working group meetings.
  • Request feedback on SAR quality from your FinCEN analyst.
  • Document specific typologies in your SAR narratives, not just account activity summaries.
  • Use the Continuing Activity SAR designation for ongoing schemes.

Common Pitfalls

Pitfall 1: Treating All Customers as Equal Risk

You can't perform the same due diligence depth on every customer. Risk-based allocation means higher scrutiny for higher risk, not uniform scrutiny everywhere.

Pitfall 2: Assuming the Government Has Better Information

Post-9/11 regulations shifted information-gathering responsibility to banks. You're expected to investigate and make judgments about customer activity. Law enforcement often has less transaction-level visibility than you do.

Pitfall 3: Ignoring the Shell Company Gap

Eliminating beneficial ownership reporting for U.S. entities means bad actors can avoid the requirement by forming a domestic LLC. If you bank business entities, you need compensating controls in your Customer Due Diligence process.

Pitfall 4: Filing SARs to Satisfy Metrics

SAR volume isn't a success metric. Actionable intelligence is. If your compliance team measures success by SAR count rather than quality, you've lost the original purpose.

Pitfall 5: Waiting for Regulatory Clarity on Risk-Based Approaches

Your regulator expects you to apply risk-based principles. Waiting for explicit permission to reduce scrutiny on low-risk segments means you're over-investing in low-value activity.

Quick Reference Table

Requirement Citation Key Obligation Record Retention
Customer Identification Program 31 CFR § 1020.220 Obtain and verify identifying information at account opening 5 years after account closure
Beneficial Ownership (foreign entities only) 31 CFR § 1010.230 Identify natural persons owning 25%+ or with significant control 5 years after account closure
Suspicious Activity Report 31 CFR § 1020.320 File within 30 days of detection (60 if no suspect) 5 years from filing date
Currency Transaction Report 31 CFR § 1010.310 Report currency transactions over $10,000 5 years from filing date
AML/CFT Framework 31 CFR § 1020.210 Maintain written program with internal controls, independent testing, training, and designated officer Current version plus 5 years
Ongoing Due Diligence 31 CFR § 1010.610 Conduct risk-based monitoring and update customer information Duration of relationship plus 5 years

Bottom line: Your AML/CFT framework should produce intelligence, not just documentation. The regulatory environment now expects risk-based resource allocation. Direct your scrutiny where the risk is, collect beneficial ownership information yourself, and measure success by whether law enforcement can act on what you report.

You Might Also Like