BSA/AML Compliance Program
A BSA/AML compliance program is the set of policies, procedures, and controls that a financial institution puts in place to help it comply with U.S. anti-money laundering laws and to detect and report suspicious financial activity. It is not a single tool but an organized framework covering how a firm monitors transactions, trains staff, and oversees its own compliance. Such a program is designed to manage and mitigate financial crime risk, though no program can guarantee that all money laundering is prevented.
In the U.S. context, a BSA/AML compliance program refers to the policies, procedures, and internal controls that certain obliged entities, such as banks, must establish and maintain to assure and monitor compliance with Bank Secrecy Act regulatory requirements. The Bank Secrecy Act, sometimes referred to as an 'anti-money laundering' (AML) law or jointly as 'BSA/AML,' is administered in part by FinCEN, and examination expectations for banks are set out in the FFIEC BSA/AML Examination Manual. Program requirements are commonly described by practitioners as a set of statutory and regulatory 'pillars,' generally comprising a system of internal controls, a designated BSA compliance officer, independent testing of the program, and ongoing training, with risk-based customer due diligence (including beneficial ownership requirements) added by later regulation. The precise obligations, the entities in scope, and the applicable statutory and regulatory citations vary and should be confirmed against the current text of the BSA (the core provisions of which are codified in Title 31 of the U.S. Code, with certain related recordkeeping provisions in Title 12) and the implementing regulations and examination guidance applicable to the particular type of institution.
Why it matters
A BSA/AML compliance program is the operational backbone that allows a financial institution to meet its obligations under the U.S. Bank Secrecy Act and related anti-money laundering rules. Without an organized framework of policies, procedures, and internal controls, a firm has no systematic way to monitor transactions, escalate and report suspicious activity, or demonstrate to examiners that it is managing financial crime risk. For banks in particular, the program is not optional: the FFIEC BSA/AML Examination Manual sets out how examiners assess whether an institution has established and maintained procedures reasonably designed to assure and monitor compliance with BSA regulatory requirements.
The stakes are both regulatory and reputational. Deficiencies in a program, weak internal controls, inadequate independent testing, insufficient training, or gaps in customer due diligence, are frequently the focus of supervisory findings and enforcement actions, and can expose an institution to remediation costs, consent orders, and heightened scrutiny. It is important to stress, however, that a compliance program is a risk-management framework, not a guarantee: even a well-designed program cannot ensure that all money laundering is detected or prevented, and the existence of a filing or an alert does not by itself establish that any wrongdoing has occurred.
Because the precise obligations, the entities in scope, and the applicable citations vary by institution type and evolve over time, treating the program as a living framework, periodically tested and updated, is central to sustaining compliance. Practitioners should confirm specific requirements against the current text of the BSA and the implementing regulations and examination guidance that apply to their particular type of institution.
Who it's relevant to
Inside BSA/AML
Common questions
Answers to the questions practitioners most commonly ask about BSA/AML.