Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsiTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
In the United States, anti-money laundering (AML) compliance is built largely around the Bank Secrecy Act (BSA) and its implementing regulations. Covered financial institutions use controls to understand customer relationships, monitor activity, keep required records, investigate concerns, and file reports when the rules call for them. The exact duties vary by institution type, regulator, products, customers, and risk; there is no single checklist that applies to every financial company.
What U.S. AML rules are designed to do
The Currency and Foreign Transactions Reporting Act of 1970, its amendments, and related statutes are commonly referred to as the Bank Secrecy Act. The U.S. Treasury’s Financial Crimes Enforcement Network (FinCEN) administers important parts of the framework. The BSA authorizes Treasury to require financial institutions and certain businesses to keep records and submit reports that can help detect and prevent money laundering and other crimes.
Among the framework’s tools are records for certain cash purchases of negotiable instruments, reports of qualifying cash transactions, and reports of suspicious activity that may indicate money laundering, tax evasion, or other criminal conduct. You will often see the framework called “BSA/AML.” The Anti-Money Laundering Act of 2020 amended the BSA framework and directed modernization work; a proposed rule or modernization effort is not binding merely because it has been announced.
FinCEN sets or administers federal requirements in important areas, while institutions may also be subject to supervision and guidance from their relevant regulators. Requirements differ across sectors. For example, FinCEN’s customer due diligence (CDD) rule covers specified banks, mutual funds, securities broker-dealers, futures commission merchants, and introducing brokers in commodities; that list is not a universal map of every entity with AML duties.
How an AML program works in practice
For institutions subject to the CDD program requirements, FinCEN identifies five minimum components. Together, they turn AML from a one-time onboarding check into an accountable, ongoing process.
- Internal controls: Written policies, procedures, and processes designed around the institution’s BSA/AML risks and obligations.
- Independent testing: Testing that assesses whether the program is working, conducted by people independent of the activities being tested.
- Designated responsibility: A compliance officer or other responsible individual accountable for coordinating the program.
- Training: Appropriate personnel receive training relevant to their roles and the institution’s procedures.
- Ongoing, risk-based CDD: Procedures to understand customer relationships, develop risk profiles, monitor for suspicious activity, and maintain or update customer information on a risk basis.
These are minimum components for institutions covered by the applicable CDD program requirements, not a promise that every financial firm has identical legal duties. The relevant rules, regulator, products, channels, and risk assessment determine the details. FinCEN guidance describes controls as commensurate with an institution’s BSA/AML risk, with heightened due diligence for customers presenting higher risk. Higher risk does not automatically mean a customer must be rejected, and lower risk does not mean controls can be skipped.
What customer due diligence covers
CDD is broader than collecting an identity document. It brings together customer identification, beneficial-owner identification for covered legal-entity customers, an understanding of the relationship’s nature and purpose, and ongoing monitoring. That understanding helps an institution form a customer risk profile and assess whether later activity is consistent with what it knows about the relationship.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Rank #2
Legal-entity beneficial owners
Under the CDD rule, covered institutions generally identify and verify natural persons who own, control, and profit from covered legal-entity customers, subject to exemptions and the rule’s precise scope. The basic ownership prong threshold is 25 percent; the control prong is a separate requirement. FinCEN’s FAQs say an institution may collect ownership information at a lower percentage when its own risk assessment warrants it. The 25 percent figure comes from FinCEN’s 2016 CDD rule and FAQ materials updated May 6, 2026.
Optional relief from checking at every new account
On February 13, 2026, FinCEN granted covered institutions optional exceptive relief from identifying and verifying beneficial owners at every new account opening. An institution that elects to use the relief may generally do so at the customer’s first account opening, when facts call the reliability of previously obtained information into question, and as needed through risk-based ongoing CDD. An institution may instead retain its existing every-account-opening process. The relief changed when certain institutions may perform the step; it did not abolish beneficial-owner identification.
Institutional CDD is separate from company BOI reporting
Customer due diligence by a financial institution is not the same obligation as a company’s beneficial ownership information (BOI) reporting under the Corporate Transparency Act. FinCEN’s BOI page, updated August 11, 2026, says U.S. companies are exempt from BOI reporting requirements and U.S. persons are no longer required to report under the revised rule. That entity-reporting change does not, by itself, remove financial institutions’ separate CDD duties.
How monitoring and investigations fit together
Once a relationship is established, an institution applies monitoring and review suited to its risk and obligations. The purpose is to notice activity that may not fit the customer’s profile or that otherwise raises a concern, then assess it under internal procedures and applicable law. A flagged transaction is a prompt for review, not proof that a crime occurred.
Free tools Windows power users keep installed
One-click scans. No signup required.
- Establish context: Use the customer information and expected relationship to understand the activity being reviewed.
- Assess the concern: Review relevant transactions and available information under the institution’s procedures; determine whether the concern is explainable, requires further review, or may meet a reporting standard.
- Document and act: Record the review and its disposition, make any required report, and update customer information or controls when warranted by the risk and rules.
Monitoring is not a single universal test. Institutions’ systems, review processes, and escalation paths differ with their business and risk. FinCEN’s interagency guidance calls comprehensive CDD policies and internal controls a cornerstone of a strong BSA/AML program, particularly for customers presenting higher money-laundering or terrorist-financing risk.
CTR and SAR: two different reports
A Currency Transaction Report (CTR) and a Suspicious Activity Report (SAR) serve different purposes. A CTR is tied to qualifying cash transactions and a reporting threshold; a SAR addresses activity that meets applicable suspicious-activity reporting requirements. A CTR threshold is not a test for whether activity is suspicious.
Rank #4
| Report | What prompts it | What it does | Important limit |
|---|---|---|---|
| CTR | Covered cash transactions exceeding $10,000 in daily aggregate, according to FinCEN’s current BSA overview accessed October 7, 2026. | Reports qualifying cash transactions to support the BSA’s recordkeeping and reporting framework. | The threshold concerns reportable cash transactions under applicable rules; it does not by itself establish suspicious activity. |
| SAR | Activity that meets the institution’s applicable suspicious-activity reporting requirements; possible concerns can include suspected money laundering, structuring, or other criminal conduct. | Reports suspicious activity for government review under applicable requirements. | There is no simple universal rule that every unusual transaction triggers a SAR. The decision follows the governing rules and the institution’s procedures. |
FinCEN’s SAR FAQs, described in an October 9, 2025 release, address structuring SARs, continuing-activity reviews, and decisions not to file. Where confidentiality rules apply, an institution must not reveal a SAR’s existence to the subject. A SAR is not a finding of guilt.
When financial institutions can share information
Section 314(b) of the USA PATRIOT Act provides a safe harbor for qualifying financial institutions and associations that share information for identifying and, where appropriate, reporting possible money laundering or terrorist activity. Participation is subject to the program’s conditions; it is not blanket permission to disclose any customer information. FinCEN’s current page points to a June 12, 2026 fact sheet and marks older material rescinded, so institutions need to follow the current program materials rather than rely on superseded guidance.
Recommended Free Tools
What this means for customers and businesses
AML checks may involve identity and business information, questions about the purpose of an account or service, and review of activity over time. The information requested and the intensity of review depend on the institution’s obligations and risk assessment. A request for more information or a review does not, on its own, show that an institution has concluded a customer did something wrong.
Best Value
For a business opening a financial account, it is useful to have accurate information about ownership, control, business activity, and the account’s intended use available. Institutions may ask for additional information as needed to meet their own legal and risk-based requirements. For a financial institution, the operational task is to connect onboarding, risk assessment, monitoring, investigation, recordkeeping, reporting, and program testing rather than treat them as disconnected boxes.
How to read changes in the rules
Federal AML obligations are not frozen in one statute or one agency FAQ. The BSA, its implementing regulations, amendments such as the AML Act of 2020, agency guidance, and institution-specific supervisory requirements may all matter. Beneficial ownership reporting, CDD relief, SAR guidance, and AML/CFT program rulemaking are areas where details have changed. For a specific institution or account, the controlling rule and current agency materials matter more than a generic summary; this article is a federal overview as of October 9, 2026, not advice on a particular charter, regulator, product, customer, or state obligation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →

