Financial institutions face anti-money laundering obligations under the Bank Secrecy Act that go well beyond general cybersecurity requirements — a formal program, designated personnel, and specific reporting duties examiners actively test for, not just a general expectation of good data hygiene.
What the BSA Actually Requires
The Bank Secrecy Act requires covered financial institutions to establish a formal BSA/AML compliance program, keep records of cash purchases of negotiable instruments, file reports on cash transactions exceeding $10,000 in daily aggregate, and report suspicious activity that might indicate money laundering, tax evasion, or other criminal activity. This applies beyond traditional banks, too — check cashers, money services businesses, and other financial intermediaries can carry related obligations under the FTC’s Safeguards Rule scope.
The Four Required Components
A compliant program needs written policies, procedures, and internal controls designed to ensure BSA compliance; a designated individual responsible for day-to-day compliance; ongoing training for personnel on their specific responsibilities, including detecting suspicious activity; and independent review confirming the program remains adequate for the institution’s actual risk profile. Every covered institution must formally designate that compliance officer — in a smaller institution this can be an existing officer taking on the role alongside other duties, but the designation has to be documented, not an informal understanding of who handles it.
Suspicious Activity Reports
A Suspicious Activity Report (SAR) gets filed with FinCEN when a transaction or pattern of activity appears potentially linked to money laundering, tax evasion, or other financial crime. Institutions need documented procedures for how staff identify and escalate potentially suspicious activity for SAR filing decisions, since delayed or missed SAR filings are a common examination finding — not a rare one.
Examination Practices Are Shifting
Recent 2025 updates allow examiners discretion to carry forward prior examination conclusions for one cycle on the Training and BSA Compliance Officer components, where an institution’s risk profile hasn’t changed significantly, along with increased examiner discretion on the extent of transaction testing performed. That reflects a somewhat more risk-based examination approach for smaller institutions, but it doesn’t reduce the underlying program requirements.
What Technology Has to Do Here
Transaction monitoring systems that flag patterns consistent with structuring, unusual cash activity, or other red flags are central to an effective AML program at any meaningful transaction volume. Manual review alone becomes impractical past a certain scale, making monitoring technology a practical necessity rather than an optional upgrade for growing institutions.
Retention Requirements
BSA generally requires retaining relevant records — including SARs and supporting documentation — for five years, though specific record types can carry different timelines. See our data retention and records management guide for how this fits into a broader retention policy.
What Happens During an Examination
Examiners review the written program, test whether the designated compliance officer role is functioning as documented, sample transactions to verify monitoring and SAR filing practices are working correctly, and assess whether training has actually reached relevant personnel. See our compliance audit preparation guide for how to prepare generally for this kind of regulatory review.
How CelereTech Helps
CelereTech helps financial firms implement the technical monitoring and record-keeping systems that support an effective BSA/AML program, ensures transaction and SAR-related records are retained and accessible per regulatory requirements, and builds the documentation trail examiners expect — working alongside your designated compliance officer rather than replacing that role.
Get your BSA/AML technical infrastructure assessed ahead of your next examination.