Bank Secrecy Act / Anti-Money Laundering (BSA/AML)
Evidence request list. 44 controls, 44 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
AML Compliance Program
Financial institutions shall establish a written AML compliance programme approved by the board, with policies, procedures, internal controls and ongoing oversight under 31 CFR 1020.210.
- AML programme document
- Board resolution approving programme
- Annual programme review
- No board minutes evidencing approval
- Programme not refreshed annually
A qualified individual shall be designated as BSA Compliance Officer with authority, independence and resources to administer the AML programme.
- BSA Officer appointment letter
- Job description
- Reporting line to board/committee
- BSA Officer reports to business line
- No documented authority
The AML programme shall be subject to independent testing by qualified internal or external parties on a risk-based cadence.
- Independent AML audit reports
- Audit charter
- Remediation tracker
- Testing performed by AML function itself
- Findings unresolved
All appropriate personnel shall receive AML training tailored to their role and updated to reflect regulatory and typology changes.
- Training curriculum
- Completion records by role
- Board AML briefing materials
- Front-line staff not trained on red flags
- No role-based curriculum
Programmes shall be effective, risk-based and reasonably designed to assure compliance, considering FinCEN AML/CFT priorities as required by AMLA 2020.
- Mapping of programme to FinCEN AML/CFT priorities
- Effectiveness metrics
- Board reporting on priorities
- FinCEN priorities not yet incorporated
- No effectiveness metrics defined
Customer Identification and Due Diligence
Institutions shall implement a CIP to verify the identity of customers at account opening using documentary or non-documentary methods.
- CIP policy
- Sample identification records
- Vendor verification reports
- No documented non-documentary method
- CIP exceptions undocumented
Institutions shall conduct risk-based CDD to understand the nature and purpose of customer relationships and develop customer risk profiles.
- CDD policy
- Risk scoring methodology
- Sample customer files
- Risk profiles not refreshed
- Source of funds not captured
For legal entity customers, institutions shall identify and verify beneficial owners (25 percent ownership) and one control person.
- Beneficial ownership certification forms
- UBO verification records
- Renewal procedures on trigger events
- Old customers not back-filled
- Verification only documentary
Enhanced due diligence shall be applied to higher-risk customers including PEPs, foreign correspondents and private banking accounts.
- EDD policy
- PEP screening reports
- Senior approval for high-risk onboarding
- PEP refresh not periodic
- No senior approval logged
Covered financial institutions must identify and verify the identity of beneficial owners of legal entity customers at account opening. A beneficial owner is each individual owning 25% or more of equity interests, and a single individual with significant control (31 CFR 1010.230).
- AML program documentation
- KYC and CDD records
- Transaction monitoring scenarios and tuning
- SAR/STR filing register
- Independent AML audit reports
- Beneficial ownership data incomplete
- Monitoring scenarios not tuned to risk
- SAR filing delays
- Independent testing missing
Institutions must verify the identity of each beneficial owner according to risk-based procedures comparable to CIP verification (31 CFR 1010.230(b)).
- AML program documentation
- KYC and CDD records
- Transaction monitoring scenarios and tuning
- SAR/STR filing register
- Independent AML audit reports
- Beneficial ownership data incomplete
- Monitoring scenarios not tuned to risk
- SAR filing delays
- Independent testing missing
Financial institutions must develop a customer risk profile for each customer, understanding the nature and purpose of the customer relationship. Risk profiles guide ongoing monitoring.
- Registration certificate copies
- Filing submission evidence
- Renewal calendar
- Public register screenshots
- Registration fee payment records
- Renewals tracked informally
- Filings missed on minor updates
- Certificates not centrally stored
- Public register entries inconsistent
Higher-risk customers (PEPs, foreign correspondents, private banking) require enhanced due diligence including additional information collection, source of funds/wealth, senior management approval, and enhanced ongoing monitoring (31 U.S.C. 5318(i), 31 CFR 1010.610, 1010.620).
- AML program documentation
- KYC and CDD records
- Transaction monitoring scenarios and tuning
- SAR/STR filing register
- Independent AML audit reports
- Beneficial ownership data incomplete
- Monitoring scenarios not tuned to risk
- SAR filing delays
- Independent testing missing
Banks must implement a written CIP appropriate for their size and type, which must include procedures for obtaining minimum identifying information from each customer opening an account: name, date of birth, address, and identification number (SSN or TIN) (31 CFR 1020.220).
- Policy referencing the control
- Documented procedure
- Evidence of operating effectiveness
- Monitoring or review reports
- Roles and responsibilities mapping
- Policy not aligned to control statement
- Procedure undocumented
- No periodic monitoring
- Evidence not retained
Banks must have risk-based procedures for verifying the identity of each customer within a reasonable time after account opening, using documents, non-documentary methods, or a combination (31 CFR 1020.220(a)(2)).
- Access control policy and standard
- Joiner/mover/leaver workflow records
- Role and entitlement matrix
- Quarterly access review attestations
- MFA enrolment and exception register
- Stale or dormant accounts not deprovisioned
- Shared or generic accounts retained
- MFA not enforced for privileged or remote access
- Access reviews skipped or rubber-stamped
Banks must retain identifying information for five years after the account is closed and retain verification records for five years after the record is made (31 CFR 1020.220(a)(3)).
- Records retention schedule
- Records inventory
- Legal hold register
- Disposal certificates
- Records management policy
- Retention schedule outdated
- Records inventory incomplete
- Legal holds not lifted on closure
- Disposal not certified
Enforcement
It is illegal for any person to structure or assist in structuring any transaction with a financial institution to evade CTR filing requirements. Banks must be alert to and report suspected structuring (31 U.S.C. 5324).
- Ofcom information request response register and disclosure logs
- Enforcement notice tracking and remediation plans
- Inspection readiness pack including evidence index and document custodians
- Penalty exposure assessment and board reporting on regulatory risk
- Records retention policy aligned to Section 105I evidence preservation
- Inspection evidence stored across disparate systems with no single index
- Ofcom information requests not logged with response timings
- Penalty risk not modelled at the Tier obligation level
- Director accountability mapping for Section 105A duty incomplete
Willful violations of BSA requirements can result in civil money penalties. For negligent violations, penalties can be up to $500 per violation. For willful violations, penalties can be the greater of $25,000 or the amount involved (up to $100,000) (31 U.S.C. 5321).
- Ofcom information request response register and disclosure logs
- Enforcement notice tracking and remediation plans
- Inspection readiness pack including evidence index and document custodians
- Penalty exposure assessment and board reporting on regulatory risk
- Records retention policy aligned to Section 105I evidence preservation
- Inspection evidence stored across disparate systems with no single index
- Ofcom information requests not logged with response timings
- Penalty risk not modelled at the Tier obligation level
- Director accountability mapping for Section 105A duty incomplete
Willful violations of BSA requirements can result in criminal penalties including fines up to $250,000 and imprisonment up to five years; if part of a pattern, fines up to $500,000 and imprisonment up to 10 years (31 U.S.C. 5322).
- Ofcom information request response register and disclosure logs
- Enforcement notice tracking and remediation plans
- Inspection readiness pack including evidence index and document custodians
- Penalty exposure assessment and board reporting on regulatory risk
- Records retention policy aligned to Section 105I evidence preservation
- Inspection evidence stored across disparate systems with no single index
- Ofcom information requests not logged with response timings
- Penalty risk not modelled at the Tier obligation level
- Director accountability mapping for Section 105A duty incomplete
High-Risk Relationships
Foreign correspondent accounts shall undergo enhanced due diligence including assessing AML controls of the respondent bank.
- Wolfsberg questionnaires
- Respondent AML programme reviews
- Senior approval
- No annual refresh
- Nested relationships not identified
Private banking accounts for non-US persons shall be subject to enhanced scrutiny including source of funds and PEP determination.
- Source of wealth/funds documentation
- PEP screening
- Relationship manager attestations
- Source of wealth not corroborated
- PEP refresh missed
Information Sharing
Institutions shall respond to FinCEN 314(a) requests by searching records for matches to subjects of money laundering or terrorism investigations.
- 314(a) point of contact registration
- Search logs
- Match handling procedures
- POC outdated
- No documented searches
Institutions may share information with other registered institutions under 314(b) safe harbour for purposes of identifying and reporting suspicious activity.
- 314(b) registration
- Information sharing logs
- Confidentiality controls
- Sharing outside permitted scope
- No annual renewal
Section 314(a) of the USA PATRIOT Act enables FinCEN to require financial institutions to search records for accounts matching subjects of investigations. Section 314(b) provides a voluntary sharing mechanism between institutions and law enforcement (31 CFR 1010.520, 1010.540).
- Records retention schedule
- Records inventory
- Legal hold register
- Disposal certificates
- Records management policy
- Retention schedule outdated
- Records inventory incomplete
- Legal holds not lifted on closure
- Disposal not certified
Monitoring and Risk
Automated and manual transaction monitoring shall identify unusual or suspicious activity using risk-based scenarios and thresholds.
- TM scenario inventory
- Threshold tuning documentation
- Above-the-line/below-the-line testing
- Model validation reports
- No model validation
- Scenarios not aligned to risk assessment
An institution-wide AML risk assessment shall consider products, services, customers, geographies and delivery channels and inform programme calibration.
- Enterprise AML risk assessment
- Inherent and residual risk ratings
- Refresh cadence
- Outdated assessment
- Not linked to TM scenarios
Recordkeeping
Records of sales of monetary instruments (e.g., money orders, cashier checks) between USD 3,000 and USD 10,000 shall be retained.
- MI sale logs
- ID verification records
- Incomplete records
- Aggregation across products missing
Originator and beneficiary information shall be collected, retained and transmitted for funds transfers of USD 3,000 or more.
- Wire transfer system logs
- Originator/beneficiary fields
- Retention evidence
- Truncated fields in correspondent leg
- Sub-threshold structuring undetected
BSA records (CIP, CDD, SAR, CTR, wire records) shall be retained for at least five years and produced upon lawful request.
- Records retention schedule
- Legal hold procedures
- Sample retrieval test
- Retention shorter than 5 years
- No legal hold integration
Banks must collect, retain, and transmit certain information relating to funds transfers of $3,000 or more, including originator name, address, account number, and amount (31 CFR 1010.410(e)).
- Transfer impact assessment documents
- Standard contractual clauses register
- Binding corporate rules approval
- Adequacy decision references
- Vendor transfer mapping
- No transfer impact assessment performed
- SCCs not updated to current versions
- Sub-processor transfers untracked
- Reliance on adequacy without supplementary measures
Records must be maintained for purchases of monetary instruments (cashier's checks, money orders, traveler's checks) in amounts between $3,000 and $10,000 inclusive (31 CFR 1010.415).
- Records retention schedule
- Records inventory
- Legal hold register
- Disposal certificates
- Records management policy
- Retention schedule outdated
- Records inventory incomplete
- Legal holds not lifted on closure
- Disposal not certified
U.S. persons with a financial interest in or signature authority over foreign financial accounts exceeding $10,000 at any time during the calendar year must file FinCEN Form 114 by April 15 (31 CFR 1010.350).
- AML program documentation
- KYC and CDD records
- Transaction monitoring scenarios and tuning
- SAR/STR filing register
- Independent AML audit reports
- Beneficial ownership data incomplete
- Monitoring scenarios not tuned to risk
- SAR filing delays
- Independent testing missing
Reporting
Institutions shall file SARs with FinCEN within 30 days of detection (or 60 if no subject identified) for transactions meeting reporting thresholds and indicia.
- SAR filing logs
- Investigation case files
- SAR decisioning memos
- Continuing activity reviews
- Late filings
- No documented no-file rationale
Cash transactions over USD 10,000 in a single business day involving the same person shall be reported on FinCEN Form 112 within 15 days.
- CTR filing logs
- Aggregation logic documentation
- Sample filed forms
- No aggregation across branches
- Late filings
Exemptions from CTR filing for eligible Phase I and Phase II customers shall be documented and reviewed annually.
- DOEP filings
- Annual exemption reviews
- Designation memos
- No annual review
- Ineligible customers exempted
Reporting companies shall file beneficial ownership information with FinCEN under the Corporate Transparency Act, and institutions may use FinCEN BOI access where authorised.
- BOI access policy
- Customer consent records
- Authorisation logs
- No BOI access workflow
- Consent not obtained
File a CTR (FinCEN Form 112) for each transaction in currency of more than $10,000 conducted by or on behalf of one person in a single business day. Multiple transactions must be aggregated (31 CFR 1010.311, 1020.315).
- Sample SMR submissions with AUSTRAC acknowledgements
- TTR exception reports and filing evidence
- IFTI submission logs (sending and receiving)
- Annual AML/CTF Compliance Report sign-off and submission
- Tipping-off training records and acknowledgements
- ML/TF risk assessment not refreshed annually
- Independent review overdue or scope-limited
- Transaction monitoring scenarios untuned to risk profile
- Beneficial ownership records incomplete
- PEP screening false positive tuning inadequate
CTRs must be filed within 15 calendar days following the day of the reportable transaction. Filed electronically with FinCEN via the BSA E-Filing System.
- Sample SMR submissions with AUSTRAC acknowledgements
- TTR exception reports and filing evidence
- IFTI submission logs (sending and receiving)
- Annual AML/CTF Compliance Report sign-off and submission
- Tipping-off training records and acknowledgements
- ML/TF risk assessment not refreshed annually
- Independent review overdue or scope-limited
- Transaction monitoring scenarios untuned to risk profile
- Beneficial ownership records incomplete
- PEP screening false positive tuning inadequate
Banks must file a SAR (FinCEN Form 111) for any transaction involving $5,000 or more when the bank knows, suspects, or has reason to suspect the transaction involves funds from illegal activity, is designed to evade BSA requirements, or has no business or apparent lawful purpose (31 CFR 1020.320(a)(2)).
- Sample SMR submissions with AUSTRAC acknowledgements
- TTR exception reports and filing evidence
- IFTI submission logs (sending and receiving)
- Annual AML/CTF Compliance Report sign-off and submission
- Tipping-off training records and acknowledgements
- ML/TF risk assessment not refreshed annually
- Independent review overdue or scope-limited
- Transaction monitoring scenarios untuned to risk profile
- Beneficial ownership records incomplete
- PEP screening false positive tuning inadequate
SARs must be filed no later than 30 calendar days after the date of initial detection. If no suspect is identified, an additional 30 days is permitted (maximum 60 days total) (31 CFR 1020.320(b)(3)).
- Sample SMR submissions with AUSTRAC acknowledgements
- TTR exception reports and filing evidence
- IFTI submission logs (sending and receiving)
- Annual AML/CTF Compliance Report sign-off and submission
- Tipping-off training records and acknowledgements
- ML/TF risk assessment not refreshed annually
- Independent review overdue or scope-limited
- Transaction monitoring scenarios untuned to risk profile
- Beneficial ownership records incomplete
- PEP screening false positive tuning inadequate
SARs and any information that would reveal the existence of a SAR are strictly confidential. No financial institution or employee may notify any person involved in the transaction that a SAR has been filed (31 U.S.C. 5318(g)(2)).
- Sample SMR submissions with AUSTRAC acknowledgements
- TTR exception reports and filing evidence
- IFTI submission logs (sending and receiving)
- Annual AML/CTF Compliance Report sign-off and submission
- Tipping-off training records and acknowledgements
- ML/TF risk assessment not refreshed annually
- Independent review overdue or scope-limited
- Transaction monitoring scenarios untuned to risk profile
- Beneficial ownership records incomplete
- PEP screening false positive tuning inadequate
Banks must maintain a copy of any SAR filed and the original or business record equivalent of any supporting documentation for five years from the date of filing (31 CFR 1020.320(d)).
- Sample SMR submissions with AUSTRAC acknowledgements
- TTR exception reports and filing evidence
- IFTI submission logs (sending and receiving)
- Annual AML/CTF Compliance Report sign-off and submission
- Tipping-off training records and acknowledgements
- ML/TF risk assessment not refreshed annually
- Independent review overdue or scope-limited
- Transaction monitoring scenarios untuned to risk profile
- Beneficial ownership records incomplete
- PEP screening false positive tuning inadequate
Sanctions and Special Measures
Institutions shall screen customers, beneficial owners, counterparties and transactions against OFAC and other applicable sanctions lists in real time.
- Screening engine config
- List update cadence
- Blocked/rejected transaction reports
- OFAC annual reports
- List updates lag
- No fuzzy matching tuning
Institutions shall implement FinCEN Section 311 special measures against jurisdictions, institutions or transactions of primary money laundering concern.
- 311 designations register
- Account/transaction restrictions evidence
- No process to ingest new 311 measures
- Restrictions not enforced
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.