Skip to content

Evidence request lists

Bank Secrecy Act / Anti-Money Laundering (BSA/AML)

Evidence request list. 44 controls, 44 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

AML Compliance Program

BSA-AML-01
AML Compliance Programme

Financial institutions shall establish a written AML compliance programme approved by the board, with policies, procedures, internal controls and ongoing oversight under 31 CFR 1020.210.

Artefacts an auditor will ask for
  • AML programme document
  • Board resolution approving programme
  • Annual programme review
Where this commonly fails
  • No board minutes evidencing approval
  • Programme not refreshed annually
BSA-AML-02
BSA Compliance Officer

A qualified individual shall be designated as BSA Compliance Officer with authority, independence and resources to administer the AML programme.

Artefacts an auditor will ask for
  • BSA Officer appointment letter
  • Job description
  • Reporting line to board/committee
Where this commonly fails
  • BSA Officer reports to business line
  • No documented authority
BSA-AML-03
Independent Testing

The AML programme shall be subject to independent testing by qualified internal or external parties on a risk-based cadence.

Artefacts an auditor will ask for
  • Independent AML audit reports
  • Audit charter
  • Remediation tracker
Where this commonly fails
  • Testing performed by AML function itself
  • Findings unresolved
BSA-AML-04
AML Training

All appropriate personnel shall receive AML training tailored to their role and updated to reflect regulatory and typology changes.

Artefacts an auditor will ask for
  • Training curriculum
  • Completion records by role
  • Board AML briefing materials
Where this commonly fails
  • Front-line staff not trained on red flags
  • No role-based curriculum
BSA-AML-24
AML Programme Effectiveness (AMLA 2020)

Programmes shall be effective, risk-based and reasonably designed to assure compliance, considering FinCEN AML/CFT priorities as required by AMLA 2020.

Artefacts an auditor will ask for
  • Mapping of programme to FinCEN AML/CFT priorities
  • Effectiveness metrics
  • Board reporting on priorities
Where this commonly fails
  • FinCEN priorities not yet incorporated
  • No effectiveness metrics defined

Customer Identification and Due Diligence

BSA-AML-05
Customer Identification Program (CIP)

Institutions shall implement a CIP to verify the identity of customers at account opening using documentary or non-documentary methods.

Artefacts an auditor will ask for
  • CIP policy
  • Sample identification records
  • Vendor verification reports
Where this commonly fails
  • No documented non-documentary method
  • CIP exceptions undocumented
BSA-AML-06
Customer Due Diligence (CDD)

Institutions shall conduct risk-based CDD to understand the nature and purpose of customer relationships and develop customer risk profiles.

Artefacts an auditor will ask for
  • CDD policy
  • Risk scoring methodology
  • Sample customer files
Where this commonly fails
  • Risk profiles not refreshed
  • Source of funds not captured
BSA-AML-07
Beneficial Ownership Identification

For legal entity customers, institutions shall identify and verify beneficial owners (25 percent ownership) and one control person.

Artefacts an auditor will ask for
  • Beneficial ownership certification forms
  • UBO verification records
  • Renewal procedures on trigger events
Where this commonly fails
  • Old customers not back-filled
  • Verification only documentary
BSA-AML-08
Enhanced Due Diligence (EDD)

Enhanced due diligence shall be applied to higher-risk customers including PEPs, foreign correspondents and private banking accounts.

Artefacts an auditor will ask for
  • EDD policy
  • PEP screening reports
  • Senior approval for high-risk onboarding
Where this commonly fails
  • PEP refresh not periodic
  • No senior approval logged
BSA-CDD-1
Beneficial Ownership Identification

Covered financial institutions must identify and verify the identity of beneficial owners of legal entity customers at account opening. A beneficial owner is each individual owning 25% or more of equity interests, and a single individual with significant control (31 CFR 1010.230).

Artefacts an auditor will ask for
  • AML program documentation
  • KYC and CDD records
  • Transaction monitoring scenarios and tuning
  • SAR/STR filing register
  • Independent AML audit reports
Where this commonly fails
  • Beneficial ownership data incomplete
  • Monitoring scenarios not tuned to risk
  • SAR filing delays
  • Independent testing missing
BSA-CDD-2
Beneficial Ownership Verification

Institutions must verify the identity of each beneficial owner according to risk-based procedures comparable to CIP verification (31 CFR 1010.230(b)).

Artefacts an auditor will ask for
  • AML program documentation
  • KYC and CDD records
  • Transaction monitoring scenarios and tuning
  • SAR/STR filing register
  • Independent AML audit reports
Where this commonly fails
  • Beneficial ownership data incomplete
  • Monitoring scenarios not tuned to risk
  • SAR filing delays
  • Independent testing missing
BSA-CDD-3
Customer Risk Profiling

Financial institutions must develop a customer risk profile for each customer, understanding the nature and purpose of the customer relationship. Risk profiles guide ongoing monitoring.

Artefacts an auditor will ask for
  • Registration certificate copies
  • Filing submission evidence
  • Renewal calendar
  • Public register screenshots
  • Registration fee payment records
Where this commonly fails
  • Renewals tracked informally
  • Filings missed on minor updates
  • Certificates not centrally stored
  • Public register entries inconsistent
BSA-CDD-4
Enhanced Due Diligence (EDD)

Higher-risk customers (PEPs, foreign correspondents, private banking) require enhanced due diligence including additional information collection, source of funds/wealth, senior management approval, and enhanced ongoing monitoring (31 U.S.C. 5318(i), 31 CFR 1010.610, 1010.620).

Artefacts an auditor will ask for
  • AML program documentation
  • KYC and CDD records
  • Transaction monitoring scenarios and tuning
  • SAR/STR filing register
  • Independent AML audit reports
Where this commonly fails
  • Beneficial ownership data incomplete
  • Monitoring scenarios not tuned to risk
  • SAR filing delays
  • Independent testing missing
BSA-CIP-1
Customer Identification Program (CIP)

Banks must implement a written CIP appropriate for their size and type, which must include procedures for obtaining minimum identifying information from each customer opening an account: name, date of birth, address, and identification number (SSN or TIN) (31 CFR 1020.220).

Artefacts an auditor will ask for
  • Policy referencing the control
  • Documented procedure
  • Evidence of operating effectiveness
  • Monitoring or review reports
  • Roles and responsibilities mapping
Where this commonly fails
  • Policy not aligned to control statement
  • Procedure undocumented
  • No periodic monitoring
  • Evidence not retained
BSA-CIP-2
Identity Verification

Banks must have risk-based procedures for verifying the identity of each customer within a reasonable time after account opening, using documents, non-documentary methods, or a combination (31 CFR 1020.220(a)(2)).

Artefacts an auditor will ask for
  • Access control policy and standard
  • Joiner/mover/leaver workflow records
  • Role and entitlement matrix
  • Quarterly access review attestations
  • MFA enrolment and exception register
Where this commonly fails
  • Stale or dormant accounts not deprovisioned
  • Shared or generic accounts retained
  • MFA not enforced for privileged or remote access
  • Access reviews skipped or rubber-stamped
BSA-CIP-3
CIP Recordkeeping

Banks must retain identifying information for five years after the account is closed and retain verification records for five years after the record is made (31 CFR 1020.220(a)(3)).

Artefacts an auditor will ask for
  • Records retention schedule
  • Records inventory
  • Legal hold register
  • Disposal certificates
  • Records management policy
Where this commonly fails
  • Retention schedule outdated
  • Records inventory incomplete
  • Legal holds not lifted on closure
  • Disposal not certified

Enforcement

BSA-ENF-1
Anti-Structuring Prohibition

It is illegal for any person to structure or assist in structuring any transaction with a financial institution to evade CTR filing requirements. Banks must be alert to and report suspected structuring (31 U.S.C. 5324).

Artefacts an auditor will ask for
  • Ofcom information request response register and disclosure logs
  • Enforcement notice tracking and remediation plans
  • Inspection readiness pack including evidence index and document custodians
  • Penalty exposure assessment and board reporting on regulatory risk
  • Records retention policy aligned to Section 105I evidence preservation
Where this commonly fails
  • Inspection evidence stored across disparate systems with no single index
  • Ofcom information requests not logged with response timings
  • Penalty risk not modelled at the Tier obligation level
  • Director accountability mapping for Section 105A duty incomplete
BSA-ENF-2
Civil Money Penalties

Willful violations of BSA requirements can result in civil money penalties. For negligent violations, penalties can be up to $500 per violation. For willful violations, penalties can be the greater of $25,000 or the amount involved (up to $100,000) (31 U.S.C. 5321).

Artefacts an auditor will ask for
  • Ofcom information request response register and disclosure logs
  • Enforcement notice tracking and remediation plans
  • Inspection readiness pack including evidence index and document custodians
  • Penalty exposure assessment and board reporting on regulatory risk
  • Records retention policy aligned to Section 105I evidence preservation
Where this commonly fails
  • Inspection evidence stored across disparate systems with no single index
  • Ofcom information requests not logged with response timings
  • Penalty risk not modelled at the Tier obligation level
  • Director accountability mapping for Section 105A duty incomplete
BSA-ENF-3
Criminal Penalties

Willful violations of BSA requirements can result in criminal penalties including fines up to $250,000 and imprisonment up to five years; if part of a pattern, fines up to $500,000 and imprisonment up to 10 years (31 U.S.C. 5322).

Artefacts an auditor will ask for
  • Ofcom information request response register and disclosure logs
  • Enforcement notice tracking and remediation plans
  • Inspection readiness pack including evidence index and document custodians
  • Penalty exposure assessment and board reporting on regulatory risk
  • Records retention policy aligned to Section 105I evidence preservation
Where this commonly fails
  • Inspection evidence stored across disparate systems with no single index
  • Ofcom information requests not logged with response timings
  • Penalty risk not modelled at the Tier obligation level
  • Director accountability mapping for Section 105A duty incomplete

High-Risk Relationships

BSA-AML-17
Correspondent Account Due Diligence

Foreign correspondent accounts shall undergo enhanced due diligence including assessing AML controls of the respondent bank.

Artefacts an auditor will ask for
  • Wolfsberg questionnaires
  • Respondent AML programme reviews
  • Senior approval
Where this commonly fails
  • No annual refresh
  • Nested relationships not identified
BSA-AML-18
Private Banking Due Diligence

Private banking accounts for non-US persons shall be subject to enhanced scrutiny including source of funds and PEP determination.

Artefacts an auditor will ask for
  • Source of wealth/funds documentation
  • PEP screening
  • Relationship manager attestations
Where this commonly fails
  • Source of wealth not corroborated
  • PEP refresh missed

Information Sharing

BSA-AML-19
Information Sharing 314(a)

Institutions shall respond to FinCEN 314(a) requests by searching records for matches to subjects of money laundering or terrorism investigations.

Artefacts an auditor will ask for
  • 314(a) point of contact registration
  • Search logs
  • Match handling procedures
Where this commonly fails
  • POC outdated
  • No documented searches
BSA-AML-20
Voluntary Information Sharing 314(b)

Institutions may share information with other registered institutions under 314(b) safe harbour for purposes of identifying and reporting suspicious activity.

Artefacts an auditor will ask for
  • 314(b) registration
  • Information sharing logs
  • Confidentiality controls
Where this commonly fails
  • Sharing outside permitted scope
  • No annual renewal
BSA-REC-4
Information Sharing (Section 314)

Section 314(a) of the USA PATRIOT Act enables FinCEN to require financial institutions to search records for accounts matching subjects of investigations. Section 314(b) provides a voluntary sharing mechanism between institutions and law enforcement (31 CFR 1010.520, 1010.540).

Artefacts an auditor will ask for
  • Records retention schedule
  • Records inventory
  • Legal hold register
  • Disposal certificates
  • Records management policy
Where this commonly fails
  • Retention schedule outdated
  • Records inventory incomplete
  • Legal holds not lifted on closure
  • Disposal not certified

Monitoring and Risk

BSA-AML-15
Transaction Monitoring

Automated and manual transaction monitoring shall identify unusual or suspicious activity using risk-based scenarios and thresholds.

Artefacts an auditor will ask for
  • TM scenario inventory
  • Threshold tuning documentation
  • Above-the-line/below-the-line testing
  • Model validation reports
Where this commonly fails
  • No model validation
  • Scenarios not aligned to risk assessment
BSA-AML-16
AML Risk Assessment

An institution-wide AML risk assessment shall consider products, services, customers, geographies and delivery channels and inform programme calibration.

Artefacts an auditor will ask for
  • Enterprise AML risk assessment
  • Inherent and residual risk ratings
  • Refresh cadence
Where this commonly fails
  • Outdated assessment
  • Not linked to TM scenarios

Recordkeeping

BSA-AML-12
Monetary Instrument Recordkeeping

Records of sales of monetary instruments (e.g., money orders, cashier checks) between USD 3,000 and USD 10,000 shall be retained.

Artefacts an auditor will ask for
  • MI sale logs
  • ID verification records
Where this commonly fails
  • Incomplete records
  • Aggregation across products missing
BSA-AML-13
Funds Transfer Recordkeeping (Travel Rule)

Originator and beneficiary information shall be collected, retained and transmitted for funds transfers of USD 3,000 or more.

Artefacts an auditor will ask for
  • Wire transfer system logs
  • Originator/beneficiary fields
  • Retention evidence
Where this commonly fails
  • Truncated fields in correspondent leg
  • Sub-threshold structuring undetected
BSA-AML-21
Recordkeeping and Retention

BSA records (CIP, CDD, SAR, CTR, wire records) shall be retained for at least five years and produced upon lawful request.

Artefacts an auditor will ask for
  • Records retention schedule
  • Legal hold procedures
  • Sample retrieval test
Where this commonly fails
  • Retention shorter than 5 years
  • No legal hold integration
BSA-REC-1
Funds Transfer Recordkeeping (Travel Rule)

Banks must collect, retain, and transmit certain information relating to funds transfers of $3,000 or more, including originator name, address, account number, and amount (31 CFR 1010.410(e)).

Artefacts an auditor will ask for
  • Transfer impact assessment documents
  • Standard contractual clauses register
  • Binding corporate rules approval
  • Adequacy decision references
  • Vendor transfer mapping
Where this commonly fails
  • No transfer impact assessment performed
  • SCCs not updated to current versions
  • Sub-processor transfers untracked
  • Reliance on adequacy without supplementary measures
BSA-REC-2
Monetary Instrument Purchase Records

Records must be maintained for purchases of monetary instruments (cashier's checks, money orders, traveler's checks) in amounts between $3,000 and $10,000 inclusive (31 CFR 1010.415).

Artefacts an auditor will ask for
  • Records retention schedule
  • Records inventory
  • Legal hold register
  • Disposal certificates
  • Records management policy
Where this commonly fails
  • Retention schedule outdated
  • Records inventory incomplete
  • Legal holds not lifted on closure
  • Disposal not certified
BSA-REC-3
Foreign Bank Account Reporting (FBAR)

U.S. persons with a financial interest in or signature authority over foreign financial accounts exceeding $10,000 at any time during the calendar year must file FinCEN Form 114 by April 15 (31 CFR 1010.350).

Artefacts an auditor will ask for
  • AML program documentation
  • KYC and CDD records
  • Transaction monitoring scenarios and tuning
  • SAR/STR filing register
  • Independent AML audit reports
Where this commonly fails
  • Beneficial ownership data incomplete
  • Monitoring scenarios not tuned to risk
  • SAR filing delays
  • Independent testing missing

Reporting

BSA-AML-09
Suspicious Activity Reporting (SAR)

Institutions shall file SARs with FinCEN within 30 days of detection (or 60 if no subject identified) for transactions meeting reporting thresholds and indicia.

Artefacts an auditor will ask for
  • SAR filing logs
  • Investigation case files
  • SAR decisioning memos
  • Continuing activity reviews
Where this commonly fails
  • Late filings
  • No documented no-file rationale
BSA-AML-10
Currency Transaction Reporting (CTR)

Cash transactions over USD 10,000 in a single business day involving the same person shall be reported on FinCEN Form 112 within 15 days.

Artefacts an auditor will ask for
  • CTR filing logs
  • Aggregation logic documentation
  • Sample filed forms
Where this commonly fails
  • No aggregation across branches
  • Late filings
BSA-AML-11
CTR Exemptions

Exemptions from CTR filing for eligible Phase I and Phase II customers shall be documented and reviewed annually.

Artefacts an auditor will ask for
  • DOEP filings
  • Annual exemption reviews
  • Designation memos
Where this commonly fails
  • No annual review
  • Ineligible customers exempted
BSA-AML-22
Beneficial Ownership Reporting (Corporate Transparency Act)

Reporting companies shall file beneficial ownership information with FinCEN under the Corporate Transparency Act, and institutions may use FinCEN BOI access where authorised.

Artefacts an auditor will ask for
  • BOI access policy
  • Customer consent records
  • Authorisation logs
Where this commonly fails
  • No BOI access workflow
  • Consent not obtained
BSA-CTR-1
Currency Transaction Reports

File a CTR (FinCEN Form 112) for each transaction in currency of more than $10,000 conducted by or on behalf of one person in a single business day. Multiple transactions must be aggregated (31 CFR 1010.311, 1020.315).

Artefacts an auditor will ask for
  • Sample SMR submissions with AUSTRAC acknowledgements
  • TTR exception reports and filing evidence
  • IFTI submission logs (sending and receiving)
  • Annual AML/CTF Compliance Report sign-off and submission
  • Tipping-off training records and acknowledgements
Where this commonly fails
  • ML/TF risk assessment not refreshed annually
  • Independent review overdue or scope-limited
  • Transaction monitoring scenarios untuned to risk profile
  • Beneficial ownership records incomplete
  • PEP screening false positive tuning inadequate
BSA-CTR-2
CTR Filing Deadline

CTRs must be filed within 15 calendar days following the day of the reportable transaction. Filed electronically with FinCEN via the BSA E-Filing System.

Artefacts an auditor will ask for
  • Sample SMR submissions with AUSTRAC acknowledgements
  • TTR exception reports and filing evidence
  • IFTI submission logs (sending and receiving)
  • Annual AML/CTF Compliance Report sign-off and submission
  • Tipping-off training records and acknowledgements
Where this commonly fails
  • ML/TF risk assessment not refreshed annually
  • Independent review overdue or scope-limited
  • Transaction monitoring scenarios untuned to risk profile
  • Beneficial ownership records incomplete
  • PEP screening false positive tuning inadequate
BSA-SAR-1
Suspicious Activity Reports - Threshold

Banks must file a SAR (FinCEN Form 111) for any transaction involving $5,000 or more when the bank knows, suspects, or has reason to suspect the transaction involves funds from illegal activity, is designed to evade BSA requirements, or has no business or apparent lawful purpose (31 CFR 1020.320(a)(2)).

Artefacts an auditor will ask for
  • Sample SMR submissions with AUSTRAC acknowledgements
  • TTR exception reports and filing evidence
  • IFTI submission logs (sending and receiving)
  • Annual AML/CTF Compliance Report sign-off and submission
  • Tipping-off training records and acknowledgements
Where this commonly fails
  • ML/TF risk assessment not refreshed annually
  • Independent review overdue or scope-limited
  • Transaction monitoring scenarios untuned to risk profile
  • Beneficial ownership records incomplete
  • PEP screening false positive tuning inadequate
BSA-SAR-2
SAR Filing Deadline

SARs must be filed no later than 30 calendar days after the date of initial detection. If no suspect is identified, an additional 30 days is permitted (maximum 60 days total) (31 CFR 1020.320(b)(3)).

Artefacts an auditor will ask for
  • Sample SMR submissions with AUSTRAC acknowledgements
  • TTR exception reports and filing evidence
  • IFTI submission logs (sending and receiving)
  • Annual AML/CTF Compliance Report sign-off and submission
  • Tipping-off training records and acknowledgements
Where this commonly fails
  • ML/TF risk assessment not refreshed annually
  • Independent review overdue or scope-limited
  • Transaction monitoring scenarios untuned to risk profile
  • Beneficial ownership records incomplete
  • PEP screening false positive tuning inadequate
BSA-SAR-3
SAR Confidentiality

SARs and any information that would reveal the existence of a SAR are strictly confidential. No financial institution or employee may notify any person involved in the transaction that a SAR has been filed (31 U.S.C. 5318(g)(2)).

Artefacts an auditor will ask for
  • Sample SMR submissions with AUSTRAC acknowledgements
  • TTR exception reports and filing evidence
  • IFTI submission logs (sending and receiving)
  • Annual AML/CTF Compliance Report sign-off and submission
  • Tipping-off training records and acknowledgements
Where this commonly fails
  • ML/TF risk assessment not refreshed annually
  • Independent review overdue or scope-limited
  • Transaction monitoring scenarios untuned to risk profile
  • Beneficial ownership records incomplete
  • PEP screening false positive tuning inadequate
BSA-SAR-4
SAR Recordkeeping

Banks must maintain a copy of any SAR filed and the original or business record equivalent of any supporting documentation for five years from the date of filing (31 CFR 1020.320(d)).

Artefacts an auditor will ask for
  • Sample SMR submissions with AUSTRAC acknowledgements
  • TTR exception reports and filing evidence
  • IFTI submission logs (sending and receiving)
  • Annual AML/CTF Compliance Report sign-off and submission
  • Tipping-off training records and acknowledgements
Where this commonly fails
  • ML/TF risk assessment not refreshed annually
  • Independent review overdue or scope-limited
  • Transaction monitoring scenarios untuned to risk profile
  • Beneficial ownership records incomplete
  • PEP screening false positive tuning inadequate

Sanctions and Special Measures

BSA-AML-14
OFAC Sanctions Screening

Institutions shall screen customers, beneficial owners, counterparties and transactions against OFAC and other applicable sanctions lists in real time.

Artefacts an auditor will ask for
  • Screening engine config
  • List update cadence
  • Blocked/rejected transaction reports
  • OFAC annual reports
Where this commonly fails
  • List updates lag
  • No fuzzy matching tuning
BSA-AML-23
Section 311 Special Measures

Institutions shall implement FinCEN Section 311 special measures against jurisdictions, institutions or transactions of primary money laundering concern.

Artefacts an auditor will ask for
  • 311 designations register
  • Account/transaction restrictions evidence
Where this commonly fails
  • No process to ingest new 311 measures
  • Restrictions not enforced
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.