Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

BSA AML Compliance

Bank Secrecy Act & Anti-Money Laundering — How IT Controls Support Financial Crime Compliance

lbttechgroup.com · +1 (916) 333-1062 · Sacramento, California · Veteran-Owned

WHAT ARE BSA & AML?

Anti-money laundering compliance runs on the same infrastructure as cybersecurity.

The Bank Secrecy Act (BSA), enacted in 1970 and substantially amended by the USA PATRIOT Act and the Anti-Money Laundering Act of 2020, is the primary U.S. federal law governing financial institutions’ obligations to detect, report, and prevent money laundering and other financial crimes. Anti-Money Laundering (AML) programs are the operational implementation of BSA requirements — the policies, procedures, controls, and monitoring systems that financial institutions maintain to identify suspicious activity and report it to the Financial Crimes Enforcement Network (FinCEN).

For Sacramento-area financial services firms — mortgage lenders, independent financial advisors, insurance agencies, check cashing services, and money services businesses — BSA/AML compliance is directly dependent on IT infrastructure. Transaction monitoring, customer due diligence (CDD), suspicious activity reporting (SAR), and recordkeeping are technology-dependent functions. An IT provider that manages the systems on which these functions run is embedded in the BSA/AML compliance architecture, whether or not either party recognizes it.

FinCEN

federal enforcement authority

$10K+

reporting threshold for CTRs

5 years

BSA recordkeeping requirement

$280B+

AML fines in the US 2008–2023

WHO MUST COMPLY

BSA applies to far more businesses than ‘banks.’

The BSA defines ‘financial institution’ broadly — far beyond traditional banking. Sacramento businesses in the following categories have BSA/AML obligations and must register with FinCEN or maintain a formal AML program:

Business Type

BSA/AML Obligation

Banks, credit unions, and thrifts

Full BSA compliance program required; federal banking regulator (OCC, FDIC, NCUA) examination of AML controls

Mortgage lenders and brokers

BSA reporting obligations including CTRs and SARs; FinCEN registration required for non-depository mortgage companies

Money services businesses (MSBs)

Includes check cashing, money orders, currency exchange, and prepaid access. FinCEN registration required; full AML program.

Insurance companies

BSA applies to certain insurance products (permanent life, annuities). Insurance companies must file SARs for suspicious transactions.

Independent financial advisors / RIAs

FinCEN proposed rules (pending) would extend AML program requirements to investment advisers. Many RIAs voluntarily maintain AML programs.

Casinos

Full BSA compliance program; gaming-specific reporting requirements

Precious metals and jewelry dealers

Cash transactions over $10,000 trigger CTR obligations; SARs required for suspicious transactions regardless of amount

THE FIVE BSA/AML PROGRAM PILLARS

What a compliant AML program must include.

FinCEN requires covered financial institutions to maintain an AML program built on five core pillars. Each pillar has direct technology dependencies that fall within the scope of an MSP’s managed services delivery.

Pillar

IT & Cybersecurity Dependency

1. Internal Controls

Policies and procedures governing transaction monitoring, customer due diligence, and suspicious activity identification. IT systems must be configured to enforce these controls — access restrictions, audit logging, and transaction flagging.

2. Compliance Officer

A designated BSA/AML Compliance Officer responsible for the program. LBT supports the Compliance Officer by providing the system access, logging, and monitoring data they need to perform their oversight function.

3. Training

Annual BSA/AML training for all staff. LBT’s security awareness training program can be coordinated with BSA/AML training delivery to ensure both obligations are met through a unified training calendar.

4. Independent Testing (Audit)

Annual independent testing of the AML program by internal audit or an external third party. Auditors test IT controls — transaction monitoring system configurations, log retention, and access controls — as part of BSA/AML program review.

5. Customer Due Diligence (CDD)

Know Your Customer (KYC) and Customer Due Diligence procedures, including beneficial ownership identification. CDD systems must be secure, access-controlled, and auditable — IT requirements that LBT manages directly.

BSA REPORTING REQUIREMENTS

The filings that create the paper trail regulators examine.

Report

Trigger & Requirement

Currency Transaction Report (CTR)

Required for any cash transaction over $10,000. Must be filed with FinCEN within 15 days. IT systems must flag, record, and track cash transactions to ensure CTR obligations are met.

Suspicious Activity Report (SAR)

Required when the institution knows, suspects, or has reason to suspect a transaction of $5,000 or more involves funds from illegal activity, is designed to evade BSA reporting, or lacks a lawful purpose. Must be filed within 30 days of detection. SARs are confidential — strict IT access controls required.

Foreign Bank Account Report (FBAR)

Required for US persons with foreign financial accounts exceeding $10,000 in aggregate value at any point during the year. Filed with FinCEN annually.

8300 (IRS/FinCEN)

Required for businesses that receive more than $10,000 in cash in a single transaction or related transactions. Filed within 15 days.

SAR Confidentiality Is an IT Security Requirement

The BSA prohibits financial institutions from disclosing to the subject of a SAR that a report has been filed — a requirement known as the ‘tipping off’ prohibition. Violation is a federal crime. This means SAR documentation must be stored in access-controlled, auditable systems where only authorized personnel can view it. An MSP that manages systems containing SAR records must implement access controls that prevent unauthorized personnel — including the subjects of SARs — from accessing this information.

PENALTIES

BSA enforcement is criminal, civil, and reputational.

BSA CIVIL MONEY PENALTY

Up to $1,000,000 per day of violation

FinCEN and federal banking regulators assess civil money penalties per day for systemic BSA/AML program failures. Individual officers and compliance personnel can also face personal liability. Criminal penalties for willful violations include fines and imprisonment.

Enforcement Path

Consequences

FinCEN civil money penalties

Up to $1,000,000 per day for systemic failures; $25,000+ per negligent violation

Federal criminal prosecution

Willful BSA violations: fines up to $250,000 and/or 5 years imprisonment for individuals

Federal banking regulator action

Cease and desist orders, consent orders, removal of officers — OCC, FDIC, NCUA, and CFPB can all act on BSA deficiencies

FinCEN 314(a) non-compliance

Failure to respond to FinCEN 314(a) information requests is a BSA violation in itself — IT systems must be configured to search and respond within the required 2-week window

Reputational consequences

BSA enforcement actions are public. Loss of correspondent banking relationships is a practical consequence that can effectively end a financial firm’s operations

HOW LBT SUPPORTS BSA/AML PROGRAM INFRASTRUCTURE

IT controls that underpin every pillar of an effective AML program.

LBT’s role in BSA/AML compliance is infrastructure and controls — not the legal or regulatory analysis that is the domain of your compliance officer and legal counsel. LBT ensures the IT systems on which AML functions depend are secure, auditable, and operating as your program requires.

✓ Audit Log Management & Retention (5-Year BSA Standard)

BSA requires a 5-year recordkeeping period for most transaction records and reports. LBT’s log management and backup program is configured to meet this retention requirement — ensuring audit trails are available for FinCEN or federal banking regulator examination requests.

✓ SAR System Access Controls

Role-based access controls ensuring only authorized AML compliance personnel can access systems containing SAR filings, SAR-supporting documentation, and related investigation records — satisfying the BSA’s tipping-off prohibition and FinCEN access requirements.

✓ FinCEN 314(a) Response Capability

IT systems configured to enable rapid search of customer records in response to FinCEN 314(a) information requests — which require a response within two weeks of the request posting date. Delayed response is itself a BSA violation.

✓ Transaction Monitoring System Security

Security hardening, access control, and monitoring of transaction monitoring platforms — ensuring the systems that flag suspicious activity are themselves protected from unauthorized access or manipulation.

✓ Customer Due Diligence System Security

Secure, access-controlled storage for KYC documentation, beneficial ownership records, and CDD files — with audit logging of all access to ensure the integrity of the customer identification program.

✓ Independent Audit Support

System documentation, access logs, change records, and security evidence packaged to support the annual independent BSA/AML program audit — ensuring auditors can verify IT controls without requiring LBT to produce documentation in real time during the audit.

Is Your Business BSA/AML Ready?

Schedule a complimentary scoping consultation. LBT will assess your current compliance posture, identify gaps, and show you exactly what it takes to close them — at no cost and no obligation.

BOOK YOUR FREE BSA/AML INFRASTRUCTURE ASSESSMENT →

+1 (916) 333-1062 · lbttechgroup.com · Sacramento, California

© 2026 LBT Technology Group, LLC · BSA / AML Compliance — Financial Services · Sacramento, CA · Confidential

This document is for informational purposes only and does not constitute legal advice.

Financial Services Compliance

BSA/AML Compliance

Bank Secrecy Act and Anti-Money Laundering controls depend on secure, auditable technology.

$10K+CTR threshold

Cash transaction reporting

5 yearsRecord retention

Core BSA requirement

5Program pillars

One connected AML program

Why this matters

WHAT ARE BSA & AML?

Anti-money laundering compliance runs on the same infrastructure as cybersecurity.

The Bank Secrecy Act (BSA), enacted in 1970 and substantially amended by the USA PATRIOT Act and the Anti-Money Laundering Act of 2020, is the primary U.S. federal law governing financial institutions’ obligations to detect, report, and prevent money laundering and other financial crimes. Anti-Money Laundering (AML) programs are the operational implementation of BSA requirements — the policies, procedures, controls, and monitoring systems that financial institutions maintain to identify suspicious activity and report it to the Financial Crimes Enforcement Network (FinCEN).

For Sacramento-area financial services firms — mortgage lenders, independent financial advisors, insurance agencies, check cashing services, and money services businesses — BSA/AML compliance is directly dependent on IT infrastructure. Transaction monitoring, customer due diligence (CDD), suspicious activity reporting (SAR), and recordkeeping are technology-dependent functions. An IT provider that manages the systems on which these functions run is embedded in the BSA/AML compliance architecture, whether or not either party recognizes it.

Applicability

BSA applies to far more businesses than ‘banks.’

The BSA defines ‘financial institution’ broadly — far beyond traditional banking. Sacramento businesses in the following categories have BSA/AML obligations and must register with FinCEN or maintain a formal AML program:

01

Banks, credit unions, and thrifts

Full BSA compliance program required; federal banking regulator (OCC, FDIC, NCUA) examination of AML controls

02

Mortgage lenders and brokers

BSA reporting obligations including CTRs and SARs; FinCEN registration required for non-depository mortgage companies

03

Money services businesses (MSBs)

Includes check cashing, money orders, currency exchange, and prepaid access. FinCEN registration required; full AML program.

04

Insurance companies

BSA applies to certain insurance products (permanent life, annuities). Insurance companies must file SARs for suspicious transactions.

05

Independent financial advisors / RIAs

FinCEN proposed rules (pending) would extend AML program requirements to investment advisers. Many RIAs voluntarily maintain AML programs.

06

Casinos

Full BSA compliance program; gaming-specific reporting requirements

07

Precious metals and jewelry dealers

Cash transactions over $10,000 trigger CTR obligations; SARs required for suspicious transactions regardless of amount

Explore the program

What a compliant AML program must include.

FinCEN requires covered financial institutions to maintain an AML program built on five core pillars. Each pillar has direct technology dependencies that fall within the scope of an MSP’s managed services delivery.

Program pillar 1

Internal Controls

Policies and procedures governing transaction monitoring, customer due diligence, and suspicious activity identification. IT systems must be configured to enforce these controls — access restrictions, audit logging, and transaction flagging.

Reporting requirements

The filings that create the paper trail regulators examine.

01

Currency Transaction Report (CTR)

Required for any cash transaction over $10,000. Must be filed with FinCEN within 15 days. IT systems must flag, record, and track cash transactions to ensure CTR obligations are met.

02

Foreign Bank Account Report (FBAR)

Required for US persons with foreign financial accounts exceeding $10,000 in aggregate value at any point during the year. Filed with FinCEN annually.

03

8300 (IRS/FinCEN)

Required for businesses that receive more than $10,000 in cash in a single transaction or related transactions. Filed within 15 days.

Enforcement exposure

BSA enforcement is criminal, civil, and reputational.

Up to $1,000,000 per day of violation

FinCEN and federal banking regulators assess civil money penalties per day for systemic BSA/AML program failures. Individual officers and compliance personnel can also face personal liability. Criminal penalties for willful violations include fines and imprisonment.

01FinCEN civil money penalties

Up to $1,000,000 per day for systemic failures; $25,000+ per negligent violation

02Federal criminal prosecution

Willful BSA violations: fines up to $250,000 and/or 5 years imprisonment for individuals

03Federal banking regulator action

Cease and desist orders, consent orders, removal of officers — OCC, FDIC, NCUA, and CFPB can all act on BSA deficiencies

04FinCEN 314(a) non-compliance

Failure to respond to FinCEN 314(a) information requests is a BSA violation in itself — IT systems must be configured to search and respond within the required 2-week window

05Reputational consequences

BSA enforcement actions are public. Loss of correspondent banking relationships is a practical consequence that can effectively end a financial firm’s operations

How LBT supports financial firms

IT controls that underpin every pillar of an effective AML program.

LBT’s role in BSA/AML compliance is infrastructure and controls — not the legal or regulatory analysis that is the domain of your compliance officer and legal counsel. LBT ensures the IT systems on which AML functions depend are secure, auditable, and operating as your program requires.

01
Audit Log Management & Retention (5-Year BSA Standard)

BSA requires a 5-year recordkeeping period for most transaction records and reports. LBT’s log management and backup program is configured to meet this retention requirement — ensuring audit trails are available for FinCEN or federal banking regulator examination requests.

02
SAR System Access Controls

Role-based access controls ensuring only authorized AML compliance personnel can access systems containing SAR filings, SAR-supporting documentation, and related investigation records — satisfying the BSA’s tipping-off prohibition and FinCEN access requirements.

03
FinCEN 314(a) Response Capability

IT systems configured to enable rapid search of customer records in response to FinCEN 314(a) information requests — which require a response within two weeks of the request posting date. Delayed response is itself a BSA violation.

04
Transaction Monitoring System Security

Security hardening, access control, and monitoring of transaction monitoring platforms — ensuring the systems that flag suspicious activity are themselves protected from unauthorized access or manipulation.

05
Customer Due Diligence System Security

Secure, access-controlled storage for KYC documentation, beneficial ownership records, and CDD files — with audit logging of all access to ensure the integrity of the customer identification program.

06
Independent Audit Support

System documentation, access logs, change records, and security evidence packaged to support the annual independent BSA/AML program audit — ensuring auditors can verify IT controls without requiring LBT to produce documentation in real time during the audit.

Next step

Build technology controls your AML program can rely on.

Schedule a complimentary scoping consultation. LBT will assess your current compliance posture, identify gaps, and show you exactly what it takes to close them — at no cost and no obligation.

This document is for informational purposes only and does not constitute legal advice.