BSA AML Compliance
Bank Secrecy Act & Anti-Money Laundering — How IT Controls Support Financial Crime Compliance
lbttechgroup.com · +1 (916) 333-1062 · Sacramento, California · Veteran-Owned
WHAT ARE BSA & AML?
Anti-money laundering compliance runs on the same infrastructure as cybersecurity.
The Bank Secrecy Act (BSA), enacted in 1970 and substantially amended by the USA PATRIOT Act and the Anti-Money Laundering Act of 2020, is the primary U.S. federal law governing financial institutions’ obligations to detect, report, and prevent money laundering and other financial crimes. Anti-Money Laundering (AML) programs are the operational implementation of BSA requirements — the policies, procedures, controls, and monitoring systems that financial institutions maintain to identify suspicious activity and report it to the Financial Crimes Enforcement Network (FinCEN).
For Sacramento-area financial services firms — mortgage lenders, independent financial advisors, insurance agencies, check cashing services, and money services businesses — BSA/AML compliance is directly dependent on IT infrastructure. Transaction monitoring, customer due diligence (CDD), suspicious activity reporting (SAR), and recordkeeping are technology-dependent functions. An IT provider that manages the systems on which these functions run is embedded in the BSA/AML compliance architecture, whether or not either party recognizes it.
FinCEN
federal enforcement authority
$10K+
reporting threshold for CTRs
5 years
BSA recordkeeping requirement
$280B+
AML fines in the US 2008–2023
WHO MUST COMPLY
BSA applies to far more businesses than ‘banks.’
The BSA defines ‘financial institution’ broadly — far beyond traditional banking. Sacramento businesses in the following categories have BSA/AML obligations and must register with FinCEN or maintain a formal AML program:
Business Type
BSA/AML Obligation
Banks, credit unions, and thrifts
Full BSA compliance program required; federal banking regulator (OCC, FDIC, NCUA) examination of AML controls
Mortgage lenders and brokers
BSA reporting obligations including CTRs and SARs; FinCEN registration required for non-depository mortgage companies
Money services businesses (MSBs)
Includes check cashing, money orders, currency exchange, and prepaid access. FinCEN registration required; full AML program.
Insurance companies
BSA applies to certain insurance products (permanent life, annuities). Insurance companies must file SARs for suspicious transactions.
Independent financial advisors / RIAs
FinCEN proposed rules (pending) would extend AML program requirements to investment advisers. Many RIAs voluntarily maintain AML programs.
Casinos
Full BSA compliance program; gaming-specific reporting requirements
Precious metals and jewelry dealers
Cash transactions over $10,000 trigger CTR obligations; SARs required for suspicious transactions regardless of amount
THE FIVE BSA/AML PROGRAM PILLARS
What a compliant AML program must include.
FinCEN requires covered financial institutions to maintain an AML program built on five core pillars. Each pillar has direct technology dependencies that fall within the scope of an MSP’s managed services delivery.
Pillar
IT & Cybersecurity Dependency
1. Internal Controls
Policies and procedures governing transaction monitoring, customer due diligence, and suspicious activity identification. IT systems must be configured to enforce these controls — access restrictions, audit logging, and transaction flagging.
2. Compliance Officer
A designated BSA/AML Compliance Officer responsible for the program. LBT supports the Compliance Officer by providing the system access, logging, and monitoring data they need to perform their oversight function.
3. Training
Annual BSA/AML training for all staff. LBT’s security awareness training program can be coordinated with BSA/AML training delivery to ensure both obligations are met through a unified training calendar.
4. Independent Testing (Audit)
Annual independent testing of the AML program by internal audit or an external third party. Auditors test IT controls — transaction monitoring system configurations, log retention, and access controls — as part of BSA/AML program review.
5. Customer Due Diligence (CDD)
Know Your Customer (KYC) and Customer Due Diligence procedures, including beneficial ownership identification. CDD systems must be secure, access-controlled, and auditable — IT requirements that LBT manages directly.
BSA REPORTING REQUIREMENTS
The filings that create the paper trail regulators examine.
Report
Trigger & Requirement
Currency Transaction Report (CTR)
Required for any cash transaction over $10,000. Must be filed with FinCEN within 15 days. IT systems must flag, record, and track cash transactions to ensure CTR obligations are met.
Suspicious Activity Report (SAR)
Required when the institution knows, suspects, or has reason to suspect a transaction of $5,000 or more involves funds from illegal activity, is designed to evade BSA reporting, or lacks a lawful purpose. Must be filed within 30 days of detection. SARs are confidential — strict IT access controls required.
Foreign Bank Account Report (FBAR)
Required for US persons with foreign financial accounts exceeding $10,000 in aggregate value at any point during the year. Filed with FinCEN annually.
8300 (IRS/FinCEN)
Required for businesses that receive more than $10,000 in cash in a single transaction or related transactions. Filed within 15 days.
SAR Confidentiality Is an IT Security Requirement
The BSA prohibits financial institutions from disclosing to the subject of a SAR that a report has been filed — a requirement known as the ‘tipping off’ prohibition. Violation is a federal crime. This means SAR documentation must be stored in access-controlled, auditable systems where only authorized personnel can view it. An MSP that manages systems containing SAR records must implement access controls that prevent unauthorized personnel — including the subjects of SARs — from accessing this information.
PENALTIES
BSA enforcement is criminal, civil, and reputational.
BSA CIVIL MONEY PENALTY
Up to $1,000,000 per day of violation
FinCEN and federal banking regulators assess civil money penalties per day for systemic BSA/AML program failures. Individual officers and compliance personnel can also face personal liability. Criminal penalties for willful violations include fines and imprisonment.
Enforcement Path
Consequences
FinCEN civil money penalties
Up to $1,000,000 per day for systemic failures; $25,000+ per negligent violation
Federal criminal prosecution
Willful BSA violations: fines up to $250,000 and/or 5 years imprisonment for individuals
Federal banking regulator action
Cease and desist orders, consent orders, removal of officers — OCC, FDIC, NCUA, and CFPB can all act on BSA deficiencies
FinCEN 314(a) non-compliance
Failure to respond to FinCEN 314(a) information requests is a BSA violation in itself — IT systems must be configured to search and respond within the required 2-week window
Reputational consequences
BSA enforcement actions are public. Loss of correspondent banking relationships is a practical consequence that can effectively end a financial firm’s operations
HOW LBT SUPPORTS BSA/AML PROGRAM INFRASTRUCTURE
IT controls that underpin every pillar of an effective AML program.
LBT’s role in BSA/AML compliance is infrastructure and controls — not the legal or regulatory analysis that is the domain of your compliance officer and legal counsel. LBT ensures the IT systems on which AML functions depend are secure, auditable, and operating as your program requires.
✓ Audit Log Management & Retention (5-Year BSA Standard)
BSA requires a 5-year recordkeeping period for most transaction records and reports. LBT’s log management and backup program is configured to meet this retention requirement — ensuring audit trails are available for FinCEN or federal banking regulator examination requests.
✓ SAR System Access Controls
Role-based access controls ensuring only authorized AML compliance personnel can access systems containing SAR filings, SAR-supporting documentation, and related investigation records — satisfying the BSA’s tipping-off prohibition and FinCEN access requirements.
✓ FinCEN 314(a) Response Capability
IT systems configured to enable rapid search of customer records in response to FinCEN 314(a) information requests — which require a response within two weeks of the request posting date. Delayed response is itself a BSA violation.
✓ Transaction Monitoring System Security
Security hardening, access control, and monitoring of transaction monitoring platforms — ensuring the systems that flag suspicious activity are themselves protected from unauthorized access or manipulation.
✓ Customer Due Diligence System Security
Secure, access-controlled storage for KYC documentation, beneficial ownership records, and CDD files — with audit logging of all access to ensure the integrity of the customer identification program.
✓ Independent Audit Support
System documentation, access logs, change records, and security evidence packaged to support the annual independent BSA/AML program audit — ensuring auditors can verify IT controls without requiring LBT to produce documentation in real time during the audit.
Is Your Business BSA/AML Ready?
Schedule a complimentary scoping consultation. LBT will assess your current compliance posture, identify gaps, and show you exactly what it takes to close them — at no cost and no obligation.
BOOK YOUR FREE BSA/AML INFRASTRUCTURE ASSESSMENT →
+1 (916) 333-1062 · lbttechgroup.com · Sacramento, California
© 2026 LBT Technology Group, LLC · BSA / AML Compliance — Financial Services · Sacramento, CA · Confidential
This document is for informational purposes only and does not constitute legal advice.
