AML

Bank Secrecy Act: Definition and Use in Compliance

Published: Last updated: Also known as: BSA

The Bank Secrecy Act (BSA) is a United States federal law that requires financial institutions to maintain transaction records and file reports on cash transactions and suspicious activity to assist government agencies in detecting and preventing money laundering.

What Is the Bank Secrecy Act?

The Bank Secrecy Act (BSA), codified at 31 U.S.C. §§ 5311-5336, is the primary U.S. federal law directing financial institutions to help detect and prevent money laundering, tax evasion, and terrorism financing. President Nixon signed it on October 26, 1970. It was the first U.S. law to position the financial system as an active intelligence tool for law enforcement rather than a passive record-keeper.

Three obligations form the operational core. First, financial institutions must file Currency Transaction Reports (CTRs) on cash transactions exceeding $10,000 within 15 calendar days. Second, they must file Suspicious Activity Reports (SARs) when transactions suggest illegal activity, structuring, or an intent to evade reporting requirements; the standard filing window is 30 days, extended to 60 when the suspect is initially unknown. Third, institutions must maintain records for five years in a form accessible to regulators and law enforcement.

FinCEN, a bureau of the U.S. Department of the Treasury, administers the BSA and runs the financial intelligence database populated by these filings. FinCEN's BSA resource page lists every covered institution type and the specific reporting thresholds applicable to each.

The USA PATRIOT Act of 2001 added Customer Identification Programs (CIPs), requiring identity verification at account opening. The Anti-Money Laundering Act of 2020 went further: a beneficial ownership registry under the Corporate Transparency Act, financial incentives for BSA whistleblowers, and formal direction for FinCEN to bring technology into its examination methodology. For a practical breakdown of how these requirements translate into operations, the BSA/AML Compliance Checklist maps each statutory obligation to the controls and documentation an institution needs.

Penalties for willful BSA violations are substantial. Criminal fines reach $250,000 per count with imprisonment up to five years. Civil penalties for ongoing violations reach $1 million per day.


How Is the Bank Secrecy Act Used in Practice?

BSA compliance in practice is a five-pillar program: internal controls, a designated compliance officer, employee training, independent testing, and customer due diligence. Regulators expect all five to be documented, tested, and operational at all times.

Transaction monitoring carries most of the daily load. Analysts work queues of alerts and review flagged transactions against customer profiles. Structuring, the practice of breaking transactions into smaller amounts to stay below the $10,000 CTR threshold, is one of the most common patterns. Others include wire activity inconsistent with a customer's stated business purpose, large cash deposits from customers with no apparent cash business, and fund movements through accounts opened within the last 90 days.

Every alert needs a disposition: filed as a SAR, or closed with documented rationale. That documentation record is what examiners audit. Most mid-size banks generate tens of thousands of alerts monthly and file SARs on fewer than 2% of them. Calibrating that ratio without missing genuine cases is the defining operational challenge of AML; AML Transaction Monitoring Rules Tuning covers the methodology in detail.

SAR committees, typically weekly or bi-weekly, are where filing decisions happen. The BSA officer reviews analyst presentations and makes the call. The tipping-off prohibition bars any contact with the subject of a filed SAR.

CTR filing is more mechanical. Core banking systems flag qualifying cash transactions automatically. The compliance team manages exemption lists for businesses with predictable large-cash needs, like armored car services or grocery chains. Maintaining those exemptions accurately is its own task. We've seen banks consistently underestimate the operational load of managing exemption lists as their customer base grows. It's a common finding in first-year BSA audits.


Bank Secrecy Act in Regulatory Context

The BSA doesn't operate in isolation. It sits at the center of a framework that includes OFAC sanctions compliance, FATF's 40 Recommendations, the FinCEN Customer Due Diligence Rule (effective May 2018), and state money transmitter licensing laws.

Prudential regulators treat BSA as a safety-and-soundness issue. The OCC, FDIC, Federal Reserve, and NCUA jointly publish the FFIEC BSA/AML Examination Manual, which details exactly what examiners look for when they enter an institution. Institutions that fail BSA examinations receive formal enforcement actions: consent orders, civil money penalties, or referrals to the Department of Justice. Single enforcement actions have exceeded $1 billion; HSBC's 2012 deferred prosecution agreement reached $1.9 billion, according to Department of Justice records.

FinCEN published its first formal AML/CFT National Priorities in June 2021, identifying corruption, cybercrime, domestic violent extremism, human trafficking, drug trafficking, fraud, and proliferation financing as its focus areas. Institutions are expected to incorporate those priorities into risk assessments and tune monitoring rules accordingly. The CTR Filing Rules and Automation resource covers the mechanics of one of the BSA's most operationally demanding requirements; a CTR filed accurately without a supporting exemption review process is a gap examiners will flag.

Internationally, the BSA is the domestic implementation of FATF's 40 Recommendations. AMLA 2020 brought U.S. beneficial ownership standards into closer alignment with those recommendations; the FATF Mutual Evaluation of the United States in 2016 had explicitly identified that gap.

Non-bank financial institutions, including money services businesses, virtual asset service providers, and certain insurance companies, are also covered by BSA. Their obligations mirror those of depository banks, though examination authority varies by regulator and business type.


Common Challenges and How to Address Them

Three problems appear consistently in BSA programs, regardless of institution size.

Alert fatigue. A mid-size regional bank can generate 40,000 to 60,000 transaction monitoring alerts per month and file SARs on fewer than 1,000 of them. Analysts spend the bulk of their time closing noise. One institution cut its monthly alert volume from 48,000 to 6,200 by segmenting customers into risk tiers and applying different rule thresholds by segment, with no drop in genuine SAR filings. The fix is improving the signal-to-noise ratio through calibration and segmentation, not adding headcount.

AI-based behavioral analytics can push that ratio further. AI Agents in Financial Crime Investigation describes how AI-driven monitoring differs from traditional rule systems in operational practice: it catches subtle behavioral patterns that rule thresholds miss while producing fewer alerts per true positive.

Documentation gaps. Examiners want to see that analysts made a decision and recorded why. "Reviewed, no action" doesn't meet the standard. Institutions with weak documentation platforms fail audits on process even when their substantive decisions were correct. Structured SAR decision forms with required fields for analyst rationale and supervisory sign-off are a low-cost, high-impact fix.

CDD gaps at onboarding. Many BSA problems trace back to customers who were inadequately profiled when they opened accounts. If the institution doesn't know what's normal for a given customer, monitoring can't identify abnormal. Identity Verification and KYC/AML Automation addresses the onboarding pipeline where these gaps most commonly originate.

FinCEN's public enforcement actions consistently cite risk assessment deficiencies and CDD failures as the most frequently found weaknesses across formal actions.


Related Terms and Concepts

The BSA anchors a cluster of overlapping obligations that compliance teams manage together.

Anti-Money Laundering (AML) is the broader discipline. The BSA is the U.S. statute; AML describes the global practice of detecting and preventing money laundering. In U.S. contexts, the two are routinely combined into "BSA/AML," which signals that they function as a unified program rather than separate obligations.

Customer Due Diligence (CDD) became a formal BSA requirement in 2018 through the FinCEN CDD Rule. It requires institutions to collect and verify customer information and, for legal entities, to identify beneficial owners. CDD quality at onboarding feeds directly into SAR quality downstream: if the institution doesn't understand what's normal for a customer, it can't reliably flag what's not.

Suspicious Activity Report (SAR) and Currency Transaction Report (CTR) are the two primary BSA reporting instruments. SARs require a filing decision, committee oversight, and analyst documentation. CTRs are largely automated but require exemption list management and ongoing review.

OFAC compliance is a parallel obligation. Sanctions screening isn't technically a BSA requirement, but regulators assess it alongside BSA because the underlying customer data and risk frameworks overlap. It's standard practice to run sanctions screening and AML monitoring on the same data feeds.

AMLA 2020 is the most consequential BSA amendment in two decades. It added anti-structuring provisions for digital assets, financial incentives for BSA whistleblowers, and directed FinCEN to bring technology into its examination methodology. The Corporate Transparency Act, which took effect in January 2024, implements the beneficial ownership registry AMLA 2020 established.

Institutions managing these obligations through integrated platforms find it easier to meet examination standards than those running separate point solutions, particularly when an examiner asks for a unified audit trail across SAR decisions, CTR filings, and CDD records.


Where does the term come from?

The Bank Secrecy Act was signed into law on October 26, 1970, under President Nixon. Congress designed it in response to growing use of foreign bank accounts, particularly numbered Swiss accounts, to conceal taxable income and criminal proceeds. The Supreme Court upheld its constitutionality in California Bankers Assn. v. Shultz (1974). The Money Laundering Control Act of 1986 made money laundering a federal crime and sharpened BSA enforcement. Subsequent amendments in 2001 and 2020 expanded the statute from basic recordkeeping to a comprehensive financial intelligence and compliance framework.


How FluxForce handles bank secrecy act

FluxForce AI agents monitor bank secrecy act-related patterns in real time, flag anomalies for analyst review, and generate evidence-backed decisions with full audit trails.

← Back to Glossary