10.3 BSA/AML, SAR/CTR Reporting & OFAC Sanctions Compliance in ACH

Key Takeaways

  • The Bank Secrecy Act (BSA / 31 CFR Chapter X) and Anti-Money Laundering (AML) regulations mandate that all financial institutions maintain risk-based compliance programs, automated transaction monitoring, and rigorous customer due diligence for ACH activities.
  • For banks, SARs are generally due within 30 calendar days after initial detection. If no suspect is identified, filing may be delayed for up to an additional 30 days, but never beyond 60 calendar days after initial detection; the applicable reporting thresholds still depend on the type of suspicious activity.
  • Currency Transaction Reports (CTRs / FinCEN Form 112) must be filed for aggregate physical cash transactions exceeding $10,000 in a single business day, which applies to physical cash funding or cash withdrawals linked to ACH origination/receipt.
  • The Office of Foreign Assets Control (OFAC / 31 CFR Part 500) enforces economic sanctions under strict liability, requiring both ODFIs and RDFIs to screen originators, receivers, and transaction addenda against the Specially Designated Nationals (SDN) list.
  • Blocked transactions are placed in an interest-bearing blocked account and reported to OFAC within 10 business days; rejected transactions are not processed and are also reported. In October 2026, R16 remains the ACH code for an Entry returned per OFAC instruction; R90 does not take effect until March 17, 2028.
Last updated: August 2026

10.3 BSA/AML, SAR/CTR Reporting & OFAC Sanctions Compliance in ACH

Core Principle: Financial institutions participating in the Automated Clearing House Network operate under strict federal statutory mandates to detect, prevent, and report illicit financial activity under the Bank Secrecy Act (BSA) (31 U.S.C. § 5311 et seq., 31 CFR Chapter X) and enforce U.S. economic sanctions administered by the Office of Foreign Assets Control (OFAC) (31 CFR Parts 500–598). Non-compliance carries severe regulatory enforcement actions, multi-million-dollar civil monetary penalties, and criminal liability.


1. BSA/AML Regulatory Architecture & The Five Pillars

Under the BSA, the USA PATRIOT Act of 2001, and the Anti-Money Laundering Act of 2020 (AMLA), depository financial institutions (DFIs) must implement and maintain a written, board-approved Anti-Money Laundering / Counter-Terrorist Financing (AML/CFT) Compliance Program (31 CFR § 1020.210).

+---------------------------------------------------------------------------------------------------------+
|                                THE FIVE PILLARS OF A BSA/AML COMPLIANCE PROGRAM                         |
+---------------------------------------------------------------------------------------------------------+
| 1. Internal Controls          | Written policies, procedures, and automated monitoring systems tailored |
|                               | to institutional ACH risk profiles and transaction volume.             |
| 2. Designated BSA Officer     | A designated, qualified individual responsible for day-to-day oversight,|
|                               | SAR/CTR filings, and regulatory liaison.                                |
| 3. Ongoing Employee Training  | Comprehensive, role-specific training for ACH operations, wire transfer,|
|                               | and treasury management personnel.                                      |
| 4. Independent Audit / Testing| Periodic independent testing and audit of the BSA/AML program conducted |
|                               | by internal audit staff or qualified external third-party reviewers.    |
| 5. Customer Due Diligence     | Risk-based procedures for Know Your Customer (KYC), Customer Due        |
|    (CDD) & Beneficial Owners  | Diligence (CDD), and identifying 25%+ Beneficial Owners (31 CFR 1010.230)|
+---------------------------------------------------------------------------------------------------------+

ACH-Specific AML Vulnerabilities

Because ACH is a batch-processing, deferred settlement system handling billions of low-value and high-value payments daily, it presents unique AML vulnerabilities:

  • Rapid Flow-Through: Depositing funds via ACH credit and immediately wiring the balance out to international jurisdictions.
  • Nested Third-Party Senders (TPS): Layered intermediaries obscuring the identity of the true underlying originator.
  • Velocity & Aggregation Masking: Dispersing large illicit sums across thousands of small PPD or WEB debits/credits to evade single-transaction monitoring.

2. Suspicious Activity Reports (SAR) in ACH (31 CFR § 1020.320)

Financial institutions must file a Suspicious Activity Report (SAR / FinCEN Form 111) with the Financial Crimes Enforcement Network (FinCEN) whenever they detect a known or suspected violation of federal law or a suspicious transaction related to money laundering or terrorist financing.

+---------------------------------------------------------------------------------------------------------+
|                                 SAR MANDATORY FILING THRESHOLDS & TIMELINES                             |
+---------------------------------------------------------------------------------------------------------+
| SCENARIO                                                | THRESHOLD     | MANDATORY FILING TIMELINE     |
+---------------------------------------------------------+---------------+-------------------------------+
| Known Suspect Identified                                | $5,000+       | Within 30 calendar days of    |
| (Transaction has no business/lawful purpose or is       |               | initial date of detection.    |
| structured to evade BSA reporting)                      |               |                               |
+---------------------------------------------------------+---------------+-------------------------------+
| Unknown Suspect (No Suspect Identified)                 | $25,000+      | Within 60 calendar days of    |
| (Suspicious pattern detected, but perpetrator is        |               | initial detection (30-day base|
| unidentified)                                           |               | + 30-day extension allowed).  |
+---------------------------------------------------------+---------------+-------------------------------+
| Insider Abuse / Employee Malfeasance                    | Any amount     | Within 30 calendar days of    |
| (Any employee, officer, director involvement)           | (ANY AMOUNT)  | detection.                    |
+---------------------------------------------------------+---------------+-------------------------------+
| Money Laundering / BSA Structuring Violations           | $5,000+       | Within 30 calendar days of    |
|                                                         |               | detection.                    |
+---------------------------------------------------------+---------------+-------------------------------+

ACH Red Flags for Suspicious Activity

  1. Structuring: An Originator submits batches broken into increments just below internal underwriting review thresholds (e.g., submitting multiple $9,900 batches instead of a single $50,000 file).
  2. Abnormal Return Velocity: Sudden surges in administrative or unauthorized returns, specifically:
    • R03 (No Account / Unable to Locate Account)
    • R04 (Invalid Account Number Structure)
    • R10 (Customer Advises Unauthorized / Revoked)
    • Elevated returns often indicate stolen account testing, phishing, or synthetic identity fraud.
  3. Flow-Through Inconsistency: A commercial account receiving high-volume ACH credits from unrelated individuals that are immediately liquidated via ATM withdrawals, cashier's checks, or offshore wire transfers with zero normal operating expenses.
  4. SEC Code Anomalies: A retail merchant account registered for consumer billing (PPD) suddenly originating large corporate payments (CCD) or international transactions (IAT) with no business justification.
  5. Shell Company Activity: A newly established legal entity with no physical footprint or online presence originating multi-million-dollar payroll files within days of account opening.

Strict Confidentiality & Anti-Tipping-Off Mandate (31 CFR § 1020.320(e))

  • Federal Prohibition: Under federal law (31 U.S.C. § 5318(g)(2)), no financial institution, director, officer, employee, or agent of an institution may disclose to any person involved in the transaction that a SAR has been reported, filed, or considered.
  • Absolute Immunity: Financial institutions and personnel who file SARs are granted broad statutory safe harbor immunity from civil liability under federal and state law for disclosures made in SAR filings.

3. Currency Transaction Reporting (CTR) in ACH Operations (31 CFR § 1010.311)

A Currency Transaction Report (CTR / FinCEN Form 112) must be filed for each deposit, withdrawal, exchange of currency, or other payment or transfer by, through, or to the financial institution which involves a transaction in physical cash currency of more than $10,000 in a single business day.

+---------------------------------------------------------------------------------------------------------+
|                                 CTR REQUIREMENTS & ACH INTERSECTION                                     |
+---------------------------------------------------------------------------------------------------------+
| Cash Threshold        | Physical currency exceeding $10,000 ($10,000.01 or greater).                   |
| Filing Deadline       | Filed electronically with FinCEN within 15 calendar days of the transaction.    |
| Aggregation Rule      | Multiple cash transactions conducted by or on behalf of the same person across |
|                       | all branches in a single business day must be aggregated as a single deposit/wd.|
| ACH Intersection      | Electronic ACH transfers are NOT cash and do not trigger a CTR alone. HOWEVER, |
|                       | CTR applies when physical cash >$10k is used to fund an ACH origination or when |
|                       | physical cash >$10k is withdrawn immediately following an incoming ACH credit. |
+---------------------------------------------------------------------------------------------------------+

4. Office of Foreign Assets Control (OFAC) Compliance

The Office of Foreign Assets Control (OFAC), an agency of the U.S. Department of the Treasury, administers and enforces economic and trade sanctions based on U.S. foreign policy and national security goals against targeted foreign countries, terrorists, international narcotics traffickers, and entities engaged in weapons proliferation.

A. Legal Standard: Strict Liability

  • OFAC regulations apply to all U.S. persons and financial institutions located in the United States.
  • Compliance operates under a standard of strict liability: A financial institution that processes an unauthorized transaction involving a sanctioned party is legally liable, regardless of intent, negligence, or lack of knowledge.

B. Core Sanctions Lists

  • Specially Designated Nationals and Blocked Persons (SDN) List: Individuals, companies, and vessels owned or controlled by, or acting on behalf of, targeted countries or groups whose assets must be blocked.
  • Sectoral Sanctions Identifications (SSI) List: Entities subject to specific debt/equity financing restrictions.
  • Comprehensive Sanctions Programs: Full country-wide embargoes (e.g., Cuba, Iran, North Korea, Syria, and occupied regions of Ukraine).

C. Screening Obligations for ACH Participants

Under OFAC regulations and the Nacha Operating Rules' general obligation to comply with Applicable Legal Requirements, every participant in the ACH Network must maintain a risk-based compliance program to ensure it does not process prohibited transactions.

+---------------------------------------------------------------------------------------------------------+
|                                  ACH PARTICIPANT OFAC SCREENING MATRIX                                  |
+---------------------------------------------------------------------------------------------------------+
| Network Participant   | Mandatory Screening Responsibilities                                            |
+-----------------------+---------------------------------------------------------------------------------+
| Originating Bank      | • Screen all Originators and Third-Party Senders during onboarding and daily.   |
| (ODFI)                | • Screen transaction data: Originator names, Receiver names, and addenda records|
|                       |   prior to transmitting files to the ACH Operator.                              |
+-----------------------+---------------------------------------------------------------------------------+
| Receiving Bank        | • Screen its own account holders (Receivers) against updated OFAC SDN lists.    |
| (RDFI)                | • Screen incoming ACH transaction details, Originator names, and addenda records|
|                       |   prior to posting or making funds available.                                   |
+-----------------------+---------------------------------------------------------------------------------+
| Gateway Operator      | • Screen all cross-border International ACH Transactions (IAT) inbound/outbound.|
|                       | • Perform mandatory Travel Rule data payload verification across 7 addenda lines|
+---------------------------------------------------------------------------------------------------------+

5. Operational Execution: OFAC Blocking vs. Rejecting in ACH

When an ACH participant identifies a confirmed OFAC match, federal regulations strictly dictate whether the transaction must be Blocked (Frozen) or Rejected.

+---------------------------------------------------------------------------------------------------------+
|                                  OFAC BLOCKING VS. REJECTING IN ACH                                     |
+---------------------------------------------------------------------------------------------------------+
| DIMENSION                     | BLOCKING (FREEZING ASSETS)           | REJECTING TRANSACTIONS           |
+-------------------------------+--------------------------------------+----------------------------------+
| Legal Trigger                 | Sanction program requires asset      | Transaction violates sanctions,  |
|                               | freeze (e.g., SDN List target or     | but NO blockable property        |
|                               | comprehensive government program).   | interest exists in the transfer. |
+-------------------------------+--------------------------------------+----------------------------------+
| Handling of Funds             | • Place funds in an interest-bearing | • Do not hold funds in blocked acct.|
|                               |   segregated blocked account.        | • Funds cannot be processed.     |
|                               | • Title remains with owner; control  |                                  |
|                               |   is transferred to OFAC rules.      |                                  |
+-------------------------------+--------------------------------------+----------------------------------+
| ACH Return Processing         | **DO NOT RETURN BLOCKED PROPERTY.**  | Follow the applicable OFAC       |
|                               | Returning blocked funds can be an    | instruction. In October 2026,    |
|                               | unlawful transfer. Hold the property | **R16** is used when an RDFI is  |
|                               | unless OFAC authorizes release.      | instructed by OFAC to return an  |
|                               |                                      | Entry. R85 is not a sanctions code.|
+-------------------------------+--------------------------------------+----------------------------------+
| Regulatory Reporting          | File Blocked Property Report with    | File Rejected Transaction Report |
|                               | OFAC within **10 business days**.    | with OFAC within **10 business   |
|                               | File Annual Report by Sept 30.       | days**.                          |
+---------------------------------------------------------------------------------------------------------+

CRITICAL AAP EXAM POINT: If an RDFI receives an ACH credit for a confirmed Specially Designated National (SDN), the RDFI must freeze and block the funds internally. The RDFI MUST NEVER RETURN THE ITEM through the ACH Network. Returning a blocked credit returns the money to the prohibited party, constituting an unlawful unlicensed transfer of blocked property!


6. The BSA Travel Rule & Recordkeeping Rule (31 CFR § 1010.410)

To ensure audit trails for electronic funds transfers moving through financial institutions, FinCEN enforces the Recordkeeping Rule and the Travel Rule.

A. The Recordkeeping Rule (31 CFR § 1010.410(e))

For all funds transmittals of $3,000 or more, the transmittor's financial institution must collect and retain:

  1. Name and address of the transmittor.
  2. Amount of the transmittal order.
  3. Execution date of the transmittal order.
  4. Any payment instructions received from the transmittor.
  5. Identity of the recipient's financial institution.
  6. Name, address, and account number of the recipient (if received with order).
  • Records must be retained for at least five (5) years and made available to FinCEN or regulators upon request.

B. The Travel Rule (31 CFR § 1010.410(f))

For transmittals of funds of $3,000 or more involving more than one financial institution, the transmittor's institution must "pass along" (travel with) the payment order throughout the payment chain:

  • Transmittor's name, account number, and physical address.
  • Identity of the transmittor's financial institution.
  • Amount and execution date of the transmittal order.
  • Recipient's name, address, and account number.

C. Integration with International ACH Transactions (IAT)

In the ACH Network, domestic CCD/PPD formats do not accommodate all Travel Rule address and identification fields. Therefore, Nacha created the International ACH Transaction (IAT) SEC code:

  • An IAT entry carries seven (7) mandatory addenda records containing complete originator name/address, beneficiary name/address, foreign gateway identifiers, and intermediate correspondent banking details to ensure total Travel Rule and OFAC compliance for cross-border ACH flows.
Loading diagram...
OFAC ACH Screening, Match Resolution & Blocking Workflow
Test Your Knowledge

Under FinCEN regulations (31 CFR § 1020.320), what is the mandatory dollar threshold for filing a Suspicious Activity Report (SAR) when a financial institution detects an ACH transaction pattern involving money laundering or BSA violations and a known suspect can be identified?

A
B
C
D
Test Your Knowledge

An RDFI receives an incoming standard PPD credit entry for $15,000 destined for an individual who is positively confirmed to be a Specially Designated National (SDN) on the OFAC Sanctions List. What is the legally mandated procedure the RDFI must execute?

A
B
C
D
Test Your Knowledge

Under the Bank Secrecy Act Travel Rule (31 CFR § 1010.410(f)), what is the monetary threshold that triggers the mandatory transmission of transmittor and recipient identification information through the payment chain for electronic funds transfers?

A
B
C
D
Test Your Knowledge

A corporate customer deposits $14,000 in physical cash currency across three different teller windows at the same financial institution in a single morning, followed immediately by submitting an ACH origination file to disburse payroll credits. What compliance filing is triggered by this cash activity?

A
B
C
D