15.1 BSA Program Pillars and Independent Testing
Key Takeaways
A bank BSA program combines internal controls, designated responsibility, training and independent testing.
Customer due diligence complements the traditional program pillars.
Testing independence and scope should reflect the institution’s actual risks and applicable BSA requirements.
1. Statutory Architecture and Regulatory Scope
The BSA regulatory architecture operates through a dual-tiered framework of Treasury/FinCEN administrative regulations and federal functional banking supervisor rules:
- FinCEN Regulations (31 CFR Chapter X): FinCEN serves as the administrator of the BSA. Regulations are structured into general provisions applicable to all covered financial institutions (Part 1010) and specific provisions tailored directly to banks and depository institutions (Part 1020).
- Federal Banking Agency Safety and Soundness Rules: Each primary federal banking regulator requires every insured institution under its jurisdiction to establish and maintain a written BSA compliance program approved by its Board of Directors and reflected in board minutes:
- Office of the Comptroller of the Currency (OCC): 12 CFR § 21.21
- Federal Reserve Board (FRB): 12 CFR § 208.63
- Federal Deposit Insurance Corporation (FDIC): 12 CFR § 326.8
- National Credit Union Administration (NCUA): 12 CFR § 748.2
- Anti-Money Laundering Act of 2020 (AMLA 2020): Enacted within the National Defense Authorization Act for Fiscal Year 2021, AMLA 2020 enacted sweeping reforms, including establishing National AML/CFT Priorities, enhancing FinCEN whistleblower incentives and protections, modernizing compliance technologies, codifying risk-based supervision, and enacting the Corporate Transparency Act (CTA) for beneficial ownership reporting directly to FinCEN.
2. The Five Pillars of a Defensible BSA/AML Program
Federal banking regulations historically established four foundational pillars for a bank's BSA compliance program. In May 2018, FinCEN's Customer Due Diligence (CDD) rule formally codified Customer Due Diligence and Beneficial Ownership as the explicit Fifth Pillar of a compliant BSA/AML program.
- Retention: Many BSA records have a five-year period, but identify its start date. CIP identifying information is retained five years after account closure; verification descriptions and results are retained five years after the record is made. OFAC has separate ten-year requirements. Do not use a single retention clock for all records.
Pillar 2: Designated BSA Compliance Officer
The institution's Board of Directors must formally designate a qualified individual as the BSA Compliance Officer. This appointment must be officially recorded in the Board minutes.
- Qualifications and Stature: The designated officer must possess sufficient expertise regarding BSA/AML laws, FinCEN regulations, supervisory guidance, and banking operations. Crucially, the individual must hold adequate authority and executive stature within the organization.
- Operational Independence: The BSA Compliance Officer should have sufficient authority and avoid conflicts of interest (such as commercial lending or wealth management) to prevent conflicts of interest between profit targets and compliance obligations.
- Reporting Lines: The officer should have effective access to the Board of Directors or its designated Audit Committee. Regular reports must detail transaction monitoring metrics, SAR/CTR filing volumes, high-risk customer reviews, regulatory updates, and systemic control weaknesses.
- Resource Allocation: The Board and senior management are legally obligated to provide the BSA officer with adequate human, technological, and budgetary resources to administer an effective program commensurate with the bank's size, geographic footprint, and risk profile.
Pillar 3: Comprehensive, Role-Tailored Training Program
Depository institutions must provide ongoing, comprehensive BSA/AML training to all personnel whose job responsibilities bring them into contact with transactions or customer onboarding.
- Role-Based Curriculum: Training cannot consist solely of generic, one-size-fits-all overviews. The curriculum must be customized to the operational duties of specific employee groups:
- Tellers and Frontline Staff: Currency transaction reporting thresholds, red flags for cash structuring, identification of counterfeit instruments, and logging monetary instrument sales.
- Lending Personnel: Identifying trade finance anomalies, layered corporate borrowing structures, unexplained third-party payoffs, and cash-collateralized loan schemes.
- Customer Onboarding & Account Representatives: Customer Identification Program (CIP) procedures, beneficial ownership identification, risk questionnaire completion, and documentary verification.
- Wire Transfer and Operations Staff: Funds transfer recordkeeping and Travel Rule data integrity, real-time sanctions screening, and unusual message flows.
- Senior Management and Board of Directors: Fiduciary responsibilities, regulatory enforcement environment, personal liability risks, resource management, and risk assessment review.
- Frequency and Tracking: Training must be conducted on an ongoing basis (at intervals appropriate to risk and roles, with updates when requirements or procedures change; annual training is a common policy choice). The bank must maintain documented records of attendance, completed training modules, comprehension testing scores, and escalation protocols for delinquent employees.
Pillar 4: Independent Testing (Audit)
The BSA/AML compliance program must be independently tested at regular intervals by internal audit personnel or a qualified external third party.
- Auditor Independence: The individuals conducting the independent testing must be completely independent of the BSA compliance function, transaction monitoring operations, and policy formulation. Staff reporting to the BSA Compliance Officer cannot perform independent testing.
- Frequency: Testing must be performed at a frequency commensurate with the bank's inherent risk profile. For most depository institutions, comprehensive testing is conducted annually. High-risk institutions or banks operating under formal regulatory enforcement actions may require semi-annual or continuous targeted testing.
- Audit Scope: Independent testing must evaluate the entire operational spectrum of the program, including:
- Validation of the institution-wide BSA/AML risk assessment methodology;
- Transaction testing of CTR and SAR filings to verify accuracy, completeness, and timeliness;
- System validation of automated transaction monitoring rules, data feeds, and threshold parameters;
- Review of high-risk customer files, including Enhanced Due Diligence (EDD) documentation and beneficial ownership certifications;
- Verification of staff training records and management information systems (MIS);
- Review of CIP exception logs and list-screening procedures (OFAC and Section 314(a)).
- Audit Reporting: Written audit findings, control deficiencies, and corrective action recommendations must be delivered directly to the Board of Directors or Audit Committee, and tracked through formal remediation.
Pillar 5: Customer Due Diligence (CDD) & Beneficial Ownership
Promulgated under 31 CFR § 1010.230 (the FinCEN CDD Rule), the Fifth Pillar mandates that covered institutions establish risk-based procedures covering four core elements:
- Identifying and verifying customer identity (Customer Identification Program);
- Identifying and verifying the beneficial owners of legal entity customers;
- Understanding the nature and purpose of customer relationships to develop customer risk profiles; and
- Conducting ongoing monitoring to identify and report suspicious transactions and, on a risk basis, updating customer information.
During a federal safety and soundness examination, examiners review the independent testing pillar of a community bank's BSA/AML program. Which of the following arrangements constitutes a critical supervisory deficiency in independent testing under 12 CFR § 21.21 / § 208.63?
Permitting the Assistant BSA Officer to conduct the annual independent testing of the automated transaction monitoring and alert clearing systems.
Engaging an external certified public accounting firm to perform testing every 12 months with findings reported directly to the Audit Committee.
Having the internal audit department conduct testing using statistical sampling of CTR and SAR filings while reporting to the Board of Directors.
Utilizing a third-party compliance consultant who validates the risk assessment and presents formal corrective action plans to executive management.
Sections you finish are checked off in the contents.