7.2 BSA/AML, CDD, OFAC Sanctions, and Fiduciary Account Controls
Key Takeaways
- The Bank Secrecy Act (BSA) requires fiduciary institutions to establish and maintain five core compliance pillars: internal controls, a designated compliance officer, ongoing employee training, independent audit testing, and risk-based Customer Due Diligence (CDD).
- Customer Identification Programs (CIP under 31 CFR § 1020.220) mandate collecting four core data points (Name, DOB/Date of Formation, Physical Address, and Taxpayer ID) prior to account opening, while the 2016/2018 FinCEN CDD Rule requires identifying beneficial owners owning 25%+ equity and one individual with significant managerial control.
- Currency Transaction Reports (CTRs / FinCEN Form 112) must be filed for aggregate physical currency transactions exceeding $10,000 conducted by or on behalf of the same person in a single business day; structuring transactions to evade this threshold is a federal crime under 31 U.S.C. § 5324.
- Suspicious Activity Reports (SARs / FinCEN Form 111) must be filed within 30 calendar days of initial detection (up to 60 days if suspect is unknown) for suspicious transactions of $5,000 or more, protected by absolute statutory non-disclosure rules (31 U.S.C. § 5318(g)(2)) and civil liability safe harbors.
- OFAC sanctions require financial institutions to immediately block and freeze property belonging to Specially Designated Nationals (SDNs), place the funds into an interest-bearing blocked escrow account, and file a blocking report with OFAC within 10 business days.
BSA/AML, CDD, OFAC Sanctions, and Fiduciary Account Controls
Quick Answer: Corporate fiduciaries must maintain a comprehensive Bank Secrecy Act / Anti-Money Laundering (BSA/AML) compliance program built upon five core pillars: internal controls, a designated BSA compliance officer, ongoing employee training, independent audit testing, and risk-based Customer Due Diligence (CDD). Financial institutions must file Currency Transaction Reports (CTRs / FinCEN Form 112) for cash transactions exceeding $10,000 in a single business day and Suspicious Activity Reports (SARs / FinCEN Form 111) within 30 calendar days (or 60 days if the suspect is unknown) for suspicious activity meeting the $5,000 threshold ($25,000 if no suspect). SAR filings are subject to strict non-disclosure "tipping off" prohibitions and absolute safe harbor protections under 31 U.S.C. § 5318(g). Office of Foreign Assets Control (OFAC) regulations mandate immediate asset blocking and a 10-business-day reporting deadline for transactions involving Specially Designated Nationals (SDNs).
1. The BSA/AML Regulatory Architecture and the Five Pillars
Congress established the modern anti-money laundering legal framework through successive landmark statutes: the Bank Secrecy Act of 1970 (BSA) (31 U.S.C. § 5311 et seq.), the USA PATRIOT Act of 2001 (Title III), and the Anti-Money Laundering Act of 2020 (AMLA). Corporate fiduciaries and trust banks are classified as "financial institutions" under federal law and must maintain an effective, written BSA/AML compliance program approved by their Board of Directors.
┌─────────────────────────────────────────────────────────────────────────────┐
│ THE FIVE PILLARS OF BSA/AML COMPLIANCE │
├─────────────────────────────────────────────────────────────────────────────┤
│ PILLAR 1: System of Comprehensive Internal Controls │
│ • Written policies, account onboarding filters, CIP/CDD matrices │
│ PILLAR 2: Designated BSA/AML Compliance Officer │
│ • Qualified, fully authorized officer overseeing daily operations│
│ PILLAR 3: Ongoing, Comprehensive Employee Training Program │
│ • Tailored annual training for trust officers, administrators, ops│
│ PILLAR 4: Independent Audit and Testing │
│ • Annual independent testing by internal audit or outside CPAs │
│ PILLAR 5: Risk-Based Customer Due Diligence (CDD) │
│ • Codified in FinCEN 2016/2018 Rule: ongoing monitoring & KYC │
└─────────────────────────────────────────────────────────────────────────────┘
2. Customer Identification Program (CIP) and Due Diligence (CDD)
Under 31 CFR § 1020.220 (implementing Section 326 of the USA PATRIOT Act), banks must implement a written Customer Identification Program (CIP) appropriate for their size and business type.
The Core Four CIP Data Points
Before opening any fiduciary account, the institution must obtain, at a minimum, four identifying data points for every individual or entity customer:
- Legal Name (verified via government-issued photo ID, passport, or certified corporate charter);
- Date of Birth (for natural persons) or Date of Formation (for legal entities);
- Physical Street Address (residential street address for individuals; principal place of business or physical office for entities; P.O. Boxes are strictly prohibited as primary addresses);
- Taxpayer Identification Number (TIN): Social Security Number (SSN) or Individual Taxpayer Identification Number (ITIN) for U.S. citizens/residents, or Employer Identification Number (EIN) for domestic entities; passport number, alien identification card number, or foreign tax number for foreign persons.
┌─────────────────────────────────────────────────────────────────────────────┐
│ TRUST BENEFICIAL OWNERSHIP & CDD MATRIX │
├──────────────────────────────────────┬──────────────────────────────────────┤
│ TRUST PARTY ROLE │ REQUIRED DUE DILIGENCE │
├──────────────────────────────────────┼──────────────────────────────────────┤
│ Grantor / Settlor / Trustor │ • Full CIP verification (4 points) │
│ │ • Document Source of Wealth (SOW) │
│ │ • Verify legitimacy of funding assets│
├──────────────────────────────────────┼──────────────────────────────────────┤
│ Trustee / Co-Trustees │ • Full CIP verification (4 points) │
│ │ • Background and OFAC screening │
├──────────────────────────────────────┼──────────────────────────────────────┤
│ Trust Protectors / Advisors │ • Identify and screen against OFAC │
│ │ • Verify powers to remove/appoint │
├──────────────────────────────────────┼──────────────────────────────────────┤
│ Current Distributees & Remaindermen │ • Identify all named beneficiaries │
│ │ • CIP verification prior to making │
│ │ any financial distribution │
└──────────────────────────────────────┴──────────────────────────────────────┘
FinCEN Beneficial Ownership Rule (31 CFR § 1010.230)
For legal entity customers (corporations, LLCs, general/limited partnerships, and business statutory trusts) opening fiduciary accounts, banks must identify and verify beneficial owners under a two-pronged test:
- The Ownership Prong: Each individual who, directly or indirectly, owns 25% or more of the equity interests of the legal entity customer (between zero and four individuals);
- The Control Prong: A single individual with significant responsibility to control, manage, or direct the legal entity customer (e.g., Chief Executive Officer, Chief Financial Officer, Managing Member, General Partner, or Senior Vice President).
Fiduciary Entity Application: When an irrevocable family trust owns 25% or more of an LLC opening an account, the trustee is identified under the ownership prong. If a corporate trustee is named, the bank identifies the trust officer or designated individual exercising fiduciary management.
Source of Wealth (SOW) vs. Source of Funds (SOF)
In high-net-worth wealth management, regulators expect robust distinction between:
- Source of Wealth (SOW): The origin of the client's entire accumulated net worth over time (e.g., sale of a multi-generational manufacturing enterprise, corporate executive equity compensation, commercial real estate development);
- Source of Funds (SOF): The specific origin and flow of the particular assets being transferred into the fiduciary account (e.g., a wire transfer originating from the client's verified commercial checking account at a regulated domestic bank).
3. Currency Transaction Reports (CTR / FinCEN Form 112)
Under 31 CFR § 1010.311, financial institutions must file a Currency Transaction Report (CTR / FinCEN Form 112) for each deposit, withdrawal, exchange of currency, or other payment or transfer involving physical currency in excess of $10,000 conducted in a single business day.
┌─────────────────────────────────────────────────────────────────────────────┐
│ CTR AGGREGATION & STRUCTURING RULES │
├─────────────────────────────────────────────────────────────────────────────┤
│ Scenario A: Permissible CTR Aggregation │
│ • 10:00 AM: Settlor deposits $6,000 cash into Family Trust Account A. │
│ • 02:30 PM: Same Settlor deposits $5,500 cash into Family Trust Account B. │
│ • TOTAL CASH = $11,500 (> $10,000 threshold). │
│ • ACTION: System aggregates deposits; Bank MUST file Form 112 within 15 │
│ calendar days (25 days electronically). │
├─────────────────────────────────────────────────────────────────────────────┤
│ Scenario B: Criminal Structuring (31 U.S.C. § 5324) │
│ • Client attempts to deposit $9,800 cash to avoid triggering a CTR. │
│ • When informed of CTR rules, client cancels transaction or splits into │
│ two $4,900 cash deposits over two days. │
│ • ACTION: DO NOT discuss evasion techniques; Bank MUST file a SAR! │
└─────────────────────────────────────────────────────────────────────────────┘
- Physical Currency Defined: Coin and paper money of the United States or any foreign country. Physical currency does not include electronic wire transfers, ACH entries, cashier's checks, or personal checks.
- Filing Deadlines: CTRs must be filed electronically through FinCEN's BSA E-Filing System within 15 calendar days following the date of the transaction (or 25 calendar days under certain electronic filing formats).
- Anti-Structuring Prohibition (31 U.S.C. § 5324): It is a federal felony to structure, assist in structuring, or attempt to structure transactions to evade BSA reporting thresholds. Bank personnel are strictly prohibited from advising clients on how to avoid CTR filings.
4. Suspicious Activity Reports (SAR / FinCEN Form 111)
Under 12 CFR § 21.11 (OCC) and 31 CFR § 1020.320 (FinCEN), national banks and corporate fiduciaries must file a Suspicious Activity Report (SAR / FinCEN Form 111) whenever they detect a known or suspected violation of federal law or suspicious transaction involving funds derived from illegal activity.
Mandatory SAR Filing Thresholds
| Threshold Category | Minimum Monetary Trigger | Suspect Identification Status |
|---|---|---|
| Insider Abuse / Self-Dealing | $0 (Any Dollar Amount) | Involves any officer, director, employee, or agent of the bank. |
| Known Suspect | $5,000 or More | Bank can identify an individual or entity suspect. |
| Unknown Suspect | $25,000 or More | Bank cannot identify any suspect involved in the activity. |
| Money Laundering / BSA Evasion | $5,000 or More | Transaction has no business/lawful purpose or involves structuring. |
SAR Filing Timelines and Procedures
- Standard 30-Day Rule: The SAR must be filed no later than 30 calendar days after the date of initial detection of facts that may constitute a basis for filing.
- Extended 60-Day Rule: If no suspect was identified on the date of initial detection, the bank may delay filing for an additional 30 calendar days to attempt to identify a suspect, but in no case may the filing exceed 60 calendar days after the date of initial detection.
- Immediate Law Enforcement Notification: For ongoing violations or imminent threats (e.g., active terrorist financing or ongoing cyber heists), the bank must immediately notify appropriate law enforcement by telephone in addition to filing a SAR.
┌─────────────────────────────────────────────────────────────────────────────┐
│ SAR STATUTORY PROTECTIONS & NON-DISCLOSURE RULES │
├──────────────────────────────────────┬──────────────────────────────────────┤
│ ABSOLUTE NON-DISCLOSURE MANDATE │ STATUTORY SAFE HARBOR PROTECTION │
│ (31 U.S.C. § 5318(g)(2)) │ (31 U.S.C. § 5318(g)(3)) │
├──────────────────────────────────────┼──────────────────────────────────────┤
│ • Strict criminal & civil liability │ • Financial institutions, directors, │
│ for 'tipping off' any person │ officers, and employees are immune │
│ • Bank CANNOT disclose SAR existence │ from ALL civil liability under any │
│ or SAR contents to customer, │ federal, state, or local law for │
│ beneficiary, or outside counsel │ disclosing suspicious activity or │
│ • In response to civil subpoena, │ filing a SAR in good faith. │
│ bank MUST refuse production & │ • Protection applies even if no │
│ immediately notify OCC and FinCEN │ criminal wrongdoing is proven. │
└──────────────────────────────────────┴──────────────────────────────────────┘
5. Office of Foreign Assets Control (OFAC) Sanctions Compliance
The Office of Foreign Assets Control (OFAC), an agency of the U.S. Department of the Treasury, administers and enforces economic and trade sanctions based on U.S. foreign policy and national security goals against targeted foreign countries, terrorists, international narcotics traffickers, and perpetrators of weapons of mass destruction proliferation.
The Specially Designated Nationals (SDN) List
OFAC publishes the Specially Designated Nationals and Blocked Persons List (SDN List). All U.S. persons—including corporate fiduciaries, trust officers, and national banks—are strictly prohibited from dealing with SDNs and must block their property.
┌─────────────────────────────────────────────────────────────────────────────┐
│ OFAC MANDATES: BLOCKING VS. REJECTING │
├──────────────────────────────────────┬──────────────────────────────────────┤
│ BLOCKING (FREEZING) │ REJECTING │
├──────────────────────────────────────┼──────────────────────────────────────┤
│ • Required when an SDN or sanctioned │ • Required when a transaction lacks an│
│ target holds ANY legal, equitable, │ SDN or blocked party interest but │
│ or beneficial interest in assets │ violates sanctions prohibitions │
│ • Bank immediately freezes property │ • Bank rejects/returns transaction │
│ • Place funds in an interest-bearing │ • No asset freeze or interest-bearing│
│ blocked escrow account │ escrow account established │
│ • Title remains with target, but no │ • Transaction is stopped and funds │
│ transfers or withdrawals allowed │ are returned to originating bank │
├──────────────────────────────────────┴──────────────────────────────────────┤
│ MANDATORY OFAC REPORTING: Initial Blocking/Rejecting Report must be filed │
│ with OFAC within 10 BUSINESS DAYS. Annual Report of Blocked Property must │
│ be submitted to OFAC by SEPTEMBER 30 of each calendar year. │
└─────────────────────────────────────────────────────────────────────────────┘
6. BSA/AML and OFAC Threshold & Reporting Matrix
| Regulatory Regime | Governing Regulation | Filing Mechanism | Reporting Threshold | Mandatory Deadline | Statutory Safe Harbor / Secrecy |
|---|---|---|---|---|---|
| Currency Transaction Report (CTR) | 31 CFR § 1010.311 | FinCEN Form 112 | Aggregate physical cash > $10,000 in 1 business day | Within 15 calendar days of transaction | Standard regulatory record; no strict tipping-off ban, but cannot assist structuring. |
| Suspicious Activity Report (SAR) | 31 CFR § 1020.320 / 12 CFR § 21.11 | FinCEN Form 111 | $5,000+ (known suspect); $25,000+ (unknown); $0 (insider abuse) | Within 30 calendar days of detection (max 60 days if no suspect) | Absolute non-disclosure under 31 U.S.C. § 5318(g)(2); full civil immunity under § 5318(g)(3). |
| OFAC Asset Blocking | 31 CFR Part 501 | OFAC Block Form | Any amount involving an SDN or blocked target | Report within 10 business days of block | Annual report of all blocked property required by September 30 annually. |
| Beneficial Ownership CDD | 31 CFR § 1010.230 | Certification of Beneficial Owners | 25% or more equity ownership + 1 control person | At account opening & ongoing lifecycle events | Mandatory customer identification data retained for 5 years after account closure. |
7. Fiduciary-Specific Red Flags and High-Risk Typologies
Trusts and wealth management accounts are inherently vulnerable to illicit exploitation due to the legal separation of legal title (held by the trustee) and beneficial title (held by beneficiaries). Corporate trust officers must maintain heightened vigilance for the following fiduciary red flags:
- Rapid Movement of Funds: Immediate requests to wire contributed trust principal out to foreign jurisdictions or unrelated third-party entities shortly after account funding with no estate planning rationale;
- Reluctance to Disclose Information: Settlors, protectors, or co-trustees who refuse or display extreme reluctance to provide complete trust instruments, underlying business financial statements, or beneficial ownership identification;
- Unexplained Complex Multi-Layered Structures: Creation of multi-tiered shell entities (e.g., an offshore trust holding an offshore LLC holding a domestic trust holding a holding company) where no tax, creditor protection, or administrative justification exists;
- Sudden Changes in Fiduciary Parties: Frequent, unexplained replacement of trust protectors, individual co-trustees, or beneficiaries, particularly involving politically exposed persons (PEPs) or high-risk offshore secrecy jurisdictions;
- Third-Party Disbursement Requests: Beneficiary requests to wire distributions directly to unverified third parties, luxury asset dealers (yachts, fine art, rare gems), or private cryptocurrency exchanges with vague explanations;
- Uncharacteristic Cash Activity: Attempts to contribute physical cash, money orders, or structured cashier's checks into an irrevocable wealth management trust.
8. Foreign Relationships, Enhanced Due Diligence, and Pre-Acceptance Risk Tiering
The Risk and Compliance domain tests pre-acceptance risk judgment: before opening an account, the bank must identify account parties, assess jurisdiction and ownership risk, and decide whether the relationship can be administered safely.
- Identify every interested party: under risk-based KYC/CDD, document the identity of grantors, trustees, beneficiaries, protectors, and holders of financial powers of attorney — not merely the immediate customer standing at the desk. (Compare FinCEN's 25% beneficial-ownership rule for entity customers covered above.)
- Foreign clients, trustees, and beneficiaries: cross-border relationships raise documentary, tax-reporting (for example, Forms 3520/3520-A for U.S. persons engaging with foreign trusts), withholding, and OFAC-screening complexity. Foreign fiduciary parties do not disqualify an account, but they elevate the due-diligence tier and the ongoing monitoring cadence.
- Enhanced Due Diligence (EDD) triggers: politically exposed persons (PEPs — senior foreign political figures together with their immediate family and close associates), complex or opaque ownership structures, cash-intensive businesses, private-investment-company wrappers organized in bank-secrecy jurisdictions, elevated-risk geographies identified by FATF as having weak AML regimes, and inconsistent source-of-wealth narratives.
- EDD measures: senior-management approval, corroborated source-of-wealth/source-of-funds documentation, higher-frequency transaction and relationship reviews, and — where warranted — site visits or third-party verification.
- Accept, condition, or decline: pre-acceptance review (12 CFR § 9.6(a)) culminates in a documented acceptance-committee decision. Where controls cannot mitigate the risk — unresolved sanctions exposure, unidentified beneficial owners, or refusal to verify wealth origin — the fiduciary answer is to decline or resign rather than inherit unmanageable compliance liability.
A trust officer at a national bank discovers that an individual co-trustee has engaged in a complex series of wire transfers totaling $350,000 from the trust account to an offshore entity that appears to be owned by the co-trustee's brother. The activity has no legitimate estate planning purpose. The bank files a Suspicious Activity Report (SAR) with FinCEN on day 20 following detection. Two weeks later, the co-trustee visits the bank and demands to know why his recent wire was scrutinized, asking if a SAR was filed. How should the trust officer respond?
On June 1, 2026, a wealth management compliance team identifies an unusual pattern of wire disbursements totaling $85,000 from an irrevocable trust to shell corporate entities. After preliminary research, the compliance officer is unable to identify any known individual or entity suspect behind the receiving entities. What is the mandatory regulatory timeline for filing a Suspicious Activity Report (SAR) under FinCEN and OCC regulations?
A national bank's trust department processes an incoming international wire transfer of $2,000,000 intended to fund an irrevocable asset protection trust. Real-time automated screening generates an exact match showing that the named settlor is on OFAC's Specially Designated Nationals and Blocked Persons (SDN) List. What immediate actions are legally required of the bank under OFAC regulations?