This guide is general legal information, not legal advice, and does not create an attorney–client relationship. Rules change and vary by state — verify current requirements with official sources or a licensed attorney.
Three acronyms sit at the center of financial-crime compliance. The Bank Secrecy Act (BSA) is the 1970 statute — much amended, most recently by the Anti-Money Laundering Act of 2020 — that requires U.S. financial institutions to help detect and report money laundering. AML (anti-money laundering) is the compliance program the BSA demands. KYC (know your customer) is the identity-verification and due-diligence portion of that program. For a fintech, the practical question is simple to state and consequential to answer: does the BSA treat us as a financial institution, and if so, what must our program contain?
This primer answers both, using the framework FinCEN — the Treasury bureau that administers the BSA — and the federal examiners' FFIEC BSA/AML Examination Manual apply.
Key takeaways
- The BSA covers far more than banks: money services businesses — including money transmitters, a category many fintechs fall into — must register with FinCEN within 180 days and build full AML programs.
- An AML program rests on five pillars: internal controls, a designated compliance officer, training, independent testing, and risk-based customer due diligence.
- KYC has two layers — the customer identification program (collect and verify name, date of birth, address, ID number) and ongoing due diligence, including beneficial-ownership checks for legal-entity customers.
- Core reports: currency transaction reports for cash over $10,000, and suspicious activity reports at a $5,000 threshold for banks or $2,000 for money services businesses.
- In partner-bank models, the bank keeps legal responsibility for BSA compliance, but fintechs perform much of the work by contract — and can face direct liability if they are themselves MSBs.
Step one: figure out whether the BSA covers you
"Financial institution" under the BSA is a long list: banks and credit unions, broker-dealers, casinos, and — critically for fintech — money services businesses (MSBs). The MSB category includes money transmitters, check cashers, currency exchangers, and issuers or sellers of money orders and traveler's checks. FinCEN publishes a plain-language guide, "Am I an MSB?", and its answer turns on function, not branding: if you accept funds from one person and transmit them to another person or location, you are likely a money transmitter regardless of what your app calls the feature. FinCEN has long taken the position that this includes many businesses dealing in convertible virtual currency.
An MSB must register with FinCEN within 180 days of beginning operations and renew every two years; failure to register carries civil penalties per day and can be a federal crime. Note that FinCEN registration is separate from the state-by-state licensing analyzed in our guide to money transmitter licensing — most transmitters need both. Also note the important exception: a company acting solely as an agent of another MSB, or operating strictly as a service provider to a bank that holds the customer relationship, may fall outside MSB status. That structural question deserves careful analysis before launch, because it determines your entire compliance posture — part of the broader jurisdictional sorting described in our U.S. fintech regulatory map.
The five pillars of an AML program
Every covered institution must maintain a written, board-approved (or ownership-approved) AML program reasonably designed to prevent the institution from being used for money laundering or terrorist financing. Examiners look for five elements:
- Internal controls. Policies, procedures, and systems — onboarding rules, transaction monitoring, sanctions screening, escalation paths — proportionate to the institution's risk profile.
- A designated BSA/AML compliance officer. A named individual with the authority, resources, and independence to run the program day to day.
- Training. Ongoing, role-appropriate education for employees, from support agents who see the customer complaints to engineers who build the monitoring rules.
- Independent testing. Periodic audits by internal audit or an outside party that does not report to the compliance officer.
- Customer due diligence. Added as an explicit "fifth pillar" by FinCEN's 2016 CDD Rule (effective 2018): risk-based procedures to understand who customers are and what normal activity looks like for them.
Everything is risk-based. A program serving domestic salaried consumers with small balances can be leaner than one moving cross-border payments for shell-company-prone industries — but "risk-based" must be a documented analysis, not a slogan.
KYC in practice: CIP, CDD, and beneficial ownership
The customer identification program
The CIP is the front door. Before or shortly after opening an account, the institution must collect at minimum a customer's name, date of birth (for individuals), address, and identification number — a Social Security number for U.S. persons, or passport or similar documentation for others — and then verify identity through documents, databases, or both. The program must also say what happens when verification fails: decline, restrict, or file a suspicious activity report. Fintechs typically implement CIP through automated document-plus-database vendors, but the legal obligation and its documentation remain the institution's.
Ongoing due diligence and legal-entity customers
The CDD Rule adds a second layer: build a risk profile for each customer, monitor activity against it, and keep information current. For legal-entity customers, covered institutions must identify and verify beneficial owners — under the rule, each individual owning 25% or more of the entity, plus one individual with managerial control.
Do not confuse two "beneficial ownership" regimes: The CDD Rule (institutions collect ownership data from entity customers) is separate from the Corporate Transparency Act's reporting database (companies report their owners directly to FinCEN). In March 2025, FinCEN issued an interim final rule exempting U.S.-formed companies from CTA reporting, leaving the requirement focused on certain foreign-formed companies — but that change did not repeal banks' and fintechs' CDD obligations, which continue to apply. See FinCEN's beneficial ownership page for the current rules.
The reports FinCEN expects
| Report | Trigger | Deadline | Notes |
|---|---|---|---|
| Currency Transaction Report (CTR) | Cash transactions over $10,000 in one business day (aggregated per customer) | Within 15 calendar days | Threshold unchanged since 1970; structuring transactions to evade it is itself a crime |
| Suspicious Activity Report (SAR) | Known or suspected illegal activity — generally $5,000+ for banks, $2,000+ for MSBs; no threshold for some insider abuse | Generally within 30 days of detection | Strictly confidential — disclosing a SAR's existence to the subject is prohibited |
| Funds transfer records ("travel rule") | Transmittals of $3,000 or more | Recordkeeping and information passed to the next institution | Applies to transmitters as well as banks |
Recordkeeping generally runs five years. Monitoring systems exist largely to feed the SAR process: alerts, investigation, a documented decision, and filing where warranted. Examiners judge programs less on alert volume than on whether the institution can show a coherent path from red flag to decision.
Fintech-specific wrinkles
Most consumer fintechs operate through a partner bank, which changes the shape — not the existence — of AML work. The bank owns the legal obligation for accounts on its books, but program agreements delegate execution: the fintech runs onboarding KYC, front-line monitoring, and case preparation, while the bank reviews, files, and audits. Regulators have repeatedly faulted banks for weak oversight of exactly this delegation, which is why AML capability is now a gating item in partner-bank due diligence, as covered in our article on bank–fintech partnerships.
Other recurring issues deserve attention. Sanctions screening under OFAC rules applies to essentially every U.S. business, MSB or not. Crypto features can independently trigger MSB status. FinCEN has extended BSA obligations to new sectors under the AML Act of 2020 — its rule for certain investment advisers, for example, was adopted in 2024 with compliance subsequently postponed (to 2028, per FinCEN's announcement), so verify current effective dates for any newly covered sector. And AML data practices intersect with privacy law: identity records must be retained for BSA purposes even when customers request deletion, a tension addressed in our guide to fintech data privacy and cybersecurity.
Frequently asked questions
We only move money between a user's own accounts. Are we a money transmitter?
Maybe not — transmission generally involves accepting value from one person and moving it to another person or location, and several exemptions exist, including for payment processors using regulated networks under agreements with sellers. But the analysis is fact-specific and FinCEN interpretations are narrow, so get a written legal opinion before relying on an exemption.
Our partner bank handles BSA compliance. Do we still need our own program?
You need, at minimum, the capabilities your contract assigns you — typically KYC execution, monitoring, and reporting support — plus your own program if any activity makes you an MSB in your own right. Banks increasingly refuse to onboard fintechs without a documented AML program and a qualified compliance lead, whatever the legal allocation.
Can we tell a customer we filed a SAR about them?
No. Federal law prohibits disclosing that a SAR exists, to the subject or anyone else outside authorized channels, and violations carry civil and criminal penalties. Customer-facing teams need scripts for handling account restrictions without referencing suspicious-activity filings — a routine but high-stakes training point.
What are the penalties for BSA violations?
They scale from civil money penalties per violation to criminal prosecution for willful violations, and FinCEN, banking agencies, and the Justice Department have imposed multimillion- and even billion-dollar resolutions on institutions with systemic failures. Individuals, including compliance officers, can be personally penalized. Failure to register as an MSB is separately punishable.
How much does program size matter?
The obligations are the same in kind, scaled in degree. A seed-stage MSB still needs registration, a written program, a named officer, training, independent testing, and reporting capability — but risk-based design lets it size monitoring and staffing to its actual volume and risk, then grow the program with the business.
Standing up the program
A workable build sequence for a fintech starting from zero: classify your activities against the MSB definitions and confirm registration duties; appoint a compliance officer with real authority; draft the risk assessment before the policies, so the program reflects your actual exposure; implement CIP and sanctions screening at onboarding; layer transaction monitoring tuned to your product's typologies; schedule independent testing within the first year; and document everything as if an examiner will read it — because one eventually will, whether from FinCEN's delegated examiners at the IRS, a state regulator, or your partner bank's auditors. Treat the program as production infrastructure, not paperwork, and it will scale with the company rather than against it. For adjacent obligations, browse our fintech law coverage.