Compliance Guide · 2026 · 08 · 8 min read

The Five Pillars of a BSA/AML Compliance Program

Federal regulation requires every bank to maintain a written anti-money laundering program, and 31 CFR 1020.210 defines its required components. Examiners, and the public enforcement actions that follow failed examinations, organize BSA findings around these same pillars — which makes them the natural structure for assessing your own program.

1. Internal controls

A system of policies, procedures, and controls reasonably designed to assure compliance with the Bank Secrecy Act: customer identification, suspicious activity monitoring and SAR decisioning, currency transaction reporting, and recordkeeping. The test examiners apply is not whether the policy binder exists but whether the controls demonstrably operate — alert volumes reviewed, cases dispositioned with documented reasoning, filings made on time.

2. Independent testing

Periodic testing of the program by qualified parties independent of the BSA function — internal audit or an external reviewer. The findings that recur in public enforcement actions here are testing that never happened on schedule, testing scoped too narrowly to mean anything, and testing whose findings were reported and then never remediated. An audit finding left open across two cycles is examiner bait.

3. A designated BSA officer

A named individual responsible for day-to-day compliance, with the authority, resources, and independence to do the job. Regulators have pursued enforcement actions against BSA officers personally, which is worth remembering in both directions: the role carries individual exposure, and a bank that under-resources it is transferring institutional risk onto one employee's license and career.

4. Training

Ongoing training for appropriate personnel, tailored to role — a teller's red flags are not a lender's, and neither matches the board's oversight duties. The evidentiary standard is the same as everywhere else in BSA: if attendance and content aren't documented, the training didn't happen.

5. Customer due diligence

The CDD requirements — understanding the nature and purpose of customer relationships, maintaining risk profiles, and identifying beneficial owners of legal entity customers under 31 CFR 1010.230 — function as the program's fifth pillar. Risk ratings assigned at account opening and never revisited, and beneficial ownership collected but never verified or refreshed, are two of the most common CDD findings.

Reading your own program the way an examiner will

Take the written program document and ask, pillar by pillar: where is the evidence this operated in the last twelve months? The program document itself is the easiest thing to get right and the least of what examiners test. Public consent orders in the BSA space overwhelmingly cite operational failure — monitoring systems tuned so nothing alerts, SAR backlogs, testing findings unremediated — behind a policy that read perfectly well.

See how your own public documents read.

The free RegentForge diagnostic analyzes a bank's published documents — no account, no internal uploads — and returns findings with CFR citations for your counsel to review.

Start the free diagnostic