BSA officer & governance
Role-based ownership, escalation paths and board reporting packs generated from live programme data.
ComplianceSuite runs the whole US AML programme in one platform — CIP and CDD onboarding, beneficial-ownership identification, OFAC screening, risk-based transaction monitoring, alert investigation and FinCEN SAR and CTR filing — with the tuning evidence, audit trail and five-year records that the FFIEC BSA/AML Examination Manual expects.
What the BSA requires
The Bank Secrecy Act and FinCEN's implementing rules require covered US financial institutions — banks, credit unions, money services businesses, broker-dealers, casinos and many fintechs operating through a sponsor bank — to maintain a written, risk-based AML programme, verify customer identity under the Customer Identification Program rule, identify beneficial owners of legal-entity customers under the CDD Rule, monitor for suspicious activity, and file SARs and CTRs to FinCEN within statutory deadlines.
Enforcement is the expensive part: civil money penalties, consent orders and look-back reviews almost always trace back to late or missed SARs, untuned monitoring rules, or an inability to evidence decisions after the fact. ComplianceSuite closes all three gaps from one system of record.
The five pillars
Role-based ownership, escalation paths and board reporting packs generated from live programme data.
Written policies mapped control-by-control to the rules, workflows and thresholds actually running in production.
Assign, track and evidence role-specific AML training with completion records held against each user.
Exportable rule inventories, tuning history, back-tests and above/below-the-line results for your independent test.
Risk-based CIP/CDD, beneficial-owner identification at 25%, and refresh cycles driven by risk rating.
Capabilities
SARs and CTRs auto-populated from the case file, schema-validated, and filed through BSA E-Filing with acknowledgements stored against the case.
Currency activity aggregated across branches and channels in one business day, with structuring detection below the $10,000 threshold.
The filing deadline starts at detection and is tracked with escalation alerts so no SAR runs past 31 CFR 1020.320.
SDN, consolidated and 50-percent-rule screening on customers, beneficial owners and payment messages — see OFAC screening.
Every rule, threshold change and decision carries an owner, rationale and audit trail mapped to the FFIEC examination manual.
Back-test proposed thresholds against your production history and show projected alert volume before anything goes live.
Related: OFAC sanctions screening, MSB & money transmitter compliance, transaction monitoring.
How it works
Onboard
CIP verification, beneficial-ownership collection at 25% and risk rating drive the customer's due-diligence tier from day one.
Screen
OFAC SDN, consolidated lists, PEP and adverse-media screening at onboarding and continuously on list updates.
Monitor
Risk-based rules and behavioural models flag structuring, rapid movement of funds, funnel accounts and high-risk geography exposure.
Investigate
Alerts route into case management with account, counterparty and transaction context, plus reviewer notes that become the SAR narrative.
File
SAR or CTR generated, validated against FinCEN's schema and filed via BSA E-Filing with the BSA ID captured automatically.
Evidence
Supporting documentation, decisions and filings retained five years in the immutable repository for examiners and independent testing.
Late SARs and untuned monitoring rules are the two most common findings in US BSA/AML enforcement actions. Deadline tracking and documented tuning evidence are the cheapest controls you can put in place.
FAQ
BSA/AML compliance software automates the five pillars of a US anti-money-laundering programme required under the Bank Secrecy Act and FinCEN's AML Program Rule (31 CFR 1020.210): a designated BSA officer, written policies and internal controls, ongoing training, independent testing, and risk-based customer due diligence including beneficial-ownership identification. ComplianceSuite delivers the control layer — CIP/CDD onboarding, OFAC and PEP screening, transaction monitoring, alert investigation, and SAR/CTR filing to FinCEN — with the audit evidence examiners ask for.
FinCEN SARs (FinCEN Form 111), CTRs (FinCEN Form 112) for cash transactions over $10,000 including same-day aggregation, Designation of Exempt Person (FinCEN Form 110), FBAR-supporting records, and 314(a)/314(b) information-request tracking. Filings are produced from the case file and validated against FinCEN's BSA E-Filing schema before submission.
A SAR must be filed within 30 calendar days of initial detection of facts that may constitute a basis for filing, extended to 60 days if no suspect has been identified. ComplianceSuite starts the clock at alert creation, tracks it on a filing calendar with escalation alerts, and preserves the supporting documentation for five years as 31 CFR 1020.320(d) requires.
Yes. Currency transactions by or on behalf of the same person totalling more than $10,000 in one business day are aggregated automatically across branches, channels and accounts, with structuring detection for patterns that sit deliberately below the threshold.
The FFIEC BSA/AML Examination Manual, FinCEN's CDD Rule, OCC, FRB, FDIC and NCUA supervisory guidance, and — for money services businesses — 31 CFR Chapter X plus state money-transmitter requirements. Model risk management follows OCC 2011-12 / SR 11-7 expectations, including documented tuning and back-testing evidence.
It produces the artefacts independent testing asks for: rule inventories with owners and rationale, threshold change history with four-eyes approval, back-test results against production data, alert-to-SAR conversion statistics, and above/below-the-line testing output — all exportable for your independent test or examination.
Typical US deployments run 6-10 weeks: data mapping and CIP/CDD configuration, rule library tuning against your historical transactions, parallel run alongside your current system, then cutover with the migrated alert and SAR history preserved.
US data residency is available for BSA workloads, with AES-256 encryption at rest, TLS 1.3 in transit, role-based access with maker-checker controls, and an immutable audit log of every read, write and filing. ComplianceSuite is ISO 27001, ISO 9001 and ISO 22301 certified.
Bring an anonymised transaction extract — in 30 minutes we'll detect the structuring pattern, build the case, draft the narrative and walk through BSA E-Filing submission. Prefer to learn first? Start with the free ComplianceSuite Academy.
We use essential cookies to make ComplianceSuite work. With your consent, we'll also use analytics and marketing cookies to improve the site and measure campaign performance. You can change your choice at any time. Read our Privacy Policy and Cookie Notice.