Jurisdictional Framework — United States
The United States banking framework
Built on the Bank Secrecy Act of 1970, fortified by the USA PATRIOT Act, and modernized by the Anti-Money Laundering Act of 2020 — the US regime sets the global benchmark for what a financial crime compliance program must be.
The statutory spine
The Bank Secrecy Act (BSA) established the recordkeeping and reporting foundation. The USA PATRIOT Act added customer identification, special due diligence for correspondent and private banking, and information-sharing provisions. The AMLA of 2020 is the most sweeping reform since 2001 — codifying national priorities, whistleblower incentives, and beneficial ownership reporting.
FFIEC examination expectations
While FinCEN writes the regulations, the federal banking agencies assess compliance using the FFIEC BSA/AML Examination Manual. A program is evaluated not just on technical compliance, but on the adequacy of its risk management relative to the institution's specific profile.
Enterprise risk assessment
The absolute foundation of the manual. Examiners expect a documented, analytical mapping of the institution's unique footprint across products, services, customers, and geographies — and internal controls that demonstrably flow from it.
Model risk management
Under OCC 11-12 and SR 11-7, transaction monitoring and sanctions screening systems are models. Examiners scrutinize validation, data lineage, and the statistical tuning of alert thresholds — untuned vendor defaults are a finding waiting to happen.
SAR decisioning
Clear, written escalation procedures from alert to investigation to filing. The sharpest scrutiny falls on the rationale for not filing — documentation must be robust enough to withstand regulatory second-guessing years later.
The Corporate Transparency Act
The CTA requires reporting companies to file Beneficial Ownership Information with FinCEN, reshaping the Customer Due Diligence landscape. Institutions must prepare to reconcile internal CDD collections with the federal database.
- — Shifts reliance toward verified central data.
- — Requires updates to onboarding workflows.
- — Impacts commercial banking CDD remediation.
FinCEN national priorities
Institutions are explicitly required to incorporate these priorities into risk assessments and monitoring tuning:
- — Corruption and cybercrime.
- — Terrorist financing, domestic and international.
- — Fraud and transnational criminal organizations.
- — Drug trafficking organization activity.
Practitioner Note
The Treasury's BSA modernization agenda signals a durable direction: risk-based, efficient, and innovation-tolerant. Programs built on defensible risk assessment — rather than checkbox coverage — are positioned for where the regime is going, not just where it has been.
United States
Facing a FinCEN registration, an exam, or a program buildout?
QAML's founder is the serving BSA/AML Compliance Officer of a large public US company and has stood up BSA programs at venture-backed fintechs from zero.