The Bank Secrecy Act is the U.S. framework for specified financial records, reports, AML programs, customer controls, and information sharing.
The Bank Secrecy Act (BSA) is the name commonly used for a group of U.S. statutes and regulations that require covered financial institutions and certain other businesses to keep specified records, file reports, and maintain controls that help authorities detect money laundering, terrorism financing, tax evasion, and other financial crime. The framework began with the Currency and Foreign Transactions Reporting Act of 1970 and has been amended many times.
The BSA does not impose one identical checklist on every financial business. Banks, broker-dealers, mutual funds, money services businesses, casinos, dealers in precious metals, and other covered sectors can have different program, reporting, registration, and recordkeeping rules.
The BSA authorizes Treasury to require records and reports considered useful for criminal, tax, regulatory, intelligence, and counterterrorism purposes. Its modern framework includes statutes, FinCEN regulations, sector-specific rules, filing instructions, exemptions, administrative rulings, and guidance.
Common obligations include:
| Control area | Purpose | Important limitation |
|---|---|---|
| AML/CFT program | Assigns governance, controls, training, testing, and risk management | Required elements vary by institution type |
| Customer identification | Forms a reasonable belief about customer identity | Procedures and exceptions depend on the applicable rule |
| Customer due diligence | Understands relationships and supports risk-based monitoring | Not every institution has the same CDD rule |
| Beneficial-owner information | Identifies relevant natural persons behind certain legal-entity customers | Definitions, exceptions, and transition rules must be checked |
| Currency reporting | Reports covered cash activity above the threshold | Aggregation and exemptions affect the result |
| Suspicious-activity reporting | Reports specified activity meeting the applicable SAR rule | Thresholds and reportable categories vary by sector |
| Recordkeeping | Preserves transaction and customer evidence | Record type and retention period vary |
| Information sharing | Supports specified law-enforcement and institution-to-institution processes | Access, use, and confidentiality are controlled |
The term “BSA/AML” is often used operationally, but the BSA is not the federal criminal money-laundering statute itself. Money-laundering offenses also appear in Title 18 of the U.S. Code.
| Feature | Currency Transaction Report | Suspicious Activity Report |
|---|---|---|
| Main trigger | Covered transaction in physical currency over a stated threshold | Facts meeting the institution’s suspicious-activity rule |
| Public threshold | Generally more than USD 10,000 in one business day | No single universal threshold for every institution or report category |
| Aggregation | Known same-person cash activity can be aggregated | Review can connect activity across time, accounts, entities, and channels |
| Meaning | Routine threshold report | Report of activity that meets a regulatory suspicion standard |
| Customer notice | CTR filing is not treated like SAR confidentiality | A SAR or its existence generally must not be disclosed to the subject |
Multiple cash transactions must generally be aggregated when the institution knows they are by or on behalf of the same person and total more than USD 10,000 in cash in or cash out during one business day. Cash deposits and withdrawals are assessed separately rather than netted.
SAR rules are different. Covered institutions apply the rule for their sector, investigate alerts, document relevant facts, and file when the applicable criteria are met. A low-value pattern can be reportable, while a large transaction can be legitimate and require only routine reporting.
Assume a bank customer deposits USD 6,200 in cash at one branch and USD 5,300 at another branch for the same business on the same business day.
The bank knows both deposits are on behalf of the same business, so the cash-in total is USD 11,500. Subject to the current rules and any valid exemption, the bank generally files a Currency Transaction Report. That filing does not mean the deposits are unlawful.
Now assume the customer first asked how to avoid a report, changed a planned USD 11,500 deposit into smaller transactions, used several people, and gave inconsistent explanations. Those additional facts may warrant a suspicious-activity review for possible Structuring a Deposit. The bank should preserve evidence, apply its SAR rule, and avoid telling the customer whether a SAR was or will be filed.
The controls produce separate decisions:
BSA regulations require specified covered institutions to identify customers and, for defined legal-entity accounts, obtain and verify information about relevant beneficial owners. The rules do not mean that every owner of every business account is treated identically.
An effective process distinguishes:
Customer due diligence supports monitoring, but identity verification alone does not establish the source of funds or prove that future transactions are legitimate.
The BSA framework includes more than CTRs and SARs. Depending on the person and activity, it can involve foreign-account reports, cross-border monetary-instrument reports, cash reports by trades or businesses, money-services-business registration, records for funds transfers or monetary instruments, and other filings.
Each report has its own filer, trigger, form, deadline, exemptions, and retention requirements. Businesses should not copy a bank procedure into another sector without checking that sector’s Chapter X rule.
Supporting documentation matters. FinCEN guidance says institutions must retain SAR supporting documentation and provide it to FinCEN or appropriate law-enforcement or supervisory agencies upon request under the applicable rules. The institution’s case file should explain the transactions, parties, analysis, filing decision, and source records without unsupported accusations.
FinCEN is a bureau of the U.S. Treasury and administers the BSA regulatory framework. It receives and analyzes BSA data, issues rules and guidance, and can take enforcement action.
It is inaccurate to describe FinCEN as the only BSA authority. Federal banking agencies, the SEC, FINRA, the CFTC, the IRS, state supervisors, and other authorities can have examination or enforcement roles depending on the institution. Criminal matters are handled through the relevant law-enforcement and prosecutorial process.
Consequences can include remediation, supervisory findings, civil money penalties, restrictions, and criminal exposure where statutory elements are met. The legal basis and responsible authority must be identified rather than inferred from the BSA label alone.
Calling every transaction over USD 10,000 suspicious. A CTR is generally threshold-based and does not itself imply wrongdoing.
Saying SARs are filed regardless of amount. Thresholds and categories vary by institution and rule; some reportable situations can be below common thresholds.
Assuming the BSA applies identically to every financial firm. Program and reporting rules are sector-specific.
Telling a customer that a SAR was filed. SAR confidentiality requires controlled handling and escalation.
Treating customer identification as complete AML analysis. Identity, expected activity, ownership, transactions, counterparties, and changes can all matter.
Using an old form or threshold. Regulations, exemptions, filing instructions, and guidance can change.
This article provides general U.S. financial-compliance education, not legal or compliance advice. Apply the current rule, institution type, facts, forms, and official instructions to a specific decision.