Bank Secrecy Act (BSA)

The Bank Secrecy Act is the U.S. framework for specified financial records, reports, AML programs, customer controls, and information sharing.

The Bank Secrecy Act (BSA) is the name commonly used for a group of U.S. statutes and regulations that require covered financial institutions and certain other businesses to keep specified records, file reports, and maintain controls that help authorities detect money laundering, terrorism financing, tax evasion, and other financial crime. The framework began with the Currency and Foreign Transactions Reporting Act of 1970 and has been amended many times.

The BSA does not impose one identical checklist on every financial business. Banks, broker-dealers, mutual funds, money services businesses, casinos, dealers in precious metals, and other covered sectors can have different program, reporting, registration, and recordkeeping rules.

Key Takeaways

  • FinCEN administers BSA regulations in 31 CFR Chapter X, while federal and state regulators may examine or enforce compliance for institutions they supervise.
  • A Currency Transaction Report generally concerns covered currency activity over USD 10,000 in a business day, including required aggregation.
  • Suspicious Activity Report rules use institution-specific thresholds, categories, and timing; they are not limited to transactions over USD 10,000.
  • A CTR or SAR is a regulatory report, not a judicial finding that a customer committed a crime.
  • Customer identification, due diligence, beneficial-ownership, AML/CFT program, and information-sharing duties depend on the covered institution and rule.
  • SARs and their existence are subject to strict confidentiality rules; customer communication must follow applicable law and policy.
  • Current regulations, form instructions, exemptions, and official guidance control a filing decision.

Bank Secrecy Act workflow showing customer controls and transaction records feeding monitoring, regulatory decisions, reports, retention, and supervisory review.

What the BSA Framework Includes

The BSA authorizes Treasury to require records and reports considered useful for criminal, tax, regulatory, intelligence, and counterterrorism purposes. Its modern framework includes statutes, FinCEN regulations, sector-specific rules, filing instructions, exemptions, administrative rulings, and guidance.

Common obligations include:

Control areaPurposeImportant limitation
AML/CFT programAssigns governance, controls, training, testing, and risk managementRequired elements vary by institution type
Customer identificationForms a reasonable belief about customer identityProcedures and exceptions depend on the applicable rule
Customer due diligenceUnderstands relationships and supports risk-based monitoringNot every institution has the same CDD rule
Beneficial-owner informationIdentifies relevant natural persons behind certain legal-entity customersDefinitions, exceptions, and transition rules must be checked
Currency reportingReports covered cash activity above the thresholdAggregation and exemptions affect the result
Suspicious-activity reportingReports specified activity meeting the applicable SAR ruleThresholds and reportable categories vary by sector
RecordkeepingPreserves transaction and customer evidenceRecord type and retention period vary
Information sharingSupports specified law-enforcement and institution-to-institution processesAccess, use, and confidentiality are controlled

The term “BSA/AML” is often used operationally, but the BSA is not the federal criminal money-laundering statute itself. Money-laundering offenses also appear in Title 18 of the U.S. Code.

CTR and SAR Are Different

FeatureCurrency Transaction ReportSuspicious Activity Report
Main triggerCovered transaction in physical currency over a stated thresholdFacts meeting the institution’s suspicious-activity rule
Public thresholdGenerally more than USD 10,000 in one business dayNo single universal threshold for every institution or report category
AggregationKnown same-person cash activity can be aggregatedReview can connect activity across time, accounts, entities, and channels
MeaningRoutine threshold reportReport of activity that meets a regulatory suspicion standard
Customer noticeCTR filing is not treated like SAR confidentialityA SAR or its existence generally must not be disclosed to the subject

Multiple cash transactions must generally be aggregated when the institution knows they are by or on behalf of the same person and total more than USD 10,000 in cash in or cash out during one business day. Cash deposits and withdrawals are assessed separately rather than netted.

SAR rules are different. Covered institutions apply the rule for their sector, investigate alerts, document relevant facts, and file when the applicable criteria are met. A low-value pattern can be reportable, while a large transaction can be legitimate and require only routine reporting.

Worked Example: Cash Activity and Suspicion

Assume a bank customer deposits USD 6,200 in cash at one branch and USD 5,300 at another branch for the same business on the same business day.

The bank knows both deposits are on behalf of the same business, so the cash-in total is USD 11,500. Subject to the current rules and any valid exemption, the bank generally files a Currency Transaction Report. That filing does not mean the deposits are unlawful.

Now assume the customer first asked how to avoid a report, changed a planned USD 11,500 deposit into smaller transactions, used several people, and gave inconsistent explanations. Those additional facts may warrant a suspicious-activity review for possible Structuring a Deposit. The bank should preserve evidence, apply its SAR rule, and avoid telling the customer whether a SAR was or will be filed.

The controls produce separate decisions:

  1. aggregate covered cash for the CTR test;
  2. determine whether an exemption applies;
  3. analyze the broader pattern under the SAR rule;
  4. retain supporting records and investigation evidence; and
  5. continue risk-based monitoring where appropriate.

Customer and Beneficial-Ownership Controls

BSA regulations require specified covered institutions to identify customers and, for defined legal-entity accounts, obtain and verify information about relevant beneficial owners. The rules do not mean that every owner of every business account is treated identically.

An effective process distinguishes:

  • the customer that opens or owns the account;
  • individuals authorized to act for the customer;
  • natural persons who satisfy the applicable ownership or control definition;
  • intermediaries, counterparties, and beneficiaries in transactions; and
  • changes that alter the customer’s expected activity or risk.

Customer due diligence supports monitoring, but identity verification alone does not establish the source of funds or prove that future transactions are legitimate.

BSA Reports and Records

The BSA framework includes more than CTRs and SARs. Depending on the person and activity, it can involve foreign-account reports, cross-border monetary-instrument reports, cash reports by trades or businesses, money-services-business registration, records for funds transfers or monetary instruments, and other filings.

Each report has its own filer, trigger, form, deadline, exemptions, and retention requirements. Businesses should not copy a bank procedure into another sector without checking that sector’s Chapter X rule.

Supporting documentation matters. FinCEN guidance says institutions must retain SAR supporting documentation and provide it to FinCEN or appropriate law-enforcement or supervisory agencies upon request under the applicable rules. The institution’s case file should explain the transactions, parties, analysis, filing decision, and source records without unsupported accusations.

Oversight and Enforcement

FinCEN is a bureau of the U.S. Treasury and administers the BSA regulatory framework. It receives and analyzes BSA data, issues rules and guidance, and can take enforcement action.

It is inaccurate to describe FinCEN as the only BSA authority. Federal banking agencies, the SEC, FINRA, the CFTC, the IRS, state supervisors, and other authorities can have examination or enforcement roles depending on the institution. Criminal matters are handled through the relevant law-enforcement and prosecutorial process.

Consequences can include remediation, supervisory findings, civil money penalties, restrictions, and criminal exposure where statutory elements are met. The legal basis and responsible authority must be identified rather than inferred from the BSA label alone.

Common Mistakes

Calling every transaction over USD 10,000 suspicious. A CTR is generally threshold-based and does not itself imply wrongdoing.

Saying SARs are filed regardless of amount. Thresholds and categories vary by institution and rule; some reportable situations can be below common thresholds.

Assuming the BSA applies identically to every financial firm. Program and reporting rules are sector-specific.

Telling a customer that a SAR was filed. SAR confidentiality requires controlled handling and escalation.

Treating customer identification as complete AML analysis. Identity, expected activity, ownership, transactions, counterparties, and changes can all matter.

Using an old form or threshold. Regulations, exemptions, filing instructions, and guidance can change.

How to Verify a BSA Requirement

  1. Identify the exact legal entity and covered institution category.
  2. Locate its regulations in 31 CFR Chapter X.
  3. Identify the transaction, account, customer, and report involved.
  4. Check thresholds, aggregation rules, exemptions, and deadlines.
  5. Review current FinCEN forms, instructions, rulings, and guidance.
  6. Check the relevant regulator’s examination manual or rulebook.
  7. Preserve the facts, analysis, disposition, and filing evidence.

Official Sources

FAQs

Does the BSA require a report for every transaction over $10,000?

No. The familiar threshold concerns covered transactions in currency and includes aggregation rules and exemptions. Noncash transactions and other report types use different tests.

Does filing a CTR mean the customer is suspected of a crime?

No. A CTR is generally a routine threshold report. Suspicious-activity reporting is a separate decision based on the applicable SAR rule and facts.

Can a bank tell a customer that it filed a SAR?

Generally, a SAR and information revealing its existence must not be disclosed to the person involved. Staff should follow the applicable confidentiality rule and institution procedures.

Does FinCEN alone enforce the BSA?

No. FinCEN administers the framework, but other federal and state regulators can examine and enforce requirements for institutions within their jurisdiction.

This article provides general U.S. financial-compliance education, not legal or compliance advice. Apply the current rule, institution type, facts, forms, and official instructions to a specific decision.

Browse Regulation