BSA compliance means following U.S. federal rules under the Bank Secrecy Act (BSA). These rules require financial institutions to watch for and report suspicious financial activity that could signal money laundering, fraud, or other crimes.
What’s happening with BSA compliance?
BSA compliance forces financial institutions to file Currency Transaction Reports (CTRs) for cash transactions of $10,000 or more in a single day, and Suspicious Activity Reports (SARs) whenever they suspect illegal activity
Since Congress passed the BSA in 1970, it’s been the cornerstone of anti-money laundering efforts. Today, the rules apply not just to banks and credit unions, but also to money services businesses, broker-dealers, casinos, and some fintech companies. Get it wrong, and the fallout can be brutal—massive fines, criminal charges, or even losing your license. That’s why most institutions rely on rock-solid internal controls, a dedicated BSA compliance officer, independent testing, and ongoing staff training to stay on the right side of the law.
The BSA got a major update in 2001 with the USA PATRIOT Act, which beefed up requirements around customer identification, due diligence, and information-sharing programs. Now, compliance programs also need to tackle risks tied to correspondent banking and private banking accounts, as outlined in FinCEN's 2025 guidance on enhanced due diligence.
How do we actually achieve BSA compliance?
Start by naming a BSA compliance officer, automating CTR filings, scheduling quarterly board reviews, and building solid training and record-keeping systems
Put someone in charge
• Create a dedicated “BSA Compliance Officer” role in your HR system.
• Grant this person full BSA Admin rights in your core banking platform (FIS, Fiserv, or Jack Henry) via Settings → User Management → Add Role → BSA Compliance Officer.
• Make sure they have direct access to senior leadership and the board.
Build a proper BSA/AML program
• Grab a current template like “BSA AML Program Template 2026” to structure your approach.
• Cover the four required pillars from 31 CFR §1020.210: internal controls, annual independent testing, a designated compliance officer, and a yearly training schedule.
• Store the finalized program in a secure shared drive (e.g., \\Compliance\BSA\Program) and update it every year—or whenever regulations change.
Automate CTR filings where you can
• Turn on “Auto-calculate daily aggregate” in your BSA module under Compliance → BSA → CTR Settings.
• Set the threshold at $10,000 for single-day cash or cash equivalents.
• Test your setup: try a $9,999 deposit followed by a $1 deposit—no CTR should appear. Then combine deposits to hit $10,000 and confirm the CTR triggers correctly.
Keep the board in the loop
• Block off time every quarter with a recurring calendar event titled “Board Meeting → BSA Update.”
• Pull data into the template at \\Compliance\BSA\Board Report Template Q1 2026.docx—include SAR/CTR trends, suspicious activity patterns, training stats, and any open audit findings.
• Have the BSA compliance officer present and ready to answer questions.
Train your team—everyone
• Enroll staff in a SCORM-compliant LMS like Cornerstone or Moodle.
• Assign Course ID BSA-2026-v3.2 to all customer-facing or cash-handling roles.
• Require 100% completion and auto-save certificates to \\Compliance\BSA\Training Records for easy audits.
• Track exemptions and keep a log of any training gaps.
Hold onto records for five years
• Stash CTRs, SARs, training records, and board reports in a secure SharePoint or similar system under Site → Compliance → BSA Archive → [Year].
• Use clear naming conventions: CTR_YYYYMMDD_BranchID_Sequence.xlsx for CTRs and SAR_YYYYMMDD_BranchID_Sequence.pdf for SARs.
• Make sure records are tamper-proof and examiners can access them within 24–48 hours.
What if our automated systems fail or gaps pop up?
If automation breaks down or you spot compliance gaps, switch to manual processes, update risk assessments using FinCEN templates, and fix training shortfalls fast to avoid penalties
CTRs not firing automatically?
• Fall back to manual entry: go to Compliance → BSA → CTR → New Entry → Manual Entry.
• Pull yesterday’s transaction tape from your core system as a CSV and import it into the BSA module to catch anything missed.
Missing risk assessment in board reports?
• Grab the latest FinCEN BSA E-Filing XML risk-assessment template (updated March 2025) from FinCEN.
• Fill out the “Products & Services” tab—it auto-generates risk heat maps for high-risk lines of business, making board presentations a breeze.
Training stuck at 98% completion?
• Run the “BSA Hold” report in your LMS under Reports → Compliance → Users with Incomplete BSA Training.
• Send bulk reminders via the LMS scheduler. If progress stalls, loop in HR for direct follow-up and off-cycle completion tracking.
SAR filings delayed or full of errors?
• Test SAR templates in the FinCEN BSA E-Filing sandbox before going live.
• Make sure every SAR narrative spells out the “why suspicious” in specific terms and follows FinCEN’s updated guidance from March 2026.
In 2024, FinCEN issued updated guidance emphasizing the need for institutions to document decisions around SAR filings, including cases where suspicious activity was identified but not reported. This reflects a broader push toward greater transparency in BSA compliance practices FinCEN News Release.
How can we prevent BSA compliance failures before they happen?
Keep compliance failures at bay by updating customer risk ratings twice a year, testing SAR/CTR thresholds every quarter, running surprise cash counts annually, and refreshing AML typology lists as soon as FinCEN issues updates
According to the Office of the Comptroller of the Currency (OCC), financial institutions should also conduct periodic reviews of their BSA/AML programs to ensure they stay effective as risks evolve—especially with cryptocurrency and other emerging financial technologies.
What’s Happening
The BSA is the legal backbone that forces banks, credit unions, money-services businesses, and even some fintechs to document large or questionable cash movements. Two key duties stand out:
File a Currency Transaction Report (CTR) when someone hands over cash or cash equivalents totaling $10,000 or more on the same business day.
File a Suspicious Activity Report (SAR) when you suspect—but can’t prove—funds come from illegal activity, no matter the dollar amount.
It also demands four program-management pillars: strong internal controls, independent testing, a named compliance officer, and ongoing training. Miss any one of these, and examiners won’t hesitate to hit you with civil penalties or even cease-and-desist orders.
Step-by-Step Solution
Appoint the BSA Compliance Officer
• Set up a new role in your HR system called “BSA Compliance Officer.”
• In most core banking platforms (FIS, Fiserv, Jack Henry) the route is Settings → User Management → Add Role → BSA Compliance Officer. Give full BSA Admin rights.
Draft the Written BSA/AML Compliance Program
• Grab the Word template: File → New → Search “BSA AML Program Template 2026”.
• You’ll need these sections per 31 CFR §1020.210:
– Internal controls
– Independent testing schedule (once a year)
– Designation of compliance officer
– Training calendar
• Save it in the shared drive under \\Compliance\BSA\Program.
Turn on CTR Automation (if your core supports it)
• Go here: Compliance → BSA → CTR Settings → Enable “Auto-calculate daily aggregate”.
• Set the threshold at $10,000 single-day aggregate.
• Test it by running a $9,999 cash deposit, then a $1 deposit right after; confirm the system stays quiet, then drop another $1 to trigger the CTR.
Schedule Quarterly Board Reports
• Create a recurring calendar event: Board Meeting → BSA Update.
• Use this template: \\Compliance\BSA\Board Report Template Q1 2026.docx.
• Required slides: fresh SAR/CTR trends, typologies spotted, training completion rates, open audit findings.
Train Staff (Annual Requirement)
• Pick any SCORM-compliant LMS (Cornerstone, Moodle, etc.).
• Course ID: BSA-2026-v3.2.
• Everyone with customer-facing or cash-handling roles must finish it 100 %.
• Certificates auto-save to \\Compliance\BSA\Training Records.
Keep the Logs for Five Years
• Store CTR and SAR images in the secure SharePoint archive under Site → Compliance → BSA Archive → [Year].
• Use this naming format: CTR_YYYYMMDD_BranchID_Sequence.xlsx.
If This Didn’t Work
CTRs not firing automatically?
• Switch to manual mode: Compliance → BSA → CTR → New Entry → Manual Entry.
• Pull yesterday’s transaction tape from the core in CSV and import it into the BSA module.
Board reports missing risk assessment?
• Grab the latest FinCEN BSA E-Filing XML risk-assessment template (updated March 2025).
• Fill in the “Products & Services” tab; the tool builds heat maps for high-risk lines automatically.
Training completion stuck at 98 %?
• Run the “BSA Hold” report in the LMS: Reports → Compliance → Users with Incomplete BSA Training.
• Send a bulk reminder via the LMS scheduler; if it’s still stuck, loop in HR for off-cycle completion.
Prevention Tips
Action
Frequency
Tool
Update customer risk ratings
Semi-annually
Core banking risk-score engine
Test SAR-CTR thresholds
Edited and fact-checked by the TechFactsHub editorial team.
Ryan Foster is a networking and cybersecurity writer with 12 years of experience as a network engineer. He's configured more routers than he can count and firmly believes that 90% of internet problems are DNS-related. He lives in Austin, TX.