Home Compliance AML / KYC

AML / KYC Compliance Guide 2026

The complete guide to Anti-Money Laundering and Know Your Customer compliance — Bank Secrecy Act requirements, FinCEN CDD Rule, 5 BSA pillars, SAR/CTR filing, FATF standards, and the Corporate Transparency Act.

✓ FinCEN Official Source CTA BOI Rule — 2024 Updated March 2026

What Is AML / KYC?

✓ Verified Data Verified: FinCEN official BSA documentation

Anti-Money Laundering (AML) refers to the laws, regulations, and programs designed to detect and prevent the conversion of illegally-obtained funds ("dirty money") into seemingly legitimate assets ("clean money"). The three stages of money laundering are placement (introducing illicit cash into the financial system), layering (concealing the trail), and integration (making funds appear legitimate). (FinCEN BSA Overview)

Know Your Customer (KYC) is the due diligence process by which financial institutions verify customer identity, assess customer risk, and monitor ongoing account activity. KYC is the customer-facing component of a broader AML compliance program. (FinCEN CDD Final Rule)

The primary US law governing AML is the Bank Secrecy Act (BSA) of 1970 (31 U.S.C. 5311–5336), as amended by the USA PATRIOT Act (2001), the Anti-Money Laundering Act of 2020 (AMLA), and the Corporate Transparency Act (2021). Enforcement is led by FinCEN (US Treasury), with examination by federal banking regulators (OCC, FDIC, Fed, NCUA). (31 U.S.C. 5311)

1970
Bank Secrecy Act Enacted
5
BSA Program Pillars
$10K
CTR Threshold
30 days
SAR Filing Deadline
$1.9B
Largest AML Fine (HSBC)

The 5 BSA / AML Program Pillars

✓ Verified Data FinCEN CDD Final Rule adds 5th pillar, effective May 2018

FinCEN requires covered financial institutions to maintain a written AML compliance program with at minimum five elements. (FinCEN CDD Final Rule, May 2018) as of March 2026

Pillar 1
Internal Controls & Policies
Written BSA/AML policies, procedures, and controls that identify and manage money laundering risks. Must be approved by the board of directors and reviewed annually.
Pillar 2
BSA Compliance Officer
Designate a qualified individual responsible for day-to-day BSA/AML program management, filing SARs and CTRs, and coordinating with law enforcement.
Pillar 3
Ongoing Employee Training
Annual AML training for all applicable employees covering red flags, reporting obligations, tipping-off prohibition, and institution-specific procedures.
Pillar 4
Independent Testing (Audit)
Annual independent testing of the BSA/AML compliance program by qualified internal audit staff or an external firm. Must evaluate effectiveness of controls and CDD procedures.
Pillar 5
Customer Due Diligence (CDD)
The fifth pillar added by the FinCEN CDD Final Rule (2016, effective May 2018): Know your customers, understand the nature of their transactions, and conduct ongoing monitoring. Includes Beneficial Ownership for legal entities.

SAR & CTR Filing Requirements

✓ Verified Data FinCEN official SAR/CTR requirements

Currency Transaction Reports (CTRs)

Financial institutions must file a CTR for any single or aggregated cash transaction(s) of more than $10,000 by or for the same person in a business day. CTRs must be filed within 15 days of the transaction. (31 CFR § 1010.311)

Structuring Warning: Breaking up transactions specifically to avoid the $10,000 CTR threshold ("structuring" or "smurfing") is itself a federal crime under 31 U.S.C. 5324, punishable by up to 5 years imprisonment, regardless of whether the underlying funds are legitimate.

Suspicious Activity Reports (SARs)

Financial institutions must file a SAR when they know, suspect, or have reason to suspect that a transaction involves funds from illegal activity, is designed to evade BSA requirements, lacks a lawful purpose, or involves potential insider fraud exceeding $5,000. (31 CFR § 1020.320)

Report TypeThresholdFiling DeadlineRetention
Currency Transaction Report (CTR)Cash transactions >$10,00015 calendar days5 years
Suspicious Activity Report (SAR)$5,000+ (depository inst.) / $2,000+ (broker-dealer)30 calendar days (60 if no known suspect)5 years
Foreign Bank Account Report (FBAR)Foreign accounts >$10,000 aggregateApril 15 (6-month extension available)5 years
Form 8300 (IRS/FinCEN)Cash >$10,000 from trade/business15 days after receipt5 years

Customer Due Diligence (CDD) & Beneficial Ownership

✓ Verified Data FinCEN CDD Final Rule, effective May 2018; CTA BOI Rule effective 2024

The FinCEN CDD Final Rule (effective May 11, 2018) requires covered financial institutions to identify and verify the beneficial owners of legal entity customers — individuals who own 25%+ or exercise significant control. (FinCEN CDD Final Rule)

CDD Four Core Elements

Corporate Transparency Act (CTA) — Beneficial Ownership Information (BOI)

Effective January 1, 2024, the Corporate Transparency Act requires most US companies (LLCs, corporations, etc.) to report beneficial ownership information directly to FinCEN. Note: In early 2025, BOI reporting was subject to court injunctions; consult FinCEN.gov for current status. (FinCEN BOI Rule)

AML Penalties — Historical Enforcement Actions

✓ Verified Data Verified from FinCEN/DOJ public enforcement records
InstitutionYearFineViolation
HSBC2012$1.9 billionLaundered $881M for drug cartels; failed SAR filing; Iran sanctions violations
Deutsche Bank2017$630 millionRussian mirror trading scheme; $10B in suspicious equities transactions
Western Union2017$586 millionAnti-money laundering failures; willfully failed to maintain effective AML program
BitMEX2021$100 millionFailure to implement required BSA/AML program; KYC failures for crypto exchange
Binance2023$4.3 billionBSA/AML failures; OFAC sanctions violations; failure to file SARs

Source: FinCEN enforcement actions, DOJ press releases, and FinCEN/CFTC published settlement documents.

AML / KYC Compliance Checklist

~ AI-Estimated Based on FinCEN BSA examination manual and FFIEC guidelines
This checklist reflects BSA/AML program requirements for US financial institutions. Non-bank financial institutions (NBFIs), crypto businesses, and international entities may have different requirements.

Frequently Asked Questions

Do cryptocurrency exchanges need BSA/AML programs?
Yes. FinCEN has clarified since 2013 that money services businesses (MSBs) engaging in virtual currency exchange or transmission must register with FinCEN and implement BSA/AML programs — including CIP, SAR filing, and CTR filing. The 2023 Binance settlement for $4.3 billion underscores enforcement severity in the crypto space.
What is the difference between AML and CFT?
AML (Anti-Money Laundering) focuses on preventing profits of crime from entering the financial system. CFT (Countering the Financing of Terrorism) addresses preventing funds from reaching terrorist organizations. While distinct legal frameworks exist, in practice compliance programs address both together — referred to as AML/CFT. The FATF 40 Recommendations cover both.
What is a Politically Exposed Person (PEP)?
A PEP is a current or former senior government official, political party official, or closely associated individual who presents elevated corruption and money laundering risk. US banks must apply enhanced due diligence (EDD) to PEPs and their immediate family members and close associates. FATF defines the PEP standard internationally.
What is FATF and how does it affect US compliance?
The Financial Action Task Force (FATF) is an intergovernmental body that sets international AML/CFT standards through its 40 Recommendations. Countries on the FATF "grey list" or "black list" require enhanced due diligence from US financial institutions when processing transactions from those jurisdictions. The US is a founding FATF member; US laws substantially implement the 40 Recommendations.

Related Compliance Topics

Navigate the AML/BSA landscape with confidence

Weekly regulatory updates, BSA/AML alerts, and compliance insights — free.

⚖️
Need deeper legal & compliance resources?
Contract templates, legal guides, compliance frameworks, and regulatory intelligence — on LegalStackHub.
LegalStackHub →
📈 THE FINANCE STACK

Get your weekly market edge. Free.

Market pulse, stock spotlights, and actionable frameworks — delivered every week.

No spam · Unsubscribe anytime · View all issues →