FintechAustin

Compliance · AML

Building a BSA/AML program for a fintech startup

A Bank Secrecy Act and anti-money-laundering program is the first thing a partner bank, a state examiner or a licensing reviewer will ask to see. This guide sets out what the program has to contain, the order to build it in, and the reports it has to produce.

Not legal advice. The rules differ by type of institution. This page describes the requirements for money services businesses in 31 CFR Part 1022 and what partner banks commonly expect. Confirm your own obligations with counsel. Checked September 2026.

Who needs a program

Three groups of fintechs end up running a BSA/AML program:

The required elements

The MSB rule requires a program that is reasonably designed to prevent the business from being used to facilitate money laundering and terrorist financing, commensurate with the risks posed by its location, size and the nature and volume of its services. It must be in writing, and it must include:

ElementWhat it means in practice
Policies, procedures and internal controlsCustomer identification, report filing, record creation and retention, and responding to law enforcement requests
A designated compliance officerA named person responsible for day-to-day compliance, with enough authority and resources to do the job
TrainingEducation for appropriate staff, including how to spot suspicious transactions
Independent reviewPeriodic testing of the program by someone other than the compliance officer, scaled to the risk

Banks work under a similar framework and add customer due diligence as an explicit element, which is why fintech checklists often speak of "five pillars". A written risk assessment is the thread that ties the elements together, and FinCEN's April 2026 proposed rule would make it an explicit requirement. As of September 2026 that rule is still a proposal.

Build it in this order

  1. Write the risk assessment. List your products, customer types, geographies, payment channels and partners, and rate the money laundering, terrorist financing and sanctions risk of each. The rest of the program should follow from this document.
  2. Appoint the compliance officer. Choose someone with relevant experience and a direct line to leadership. A small company can use outside support, but one person inside the company should own the program.
  3. Write the policy and procedures. The policy says what you do; procedures say how, who and when. Examiners test the procedures against what actually happens.
  4. Set up customer identification. Decide what you collect and verify for individuals and businesses, and when you apply enhanced due diligence. See KYC and KYB requirements.
  5. Screen for sanctions. Screen customers and counterparties against OFAC lists at onboarding and on an ongoing basis, including when lists change.
  6. Monitor transactions. Write rules that match your risk assessment, document how alerts are reviewed and closed, and tune the rules as you learn.
  7. Set up reporting. Build the workflow for suspicious activity reports, currency transaction reports if you handle cash, and funds transfer recordkeeping.
  8. Train people. Train at hire and at least yearly, with role-specific content for support, operations and engineering staff.
  9. Arrange independent testing. Plan a review before or soon after launch and at a regular interval after that, and track findings to closure.

Reports and thresholds for MSBs

RequirementThreshold and timingRule
Suspicious activity report (SAR)Transactions of at least $2,000 that the MSB knows, suspects or has reason to suspect meet the rule's criteria; filed within 30 calendar days of initial detection31 CFR 1022.320
SAR confidentialityAn MSB may not disclose a SAR or information that would reveal its existence, with limited exceptions31 CFR 1022.320(d)
Currency transaction report (CTR)Cash transactions of more than $10,000 in one business day31 CFR 1010.311
Funds transfer recordsTransmittals of $3,000 or more, with information that travels with the transfer31 CFR 1010.410
RetentionSARs and supporting documents for five years from filing; most other records for five years31 CFR 1022.320(c), 1010.430

What bank partners look for

More on the bank relationship is in sponsor bank due diligence.

Mistakes that show up in exams and audits

Common questions

Can a startup outsource its AML program?

Vendors can provide identity verification, screening, monitoring software and even staff. The legal responsibility stays with the company, and a named person inside the company should own the program.

How often should independent testing happen?

The MSB rule requires independent review scaled to the risk but does not set a fixed interval. State regulators and partner banks often set expectations of their own, so check both.

Does a fintech file SARs itself?

An MSB files its own. In a bank partnership where the bank is the regulated institution, the bank usually files, and the fintech's job is to detect and escalate promptly under the program agreement.

Is OFAC screening part of the BSA program?

Sanctions compliance comes from separate Treasury rules administered by OFAC, which apply to U.S. persons generally. Most companies run the two programs together because they share data and tools.

The wider set of obligations is on the fintech compliance checklist.

Last reviewed 2026-09-17