Compliance · AML
Building a BSA/AML program for a fintech startup
A Bank Secrecy Act and anti-money-laundering program is the first thing a partner bank, a state examiner or a licensing reviewer will ask to see. This guide sets out what the program has to contain, the order to build it in, and the reports it has to produce.
Not legal advice. The rules differ by type of institution. This page describes the requirements for money services businesses in 31 CFR Part 1022 and what partner banks commonly expect. Confirm your own obligations with counsel. Checked September 2026.
Who needs a program
Three groups of fintechs end up running a BSA/AML program:
- Money services businesses. A company that is an MSB under federal rules must have a written program under 31 CFR 1022.210, generally in place within 90 days after the business is established. See FinCEN MSB registration.
- State licensees. The Texas Money Services Modernization Act requires licensees and their authorized delegates to file the reports the Bank Secrecy Act requires (Texas Finance Code ยง152.206), and a compliance program is part of a license application.
- Bank partners. A fintech that is not itself subject to the rule often runs a program anyway, because the partner bank is, and the bank's program has to cover activity the fintech handles.
The required elements
The MSB rule requires a program that is reasonably designed to prevent the business from being used to facilitate money laundering and terrorist financing, commensurate with the risks posed by its location, size and the nature and volume of its services. It must be in writing, and it must include:
| Element | What it means in practice |
|---|---|
| Policies, procedures and internal controls | Customer identification, report filing, record creation and retention, and responding to law enforcement requests |
| A designated compliance officer | A named person responsible for day-to-day compliance, with enough authority and resources to do the job |
| Training | Education for appropriate staff, including how to spot suspicious transactions |
| Independent review | Periodic testing of the program by someone other than the compliance officer, scaled to the risk |
Banks work under a similar framework and add customer due diligence as an explicit element, which is why fintech checklists often speak of "five pillars". A written risk assessment is the thread that ties the elements together, and FinCEN's April 2026 proposed rule would make it an explicit requirement. As of September 2026 that rule is still a proposal.
Build it in this order
- Write the risk assessment. List your products, customer types, geographies, payment channels and partners, and rate the money laundering, terrorist financing and sanctions risk of each. The rest of the program should follow from this document.
- Appoint the compliance officer. Choose someone with relevant experience and a direct line to leadership. A small company can use outside support, but one person inside the company should own the program.
- Write the policy and procedures. The policy says what you do; procedures say how, who and when. Examiners test the procedures against what actually happens.
- Set up customer identification. Decide what you collect and verify for individuals and businesses, and when you apply enhanced due diligence. See KYC and KYB requirements.
- Screen for sanctions. Screen customers and counterparties against OFAC lists at onboarding and on an ongoing basis, including when lists change.
- Monitor transactions. Write rules that match your risk assessment, document how alerts are reviewed and closed, and tune the rules as you learn.
- Set up reporting. Build the workflow for suspicious activity reports, currency transaction reports if you handle cash, and funds transfer recordkeeping.
- Train people. Train at hire and at least yearly, with role-specific content for support, operations and engineering staff.
- Arrange independent testing. Plan a review before or soon after launch and at a regular interval after that, and track findings to closure.
Reports and thresholds for MSBs
| Requirement | Threshold and timing | Rule |
|---|---|---|
| Suspicious activity report (SAR) | Transactions of at least $2,000 that the MSB knows, suspects or has reason to suspect meet the rule's criteria; filed within 30 calendar days of initial detection | 31 CFR 1022.320 |
| SAR confidentiality | An MSB may not disclose a SAR or information that would reveal its existence, with limited exceptions | 31 CFR 1022.320(d) |
| Currency transaction report (CTR) | Cash transactions of more than $10,000 in one business day | 31 CFR 1010.311 |
| Funds transfer records | Transmittals of $3,000 or more, with information that travels with the transfer | 31 CFR 1010.410 |
| Retention | SARs and supporting documents for five years from filing; most other records for five years | 31 CFR 1022.320(c), 1010.430 |
What bank partners look for
- A risk assessment that describes your actual product, not a template
- Clear division of duties between the bank and the fintech, written into the program agreement
- Evidence that alerts are worked: queues, timelines, case notes and quality checks
- A process for escalating potential SARs to the bank when the bank is the filer
- Metrics the bank can review, such as alert volumes, backlog, SAR referrals and screening hits
- Staffing that grows with volume, and a plan for when it does not
More on the bank relationship is in sponsor bank due diligence.
Mistakes that show up in exams and audits
- Monitoring rules copied from a vendor default that do not match the risk assessment
- Alerts closed without notes explaining why the activity was not suspicious
- Growth outpacing the compliance team, leaving an alert backlog
- No independent test, or a test whose findings were never fixed
- Records scattered across tools, so the company cannot reconstruct a customer's history on request
Common questions
Can a startup outsource its AML program?
Vendors can provide identity verification, screening, monitoring software and even staff. The legal responsibility stays with the company, and a named person inside the company should own the program.
How often should independent testing happen?
The MSB rule requires independent review scaled to the risk but does not set a fixed interval. State regulators and partner banks often set expectations of their own, so check both.
Does a fintech file SARs itself?
An MSB files its own. In a bank partnership where the bank is the regulated institution, the bank usually files, and the fintech's job is to detect and escalate promptly under the program agreement.
Is OFAC screening part of the BSA program?
Sanctions compliance comes from separate Treasury rules administered by OFAC, which apply to U.S. persons generally. Most companies run the two programs together because they share data and tools.
The wider set of obligations is on the fintech compliance checklist.
Last reviewed 2026-09-17