Module 19 | Global Financial Crimes, Risk, and RegTech Library
Research verification date: 2026-08-09
Primary jurisdictions: United States federal framework, with state and cross-border operating implications.
Important notice: Educational material only; not legal advice. It does not determine obligations in any jurisdiction or replace legal counsel, regulator engagement, institution-specific risk assessment, or a documented customer, transaction, product, or account decision.
Source Quality and Currency Note
Primary-source grounding includes U.S. statutes and regulations, FinCEN and FFIEC materials, OFAC guidance, and official DOJ/FinCEN enforcement releases. U.S. legal analysis is fact-specific. The module does not provide legal advice or a conclusion about jurisdiction, licensing, sanctions exposure, reportability, or customer action.
How to Use This Module
Read this module in three passes if useful:
- Enterprise leader pass: executive thesis, decision map, Global Core / Local Edge model, maturity profile, failure cascade and executive discussion questions.
- Operator pass: workflows, decision rights, metrics, delivery dependencies, quality controls, jurisdictional configuration and execution checklists.
- Specialist pass: legal and supervisory architecture, technical terminology, reporting, data, evidence, test design, enforcement/supervisory cases and glossary.
Learning Objectives
- Explain the respective roles of the BSA, AMLA, FinCEN, federal banking agencies, DOJ, OFAC, securities and commodities regulators, and states.
- Translate core BSA program, reporting, recordkeeping, information-sharing, and customer-due-diligence concepts into executable decision paths.
- Distinguish AML/CFT, sanctions, criminal enforcement, prudential supervision, consumer-protection, and state-law implications.
- Assess how U.S. enforcement and supervisory actions test governance, data, monitoring, ownership, transactions, and remediation.
- Design a U.S. regulatory-obligation map that supports a global institution without assuming U.S. rules are universally extraterritorial.
- Recognize current modernization developments as proposed, final, or guidance-level rather than treating all policy signals as binding law.
Primary-Source Spine
The source strategy for this module is: U.S. statutes and regulations; FinCEN, OFAC, FFIEC, prudential supervisors, DOJ, and official enforcement material. Representative source anchors include S01: U.S. House Office of the Law Revision Counsel; S02: U.S. Congress / FinCEN; S03: Financial Crimes Enforcement Network; S04: Financial Crimes Enforcement Network; S05: Financial Crimes Enforcement Network; S06: Federal Financial Institutions Examination Council; S07: Financial Crimes Enforcement Network; S08: Financial Crimes Enforcement Network. Material legal, supervisory, enforcement and operating claims are identified in the companion claim/evidence ledger. [S01][S02][S03]
Executive Thesis
The United States financial-crimes framework is not one statute, one regulator, or one control standard. It is a layered system of criminal law, recordkeeping and reporting duties, prudential supervision, securities and commodities rules, consumer-protection authorities, sanctions, anti-corruption enforcement, state law, and law-enforcement information requests. The practical challenge for a regulated institution is to turn that system into one coherent operating model without pretending that its authorities are interchangeable. A Bank Secrecy Act requirement is not an OFAC prohibition; a prudential examination finding is not a criminal charge; a suspicious-activity report does not decide whether an account should be closed; and a state license obligation may materially change product design even when federal requirements are met.
The BSA provides the reporting and recordkeeping backbone, while FinCEN administers key rules, information-sharing mechanisms, and financial-intelligence functions. AMLA 2020 added modernization and effectiveness-oriented elements to the statutory environment. Federal banking agencies supervise insured depository institutions within their remits; the SEC and CFTC oversee relevant market participants; the DOJ prosecutes criminal violations; state authorities retain major roles in licensing, money transmission, consumer protection, and enforcement; OFAC administers sanctions. [S01][S02][S03][S06][S11] A mature U.S. program therefore must map the legal source, supervisory owner, operational control, evidence type, escalation path, and reporting recipient for every material obligation.
The strategic error is to use the word “compliance” as a substitute for that mapping. Strong programs use a single enterprise control spine but preserve separate legal decision paths. They know when to file a SAR, respond to a 314(a) request, evaluate 314(b) sharing, block or reject a transaction under sanctions rules, preserve records, respond to a subpoena, make a prudential escalation, and determine customer action under their own risk appetite. They use policy, data, and technology to coordinate those decisions, rather than conflating them.
Executive decision rule. Before accepting, changing, centralising, outsourcing, automating, restricting, reporting, or closing a material financial-crime control, require a clear statement of the applicable question, the in-scope population, the accountable owner, the decision evidence, the local legal configuration, the quality test and the residual-risk authority.
The Questions This Module Answers
- Which legal source creates the obligation, and which authority can test or enforce it?
- What facts trigger BSA reporting, sanctions action, information sharing, or a prudential escalation?
- How should a global program distinguish U.S.-person, U.S.-nexus, correspondent, and local-law exposure?
- Where do state licensing and state enforcement change the operating model?
- What evidence will a regulator or prosecutor expect after a control failure?
- How should a program treat proposed rules and supervisory signals before they become binding requirements?
1. Executive Layer
The strategic stakes
Financial-crimes capability becomes strategically material when it affects what customers can be served, which products can be launched, how fast payments can move, whether a market can be entered, which relationships can be retained, what data can be used, and whether regulators or partners consider the institution trustworthy. The leadership task is to avoid two bad abstractions: viewing financial crime as an isolated compliance overhead, or treating every operational difficulty as a legal prohibition. The discipline is to identify the actual source of risk and then design an evidence-led decision path that is proportionate, timely, fair and sustainable.
Every executive should ask four linked questions. First, exposure: what customers, products, transactions, geographies, delivery channels, intermediaries, technologies and networks create the risk? Second, control: which preventive, detective, investigative, reporting, action and assurance mechanisms should respond? Third, proof: what data, documents, logs, reviewer rationale, quality results, model evidence and authority records prove the mechanism works? Fourth, adaptation: how will the institution detect that the risk, rule, product, data or capacity assumption has changed? The answer must be visible by legal entity and market, not merely at head office.
Executive decision map
| Decision | Primary legal / supervisory lens | Operational evidence |
|---|---|---|
| AML program design | BSA, AMLA, FinCEN rules, prudential examination | Board approval, risk assessment, policy, staffing, independent testing, documented effectiveness measures. |
| SAR decision | BSA rules and FinCEN filing guidance | Facts, reasonable-suspicion rationale, narrative, timeliness, confidentiality controls and linked account action. |
| Information sharing | 314(a), 314(b), legal/privacy policy | Request validation, permitted data scope, records of participation, escalation and disclosure controls. |
| Sanctions action | OFAC program-specific rules, lists, licenses and guidance | Nexus analysis, ownership/control analysis, screening evidence, block/reject/licensing/reporting record. |
| Product/state launch | Federal and state licensing, BSA classification, consumer and payments requirements | Legal classification, risk assessment, registration/license inventory, control configuration and accountability map. |
The decision map is deliberately outcome-based. It prevents a program from announcing a new standard, a vendor deployment, a training campaign or a reduced backlog as a success without showing whether the actual decision quality, coverage and resilience improved. It also gives boards and transformation sponsors a more useful way to allocate capital: fund the evidence and operating capability that changes the decision, not simply the activity that surrounds it.
Read the cascade as a management diagnostic rather than an inevitability. A visible failure at the right side of the diagram—late reporting, unsafe customer action, a supervisory finding, or a costly remediation—usually began earlier with an unstated assumption about population, data, capacity, decision rights, or change control. The control response should move upstream until it identifies the first point at which evidence, ownership, or resilience was insufficient. That approach avoids treating rework, contractors, a larger backlog team, or a new dashboard as a substitute for fixing the decision path itself.
2. Operator Layer
The execution discipline
The operator layer turns legal and risk requirements into repeatable work. It begins with a controlled inventory, not a technology implementation. For each process, record the population, trigger, required evidence, key data, legal/policy basis, routing, reviewer authority, system, action, report, time standard, exception, quality test and feedback channel. If any of those elements are missing, the program is likely relying on individual memory or an undocumented work-around.
1. Classify the entity and activity
Identify the legal entity, product, customer type, transaction flow, payment role, jurisdiction, and regulatory registration. The classification determines which BSA rule, supervisor, state law, and sanctions nexus may apply.
2. Map obligations to control objects
For every material obligation, document the trigger, control objective, data object, decision owner, system, evidence, escalation, reporting destination, retention rule and testing method.
3. Run independent legal pathways
Maintain separate, coordinated procedures for SAR review, sanctions interdiction, 314(a) response, 314(b) sharing, subpoena response, regulatory exam response, complaints and account actions.
4. Govern the change horizon
Tag laws, proposed rules, agency guidance, enforcement lessons and internal policy choices distinctly. Assign a legal owner, impact assessment, effective date, configuration change and proof of implementation.
5. Test the end-to-end outcome
Sample whether the customer, entity, transaction, alert, investigation, report and action records reconcile. Test data movement across affiliates, providers, state systems and offshore operations.
Operating metrics that resist false assurance
Measure the entire decision path. Track demand and throughput, but pair them with aged risk, incomplete evidence, decision reversal, downstream escalation, report quality, customer-impact signal, QA error, model/data exceptions, vendor or system interruption, issue recurrence and time to root-cause closure. Require a management explanation for favorable metrics that move abruptly. A sharp improvement often reflects a useful control change, but it can also reveal data loss, a policy change, a case-type exclusion, a new vendor routing rule or an unrecorded suppression.
3. Specialist and Jurisdictional Layer
19.1 BSA/AML and the FinCEN operating spine
The BSA is the foundational U.S. financial-recordkeeping and reporting statute. It supports a system in which covered financial institutions establish risk-based programs, identify and report certain transactions and suspicious activity, retain prescribed information, and make records available under lawful processes. Implementing details are contained in Treasury’s regulations, principally Chapter X of title 31 of the Code of Federal Regulations, and vary by institution type. The correct operational question is not “Do we have an AML program?” It is “Which entity is covered, which activity triggers a duty, which report or record is required, and what evidence establishes timely and accurate performance?” [S01][S03]
AMLA 2020 is important because it introduced a broad modernization agenda and formalized an orientation toward national AML/CFT priorities and effectiveness. FinCEN’s April 2026 AML/CFT-program proposal is a proposal, not a final rule; it should be managed through regulatory-change governance rather than implemented as if all provisions were presently binding. [S02][S04][S05] For an executive, the practical implication is that the program must be able to show a reasoned relationship between its risk assessment, AML priorities where applicable, controls, resources, testing, and observed outcomes.
Enforcement and Supervisory Lens: TD Bank BSA resolution
Official record. DOJ announced a guilty plea and FinCEN announced a civil money penalty related to BSA violations. [S13]
Operating lesson. Large-scale U.S. programs are judged on the operation of governance, staffing, data, monitoring, escalation and remediation—not the existence of a policy.
Limit of inference. Do not infer a universal monitoring threshold or a fixed remediation formula.
19.1A Coverage, customer due diligence, and program evidence
A U.S. program starts with legal-entity and activity classification because “financial institution” is not a single operational category. The relevant regulatory definition, registration or licensing status, products, payment flows, customer relationships, geographic footprint, and use of affiliates or agents affect which requirements, supervisory expectations, forms, and timing rules must be assessed. A group should maintain a perimeter register that identifies each legal entity and business activity; the potentially applicable BSA rule set; its primary and secondary supervisors; state licensing or money-transmission posture; OFAC nexus; relevant information-sharing mechanisms; and accountable legal, compliance, operations, product, technology, and records owners. The register is the starting point for a risk assessment, not a substitute for one.
Customer due diligence should be designed as an evidence lifecycle. The institution must be able to explain what it knew at onboarding; which identifiers, ownership, purpose, expected activity, product, geography, adverse information, and source-of-funds or wealth evidence were relevant; how risk was assigned; who approved exceptions; which events require refresh or escalation; and how the evidence connects to monitoring and account action. The configuration should separate a customer’s asserted information, independently corroborated information, unavailable information, adverse information, and analyst inference. That distinction is essential when later reviewers assess whether a risk rating or monitoring decision was reasonable at the time, not merely whether a file contained many documents.
The BSA program evidence pack should connect governance to work. It includes board or appropriate management approval and oversight; policy and procedure versions; risk assessment scope and methodology; staffing and skill mix; training population and completion; independent testing scope and results; issue and remediation records; legal/regulatory-change assessments; model, scenario, and data controls where used; report and record reconciliations; and management information that reaches the accountable decision maker. A policy, annual training percentage, or aggregate SAR count alone does not show effective operation. Reviewers need to see that the in-scope population was understood, controls were operated and tested, material exceptions were escalated, and failures were remediated with evidence.
Avoid importing a single CDD rule, supervisor practice, or product process across the entire enterprise without classification. A bank, broker-dealer, futures intermediary, money services business, virtual-currency business, insurer, and payment provider can share a control grammar while retaining different formal obligations, customer journeys, data, and supervisory interfaces. The safe operating design marks the common control objective, exact legal source, local implementation, evidence standard, and decision owner. It creates efficiency without treating a common template as legal analysis.
Enforcement and Supervisory Lens: Binance resolution
Official record. DOJ and FinCEN announced resolutions concerning Binance’s BSA program and related conduct. [S15]
Operating lesson. A platform’s global reach, customer access, entity model, transaction data and controls must be reconciled to the legal obligations that apply to its activity.
Limit of inference. The official resolutions are specific to their facts and do not define the legal status of every digital-asset business.
19.1B Risk assessment, monitoring coverage, and data lineage
The enterprise risk assessment should be more than a periodic narrative. It is the bridge between the legal perimeter, threat environment, customer and product profile, geographic and transaction exposure, delivery channels, intermediaries, data quality, control design, and resource allocation. It should say what the population is, which risks are material, what information supports the conclusion, where data is incomplete or stale, how risks are scored, which controls are expected to respond, what residual risk remains, and how the assessment changes after a product launch, merger, enforcement development, material fraud event, sanctions change, or control failure. A risk assessment that does not reach configuration, staffing, quality sampling, or escalation cannot plausibly be the operating foundation of a risk-based program.
Monitoring coverage needs a population proof. For each scenario, analytic, rule, or review process, identify the eligible customers, accounts, transactions, counterparties, channels, products, legal entities, currencies, geographies, and time windows; the source systems and data fields; excluded or unavailable populations; transformation and enrichment logic; threshold or model version; alert routing; investigation standard; action/report interface; and owner. Reconcile the expected population to actual processing and investigate gaps. A low alert count can mean well-calibrated detection, but it can also mean a field stopped arriving, a product was never mapped, an alert was suppressed, a currency was excluded, or a downstream queue lost work.
Data lineage should be preserved at a level that supports both operational recovery and challenge. A material case outcome should be traceable to the source records and data versions available at the time, the transformations and entity-resolution results applied, relevant watchlists or risk factors, the rules/models and configuration active, user activity and overrides, and report/action timestamps. This does not mean retaining every possible data element forever or making every analyst an engineer. It means defining what evidence is required to reproduce a consequential decision and designing lawful retention, access, security, and retrieval around that requirement.
Independent testing should use a mixture of design review, data reconciliation, targeted sample review, negative testing, thematic investigation, change validation, and management-information challenge. Test whether controls cover edge conditions: linked entities, nested ownership, agents, unusual payment paths, rapid growth, customer migrations, outages, manual workarounds, staff turnover, and high-risk scenarios. When testing finds a defect, establish whether it is an isolated human error, a process failure, a data issue, a coverage gap, or a governance/decision-rights weakness. The appropriate corrective action and lookback scope depend on that analysis, not simply on the number of cases reviewed.
Enforcement and Supervisory Lens: USAA Federal Savings Bank enforcement action
Official record. FinCEN announced a civil enforcement action against USAA Federal Savings Bank for BSA violations. [S17]
Operating lesson. Customer onboarding, risk classification, monitoring, governance and testing need an evidentiary thread that can withstand independent review.
Limit of inference. The announcement should not be treated as a substitute for current institution-type-specific rules.
19.2 Reporting, investigation, and information sharing
Suspicious-activity reporting is a fact-based institution decision governed by rules that vary by institution type and transaction. A high-quality SAR process preserves the investigative record, source data, decision rationale, narrative quality, timeliness, confidentiality, and linkage to related reports and account action. It should not be reduced to an alert disposition or a filing-volume target. FinCEN’s filing resources and the FFIEC examination material provide the core operational reference points for banks; specific rules and forms must always be checked for the relevant entity and date. [S06][S07]
Sections 314(a) and 314(b) are distinct mechanisms. The former supports certain FinCEN information requests to financial institutions; the latter provides a statutory framework for eligible voluntary information sharing among participating institutions when conditions are met. Both require precise governance over request authenticity, information scope, confidentiality, records, legal review, and downstream use. Neither is a blanket permission to create unrestricted cross-affiliate or cross-border intelligence sharing. [S08][S09]
19.2A Reporting and intelligence lifecycle
A reporting control should be built backward from the record a competent authority may need to understand. For a SAR, the case file should identify the trigger or source; linked customer, account, entity, counterparty, transaction, device, product, and geographic facts; information reviewed and unavailable; investigation steps; rationale under the applicable standard; disposition and approvals; narrative support; filing/review dates; confidentiality controls; related reports; account restrictions or other actions; and post-filing monitoring or escalation. This is not a prescription for every institution type or case. It is an evidence architecture that makes decision quality testable and allows a later reviewer to distinguish a judgment call from an undocumented gap.
Reporting and account action must remain separate but connected. Filing a SAR does not itself determine whether an account should stay open, be restricted, be exited, or be subject to additional monitoring; nor should a commercial closure rationale be retrofitted to say that it was a reporting decision. The governing forum should be able to see the distinct legal/policy basis, information safeguards, customer communications, operational action, approvers, and timing. Similar separation is needed for reports of currency, funds-transfer, or other activity where applicable: validate the reporting entity, trigger, deadline, data fields, exception handling, correction process, retention, and reconciliation against source records rather than relying on a dashboard total.
The information-sharing control is an intelligence lifecycle as well. For 314(a), authenticate the request and current participation requirements; identify the permitted search population and time period; control who may access or search; preserve search logic and results; route potential matches to qualified review; observe response and confidentiality protocols; and record exceptions, late responses, and post-event lessons. For 314(b), establish eligibility and annual process controls where applicable, define a permitted purpose, authorize participants, limit information to the program terms, preserve sharing records, and coordinate with privacy, legal, sanctions, and cross-border policies. A “we can share because it may be useful” rationale is not a defensible process.
Quality assurance should target the cases most likely to create harm: rapid customer exit or restriction, high-value or high-risk activity, linked networks, data limitations, late reports, repeat alerts, analyst overrides, agent or provider involvement, and changes to rules or narratives. Test adverse outcomes as well as completeness. A process that reliably files a report but discards the related data, fails to preserve confidentiality, cannot explain an escalating risk pattern, or does not track follow-up action remains weak even when basic filing timeliness appears acceptable.
19.2B Investigations, requests, confidentiality, and account action
An investigation operating model needs named decision rights. Define who may collect or request additional evidence, contact a customer, restrict a payment, seek legal input, decide a report is or is not required, approve a narrative, respond to a law-enforcement or regulator request, change a risk rating, and recommend or approve account action. The controls should record the evidence standard, escalation thresholds, review expectation, time standard, and authority for each handoff. This is particularly important when a centralized investigative function supports several U.S. legal entities, state-licensed businesses, non-U.S. affiliates, or a mix of BSA and sanctions workflows.
Confidentiality must be designed into the case environment rather than treated as a label added to a report. Access should be role-based and periodically reviewed; customer-facing, commercial, collections, sales, and complaints teams should receive only the information they need for their permitted action; case notes and reports should distinguish sensitive reporting material from general operating facts; and sharing with affiliates, providers, and external parties should be evaluated under the governing legal and policy framework. A good control can explain why a particular recipient could receive a risk conclusion, a customer-restriction instruction, or a request for evidence without revealing protected filing information or investigative detail.
Requests from law enforcement, regulators, auditors, and courts require an intake-and-preservation process. Authenticate the request and authority; determine scope and deadline; identify potentially responsive records and systems; preserve data and records before routine deletion; coordinate confidentiality, privacy, legal hold, state, and cross-border constraints; maintain a production log; and record the source and outcome of any information provided. Do not let informal emails, relationship channels, or urgent operational requests bypass the record of who authorized disclosure and what was actually released. If a request overlaps a suspicious-activity matter, sanctions issue, customer complaint, or account restriction, synchronize the operational timeline while retaining the distinct legal pathways.
Account action should likewise be fact-specific. The program may identify a risk that calls for enhanced monitoring, a transactional limitation, a temporary hold under an applicable authority, a customer conversation, a risk-rating change, an exit decision, or no immediate customer action. The case record should show the business and legal basis, customer-effect assessment, decision authority, communications control, appeal or complaint route where applicable, and linkage to any regulatory report. This is how an institution prevents a confidential reporting process from being used as a vague explanation for customer treatment, or vice versa.
19.3 Sanctions is a separate legal decision path
OFAC administers U.S. economic and trade sanctions programs. Whether a transaction is prohibited, must be blocked, may be rejected, could be authorized under a general or specific license, or requires reporting depends on the applicable program, activity, persons, ownership, geography, and U.S. nexus. The 50 Percent Rule is an ownership-based OFAC interpretation and should not be conflated with AML beneficial-owner thresholds or a general “control” rule. [S11][S12]
An effective sanctions operating model therefore needs list and license governance, screening and matching design, transliteration and entity-resolution controls, payment message and trade data coverage, ownership analysis, case escalation, blocking/rejection documentation, reporting, quality assurance and change controls. OFAC’s framework identifies management commitment, risk assessment, internal controls, testing/auditing, and training as five essential components, but those components must be tailored to the particular U.S. nexus, business and products. [S11]
19.3A Sanctions decision anatomy and evidence
A sanctions alert should not be treated as a simple name-match event. The decision record needs to show the input data and system version; list or source date; match logic and score; identifiers, aliases, addresses, nationalities, ownership or control data, payment and trade facts, and other contextual information reviewed; U.S.-nexus analysis; potentially applicable program and prohibition; license analysis where relevant; escalation and legal advice; final action; required reporting; and monitoring or remediation. A weak record says “false positive” or “cleared” without showing which material identifiers were compared or why the conclusion was available at the time.
Screening coverage must follow the business model. Customer and counterparty screening, payment screening, trade data, securities or digital-asset transfer data, devices or wallet addresses where relevant, beneficial ownership, and changes in lists or ownership information may require different points in the workflow, different matching logic, and different evidence. List maintenance and tuning are controlled changes: preserve the source, activation time, affected population, test results, known limitations, exception route, release approval, and post-implementation QA. A list update deployed late, a message field not ingested, or an ownership record unavailable to an investigator can be as consequential as a poorly calibrated name-matching rule.
Blocking, rejection, licensing, disclosure, and customer action should be separately described in operating procedures because their legal effects and evidence requirements can differ. The institution must not use generic “hold” language to conceal whether it has made an OFAC-specific decision, a fraud or AML precaution, a contractual service decision, or an operational pause while facts are gathered. When multiple regimes are implicated, a coordinated case record should permit each decision owner to document the appropriate legal and policy analysis without compromising confidentiality or creating contradictory customer communications.
Sanctions governance is particularly sensitive to cross-border distribution of people, systems, and data. A global enterprise should know where U.S. persons make or approve decisions, where transactions enter U.S. financial infrastructure, where technology and support are located, where a U.S.-regulated affiliate participates, and whether another jurisdiction’s sanctions, blocking, privacy, labor, or reporting law creates a conflict. Escalation cannot be solved by a generic global “sanctions team” label; it needs specified authority, local legal input, and an audit trail for the exact fact pattern.
19.3B Licensing, ownership, and sanctions quality assurance
Licensing analysis should be controlled from the same factual record used for the interdiction decision. Identify the relevant sanctions program, prohibited activity or property interest, parties and ownership, location and timing, U.S. nexus, whether a general license or other authorization is potentially relevant, conditions and recordkeeping implications, and who has authority to conclude or seek further advice. Do not treat a general license title, a third-party screening result, or a customer assertion as a complete legal conclusion. The record should capture the source and version of the license or guidance, the factual assumptions, approval, and any operational conditions imposed on the transaction or relationship.
Ownership analysis requires disciplined data and escalation. The OFAC 50 Percent Rule is specific to blocked-person ownership and aggregate ownership concepts described in OFAC materials; it should not be simplified into a generic customer “beneficial owner” percentage or a general question of commercial control. Conversely, a legal entity may have governance, control, proxy, family, nominee, trust, or layered-ownership facts that create material risk and warrant more review even when an automated percentage calculation does not produce a conclusive result. Escalate incomplete or contradictory corporate records, rapidly changing ownership, opaque structures, and high-risk jurisdictions to the appropriate specialist rather than allowing a generic KYC approval to resolve a sanctions question.
Sanctions quality assurance should combine match-quality testing, data coverage testing, and action-quality testing. Review false clears, false positives, overrides, late screening, list update performance, ownership analysis, license treatment, blocking/rejection records, required reports, and customer/commercial communications. Include cases from all relevant payment and non-payment channels, legal entities, service centers, and providers. Where a control breaks, determine the affected population and duration before accepting a narrow “case error” explanation. This keeps the program focused on legal decision quality, not simply on achieving a low alert rate.
19.4 Prudential, market, consumer, and state overlay
A bank may be examined by the OCC, Federal Reserve, FDIC, or a state banking authority depending on charter and structure; credit unions, broker-dealers, investment advisers, futures intermediaries, money services businesses, insurers, and other entities encounter different primary supervisory regimes. The FFIEC manual harmonizes a large part of bank examination methodology but does not substitute for agency-specific authority. Securities and commodities activities can introduce SEC, FINRA, and CFTC obligations; consumer-facing conduct can implicate CFPB or state consumer-protection authority; money transmission and virtual-currency activities often require careful state-by-state licensing analysis.
For a global institution, the operating discipline is to map legal entity, booking model, U.S. person involvement, correspondent exposure, currency/payment clearing, product, customer and state nexus. Do not generalize that every overseas activity is subject to every U.S. rule. Conversely, do not assume that a booking location eliminates U.S. risk where a U.S. person, U.S. financial institution, dollar clearing, U.S.-origin service, sanctions nexus, or regulated affiliate is involved. That evaluation needs jurisdiction-specific legal input.
19.4A Regulatory perimeter, state execution, and product governance
Product governance must test the regulatory perimeter before a product is marketed, not after an examiner or enforcement authority asks why it was not classified correctly. The review should identify the customer and counterparty types, contractual roles, money and information flows, custody or control features, payment initiation and settlement mechanics, agents or intermediaries, marketing and service locations, currencies, transaction velocity, geographic reach, ownership of data and records, and responsible legal entities. It should ask whether the activity could fall within federal or state BSA, money-transmission, securities, commodities, consumer, privacy, sanctions, licensing, or reporting considerations, then record the qualified legal analysis and the control decisions that follow.
State variation is not a small footnote. State money-transmitter licensing, virtual-currency or payments regimes, consumer-protection, unclaimed-property, privacy, examination, and enforcement expectations can influence the permitted product, disclosures, customer support, agent oversight, safeguarding, complaints, data retention, and incident management. A federal or group policy can provide a common risk and evidence model, but it cannot substitute for a maintained state applicability register. The register should name the required license or registration where relevant, entity, activity, regulator, effective dates, renewal/reporting obligations, responsible owner, product configuration, evidence location, and escalation for a control breach or legal change.
The legal-entity map should also distinguish a federally supervised bank or credit union from a nonbank affiliate, broker-dealer, investment adviser, futures business, money services business, or technology/operations company. Shared services and common systems can be valuable, but a group cannot assume that one entity’s supervisory relationship or BSA program covers another entity’s activity. Conversely, a control operated by a service company may be critical to a regulated entity even if the service company itself is not the regulated party. Retained accountability, access to records, regulatory cooperation, change control, and service-continuity evidence must reflect that relationship.
Consumer outcomes should be considered early. A financial-crimes control may prevent loss or unlawful activity, but it can also delay payments, deny access, trigger repetitive verification, or result in an account restriction. Product approval should define the risk scenario, legal and policy basis, controls, customer communications, escalation, complaints data, error remediation, and decision authorities. These records let the enterprise demonstrate that it did not treat compliance, customer protection, and operational resilience as unrelated workstreams.
19.4B Digital assets, agents, correspondent relationships, and new activity
New activity must be analyzed by function rather than branding. A digital-asset, embedded-finance, marketplace, payment-facilitator, correspondent, API, or agent model can allocate customer access, transaction initiation, custody, settlement, information, and decision rights across several parties. The regulatory and control consequence depends on those facts. Product governance should map the flow of value and information; identify who is the customer and who performs each regulated activity; establish the legal-entity, state, and federal analysis; define BSA, sanctions, consumer, safeguarding, records, and complaint controls; and test whether data sufficient for monitoring and reporting is actually available in a lawful and usable form.
Agent, program-manager, and distribution arrangements require special attention because the entity closest to the customer may not own the risk system or reporting function. The sponsoring or regulated entity needs visibility into onboarding, identity/evidence collection, transaction activity, screening, exceptions, training, customer communications, complaints, quality, incidents, and subcontractors. It also needs clear authority to require corrective action, restrict activity, preserve records, and exit the relationship. A periodic certification or a volume dashboard cannot replace evidence that the distributed model is operating within the approved control design.
Correspondent and nested relationships similarly require an explicit mapping of products, flows, respondents/intermediaries, currencies, jurisdictions, access to customer/transaction information, escalation, and decision rights. The institution should know when it is relying on another party’s control and what evidence or contractual access supports that reliance. Transaction speed, cross-border routing, or privacy constraints may create gaps in information availability; those gaps must be accepted, mitigated, or addressed through product conditions rather than ignored because the relationship is commercially important.
New-activity approvals should have a controlled pilot and review. Define the target population and permitted scope; required licenses or registrations; data and control prerequisites; staffing, specialist and QA capacity; testing; customer disclosures; exception and stop conditions; management reporting; and a fixed reassessment date. Growth should be conditional on demonstrated operation, not merely on integration completion. This approach permits innovation while making the regulatory perimeter and financial-crimes evidence visible before scale turns a configuration uncertainty into a systemic exposure.
19.5 Enforcement as a control-evidence test
Public enforcement materials are most useful when read as evidence of systems interacting badly: governance fails to recognize scale; data and transaction-monitoring coverage are incomplete; alerts are not escalated; employees or third parties create workarounds; remediation commitments do not land; or an institution fails to understand the conduct its platform enables. TD Bank’s 2024 DOJ and FinCEN materials, Binance’s 2023 resolution, and FinCEN’s USAA action are not generic templates. They are instruction in how legal requirements, program design, product growth, data, monitoring, governance, and remedial evidence can be assessed together. [S13][S14][S15][S16][S17]
The key executive lesson is not “avoid the next enforcement action.” It is to build a demonstrably operated program: clear ownership, risk assessment, reliable records, coverage testing, high-quality investigations, timely reporting, independent assurance, and truthful escalation when controls are not working.
19.5A Enforcement readiness, remediation, and evidence preservation
Enforcement readiness is not a separate “defense file” created when a subpoena, examination, or inquiry arrives. It is the ability to retrieve truthful operating evidence before it is overwritten, dispersed, or reconstructed from memory. Maintain source and configuration history; process and policy versions; approvals; risk assessments; training and staffing evidence; data lineage; alerts and case histories; report records; account actions; exceptions; QA and independent-testing results; issue logs; remediation plans; supplier and affiliate dependencies; and management escalation. The evidence should connect a known population and a control design to actual operation in a defined period. A polished current policy cannot answer whether a historical decision system worked.
When a material deficiency is identified, triage the legal, customer, regulatory, and operational implications separately but with a coordinated governance record. Determine the affected population; time period; control purpose; potentially missed or incorrect decisions; data and system dependencies; whether reporting, sanctions, customer, prudential, consumer, licensing, or criminal issues could arise; immediate containment; local/state and federal authority engagement; evidence preservation; and independent validation. Do not default to a single remediation “severity” label that hides different legal clocks and customer-harm risks. A weak sanctions data issue, a delayed SAR issue, a state-license question, and an examiner concern may share root causes but require different immediate actions.
Remediation should be tested at three levels. First, design: was the requirement or issue translated into a credible policy, process, system, data, staffing, and governance solution? Second, operation: did the intended population actually receive the new control, with workable procedures, access, evidence, and escalation? Third, effectiveness and sustainability: did independent testing demonstrate the expected outcome over a defined period, including high-risk and edge conditions, while BAU funding, ownership, monitoring, and issue management were established? Deployment, policy publication, or a declining backlog is not enough. A change can reduce visible work while leaving coverage, timeliness, or evidence quality worse.
The board pack should be candid. It should distinguish confirmed facts, legal advice, hypotheses, management decisions, residual risk, and unverified benefit claims. It should show trends by entity, product, customer, geography, system, and state where needed; open actions and commitments; dependencies; interim compensating controls; customer and regulator impact; escalation dates; and who can accept or reject risk. The aim is a disciplined record of decisions under uncertainty, not a retrospective narrative engineered to look inevitable.
19.5B Examination management and issue closure
An examination or supervisory engagement should be managed as an evidence program, not a scramble to prepare slides. Maintain a current authority map and engagement log; identify the legal entity, product, scope, requested period, data and record custodians, accountable executives, legal and compliance contacts, open issues, commitments, and production status. For each request, record the exact question, source systems, data extraction/reconciliation method, review and approval, documents produced, limitations, oral explanations, follow-up, and any correction. This discipline reduces inconsistent answers across business, compliance, technology, state, and affiliate teams and makes it easier to identify a genuine control issue rather than a document-retrieval failure.
Issue management needs a complete causal story. Describe the observed problem, requirement or control objective, population and period, severity rationale, customer/regulatory/legal consequence, source data, root cause, interim safeguard, target-state remediation, dependencies, accountable owner, validation plan, evidence location, residual risk, escalation threshold, and closure authority. An issue that says “improve monitoring” or “enhance training” is not specific enough to be tested. A closure recommendation should show that the affected population was identified and handled appropriately, the change was deployed with the intended data and process, QA and independent testing tested performance, and the BAU owner has the capacity and governance to sustain it.
Treat management representations carefully. A statement to a board, regulator, examiner, auditor, counterparty, or insurer about the effectiveness of a program should be traceable to the record, scope, period, limitations, and decision authority. Avoid broad assurances based on a single metric, vendor certification, successful test sample, or policy refresh. Where evidence is incomplete, state the limitation and interim control, set a deadline, and escalate the residual risk. Honest uncertainty with a disciplined action plan is much safer than an unsupported claim of full compliance or effectiveness.
19.6 U.S.-nexus analysis, legal conflict, and cross-border casework
U.S. nexus is best handled as a fact-record and escalation process, not a shorthand conclusion. For a material cross-border customer, payment, trade, correspondent, digital-asset, or service event, capture the relevant parties and legal entities; beneficial ownership and control facts; locations; nationalities and residency where lawfully relevant; contractual roles; currency and payment path; U.S. financial institutions, intermediaries, personnel, technology, systems, or services involved; licenses or regulatory status; sanctions programs and lists considered; customer/product purpose; and the host-country legal framework. The record should distinguish facts from legal conclusions and identify the qualified legal owner who assessed the conclusion.
The operational questions differ by pathway. A payment may require a sanctions assessment because of the applicable program, persons, ownership, transaction, and nexus; a suspicious-activity decision may require an institution-type-specific BSA analysis; an information request may require the conditions of the relevant program; a correspondent activity may require its own due-diligence, records, and risk analysis; and a customer action may be governed by contract, risk appetite, consumer requirements, or local law. One fact pattern can trigger more than one of these paths, but the institution should not force them into one undifferentiated “U.S. compliance” action. Each pathway needs its own authority, deadline, evidence, reporting, confidentiality, and communication rules.
Conflicts of law should be surfaced early. Examples can include a U.S. information or sanctions-related concern alongside host-country privacy, data localization, bank-secrecy, labor, employment, blocking, reporting, or customer-notification constraints. The aim is not to assume a conflict exists whenever data crosses a border, or to decide it from a policy template. It is to obtain appropriate legal analysis, determine what facts and records can be accessed or shared, identify temporary safeguards, decide which legal entity and authority own each action, and preserve a clear audit trail. A centralized case tool should have fields for local legal constraint, advice status, permitted data access, authorized recipients, and escalation date so a restriction is visible to investigators and quality reviewers rather than buried in email.
The escalation design should cover time pressure. A time-sensitive payment or potential sanctions issue may require a short-term operational measure while legal analysis continues; that measure must have authority, scope, communications controls, review time, and an exit or next-decision trigger. A complex historical monitoring or reporting concern may require evidence preservation and a coordinated lookback rather than an immediate customer action. Senior managers should be able to see which decisions are urgent, which have a legal filing clock, which create customer or market harm, and which depend on information not yet available. This lets the enterprise act proportionately while avoiding silent acceptance of an unresolved conflict.
For global groups, train both central and local teams on what a U.S.-nexus referral is and is not. The referral should not imply that every issue is governed by U.S. law or that local staff lack authority. It should supply a structured fact pattern, preserve the local legal point of contact, record decisions, and feed lessons into product, correspondent, data, vendor, and case-management design. This improves speed and consistency without converting complex jurisdictional analysis into a mechanical currency or location rule.
19.7 Assurance calendar and executive operating cadence
A U.S. program benefits from an assurance calendar that joins legal change, control testing, risk assessment, reporting quality, sanctions readiness, state obligations, product governance, and remediation. At least annually, refresh the entity/activity perimeter and U.S.-nexus map; reassess material risks, products, geographies, customers, agents, correspondents, data sources, and providers; verify roles and authorities; and test the information needed to evidence the program. Trigger interim reviews for mergers, rapid growth, new technology, novel payment or digital-asset activity, list or legal change, an enforcement or examination event, a material alert or case issue, significant data defect, or an outsourced-service failure.
The board or accountable committee does not need raw case detail, but it needs an intelligible risk and evidence view. Recommended themes are: legal/regulatory change status; program perimeter; risk assessment and material residual risks; population coverage; backlog and aging by risk; report timeliness and quality; sanctions metrics and material escalations; 314(a)/314(b) control health; state/consumer/product developments; data and model issues; vendor and affiliate dependencies; independent testing; examination, law-enforcement, or audit engagements; remediation status; and customer-impact indicators. For each red or amber condition, state the consequence, owner, interim control, decision needed, and next evidence date.
Operators need a more granular cadence. Reconcile reports and source records; review alert and case queues; test data feeds and list updates; calibrate investigators and QA; monitor exceptions and overrides; verify user access; sample account actions; check training and staffing capacity; preserve evidence for open requests; track regulatory deadlines; and conduct root-cause analysis that reaches upstream product, customer, data, or vendor causes. When a metric improves dramatically, require the owner to explain whether the change reflects better control, a changed population, a timing shift, a data loss, a suppression, or a customer/product behavior change. This disciplined skepticism is central to credible U.S. control governance.
4. Cross-Border Operating Model
The United States is an important source of global financial-crimes influence, especially through dollar clearing, correspondent relationships, U.S. persons, sanctions, enforcement, and expectations of U.S.-regulated entities. That influence should not be misstated as universal extraterritorial jurisdiction. A global operating model should use a U.S.-nexus assessment: identify the legal entity, personnel, payment, currency, customer, product, technology, and transaction connections that may trigger a U.S. rule. Then compare the relevant U.S. rule with host-country legal duties, privacy constraints, blocking statutes, reporting rules, and regulator expectations.
Use an applicability dossier for material cross-border flows. It should record the fact pattern, entity and product map, source of legal advice, relationship to a U.S. person or financial institution, payment/currency path, customer or counterparty location, use of a U.S.-origin service, potentially applicable federal and state regimes, host-country constraints, required decisions, data and record location, account/action authority, and review date. The dossier must not declare a legal conclusion by inference from a payment currency or a group policy. It is a control for making sure the conclusion is owned, current, and operationally configured.
The global core should preserve common customer, entity, transaction, investigation, evidence, and control data; the local edge should implement country-specific report formats, threshold rules, retention, employee access, data-transfer safeguards, account action, and supervisor engagement. The most common failure is to write a global U.S.-style policy and then assume it answers legal questions in a local market. The stronger design documents the source of law, scope, applicability, local overlay, responsible owner and evidence of configuration.
5. Practical Frameworks and Assurance
Framework 01: The System Proof Test
Use the following ten questions before declaring a capability effective. This is a library operating framework, not a regulatory checklist.
- Is the applicable legal, regulatory, supervisory and policy question explicitly classified?
- Is the in-scope population known, reconciled and versioned?
- Is the required customer, entity, transaction, data or evidence object complete enough for the decision?
- Is the accountable owner clear, including the local legal-entity owner where relevant?
- Does the workflow distinguish prevention, detection, investigation, reporting, action and assurance?
- Are there measurable quality, timeliness, coverage and customer-impact guardrails?
- Can a reviewer reconstruct the rule, source, data, reasoning, override, action and report?
- Can the system absorb a surge, data failure, vendor failure, legal change or material risk event?
- Has independent challenge tested real decisions and not only written procedures?
- Does the learning loop make a controlled change, retain the evidence and test whether it worked?
Framework 02: Outcome Dashboard
| Outcome | Leading / lagging indicators | Evidence source |
|---|---|---|
| Decision quality | Accuracy, completeness, timeliness, consistency, explained overrides | QA, independent testing, case review and regulatory challenge |
| Coverage | Population, product, channel, data and legal-entity inclusion | Coverage map, reconciliations, negative testing and change control |
| Customer / counterparty outcome | Friction, hold/release timing, complaints, remediation and fairness | Journey evidence, service data, root-cause analysis and governance |
| Resilience | Surge capacity, data dependency, vendor concentration, recovery and key-person exposure | Scenario test, service review, continuity exercise and exit plan |
| Learning | Issue recurrence, typology feedback, model/process change and post-implementation result | Root-cause log, risk acceptance, validation and BAU monitoring |
The dashboard should be read as a pattern, not a scorecard contest. A sharp reduction in alert volume may be good, bad, or meaningless depending on the covered population, detection precision, missed-risk testing, quality, account/action outcomes and source data. A backlog decline may signal stronger process design, or it may result from relaxed review, unrecorded exceptions, data loss or customer exits. The governance record should require the owner to explain the causal story and the independent challenger to test it.
Framework 03: Decision-Rights Map
| Role | Minimum decision rights and evidence |
|---|---|
| Global owner | Common standard, data/evidence grammar, control taxonomy, model/vendor/QA framework, thematic risk and escalation. |
| Local entity owner | Local legal translation, reportability, data access, customer action, supervisory engagement, local source and procedure. |
| Independent challenge | Second-line challenge, quality, validation/audit, issue severity, evidence review and residual-risk escalation. |
| Executive forum | Risk appetite, funding, material exceptions, product/growth conditions, remediation closure and authority engagement. |
6. What Good Looks Like / What Failure Looks Like
What mature, defensible, sustainable capability looks like
- Mature / defensible: A legal-obligation inventory that connects each BSA, sanctions, information-sharing, state, and supervisory obligation to a control, evidence, owner and change process.
- Mature / defensible: Separate but coordinated SAR, sanctions, 314(a), 314(b), subpoena, exam, and customer-action workflows.
- Mature / defensible: A current U.S.-nexus analysis embedded in product, customer, transaction, correspondent, vendor and booking-model governance.
- Mature / defensible: Clear distinction between binding law, final rule, proposal, agency guidance, enforcement lesson and internal operating recommendation.
- Mature / defensible: Independent testing and executive escalation that tests population coverage and outcomes rather than procedure existence alone.
What weak, misleading, fragile, or non-defensible implementation looks like
- Fragile / non-defensible: A single “AML compliance” process that hides differences among reporting, sanctions, privacy, enforcement and prudential decisions.
- Fragile / non-defensible: A SAR process that is measured by filing count, does not preserve evidence, or cannot connect the narrative to related accounts and action.
- Fragile / non-defensible: Sanctions screening that uses an AML ownership threshold or does not distinguish blocking, rejection, licensing and reporting.
- Fragile / non-defensible: A global policy that assumes U.S. rules apply everywhere or ignores U.S. nexus in overseas operations.
- Fragile / non-defensible: Regulatory-change governance that treats a proposal or press release as binding law, or ignores it entirely until an examination occurs.
7. Common Misconceptions and Contrarian Insights
“BSA/AML and sanctions are the same system.”
They share data and governance, but they have different legal triggers, actions, reporting, ownership tests, authorities and consequences.
“A SAR is a criminal accusation.”
It is a confidential regulatory report based on the applicable suspicion standard; it is not a judicial finding or a substitute for an account-action decision.
“The Corporate Transparency Act eliminates bank CDD.”
Company reporting and a covered financial institution’s CDD obligations are separate regimes; current scope and exemptions must be verified.
“Dollar clearing automatically creates the same result in every case.”
U.S. nexus can be legally material, but application is fact- and rule-specific and requires proper legal analysis.
“An enforcement action is a complete rulebook.”
Enforcement materials are specific official facts. They illuminate risks but do not displace statutes, rules, or product-specific legal analysis.
8. Executive Discussion Questions
- Which U.S. requirements apply to each material legal entity, product, customer segment, payment role and booking location?
- Can management distinguish a SAR decision, a sanctions decision, a 314(a) response, a 314(b) sharing decision and an account-action decision?
- Where do we rely on a policy label rather than a current legal source and explicit scope analysis?
- Which records would allow us to reconstruct a material report, block, rejection, or customer restriction decision?
- Do state licensing and state enforcement considerations enter product governance early enough?
- What metric would reveal that monitoring coverage has failed as product volume, payment speed, or customer behavior changes?
- How do U.S. and host-country duties conflict in our highest-risk cross-border flows, and who owns resolution?
- Which requirements are final today, which are proposed, and which are institutional policy choices?
- What evidence supports our use of 314(a) and 314(b) mechanisms and protects confidentiality?
- Are our sanctions controls designed around program-specific prohibited conduct and ownership analysis rather than a single watchlist field?
- What did recent public enforcement actions reveal about our own growth gates, staffing, data, vendor, and escalation design?
- Who can accept the residual risk of continuing a U.S.-linked product when a material control deficiency is identified?
9. Practitioner and Specialist Checklists
Executive checklist
- Can we name the legal / policy question, accountable executive, local legal entity and decision authority?
- Can we see current evidence on coverage, quality, timeliness, customer impact, resilience and residual risk?
- Can we distinguish regulatory requirement, supervisory expectation, operating recommendation and untested assumption?
- Can we condition growth, product scope, outsourcing, data use or customer action when a guardrail is breached?
- Can we prove that a completed remediation is operating in BAU rather than merely deployed?
Operator checklist
- Map each decision to an in-scope population, trigger, data/evidence, procedure, system, owner, escalation, action and record.
- Reconcile source, case, report, action and quality data; do not allow unresolved data loss to become a business-as-usual assumption.
- Version rule, process, model, vendor, translation and report changes; retain test evidence and rollback/contingency decisions.
- Route complex, ambiguous, high-risk, cross-border, language or legal issues to named specialists with documented outcomes.
- Run recurring QA and root-cause analysis that reaches upstream policy, data, product, training and technology causes.
Specialist validation checklist
- Verify the applicable legal source, current effective date, scope, entity, product and authority before applying a control conclusion.
- Preserve primary source, locator, original language where relevant, translation/version, collection date, confidence and decision use.
- Test negative cases, population coverage, false positives, false negatives, overrides, edge conditions, timing and evidence reproducibility.
- Separate legal requirement, supervisory expectation, market practice and library operating inference in analysis and documentation.
- Record local variations, data restrictions, report interfaces, translation debt, legal advice and residual-risk decisions explicitly.
10. Module Glossary
| Term | Definition |
|---|---|
| AMLA | The Anti-Money Laundering Act of 2020, a statutory package that amended and expanded the U.S. AML/CFT framework. |
| BSA | The Bank Secrecy Act, the U.S. statutory recordkeeping and reporting framework administered in significant part by FinCEN. |
| Chapter X | Treasury regulations in 31 CFR Chapter X implementing many BSA obligations. |
| FinCEN | The U.S. Treasury bureau that administers key BSA rules, collects and analyzes financial intelligence, and operates specified information-sharing programs. |
| OFAC 50 Percent Rule | OFAC’s rule that property and interests in property of entities owned, directly or indirectly, 50 percent or more in the aggregate by blocked persons are considered blocked. |
| SAR | Suspicious Activity Report filed with FinCEN under applicable BSA rules; confidential and distinct from a judicial finding. |
| Section 314(a) | A FinCEN information-sharing program supporting certain law-enforcement requests to financial institutions. |
| Section 314(b) | A statutory voluntary information-sharing framework available to eligible participating financial institutions subject to conditions. |
| U.S. nexus | The facts that may connect conduct to a U.S. legal, regulatory, supervisory, or sanctions requirement. |
11. MLA 9 Works Cited
[S01] United States. Bank Secrecy Act. 31 U.S.C. §§ 5311-5336, https://uscode.house.gov/view.xhtml?path=/prelim@title31/subtitle4/chapter53/subchapter2&edition=prelim. Accessed 9 Aug. 2026.
[S02] United States. Anti-Money Laundering Act of 2020. Pub. L. 116-283, div. F, https://www.fincen.gov/resources/statutes-and-regulations/anti-money-laundering-act-2020. Accessed 9 Aug. 2026.
[S03] Financial Crimes Enforcement Network. 31 CFR Chapter X. U.S. Department of the Treasury, https://www.fincen.gov/resources/statutes-regulations. Accessed 9 Aug. 2026.
[S04] Financial Crimes Enforcement Network. FinCEN Proposes Rule to Fundamentally Reform Financial Institution AML/CFT Programs. U.S. Department of the Treasury, 7 Apr. 2026, https://www.fincen.gov/news/news-releases/fincen-proposes-rule-fundamentally-reform-financial-institution-programs. Accessed 9 Aug. 2026.
[S05] Financial Crimes Enforcement Network. FinCEN Issues First National AML/CFT Priorities and Accompanying Statements. U.S. Department of the Treasury, 30 June 2021, https://www.fincen.gov/news/news-releases/fincen-issues-first-national-amlcft-priorities-and-accompanying-statements. Accessed 9 Aug. 2026.
[S06] Federal Financial Institutions Examination Council. Bank Secrecy Act/Anti-Money Laundering Examination Manual. https://bsaaml.ffiec.gov/manual. Accessed 9 Aug. 2026.
[S07] Financial Crimes Enforcement Network. Suspicious Activity Report Filing Requirements. U.S. Department of the Treasury, https://www.fincen.gov/resources/filing-information. Accessed 9 Aug. 2026.
[S08] Financial Crimes Enforcement Network. Section 314(a) Program. U.S. Department of the Treasury, https://www.fincen.gov/section-314a. Accessed 9 Aug. 2026.
[S09] Financial Crimes Enforcement Network. Section 314(b) Fact Sheet. U.S. Department of the Treasury, https://www.fincen.gov/section-314b. Accessed 9 Aug. 2026.
[S10] Financial Crimes Enforcement Network. Beneficial Ownership Information Reporting. U.S. Department of the Treasury, updated 26 Mar. 2025, https://www.fincen.gov/boi. Accessed 9 Aug. 2026.
[S11] Office of Foreign Assets Control. A Framework for OFAC Compliance Commitments. U.S. Department of the Treasury, May 2019, https://ofac.treasury.gov/media/16331/download?inline=. Accessed 9 Aug. 2026.
[S12] Office of Foreign Assets Control. Entities Owned by Blocked Persons (50 Percent Rule). U.S. Department of the Treasury, https://ofac.treasury.gov/faqs/topic/1521. Accessed 9 Aug. 2026.
[S13] United States, Department of Justice. TD Bank Pleads Guilty to Bank Secrecy Act Violations and Agrees to Pay Over $1.8 Billion in Penalties. Office of Public Affairs, 10 Oct. 2024, https://www.justice.gov/opa/pr/td-bank-pleads-guilty-bank-secrecy-act-violations-and-agrees-pay-over-18-billion. Accessed 9 Aug. 2026.
[S14] Financial Crimes Enforcement Network. FinCEN Fines TD Bank, N.A. $1.3 Billion for Violations of the Bank Secrecy Act. U.S. Department of the Treasury, 10 Oct. 2024, https://www.fincen.gov/news/news-releases/fincen-fines-td-bank-na-13-billion-violations-bank-secrecy-act. Accessed 9 Aug. 2026.
[S15] United States, Department of Justice. Binance and CEO Plead Guilty to Federal Charges in $4 Billion Resolution. Office of Public Affairs, 21 Nov. 2023, https://www.justice.gov/opa/pr/binance-and-ceo-plead-guilty-federal-charges-4-billion-resolution. Accessed 9 Aug. 2026.
[S16] Financial Crimes Enforcement Network. FinCEN Announces $3.4 Billion Enforcement Action Against Binance. U.S. Department of the Treasury, 21 Nov. 2023, https://www.fincen.gov/news/news-releases/fincen-announces-34-billion-enforcement-action-against-binance. Accessed 9 Aug. 2026.
[S17] Financial Crimes Enforcement Network. FinCEN Announces $140 Million Enforcement Action Against USAA Federal Savings Bank. U.S. Department of the Treasury, 17 Mar. 2022, https://www.fincen.gov/news/news-releases/fincen-announces-140-million-enforcement-action-against-usaa-federal-savings-bank. Accessed 9 Aug. 2026.
[S18] Office of the Comptroller of the Currency. Bank Secrecy Act / Anti-Money Laundering. Comptroller’s Handbook, https://www.occ.treas.gov/publications-and-resources/publications/comptrollers-handbook/files/bsa-aml/pub-ch-bsa-aml.pdf. Accessed 9 Aug. 2026.