SardineCon SF/2026

Learn More
AML programs4 分で読めます

BSA/AML programとは?

SUBSCRIBE

A BSA/AML program is a US financial-crime program built to meet the Bank Secrecy Act pillars: internal controls, a named officer, ongoing training, independent testing, and risk-based customer due diligence. Examiners grade each pillar on its own, so a strong monitoring system will not make up for a missing one.

What is a BSA/AML program, in plain English?

A BSA/AML program is the full set of controls a US financial institution runs to comply with the Bank Secrecy Act and related anti-money-laundering rules. It is not one system; it is a structured framework organized around a fixed list of required components, or pillars, that regulators expect every covered firm to have.

The pillars are: a system of internal controls, a designated BSA/AML officer, ongoing training, independent testing of the program, and risk-based customer due diligence that now includes identifying beneficial owners. Each pillar is a distinct obligation, and examiners assess each one separately rather than forming a single overall impression.

That separateness is the key operating fact. You cannot trade a great score on one pillar for a poor score on another. A best-in-class monitoring engine will not paper over the absence of independent testing, and vice versa. Map your controls to each pillar clearly, because pillars that are undocumented or unstaffed are among the most frequent enforcement findings.

The pillars, broken down

Pillar

What it requires

Internal controls

Documented policies and procedures that turn AML duties into daily action.

Designated officer

A named, empowered BSA/AML officer accountable for the program and its filings.

Training

Ongoing, role-appropriate education so staff can spot and escalate red flags.

Independent testing

Periodic audit by someone with no stake in the result, checking the program actually works.

Customer due diligence

Risk-based KYC and beneficial ownership, the fifth pillar added in recent years.

Who owns each pillar?

Who

Their role

BSA/AML officer

Owns internal controls, training, and the CDD framework; answers for the whole program.

Independent auditor

Runs the independent testing pillar without reporting to the people who run the program.

Front-line staff

Apply the CDD and controls at onboarding and in daily operations.

Board and senior management

Approve the program, fund it, and are accountable for its effectiveness.

What it looks like in practice

In practice

A regional bank has an excellent transaction monitoring team and a well-run onboarding process, so leadership assumes its program is healthy. But its last independent test was three years ago and covered only a fraction of the business, and training records for the retail branches are missing.

At the next exam, the strong monitoring earns no credit against the weak pillars. The bank is cited for inadequate independent testing and incomplete training, and given a remediation plan. The lesson lands hard: being excellent at one pillar bought no slack on the others.

Why a weak pillar drags down the rest

Because examiners grade each pillar on its own, the program is only as strong as its weakest component. A gap in independent testing means nobody credible has confirmed the rest of the program works, which undermines confidence in everything else. A gap in training means the best controls in the world go unused because staff do not know how to apply them.

The practical instruction is to map your controls to each pillar explicitly and keep the evidence current. Do not assume that being good at one pillar buys you slack on another; it does not. Undocumented or unstaffed pillars are among the most common and most avoidable enforcement findings, precisely because the requirement is well known and the fix is largely administrative discipline.

What to watch for

  • Stale independent testing. A test that is years old or narrowly scoped leaves the whole program unvalidated.
  • Missing training records. If you cannot show who was trained and when, the pillar effectively does not exist for the exam.
  • Unmapped controls. Controls that do not clearly tie back to a specific pillar are hard to defend and easy to overlook.
  • Officer without power. A designated officer who lacks authority or resources hollows out the whole framework.
  • CDD gaps on beneficial ownership. The newest pillar is a frequent weak spot; unverified beneficial owners are a direct finding.

Quick questions

What are the pillars of a BSA/AML program?

Internal controls, a designated BSA/AML officer, ongoing training, independent testing, and risk-based customer due diligence including beneficial ownership. Examiners assess each one separately.

How many pillars are there, four or five?

Historically four, but customer due diligence with beneficial ownership is now commonly counted as the fifth pillar following newer rules. Firms should treat CDD as a first-class requirement either way.

Can strong monitoring make up for a weak pillar?

No. Each pillar is graded on its own, so excellence in one area does not offset a gap in another. A weak pillar drags down the overall assessment regardless of how good the rest is.

Who runs the independent testing?

Internal audit or a qualified outside party with no stake in the program's outcome. The people who run the program cannot credibly test their own work.

Why is documentation so important?

Because pillars that are undocumented or unstaffed are among the most frequent enforcement findings. If you cannot show a control operating, an examiner will assume it does not.

Is a BSA/AML program the same as an AML program elsewhere?

The idea is the same, but BSA/AML is the specific US framing tied to the Bank Secrecy Act and its pillars. Other jurisdictions have similar programs under different names and slightly different requirements.

Go deeper

  • FFIEC BSA/AML Examination Manual ↗ — The manual US examiners use to assess BSA and AML programs.
  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

BSA/AML programと併せて知っておきたい用語