SardineCon SF/2026

Learn More
Regulation & bodies4 分で読めます

FFIEC BSA/AML Examination Manualとは?

SUBSCRIBE

The FFIEC BSA/AML Examination Manual is the standard reference US examiners use to assess anti-money-laundering programs. It lays out expectations and testing procedures across risk assessment, due diligence, monitoring, and reporting, which makes it a ready-made self-assessment checklist for you.

What is the manual, in plain English?

The FFIEC BSA/AML Examination Manual is, quite literally, the exam answer key, published in advance. It is the standard reference that US examiners use to assess how well an institution's anti-money-laundering program works, and it is publicly available, which means you can see exactly what they will test before they arrive.

The manual lays out both expectations and testing procedures across the core areas of an AML program: risk assessment, customer due diligence, transaction monitoring, suspicious-activity reporting, and program governance. It is not a vague statement of principles; it is a working document that tells examiners what to look at and how to evaluate it.

Because it is effectively the playbook exams follow, it doubles as a self-assessment and audit checklist for the institution. A team that maps its own controls to the manual's procedures is preparing against the same standard the examiner will use.

What the manual covers

  1. Assess — Risk assessment. Expectations for how an institution identifies and documents its money-laundering risk.
  2. Know — Customer due diligence. Procedures for identifying customers, beneficial owners, and higher-risk relationships.
  3. Detect — Monitoring and reporting. How examiners test transaction monitoring and suspicious-activity reporting.
  4. Govern — Program governance. Expectations for controls, the compliance officer, training, and independent testing.

Who is involved?

Who

Their role

The FFIEC

Publishes and periodically updates the manual on behalf of the member agencies.

Examiners

Use the manual's procedures to assess an institution's AML program at exam.

Compliance teams

Map their controls to the manual to anticipate testing and fix gaps first.

Internal audit

Uses the manual as a benchmark when independently testing the program.

What it looks like in practice

In practice

Ahead of an exam, a BSA officer wants to know where her program is weakest. She pulls the current manual and walks the transaction-monitoring section line by line, comparing each testing procedure to how her system is actually configured and documented.

She finds two gaps: alert thresholds that were never revalidated and a thin audit trail on cleared alerts. Both are exactly the kind of thing the procedures direct examiners to test. She fixes them before the exam, and when the reviewers work through the same section, the program holds up because she prepared against their own checklist.

Why it matters to operators

The manual is the single most practical way to anticipate an exam. Because it is what examiners actually use, mapping your program controls to its procedures tells you precisely what will be tested in monitoring, due diligence, and reporting, and lets you fix gaps before anyone shows up. Few compliance tools give you the grader's rubric in advance.

One caveat to keep in mind: the manual reflects supervisory expectations, not law itself. The binding legal requirements come from the BSA and its regulations; the manual is how those are examined. It is also updated periodically, so always work from the current version rather than an older copy you happen to have on file, since procedures do change between editions.

Operator notes

  • It is the exam rubric. Examiners test to the manual, so mapping your controls to it is direct exam prep.
  • Use it for self-assessment. Its procedures double as an audit and self-check checklist for your program.
  • Expectations, not law. The binding rules come from the BSA; the manual is how they are examined.
  • Work from the current edition. The manual is updated periodically, so an old copy can steer you wrong.
  • Cover every pillar. It spans risk assessment, due diligence, monitoring, reporting, and governance; do not test only one.

Quick questions

Is the FFIEC manual law?

No. It reflects supervisory expectations and examination procedures. The binding legal requirements come from the Bank Secrecy Act and its regulations; the manual is how examiners assess compliance with them.

Can I use the manual to prepare for an exam?

Yes, and you should. Because examiners test against it, mapping your controls to its procedures lets you anticipate exactly what will be reviewed and fix gaps beforehand.

What does the manual cover?

The core areas of an AML program: risk assessment, customer due diligence, transaction monitoring, suspicious-activity reporting, and program governance, with testing procedures for each.

Who uses the manual?

Examiners use it to assess programs, and compliance and internal audit teams use it as a benchmark and self-assessment tool. The FFIEC publishes and updates it for the member agencies.

Does the manual change?

Yes. It is revised periodically to reflect evolving expectations and rules, so you should always work from the current version rather than an older copy.

How is the manual different from the FFIEC itself?

The FFIEC is the interagency body that sets standards; the manual is its best-known output. The body creates the shared approach, and the manual is the document examiners actually apply.

Go deeper

  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.
  • FinCEN ↗ — The US financial intelligence unit. Bank Secrecy Act rules, advisories, and SAR and CTR guidance.

FFIEC BSA/AML Examination Manualと併せて知っておきたい用語