Field Guide

The BSA/AML Program Pillars, Explained

The short version

A BSA/AML program rests on five pillars: a system of internal controls, a designated BSA officer, training, independent testing, and customer due diligence with beneficial-ownership identification. Four of them have defined the program for decades. The fifth, CDD, was formalized by FinCEN's 2018 rule. An examiner grades each pillar on whether it genuinely exists and operates in practice, rather than on whether a policy states that it should.

The BSA/AML program pillars are the required components of an anti-money laundering compliance program: a system of internal controls, a designated BSA compliance officer, ongoing training, independent testing of the program, and risk-based customer due diligence including beneficial-ownership identification. The program requirement itself sits at 31 U.S.C. 5318(h), and the component list for banks at 31 CFR 1020.210. The pillars supply the common vocabulary for what a BSA/AML program must contain, and an examination, a sponsor-bank review, and a gap analysis each organize themselves around them.

This guide describes each pillar in turn: what it requires, what an adequate implementation contains, and how an examiner grades it.

What the pillars are, and why five

For most of the BSA's history the program rested on four pillars. FinCEN's Customer Due Diligence rule, effective in 2018, added a fifth by formalizing risk-based CDD and the requirement to identify the beneficial owners of legal-entity customers. Today most practitioners describe the program as five pillars.

PillarIn one line
1. Internal controlsWritten policies, procedures, and processes that run the program.
2. Designated BSA officerA named, accountable person who owns the program day to day.
3. TrainingRole-specific education for the people who operate the controls.
4. Independent testingPeriodic review by someone independent of the program.
5. Customer due diligenceRisk-based CDD plus beneficial-ownership identification (the fifth pillar).

Pillar 1: Internal controls

Internal controls are the written policies, procedures, and processes that make the program run: how the institution assesses risk, onboards customers, monitors activity, escalates, and files. Adequate controls are specific to the institution and its products, with named owners and operative thresholds. An examiner reads them to determine whether the program was designed for the institution's actual risk or lifted from a template.

Pillar 2: Designated BSA officer

The program requires a named individual accountable for its day-to-day operation, with the authority and resources to carry it out. The designation identifies a specific person rather than a function or a shared mailbox. The board and senior management remain ultimately responsible, and the BSA officer is the individual an examiner expects to know the program in detail and answer for it.

Pillar 3: Training

Training reaches the people who operate the controls, in language that fits their role. Onboarding staff, support, operations, and leadership each require training scoped to their function. Examiners look for evidence of who was trained, on what, and when. Generic annual training that participants cannot recall is a common source of findings.

Pillar 4: Independent testing

The program must be reviewed periodically by a party independent of the people who run it, scoped to the institution's risk. For many institutions this is the FFIEC Pillar-3 independent test: control walkthroughs, sample testing, a findings register, and an opinion. Independence is the operative term: the reviewer sits outside the program being reviewed. Open findings from the last test are among the first items an examiner reads. (See the exam-prep guide.)

Pillar 5: Customer due diligence and beneficial ownership

The fifth pillar requires risk-based customer due diligence: identifying and verifying customers, understanding the nature and purpose of the relationship, and conducting ongoing monitoring to maintain and update customer information. For legal-entity customers it adds beneficial-ownership identification, the requirement to know the natural persons behind a company. CDD is where a program turns "who is this customer" into a risk rating that drives everything downstream.

How examiners grade the pillars

Across all five, an examiner tests the same proposition: whether the pillar exists and operates, or exists only on paper. A pillar passes when the institution can demonstrate with evidence that it works against the institution's real risk. Recurring failure patterns include the following.

The pillars function as the standing structure of the program rather than a periodic exercise. Where each one is maintained and evidenced continuously, an examination reviews work already performed rather than work assembled in advance of the review.

What is coming: the proposed program rule

FinCEN has proposed a rule, RIN 1506-AB72, that would change how these components are judged. It would add an explicit effective, risk-based, and reasonably designed standard and make a documented risk assessment a named program component tied to FinCEN's national priorities. It remains a proposal rather than law, with the comment period closed as of June 2026. The proposed AML/CFT program rule guide sets out what it would change and the preparatory steps available now.

Common questions

What are the BSA/AML program pillars?
The required components of a BSA/AML compliance program: a system of internal controls, a designated BSA compliance officer, ongoing training, independent testing of the program, and risk-based customer due diligence including beneficial-ownership identification. Together they define what a reasonably designed program must contain.
Why are there five pillars now instead of four?
For years the program rested on four pillars: internal controls, a BSA officer, training, and independent testing. FinCEN's Customer Due Diligence rule, effective in 2018, formalized risk-based CDD and beneficial-ownership identification as a fifth pillar. Most practitioners now describe the program as five pillars.
What is the fifth pillar of BSA/AML?
The fifth pillar is customer due diligence, including the requirement to identify and verify the beneficial owners of legal-entity customers. It was added by FinCEN's CDD rule (effective 2018) and requires understanding the nature and purpose of customer relationships and conducting ongoing monitoring.
Who is responsible for the BSA/AML pillars?
The institution's board and senior management are ultimately responsible for an adequate program, and a designated BSA compliance officer is accountable for its day-to-day operation. In a sponsor-bank / fintech relationship, the bank holds the non-delegable regulatory responsibility even when a fintech performs the work.
Do fintechs need all five pillars?
Yes. A fintech subject to BSA/AML obligations, or operating under a sponsor bank, needs all five pillars stood up and sized to its risk. The program does not have to be large, but each pillar must genuinely exist, be documented, and operate, because a sponsor bank and an examiner will test all five.
About this library

This reference library is maintained by Rupture Labs, the company behind Compliance Command Center, compliance software built and reviewed by practitioners. Contact.

Primary sources

The authoritative texts this guide is grounded in. Government sites may block automated access but resolve in a browser.