A BSA/AML program rests on five pillars: a system of internal controls, a designated BSA officer, training, independent testing, and customer due diligence with beneficial-ownership identification. Four of them have defined the program for decades. The fifth, CDD, was formalized by FinCEN's 2018 rule. An examiner grades each pillar on whether it genuinely exists and operates in practice, rather than on whether a policy states that it should.
The BSA/AML program pillars are the required components of an anti-money laundering compliance program: a system of internal controls, a designated BSA compliance officer, ongoing training, independent testing of the program, and risk-based customer due diligence including beneficial-ownership identification. The program requirement itself sits at 31 U.S.C. 5318(h), and the component list for banks at 31 CFR 1020.210. The pillars supply the common vocabulary for what a BSA/AML program must contain, and an examination, a sponsor-bank review, and a gap analysis each organize themselves around them.
This guide describes each pillar in turn: what it requires, what an adequate implementation contains, and how an examiner grades it.
What the pillars are, and why five
For most of the BSA's history the program rested on four pillars. FinCEN's Customer Due Diligence rule, effective in 2018, added a fifth by formalizing risk-based CDD and the requirement to identify the beneficial owners of legal-entity customers. Today most practitioners describe the program as five pillars.
| Pillar | In one line |
|---|---|
| 1. Internal controls | Written policies, procedures, and processes that run the program. |
| 2. Designated BSA officer | A named, accountable person who owns the program day to day. |
| 3. Training | Role-specific education for the people who operate the controls. |
| 4. Independent testing | Periodic review by someone independent of the program. |
| 5. Customer due diligence | Risk-based CDD plus beneficial-ownership identification (the fifth pillar). |
Pillar 1: Internal controls
Internal controls are the written policies, procedures, and processes that make the program run: how the institution assesses risk, onboards customers, monitors activity, escalates, and files. Adequate controls are specific to the institution and its products, with named owners and operative thresholds. An examiner reads them to determine whether the program was designed for the institution's actual risk or lifted from a template.
Pillar 2: Designated BSA officer
The program requires a named individual accountable for its day-to-day operation, with the authority and resources to carry it out. The designation identifies a specific person rather than a function or a shared mailbox. The board and senior management remain ultimately responsible, and the BSA officer is the individual an examiner expects to know the program in detail and answer for it.
Pillar 3: Training
Training reaches the people who operate the controls, in language that fits their role. Onboarding staff, support, operations, and leadership each require training scoped to their function. Examiners look for evidence of who was trained, on what, and when. Generic annual training that participants cannot recall is a common source of findings.
Pillar 4: Independent testing
The program must be reviewed periodically by a party independent of the people who run it, scoped to the institution's risk. For many institutions this is the FFIEC Pillar-3 independent test: control walkthroughs, sample testing, a findings register, and an opinion. Independence is the operative term: the reviewer sits outside the program being reviewed. Open findings from the last test are among the first items an examiner reads. (See the exam-prep guide.)
Pillar 5: Customer due diligence and beneficial ownership
The fifth pillar requires risk-based customer due diligence: identifying and verifying customers, understanding the nature and purpose of the relationship, and conducting ongoing monitoring to maintain and update customer information. For legal-entity customers it adds beneficial-ownership identification, the requirement to know the natural persons behind a company. CDD is where a program turns "who is this customer" into a risk rating that drives everything downstream.
How examiners grade the pillars
Across all five, an examiner tests the same proposition: whether the pillar exists and operates, or exists only on paper. A pillar passes when the institution can demonstrate with evidence that it works against the institution's real risk. Recurring failure patterns include the following.
- Paper-only controls that describe a program nobody follows.
- A BSA officer without the authority or resources to act.
- Training with no record of who completed it.
- Independent testing that is not actually independent, or whose findings were never closed.
- CDD that collects information but never risk-rates or refreshes it.
The pillars function as the standing structure of the program rather than a periodic exercise. Where each one is maintained and evidenced continuously, an examination reviews work already performed rather than work assembled in advance of the review.
What is coming: the proposed program rule
FinCEN has proposed a rule, RIN 1506-AB72, that would change how these components are judged. It would add an explicit effective, risk-based, and reasonably designed standard and make a documented risk assessment a named program component tied to FinCEN's national priorities. It remains a proposal rather than law, with the comment period closed as of June 2026. The proposed AML/CFT program rule guide sets out what it would change and the preparatory steps available now.