A BSA/AML examination is a supervisory review of whether an institution's anti-money-laundering program is reasonably designed for the institution's risk and operating as its documentation describes. Examiners measure the program against the pillars set out at 31 CFR 1020.210, evaluate the risk assessment, and then pull samples to test whether the controls operate. Readiness is a continuous condition rather than a pre-examination task: an institution that keeps its risk assessment current and retains evidence as a byproduct of daily work responds to a document request in days, while an institution that begins assembling proof at the entry letter spends the intervening weeks doing so.
A BSA/AML examination is a periodic supervisory review in which a federal or state regulator evaluates whether an institution's anti-money-laundering program satisfies the requirements of 31 U.S.C. 5318(h) and 31 CFR 1020.210, and whether the program operates in practice as its documentation describes. The examination produces written findings that the institution must address and that carry into the next supervisory cycle.
This article covers what the examination tests, how it unfolds, the documents examiners request, how examiners read a program, the findings that recur at fintechs, and the practices that constitute readiness before an entry letter arrives.
What the examination tests
Examiners evaluate two things at once. First, whether the program is reasonably designed for the institution's risk. Second, whether it operates the way the documents say it does. A program documented in policy but not followed in practice fails the second test, and most findings arise there.
The evaluation runs through the BSA program pillars: internal controls, a designated BSA officer, training, independent testing, and customer due diligence including beneficial ownership. The risk assessment sits underneath all of it, because a program can only be judged reasonable against the risk it claims to face.
How an examination unfolds
Examinations vary by regulator and institution, but most move through four phases.
| Phase | What happens |
|---|---|
| 1. Scoping | The regulator issues an entry letter and a document request, often several weeks before the on-site. The scope is shaped by the institution's risk profile, prior findings, and any intervening events. |
| 2. Review and testing | Examiners read the policies and then test them, on-site or remotely. They sample alerts, SARs, CDD files, and monitoring output to see whether the program does on the ground what it claims on paper. |
| 3. Findings | Examiners raise issues, ask follow-up questions, and discuss what they have seen. This is the window to clarify a misunderstanding before it hardens into a written finding. |
| 4. Response | The institution receives written findings and submits a remediation commitment: each issue mapped to an owner, an action, and a date. Open items carry into the next examination cycle. |
What examiners ask for
The document request is long and largely predictable. The following items recur across examinations.
- The BSA/AML policy and procedures, with version history.
- The risk assessment, current and matched to the institution's actual products and volume.
- The most recent independent test and the status of every finding it raised.
- Training records: who was trained, on what, and when.
- The designated BSA officer's appointment and reporting line.
- SAR and CTR filings for the review period, with supporting workpapers.
- Alert and case samples, including decisions to close without filing.
- CDD and beneficial-ownership files for a sample of customers.
- Transaction-monitoring configuration: the rules, thresholds, and tuning history.
- Board and committee minutes showing senior oversight of the program.
For a fintech operating under a sponsor bank, add the partner-oversight evidence: the oversight framework, the partner risk rating, and proof that monitoring and testing of the relationship actually happened. The sponsor bank is examined on the same relationship from its own side.
How examiners read a program
An examiner forms a judgment about whether the program reasons about risk or processes paper. Four indicators shape that judgment:
- Whether the risk assessment drives the program. A risk assessment that names high-risk products but is not reflected in monitoring rules or CDD depth does not influence how the program operates.
- Demonstrability of the controls. Evidence that monitoring happened carries more weight than a policy stating that it should. Examiners weigh what an institution can demonstrate over what it asserts.
- Whether SAR narratives support their filings. Conclusory narratives indicate a program filing to clear a queue rather than to report what it observed. (See the SAR narrative guide.)
- Closure of prior findings. Open items from the prior independent test or examination reduce the program's credibility with the examiner.
Recurring findings at fintechs
The same findings repeat across institutions. Drawn from public enforcement actions and examination patterns:
- A stale risk assessment that describes last year's business after a product launch or a jump in volume.
- Untuned transaction monitoring: rules inherited at launch and never calibrated to the actual customer base, producing alert floods or silence.
- Thin CDD: onboarding that collects information but does not risk-rate or refresh it.
- SAR narratives that do not hold up, with no stated reason for suspicion.
- No evidence of monitoring: a control that exists in policy with nothing to prove it ran.
- Open prior findings that were acknowledged and never remediated.
Preparation practices before and after the entry letter
Examination readiness is established before the entry letter arrives. The first set below describes standing practices; the second describes the pass an institution makes once the examination dates are set.
Standing, all year
- Keep the risk assessment current. It is refreshed when a product, customer segment, or volume materially changes, rather than annually by reflex.
- Close independent-testing findings. Each finding is tracked to closure with a named owner and a date.
- Retain evidence continuously. Controls are designed so each one leaves a timestamped artifact, so that the proof of a control's operation exists before an examiner requests it.
- Tune monitoring on a schedule and document the rationale, so the configuration carries a recorded basis.
Once the entry letter arrives
- Map the request to owners the day it lands. Every item is assigned, with internal dates ahead of the regulator's deadline.
- Review the samples internally first. The institution pulls the alerts, SARs, and CDD files it expects examiners to sample and reviews them against the standard examiners apply.
- Reconcile the record. The policy, the risk assessment, and what the samples show should be consistent with one another.
- Prepare the interviewees. The BSA officer and anyone who will be interviewed should know the program in detail and answer without speculating.
A pre-exam checklist
- The risk assessment matches the business as it operates today.
- Every prior finding is closed or has a documented, on-track remediation.
- The institution can produce evidence that monitoring ran, not only the policy requiring it.
- SAR narratives in the period support their filings and state the reason for suspicion.
- CDD files are risk-rated and current for the sample expected to be pulled.
- Monitoring rules and thresholds have a documented tuning rationale.
- For sponsor-bank fintechs, partner-oversight evidence is current and retrievable.
- The document request is mapped to owners with internal dates ahead of the deadline.
- The people who will be interviewed know the program and answer without guessing.
Examination outcomes are largely determined by ordinary operating practice rather than by pre-examination preparation. An institution that generates and retains control evidence in the normal course is able to respond to an entry letter without a separate assembly effort.