BSA/AML independent testing
Your independent test is due. Make this one tell you something.
Most independent tests pull a sample of files and report that the program looks fine, until someone pulls a different sample. We test every record, so a problem can't hide in the files nobody looked at, and every finding tells you what it would cost to leave open.
Your problem
A report everyone reads, built on a sample nobody trusts
- The test is required. The Bank Secrecy Act requires every AML program to include an independent audit function that tests it (31 U.S.C. 5318(h)(1)(D)), usually on a twelve to eighteen month cycle.
- Your sponsor bank and your examiner read it first, and they will ask how the tester reached each conclusion.
- Last year's test sampled a handful of files. It could not tell you what was in the rest.
- The findings came back as a list with no cost attached, so there was no way to decide what to fix first.
What you get
A test that answers the questions you will be asked
- A signed report for your board or audit committee that your sponsor bank and your examiner can follow from conclusion back to evidence.
- Every finding cited and priced. Each one names the rule it breaks, points to the records that show it, and carries what it's likely to cost if left open.
- A remediation order you can defend, because the most expensive gaps come first.
- Work papers for every test, showing the population, the method and the result for each record.
- The regulatory inventory the test ran against, so you can see exactly which rules were tested and why they apply to you.
How we do it
Scope, test, walk through, write up
- We scope the test against the rules that actually apply to you, not a generic checklist.
- The engine tests each in-scope control against every record in the period: customer files, alerts, case decisions, currency transaction reports and suspicious activity report timelines.
- A practitioner walks through the controls that live in people rather than systems, with the people who run them.
- The practitioner who signs the report has no role in running your program. That independence is checked before we accept the engagement.
- We never test a program we helped fix. If we remediated it, the independent test comes from someone else. Remediation is a separate service.
The Bank Secrecy Act program is commonly described in five pillars: the four in the statute, and customer due diligence, added by FinCEN's 2016 rule. The test covers all five.
How the work is done
The audit you already buy, performed by an engine.
- Every record testedControls are tested against the full population of accounts and transactions, not a sample of twenty-five.
- Every requirement citedEach requirement the work runs against is cited to the rule it comes from, with the facts behind it labelled.
- Findings pricedFindings arrive priced in dollars, so remediation is ordered by what each gap is worth.
- A signed reportThe report is signed, and any reader can check that nothing in it changed after signing.
Pricing
The same budget line you already have
This replaces the independent testing engagement you already pay an audit or consulting firm for. Same budget line, same regulatory purpose, with the full population tested instead of a sample.
Price: Priced at scoping, set once we know your size and scope. How pricing works
The published method
How this is normally done
The regulator's and the standard-setter's own method for this work, explained in plain English and cited to the source. We have nothing to hide about how we do it: check our process against it.
- Field GuideBSA/AML Independent Testing: The Third PillarThe third pillar in practice: what independent testing covers, who can perform it, how often it runs, and how examiners and sponsor banks read the findings.
- ComparisonAML Audit vs. Independent TestingThe two terms get used interchangeably but are not identical. What each means, where they overlap, and which one satisfies the third pillar.
- Field GuideThe BSA/AML Program Pillars, ExplainedThe five pillars in plain language: internal controls, a designated officer, training, independent testing, and customer due diligence. How each one shows up in an exam.
What happens next
Three steps from here.
- 01
A scoping call
Tell us about your program, when the test is due, and who will read it. We tell you plainly whether we are the right fit.
- 02
A written scope
What we will test, what you will receive, the timeline and the price, in writing before you commit.
- 03
The test and the report
We test, a practitioner reviews and signs, and you receive the report, the findings and the work papers.
Book a scoping call
Practitioner-led. Scope and price are set on the call.