AML Laws in United States: Complete Guide to the Bank Secrecy Act (BSA), AMLA & FinCEN Compliance

Table of Contents

AML Laws in the United States showing the Bank Secrecy Act, FinCEN regulations, AMLA 2020, and compliance framework for financial institutions

AML laws in United States establish the legal framework that requires financial institutions to detect, prevent, investigate, and report money laundering and terrorist financing. Understanding these regulations is essential for banks, fintechs, money services businesses, cryptocurrency firms, casinos, and other regulated entities. This guide breaks down the statutes, regulations, program requirements, and enforcement realities that compliance teams must navigate and explains how integrated technology can turn legal mandates into operational workflows.

Overview and Timeline of US AML Laws

The United States has developed one of the world’s most comprehensive anti-money laundering frameworks through a series of key laws enacted over several decades. These laws establish the legal foundation for combatting money laundering, terrorist financing, and other illicit financial activities by imposing compliance obligations on financial institutions and related entities.

Key AML Laws and Their Timeline

  • Bank Secrecy Act (BSA) – 1970

  • USA PATRIOT Act – 2001

  • Anti-Money Laundering Act (AMLA) – 2020

  • Corporate Transparency Act (CTA) – Effective 2024

Why These Laws Matter Today

Together, these statutes form a robust legal framework that governs how financial institutions must detect, prevent, and report illicit financial activity. Compliance with these laws is essential to maintain the integrity of the US financial system, disrupt criminal networks, and meet the expectations of regulators such as federal banking agencies and the Financial Crimes Enforcement Network (FinCEN).

Financial institutions, including banks, fintechs, virtual asset service providers, and foreign financial institutions operating in the US, must navigate this evolving regulatory landscape to combat money laundering effectively. The timeline of laws reflects a growing sophistication and tightening of AML requirements in response to emerging financial crime risks and technological advances.

Understanding this timeline helps compliance teams align their programs with current regulatory mandates and anticipate future developments in AML laws in the United States.

ZIGRAM provides an integrated Complete AML System that operationalises these legal requirements through screening, monitoring, investigation, and reporting workflows for regulated institutions worldwide.

Core US AML Statutes and Regulations (BSA, AMLA, CTA)

Bank Secrecy Act (BSA)

  • Enacted as the core anti-money laundering (AML) framework within US laws and regulations.

  • Codified at 31 U.S.C. §§ 5311–5336.

  • Requires financial institutions to establish AML compliance programs.

  • Imposes recordkeeping and reporting requirements for monetary instruments.

  • Mandates detection and reporting of suspicious activity.

  • Creates infrastructure for law enforcement access to financial intelligence.

Anti-Money Laundering Act of 2020 (AMLA)

  • Modernizes and consolidates existing BSA/AML laws.

  • Directs FinCEN to publish national AML and counter-terrorist financing (CFT) threat priorities.

  • Strengthens whistleblower protections to encourage reporting of violations.

  • Mandates trend reporting from BSA filings to identify emerging risks.

  • Emphasizes risk-based AML programs over mere checkbox compliance.

  • Rulemaking to refine program requirements is ongoing through 2026.

Corporate Transparency Act (CTA)

  • Part of the AMLA focused on beneficial ownership transparency.

  • Requires many US companies to report beneficial ownership information to FinCEN.

  • Applies to entities formed before January 1, 2024, with reporting deadlines in early 2025.

  • Newly formed entities must report within 30 days of formation.

  • Supports customer due diligence by enabling verification of entity ownership.

USA PATRIOT Act Sections Relevant to AML

  • Section 312: Requires correspondent banking due diligence to prevent misuse.

  • Section 313: Prohibits dealings with foreign shell banks to combat illicit flows.

  • Section 314: Facilitates information sharing among financial institutions and law enforcement.

  • Section 319(b): Regulates cross-border correspondent banking relationships.

Economic Sanctions Laws Administered by OFAC

  • Require screening of customers and transactions against Specially Designated Nationals (SDN) and other restricted party lists.

  • Closely intersect with BSA AML compliance.

  • Violations carry civil penalties, often strict liability, increasing compliance stakes.

Implementing Regulations

  • FinCEN regulations codified under 31 CFR Chapter X provide detailed rules and guidance.

  • Sector-specific guidance issued by banking regulators, the SEC, and self-regulatory organizations supplements these rules.

These statutes and regulations collectively form the backbone of the US AML legal framework, requiring financial institutions to implement comprehensive anti-money laundering compliance programs.

Key Regulators and Supervisors in the US AML Ecosystem

  • Financial Crimes Enforcement Network (FinCEN): FinCEN, part of the US Department of the Treasury, is the primary administrator of the Bank Secrecy Act (BSA). It issues AML regulations, interpretive guidance, and advisories to financial institutions. FinCEN collects and analyzes Suspicious Activity Reports (SARs) and Currency Transaction Reports (CTRs), processing over 20 million reports annually. It serves as the US financial intelligence unit and has authority to bring civil enforcement actions for BSA violations. Additionally, FinCEN facilitates information sharing among over 9,000 institutions under Section 314(b) of the USA PATRIOT Act.

  • Office of Foreign Assets Control (OFAC): OFAC administers and enforces US economic sanctions programs targeting foreign countries, terrorist organizations, narcotics traffickers, and other designated entities. Financial institutions must screen customers and transactions against OFAC’s Specially Designated Nationals (SDN) and other sanctions lists. OFAC enforces strict liability penalties, meaning institutions can be held liable for violations even if unintentional, making sanctions screening a critical component of AML compliance programs.

  • Federal Banking Regulators: This group includes the Office of the Comptroller of the Currency (OCC), the Federal Reserve Board, the Federal Deposit Insurance Corporation (FDIC), and the National Credit Union Administration (NCUA). These agencies examine financial institutions for BSA/AML program adequacy, focusing on internal controls, governance, customer due diligence, independent testing, and timely reporting. They have enforcement powers including consent orders, civil money penalties, and removal of responsible parties. For example, the OCC issued a consent order against Bank of America in December 2024 for BSA/AML and sanctions compliance deficiencies.

  • Securities and Exchange Commission (SEC) and Financial Industry Regulatory Authority (FINRA): These regulators oversee securities broker-dealers and investment firms. They enforce AML compliance requirements tailored to the securities industry, including customer due diligence, transaction monitoring, and suspicious activity reporting specific to securities transactions.

  • State Banking and Money Transmitter Regulators: State-level regulatory agencies supervise money services businesses (MSBs), payment processors, and fintech companies operating within their jurisdictions. They enforce AML compliance consistent with federal laws and may impose additional state-specific requirements or licensing obligations.

  • Internal Revenue Service (IRS): The IRS oversees AML compliance for certain non-bank entities subject to the BSA, including casinos and other financial institutions. It focuses on ensuring these entities meet their reporting requirements and recordkeeping obligations to detect and prevent money laundering.

Enforcement actions are often coordinated among these regulators, requiring financial institutions to design AML compliance programs that meet multi-agency expectations and maintain robust controls across all operational areas.

Mandatory Elements of a US BSA/AML Compliance Program

Under the BSA and USA PATRIOT Act Section 352, financial institutions subject to these laws must implement a written AML compliance program commensurate with their risk profiles. Financial institutions must implement a written AML compliance program; this is not optional.

The traditional “four pillars” are:

  • Internal policies, procedures, and controls reasonably designed to ensure compliance

  • A designated BSA/AML compliance officer with authority and resources

  • Ongoing employee training programs – AML compliance programs must include ongoing employee training programs so staff can identify red flags

  • Independent testing or audit to verify program effectiveness

The framework has evolved to include a “fifth pillar”: formal customer due diligence requirements under FinCEN’s CDD rule. This includes ongoing monitoring of customer relationships, developing risk profiles, and beneficial ownership identification as explicit program components.

A compliant program must integrate multiple operational capabilities:

  • Customer risk assessment covering entity types, geographies, products, and delivery channels

  • Transaction monitoring and payment screening

  • Sanctions screening against OFAC lists

  • Escalation, investigations, and case management workflows

  • BSA reporting, recordkeeping, and exam-readiness documentation

  • Financial institutions must file SARs within 30 days of detection.

ZIGRAM’s Complete AML System maps directly to these pillars, combining policy-driven workflows with AI-powered controls, unified case management, and reporting orchestration.

Customer Identification, Customer Due Diligence and Beneficial Ownership

  • Customer Identification Programs (CIP):
    CIP is a mandatory process under the USA PATRIOT Act Section 326 that requires financial institutions to verify the identity of every customer when opening an account. This involves collecting essential personal information such as the customer’s full name, date of birth, residential address, and a government-issued identification number. Verification can be done through documents like passports or driver’s licenses or through non-documentary methods such as database checks. Additionally, customers must be screened against terrorism and sanctions watchlists to ensure they are not involved in illicit activities. Institutions must keep detailed records of all verification steps to demonstrate compliance during regulatory examinations.

  • Customer Due Diligence (CDD):
    CDD goes beyond initial identity verification by requiring institutions to understand the nature and purpose of the customer relationship. This means assessing why the customer is opening the account, what types of transactions they are likely to conduct, and identifying any potential risks associated with the customer’s profile. Institutions develop risk profiles for each customer, categorizing them based on factors such as geography, industry, and transaction patterns. Ongoing monitoring is essential to detect suspicious or unusual activity, and risk ratings must be updated regularly to reflect any changes in customer behavior or circumstances.

  • Beneficial Ownership Identification:
    This process focuses on identifying the individuals who ultimately own or control legal entities, particularly those owning 25% or more of the entity or exercising significant control. The Corporate Transparency Act requires many US companies to report this beneficial ownership information to FinCEN, creating a centralized database. Financial institutions use this database as part of their due diligence efforts to verify ownership information provided by customers and to detect hidden or illicit ownership structures that could facilitate money laundering or fraud.

  • Enhanced Due Diligence (EDD):
    EDD is a more rigorous level of scrutiny applied to higher-risk customers. This includes politically exposed persons (PEPs), individuals or entities located in high-risk countries or regions, customers with complex or opaque ownership structures, correspondent banking relationships, and businesses involved in cryptocurrency or other emerging financial technologies. EDD involves deeper investigations such as verifying the source of funds and wealth, conducting site visits to business locations, and performing adverse media analysis to uncover any negative information or reputational risks. These enhanced checks help institutions better understand and mitigate the risks posed by these customers.

Transaction Monitoring, Sanctions Screening and BSA Reporting Duties

Ongoing monitoring is how AML regulations move from static onboarding checks to real-time detection of suspicious behavior. Transparency in transactions helps prevent financial crime, including drug trafficking and fraud.

Transaction monitoring must cover cash, wires, ACH, cards, trade finance, virtual asset flows, and instant payment rails like FedNow. Institutions deploy rules-based and model-based scenarios to detect structuring, smurfing, funnel accounts, mule activity, and typologies identified in FinCEN advisories. Tuning these scenarios to balance detection against false positives is essential – alert fatigue undermines program effectiveness.

Sanctions and payment screening require real-time screening of counterparties and beneficiaries against OFAC and other watchlists. Message screening on SWIFT, ISO 20022, and other payment formats ensures compliance across rails. Institutions must periodically rescreen their entire customer base as sanctions lists update.

Core BSA reporting duties include:

  • Suspicious activity reports: institutions must file SARs within 30 days of detection, with strict confidentiality and narrative-quality expectations

  • Currency transaction reports: Currency Transaction Reporting requires financial institutions to file CTRs for cash transactions over $10,000, including aggregated daily totals

  • Other reports including Foreign Bank and Financial Accounts (FBAR) filings and funds transfer recordkeeping where relevant

Larger institutions automate workflows from alert generation through SAR drafting and submission via the BSA E-Filing System, using batch filing to manage volume.

Sector-Specific AML Obligations: Banks, Fintechs, Crypto and Beyond

While the BSA framework applies broadly, implementation differs across sectors based on business models and risk profiles.

Banks and Credit Unions

  • Full-scope BSA/AML programs including CIP, CDD, EDD, transaction monitoring, sanctions screening, and independent audits.

  • Heightened scrutiny on correspondent banking relationships, private banking accounts, and trade finance.

  • Regular prudential examinations conducted by federal banking regulators with stringent enforcement precedents.

Money Services Businesses (MSBs) and Payment Processors

  • Required to register with FinCEN and hold state money transmitter licenses.

  • Obligated to file SARs with lower thresholds (e.g., $2,000 for MSBs) and CTRs.

  • Must maintain oversight of agent networks.

  • Face particular scrutiny on cross-border remittances.

  • Subject to FinCEN notices addressing risks such as scam payments and illicit activities in virtual currency kiosks.

Fintechs and Neobanks

  • Must comply directly with BSA regulations when regulated, even when partnering with sponsor banks.

  • Require clear contractual allocation of AML duties, data access, and reporting responsibilities.

  • Regulatory obligations cannot be delegated away by financial institutions subject to these requirements.

Virtual Asset Service Providers (VASPs) and Crypto Platforms

  • Generally treated as MSBs under FinCEN guidance.

  • Required to implement KYC, transaction monitoring, and travel rule compliance.

  • Face unique challenges including reconciling on-chain and off-chain data, monitoring mixing services, and tracing anonymity-enhancing technologies.

Other Financial Institutions

  • Includes securities broker-dealers, mutual funds, insurance companies, casinos, and dealers in precious metals and stones.

  • Each sector faces tailored AML program expectations and sector-specific red flags.

  • Designation as a primary money laundering concern may trigger additional requirements.

A modular RegTech stack like ZIGRAM’s Complete AML System supports these diverse needs, allowing screening, monitoring, and investigation modules to be configured per line of business or entity type.

Consequences of AML Non-Compliance in the United States

US authorities aggressively enforce BSA/AML laws. Penalties for AML non-compliance can include significant fines and operational limitations, and the consequences extend well beyond monetary penalties.

Civil and criminal penalties for AML non-compliance can reach $250,000 per violation or twice the value of the transaction involved. Civil money penalties at scale are staggering: US regulators assessed over $15 billion in AML-related penalties since 2010. Severe penalties for non-compliance under the AMLA include a tiered system for repeat offenders, escalating consequences for institutions that fail to remediate.

Criminal prosecution can lead to imprisonment up to 10 years for willful BSA violations, particularly when combined with substantive money laundering and terrorist financing charges. Criminal penalties extend to individuals, like compliance officers and executives, who can face personal liability and criminal forfeiture in egregious cases.

Regulatory enforcement actions include cease and desist orders, requirements to engage independent consultants, look-back reviews, and removal orders for institution-affiliated parties. Monetary penalties often accompany consent orders demanding comprehensive program overhauls.

Collateral impacts are severe. AML compliance failures can cause irreparable reputational damage. Some institutions lost correspondent banking relationships after AML scandals, leading to increased funding costs, licensing restrictions, and inability to expand.

Consider two recent cases. TD Bank was assessed $1.3 billion by FinCEN in October 2024 – the largest BSA penalty in US history – for failures including SAR backlogs and allowing illicit transactions through P2P platforms. Silvergate Bank faced $63 million in combined penalties from the Federal Reserve and California regulators for deficient transaction monitoring. Both cases illustrate how weak CDD, inadequate monitoring, and ignored alerts trigger enforcement – and how stronger, integrated programs could have mitigated exposure.

Current AML Trends and Regulatory Expectations through 2026

US regulators are shifting from checklist compliance to judging effectiveness, outcomes, and intelligence quality. FinCEN’s Year in Review emphasizes generating “highly useful information” for law enforcement, not just filing volume.

Key themes shaping the AML regulatory landscape include:

  • Implementation of Corporate Transparency Act beneficial ownership reporting, with interim final rules refining definitions

  • FinCEN’s national AML/CFT priorities covering corruption, fraud, drug trafficking, ransomware, money laundering and terrorist financing, and proliferation

  • Intensifying focus on real-time or near-real-time monitoring for instant payment schemes like FedNow and RTP

For virtual assets and DeFi, ongoing guidance for virtual asset service providers emphasizes travel rule compliance and tracing of anonymity, enhancing technologies. AML laws enhance national security by disrupting terrorist financing and protecting the financial system, and digital assets remain a priority enforcement area.

How ZIGRAM's Complete AML System Operationalizes AML Laws in United States

An end-to-end “Complete AML System” architecture should include:

  • Data ingestion from core banking, payment processors, crypto ledgers, and external data providers

  • Centralized customer and entity risk profiles shared across the lifecycle

  • Integrated modules for name screening, transaction monitoring, and case management

ZIGRAM’s Complete AML System is a modular, AI-enabled AML compliance platform designed to help banks, fintechs, crypto platforms, and other financial institutions meet US BSA/AML obligations efficiently.

The main components include:

  • PreScreening.io for customer and counterparty name screening, covering sanctions, PEPs, watchlists, and adverse media

  • Transact Comply for transaction monitoring and payment screening across multiple rails, including wires, ACH, cards, and virtual assets

  • Entity Hero for structured entity risk assessment and ongoing CDD/EDD

These modules integrate through a unified case manager that consolidates alerts from screening and monitoring, shares risk scores and profiles across the customer lifecycle, and provides configurable workflows mirroring regulatory expectations for investigations, escalations, and SAR decisions.

Mapped to specific US AML regulatory requirements, the system supports CIP and CDD through KYC data capture and verification, ongoing monitoring and BSA reporting through alert documentation and SAR/CTR preparation, and sanctions compliance through real-time and batch screening against OFAC and other lists.

"20 Things That Make The Complete AML System": Insights for US AML Teams

ZIGRAM’s newly published report, “20 Things That Make The Complete AML System,” is a 104-page practical guide (30 June 2026 edition) aimed at practitioners who must align their architectures with US and global AML regulations.

Conclusion: Building Resilient, Law-Aligned AML Programs in the US

US AML regulations, rooted in the Bank Secrecy Act, Anti-Money Laundering Act, and related rules, require holistic programs covering customer due diligence, transaction monitoring, sanctions screening, BSA reporting, and governance. Regulators increasingly judge programs on effectiveness, quality of intelligence, and risk-based design rather than volume of alerts or mere box-ticking.

The strategic imperative is clear. Institutions must understand their specific regulatory obligations under US law. They must invest in integrated AML architecture and high-quality data. And they must continually train staff and refine controls based on changing risks and evolving financial crime typologies.

ZIGRAM’s Complete AML System turns statutory and regulatory obligations into actionable, auditable workflows, combining screening, monitoring, case management, and analytics modules into a unified platform that supports exam readiness and detection quality across every line of business.

Compliance leaders, MLROs, and risk heads should review their current AML setup against the requirements outlined in this guide, explore ZIGRAM’s Complete AML System, and download the “20 Things That Make The Complete AML System” report to support their next phase of AML transformation.

Enhance Your AML Compliance Efforts

Empower your organization with ZIGRAM's integrated RegTech solutions

Financial Crime Prevention Image

Articles

Explore insightful articles on cutting-edge topics like regulations, technological advancements, and critical insights into AML and financial crime risks
https://d2g4ubq4o0ypu0.cloudfront.net/wp-content/uploads/2026/07/Philippines-Casino-AML-Directives-300x200.webp

PAGCOR Strengthens Casino AML Compliance Framework: What...

10 Min
https://d2g4ubq4o0ypu0.cloudfront.net/wp-content/uploads/2026/07/AML-Laws-in-the-United-States-300x200.webp

AML Laws in United States: Complete Guide...

12 Min
https://d2g4ubq4o0ypu0.cloudfront.net/wp-content/uploads/2026/07/Types-of-Financial-Crimes-300x200.webp

Types of Financial Crimes: Key Offences, Trends,...

12 Min
https://d2g4ubq4o0ypu0.cloudfront.net/wp-content/uploads/2026/07/Cyber-Scam-Hubs-300x200.webp

Crypto Flows to Southeast Asia Cyber Scam...

22 Min
https://d2g4ubq4o0ypu0.cloudfront.net/wp-content/uploads/2026/07/POGO-Ban-Philippines-300x200.webp

POGO Ban Philippines: 2024 Nationwide Crackdown on...

11 Min
https://d2g4ubq4o0ypu0.cloudfront.net/wp-content/uploads/2026/07/Tanihub-Scandal-300x200.webp

TaniHub Scandal in Indonesia: AML Lessons, Due...

11 Min