BSA

Master this essential documentation concept

Quick Definition

Bank Secrecy Act - a U.S. federal law requiring financial institutions to maintain detailed records and file reports that help detect and prevent money laundering and financial crimes.

How BSA Works

graph TD FI[Financial Institution] --> CTR[Currency Transaction Report Transactions over $10,000] FI --> SAR[Suspicious Activity Report Unusual or suspicious transactions] FI --> CIP[Customer Identification Program KYC verification] CTR --> FinCEN[FinCEN Database Financial Crimes Enforcement Network] SAR --> FinCEN CIP --> AML[AML Compliance Program Anti-Money Laundering] AML --> MonitorTx[Transaction Monitoring Pattern detection & alerts] MonitorTx --> SAR FinCEN --> LEA[Law Enforcement Agencies DOJ, FBI, IRS] style FI fill:#2563eb,color:#fff style FinCEN fill:#dc2626,color:#fff style LEA fill:#16a34a,color:#fff

Understanding BSA

Bank Secrecy Act - a U.S. federal law requiring financial institutions to maintain detailed records and file reports that help detect and prevent money laundering and financial crimes.

Key Features

  • Centralized information management
  • Improved documentation workflows
  • Better team collaboration
  • Enhanced user experience

Benefits for Documentation Teams

  • Reduces repetitive documentation tasks
  • Improves content consistency
  • Enables better content reuse
  • Streamlines review processes

Turning BSA Training Videos into Auditable SOPs

Many compliance teams rely on recorded walkthroughs to train staff on BSA obligations — covering topics like customer due diligence, suspicious activity report (SAR) filing, and currency transaction report (CTR) thresholds. These videos work well for onboarding, but they create a real gap when auditors or regulators ask your team to demonstrate that documented procedures exist and are being followed consistently.

The core problem is that a video is difficult to audit. If a BSA examiner requests evidence of your institution's written procedures for monitoring high-risk accounts, pointing them to a recorded screen share does not satisfy that requirement. Staff also cannot quickly search a video to confirm a specific step — such as the exact threshold that triggers a CTR filing — when they need a fast answer during a live transaction review.

Converting those existing BSA training videos into formal, versioned SOPs gives your team a searchable, referenceable document that aligns with what examiners expect to see. For example, a video walkthrough of your SAR escalation process can become a step-by-step procedure with clearly defined roles, decision points, and review dates — the kind of structured documentation that holds up under scrutiny.

If your compliance library still lives primarily in video form, see how the video-to-SOP workflow can help close that gap.

Real-World Documentation Use Cases

Documenting CTR Filing Workflows for Bank Teller Operations

Problem

Bank tellers and branch managers inconsistently file Currency Transaction Reports because the $10,000 threshold rules, structuring red flags, and FinCEN Form 104 completion steps are scattered across outdated policy manuals and training slides, leading to missed filings and regulatory penalties.

Solution

BSA compliance documentation standardizes the CTR trigger conditions, exemption categories (Phase I and Phase II), and the 15-calendar-day filing deadline into a single, searchable reference that tellers can access during transactions.

Implementation

['Map all cash transaction scenarios that trigger CTR obligations, including multiple same-day transactions by the same customer that aggregate over $10,000.', 'Document the FinCEN Form 104 field-by-field completion guide with examples for common edge cases such as armored car deposits and joint account holders.', 'Create a decision tree diagram distinguishing exempt persons (banks, government agencies, listed companies) from non-exempt customers to reduce unnecessary filings.', "Publish the workflow in the institution's compliance portal with version control tied to FinCEN regulatory update dates."]

Expected Outcome

Branch CTR filing accuracy improves to above 98%, examiner findings related to late or missing CTRs drop to zero, and teller onboarding time for BSA procedures is reduced from 3 days to half a day.

Building SAR Narrative Writing Guidelines for Fraud Investigation Teams

Problem

Compliance analysts write Suspicious Activity Reports with vague narratives that fail to answer who, what, when, where, why, and how, causing FinCEN and law enforcement to request amendments and delaying investigations into potential money laundering networks.

Solution

BSA documentation provides structured SAR narrative templates aligned with FinCEN's guidance, including activity type classifications (structuring, layering, trade-based money laundering) and mandatory data elements that ensure actionable intelligence for law enforcement.

Implementation

["Define the five W's framework for SAR narratives with annotated examples drawn from real FinCEN SAR Activity Review typologies for each suspicious activity category.", 'Document the 30-day initial filing deadline and 60-day extension conditions, along with the continuing SAR obligation for ongoing suspicious activity every 90 days.', 'Create a prohibited disclosure (tipping off) policy reference section explaining what analysts cannot share with subjects under 31 U.S.C. 5318(g)(2).', "Establish a peer review checklist that compliance managers use before SAR submission to validate narrative completeness against FinCEN's SAR filing instructions."]

Expected Outcome

SAR amendment requests from FinCEN decrease by 70%, law enforcement feedback scores on narrative quality improve, and the average time to complete a SAR filing drops from 4 hours to 90 minutes.

Documenting Customer Due Diligence Procedures for Onboarding High-Risk Clients

Problem

Relationship managers at banks onboarding money services businesses, cannabis-related businesses, and foreign politically exposed persons lack clear documentation on enhanced due diligence requirements, resulting in inconsistent risk ratings and potential BSA examination failures.

Solution

BSA compliance documentation codifies the CDD Final Rule requirements (effective May 2018) including the four core elements — customer identification, beneficial ownership identification to 25% threshold, understanding the customer relationship, and ongoing monitoring — with risk-tiered procedures for high-risk customer categories.

Implementation

['Document the beneficial ownership certification form requirements under 31 CFR 1010.230, including the legal entity customer definition and the control prong for identifying one individual with significant managerial control.', 'Create customer risk scoring matrices for high-risk industries with specific red flags, required documentation checklists, and escalation paths to the BSA Officer.', 'Write enhanced due diligence procedures for foreign correspondent banking relationships including the Wolfsberg questionnaire review process and nested correspondent account prohibitions.', 'Establish a periodic review schedule documentation framework that ties EDD refresh intervals to customer risk tier and transaction monitoring alert frequency.']

Expected Outcome

Beneficial ownership collection rates reach 100% for new legal entity customers, regulatory examination findings on CDD gaps are eliminated, and high-risk customer onboarding decisions are consistently documented and defensible.

Creating BSA Independent Testing and Audit Documentation for Compliance Examiners

Problem

Internal audit teams and third-party BSA reviewers struggle to assess the effectiveness of a financial institution's AML program because testing scopes, sampling methodologies, and findings documentation lack the structure required by the FFIEC BSA/AML Examination Manual, making regulatory exam preparation chaotic.

Solution

BSA documentation establishes a structured independent testing framework aligned with the five pillars of an effective AML program — internal controls, a designated BSA Officer, employee training, independent testing, and customer due diligence — with standardized workpapers and findings templates.

Implementation

['Document the annual independent testing scope using the FFIEC BSA/AML Examination Manual core and expanded examination procedures as the baseline requirements checklist.', 'Create transaction testing workpaper templates that capture sample selection criteria, alert disposition review steps, SAR decision validation, and CTR accuracy testing results.', 'Establish a findings classification system (Matters Requiring Immediate Attention, Matters Requiring Attention, Observations) with remediation timeline requirements and BSA Officer sign-off workflows.', 'Maintain a rolling audit issue tracker document linking each finding to the specific regulatory citation, responsible owner, target remediation date, and validation evidence.']

Expected Outcome

Regulatory examiners accept the institution's independent testing documentation as sufficient evidence of program effectiveness, reducing on-site examination duration by 30% and eliminating repeat findings across examination cycles.

Best Practices

Tie Every BSA Procedure Directly to Its Regulatory Citation

Each documented procedure should reference the specific statute (e.g., 31 U.S.C. 5313 for CTRs), regulation (e.g., 31 CFR 1020.315 for structuring), or FinCEN guidance that mandates it. This creates an auditable compliance trail and allows compliance teams to quickly identify which documents require updates when FinCEN issues new rules or FAQs. Without citations, procedures become disconnected from their legal basis and are harder to defend during examinations.

✓ Do: Include a 'Regulatory Authority' header in every BSA procedure document listing the applicable CFR section, FinCEN ruling, or FFIEC examination manual reference, and review these citations quarterly against the FinCEN regulatory update feed.
✗ Don't: Do not write BSA procedures as standalone policy statements without traceable regulatory anchors, as examiners will question the basis for your controls and internal audit cannot validate regulatory coverage gaps.

Version Control BSA Documentation Against FinCEN Rule Effective Dates

BSA regulations evolve frequently — the CDD Final Rule, AML Act of 2020 provisions, and beneficial ownership reporting rules under the Corporate Transparency Act each carry specific effective dates that must be reflected in documentation. Maintaining version history tied to regulatory effective dates allows institutions to demonstrate they updated controls in a timely manner. It also enables examiners to verify that the institution's procedures were compliant at any point in time.

✓ Do: Use a documentation system that timestamps every revision, records the triggering regulatory change (e.g., 'Updated per FinCEN CDD Final Rule effective May 11, 2018'), and retains prior versions for at least five years to match BSA recordkeeping requirements under 31 CFR 1010.430.
✗ Don't: Do not overwrite BSA procedure documents without preserving prior versions, as the inability to show what procedures were in effect during a past examination period can create significant regulatory exposure during lookback reviews.

Document Transaction Monitoring Threshold Logic with Business Justification

Automated AML transaction monitoring systems use scenarios and thresholds (e.g., cash deposits between $8,000 and $10,000 flagged for potential structuring) that must be documented with the business rationale and statistical basis for each parameter. Regulators and examiners expect institutions to demonstrate that thresholds are risk-based and periodically validated, not arbitrarily set. Undocumented or unjustified thresholds are a leading cause of AML program deficiencies cited in enforcement actions.

✓ Do: Maintain a transaction monitoring scenario inventory document that captures each scenario name, detection logic, threshold values, the typology it targets (e.g., FATF money laundering typology), the date last validated, and the validation methodology used including backtesting results.
✗ Don't: Do not rely solely on the AML system vendor's default thresholds without documenting your institution's independent risk-based justification for accepting or modifying them, as vendor defaults are not a sufficient regulatory defense.

Separate SAR Decision Documentation from SAR Filing Documentation

The decision not to file a SAR is as legally significant as the decision to file one, yet many institutions only document filed SARs. FinCEN guidance and examination procedures expect institutions to retain records of no-file decisions with supporting analysis, demonstrating that suspicious activity was reviewed and consciously declined rather than overlooked. Maintaining a SAR declination log protects the institution from allegations of willful blindness.

✓ Do: Create a SAR decision log that captures every alert escalated to SAR review, the analyst's assessment, the supervisor's final decision (file or no-file), the specific reasoning referencing transaction facts, and the date of the decision — retaining these records for five years per 31 CFR 1020.320(d).
✗ Don't: Do not close transaction monitoring alerts with only a one-word disposition like 'Reviewed' or 'Cleared' without documented analytical rationale, as this creates an undefendable paper trail during enforcement investigations or litigation.

Design BSA Training Documentation to Address Role-Specific Obligations

BSA training requirements under 31 CFR 1020.210 apply across the institution, but the compliance obligations of a wire transfer operations specialist differ substantially from those of a commercial loan officer or a customer-facing teller. Generic enterprise-wide BSA training documents fail to equip employees with the specific red flags and reporting obligations relevant to their roles, reducing detection effectiveness. Role-tailored documentation also simplifies demonstrating training adequacy to examiners.

✓ Do: Develop separate BSA training modules and reference documentation for front-line staff (cash handling, CTR triggers), operations teams (wire transfer monitoring, correspondent banking), lending staff (loan proceeds structuring red flags), and senior management (program oversight and Board reporting obligations).
✗ Don't: Do not deploy a single one-size-fits-all BSA training document across all employee groups and check the box as compliant, as examiners specifically test whether training content is relevant to the roles of the staff being trained and will cite deficiencies when it is not.

How Docsie Helps with BSA

Build Better Documentation with Docsie

Join thousands of teams creating outstanding documentation

Start Free Trial