FinCEN and BSA Duties for Banks and MSBs | Global RADAR

FinCEN and Bank Secrecy Act Obligations for Banks and MSBs

  • Home
  • FinCEN and Bank Secrecy Act Obligations for Banks and MSBs

Who this is for: BSA officers and compliance leads at US banks, credit unions and money services businesses, and at non-US firms with US operations. It sets out what the Bank Secrecy Act actually requires, with the source for every obligation. It is general information, not legal advice.

Last reviewed 23 August 2026. One part of this framework changed twelve days before that date and is covered first.

What just changed, and the distinction people are getting wrong

On 11 August 2026 FinCEN announced a final rule that permanently removes the requirement for US companies and US persons to report beneficial ownership information under the Corporate Transparency Act. It was published in the Federal Register on 14 August 2026. FinCEN has said it will delete previously reported information submitted by US persons from the beneficial ownership database.

Foreign entities that are reporting companies must still report beneficial ownership information for foreign individuals.

Now the part that is being misread.

That change does not touch the CDD Rule. The obligation on a bank to identify and verify the beneficial owners of its legal entity customers is a different rule, in a different place, imposed on a different party. It sits at 31 CFR 1010.230, it applies to covered financial institutions rather than to companies reporting about themselves, and it remains fully in force. The current regulation text was up to date as at 20 August 2026, with its most recent amendment on 14 August 2026.

In short: the company no longer files a report about itself, and the bank still has to collect the same information from that company at account opening. If anything the bank’s job gets harder, because a database it might have leaned on for corroboration is being emptied of US persons.

The framework, briefly

The Bank Secrecy Act is implemented through 31 CFR Chapter X. The obligations that matter operationally are an AML programme, customer due diligence, suspicious activity reporting, currency transaction reporting, and, for money services businesses, registration.

OFAC sanctions are a separate regime. They are administered by a different Treasury office under different statutes, and compliance with the Bank Secrecy Act does not discharge them.

The AML programme: what the regulation actually lists

For banks, 31 CFR 1020.210(a) requires a programme that complies with 31 CFR 1010.610 and 1010.620, and that includes:

  • A system of internal controls to assure ongoing compliance
  • Independent testing for compliance, conducted by bank personnel or by an outside party
  • Designation of an individual or individuals responsible for coordinating and monitoring day to day compliance
  • Training for appropriate personnel
  • Appropriate risk based procedures for conducting ongoing customer due diligence, which includes understanding the nature and purpose of the customer relationship in order to develop a risk profile, and ongoing monitoring to identify and report suspicious transactions and to maintain and update customer information including beneficial ownership

For a bank without a federal functional regulator, 31 CFR 1020.210(b) applies the same elements and adds that the programme must be approved by the board of directors, or by an equivalent governing body where there is no board.

Two points worth drawing out. Ongoing customer due diligence is a programme pillar, not an onboarding task. And the regulation places maintaining and updating beneficial ownership information inside that pillar, which makes it a continuing obligation rather than a point in time collection.

The CDD Rule: two prongs, and both are required

31 CFR 1010.230 requires covered financial institutions to identify and verify the beneficial owners of legal entity customers at the time a new account is opened, and to verify identity under risk based procedures.

Prong Test Citation
Ownership Each individual who owns 25 percent or more of the equity interests of the legal entity customer 1010.230(d)(1)
Control A single individual with significant responsibility to control, manage, or direct the legal entity customer, such as an executive officer or senior manager, or a person regularly performing similar functions 1010.230(d)(2)

The control prong is not optional and it is not an alternative. A legal entity customer with no individual owning 25 percent still has a control person who must be identified.

Suspicious activity reporting: banks and MSBs are on different rules

Banks, 31 CFR 1020.320 MSBs, 31 CFR 1022.320
Threshold Involves or aggregates at least $5,000 in funds or other assets $2,000. For issuers of money orders or traveler’s checks reviewing clearance records, $5,000
Deadline 30 calendar days after the date of initial detection 30 calendar days after the date of initial detection
Extension A further 30 calendar days where no suspect has been identified. Never more than 60 days in total The regulation provides no extension
Retention Five years from the date of filing, including supporting documentation Five years from the date of filing, including supporting documentation

The MSB position is stricter than many assume. A lower threshold, and no extension where the suspect is unidentified. An MSB that has adopted a bank style sixty day process is out of time.

Currency transaction reporting

A financial institution must report each deposit, withdrawal, exchange of currency, or other payment or transfer involving more than $10,000 in currency, and must aggregate multiple currency transactions that come to more than $10,000 in a single day. Transactions are not offset against one another, so cash in and cash out are considered separately.

Reports are retained for five years from the date of filing, under 31 CFR 1010.430(d).

MSB registration, which is separate from state licensing

Under 31 CFR 1022.380:

  • Initial registration must be filed on or before the end of the 180 day period beginning the day after the business is established
  • Renewal runs on two calendar year cycles, and the renewal form must be filed on or before the last day of the calendar year preceding the renewal period
  • An MSB must prepare and maintain a list of its agents, revised each 1 January, held at the US location given on the registration form

Registering with FinCEN is not a licence. State money transmitter licensing is a separate requirement in each state where the business operates, and registration does not satisfy it.

What this means operationally

Obligation What it requires in practice
Collect beneficial ownership at account opening Both prongs. Ownership at 25 percent or more, and a control person in every case.
Keep it current The AML programme rule puts maintaining and updating beneficial ownership inside ongoing due diligence, so it is not a one time capture.
Do not rely on the CTA database US person records are being deleted. Corroboration has to come from the customer and from independent sources.
Run the SAR clock from initial detection Not from escalation, not from investigation closing. Banks have 30 days with one 30 day extension. MSBs have 30 days and no extension.
Aggregate currency transactions daily More than $10,000 in a single day, cash in and cash out considered separately.
Diary the MSB renewal Two year cycles, filed before the end of the preceding calendar year. Agent list refreshed every 1 January.
Treat OFAC separately A clean BSA programme does not discharge sanctions obligations.
Retain for five years Ten where there is an OFAC dimension, because OFAC extended its own retention period in March 2025.

Frequently asked questions

Do US companies still have to report beneficial ownership to FinCEN?

No. FinCEN announced a final rule on 11 August 2026, published in the Federal Register on 14 August 2026, permanently removing the requirement for US companies and US persons to report beneficial ownership information under the Corporate Transparency Act. FinCEN has said it will delete previously reported information submitted by US persons. Foreign entities that are reporting companies must still report beneficial ownership information for foreign individuals.

Does that mean banks no longer need to collect beneficial ownership?

No, and this is the most common misreading. The CDD Rule at 31 CFR 1010.230 is a separate obligation on covered financial institutions, not on companies reporting about themselves, and it remains fully in force. Banks must still identify and verify beneficial owners of legal entity customers at account opening. The current regulation text was up to date as at 20 August 2026.

What are the two prongs of the CDD Rule?

The ownership prong at 31 CFR 1010.230(d)(1) captures each individual who owns 25 percent or more of the equity interests of the legal entity customer. The control prong at 1010.230(d)(2) captures a single individual with significant responsibility to control, manage, or direct the customer, such as an executive officer or senior manager. A customer with no owner at 25 percent still has a control person who must be identified.

What must a bank’s AML programme contain?

Under 31 CFR 1020.210(a): a system of internal controls to assure ongoing compliance, independent testing conducted by bank personnel or an outside party, designation of an individual or individuals responsible for coordinating and monitoring day to day compliance, training for appropriate personnel, and appropriate risk based procedures for ongoing customer due diligence including understanding the customer relationship and maintaining and updating beneficial ownership information. A bank without a federal functional regulator must also have the programme approved by its board of directors under 1020.210(b).

How long does a bank have to file a SAR?

30 calendar days after the date of initial detection, under 31 CFR 1020.320. Where no suspect has been identified the bank may take a further 30 calendar days, but reporting can never be delayed more than 60 calendar days after initial detection. The threshold is a transaction that involves or aggregates at least $5,000 in funds or other assets.

Are the SAR rules the same for money services businesses?

No, and they are stricter in two ways. Under 31 CFR 1022.320 the threshold is $2,000 rather than $5,000, with a $5,000 threshold for issuers of money orders or traveler’s checks reviewing clearance records. The deadline is 30 calendar days after initial detection and the regulation provides no extension where a suspect is unidentified. Retention is five years, as for banks.

When must a money services business register with FinCEN?

On or before the end of the 180 day period beginning the day after the business is established, under 31 CFR 1022.380. Registration then renews on two calendar year cycles, with the renewal filed on or before the last day of the calendar year preceding the renewal period. The business must also maintain a list of its agents, revised each 1 January. Registration with FinCEN is not a licence and does not replace state money transmitter licensing.

A note on what is not on this page

The currency transaction report filing deadline is set by 31 CFR 1010.306. We have not stated a number of days here because we could not verify it against a primary source we could reach at the time of review. Check the regulation or FinCEN’s filing instructions directly rather than relying on a figure repeated in secondary commentary, including ours.

Sources

How Global RADAR fits

Global RADAR screens against more than 1,400 sanctions and watchlists on a daily update cycle, resolves ultimate beneficial ownership so the 25 percent prong can be evidenced rather than asserted, and records a reason code, a rationale and a confidence score for every alert disposed of. Records are exportable and reproducible for the full retention period, which matters more now that a bank cannot fall back on the CTA database for corroboration.

Read the full alert clearing methodology and model governance, or see the separate OFAC sanctions position.