Field Guide

BSA/AML Exam Preparation: A Fintech's Field Guide

The short version

A BSA/AML examination is a supervisory review of whether an institution's anti-money-laundering program is reasonably designed for the institution's risk and operating as its documentation describes. Examiners measure the program against the pillars set out at 31 CFR 1020.210, evaluate the risk assessment, and then pull samples to test whether the controls operate. Readiness is a continuous condition rather than a pre-examination task: an institution that keeps its risk assessment current and retains evidence as a byproduct of daily work responds to a document request in days, while an institution that begins assembling proof at the entry letter spends the intervening weeks doing so.

A BSA/AML examination is a periodic supervisory review in which a federal or state regulator evaluates whether an institution's anti-money-laundering program satisfies the requirements of 31 U.S.C. 5318(h) and 31 CFR 1020.210, and whether the program operates in practice as its documentation describes. The examination produces written findings that the institution must address and that carry into the next supervisory cycle.

This article covers what the examination tests, how it unfolds, the documents examiners request, how examiners read a program, the findings that recur at fintechs, and the practices that constitute readiness before an entry letter arrives.

What the examination tests

Examiners evaluate two things at once. First, whether the program is reasonably designed for the institution's risk. Second, whether it operates the way the documents say it does. A program documented in policy but not followed in practice fails the second test, and most findings arise there.

The evaluation runs through the BSA program pillars: internal controls, a designated BSA officer, training, independent testing, and customer due diligence including beneficial ownership. The risk assessment sits underneath all of it, because a program can only be judged reasonable against the risk it claims to face.

How an examination unfolds

Examinations vary by regulator and institution, but most move through four phases.

PhaseWhat happens
1. ScopingThe regulator issues an entry letter and a document request, often several weeks before the on-site. The scope is shaped by the institution's risk profile, prior findings, and any intervening events.
2. Review and testingExaminers read the policies and then test them, on-site or remotely. They sample alerts, SARs, CDD files, and monitoring output to see whether the program does on the ground what it claims on paper.
3. FindingsExaminers raise issues, ask follow-up questions, and discuss what they have seen. This is the window to clarify a misunderstanding before it hardens into a written finding.
4. ResponseThe institution receives written findings and submits a remediation commitment: each issue mapped to an owner, an action, and a date. Open items carry into the next examination cycle.

What examiners ask for

The document request is long and largely predictable. The following items recur across examinations.

For a fintech operating under a sponsor bank, add the partner-oversight evidence: the oversight framework, the partner risk rating, and proof that monitoring and testing of the relationship actually happened. The sponsor bank is examined on the same relationship from its own side.

How examiners read a program

An examiner forms a judgment about whether the program reasons about risk or processes paper. Four indicators shape that judgment:

Recurring findings at fintechs

The same findings repeat across institutions. Drawn from public enforcement actions and examination patterns:

Preparation practices before and after the entry letter

Examination readiness is established before the entry letter arrives. The first set below describes standing practices; the second describes the pass an institution makes once the examination dates are set.

Standing, all year

  1. Keep the risk assessment current. It is refreshed when a product, customer segment, or volume materially changes, rather than annually by reflex.
  2. Close independent-testing findings. Each finding is tracked to closure with a named owner and a date.
  3. Retain evidence continuously. Controls are designed so each one leaves a timestamped artifact, so that the proof of a control's operation exists before an examiner requests it.
  4. Tune monitoring on a schedule and document the rationale, so the configuration carries a recorded basis.

Once the entry letter arrives

  1. Map the request to owners the day it lands. Every item is assigned, with internal dates ahead of the regulator's deadline.
  2. Review the samples internally first. The institution pulls the alerts, SARs, and CDD files it expects examiners to sample and reviews them against the standard examiners apply.
  3. Reconcile the record. The policy, the risk assessment, and what the samples show should be consistent with one another.
  4. Prepare the interviewees. The BSA officer and anyone who will be interviewed should know the program in detail and answer without speculating.

A pre-exam checklist

Examination outcomes are largely determined by ordinary operating practice rather than by pre-examination preparation. An institution that generates and retains control evidence in the normal course is able to respond to an entry letter without a separate assembly effort.

Common questions

What does a BSA/AML exam test?
It tests whether the institution has a reasonably designed BSA/AML program and whether it actually runs. Examiners assess the program against the pillars (internal controls, a designated BSA officer, training, independent testing, and customer due diligence including beneficial ownership), evaluate the risk assessment, and test whether controls operate in practice by sampling alerts, SARs, CDD files, and monitoring output.
How does a BSA/AML exam work, step by step?
It typically moves through four phases: scoping (the regulator issues an entry letter and a document request, often weeks ahead), review (examiners read policies and test controls against samples, on-site or remote), findings (examiners raise issues and discuss them), and response (the institution receives written findings and submits a remediation commitment with owners and dates).
What documents do examiners request?
Common requests include the BSA/AML policy and procedures, the risk assessment, the most recent independent test and its remediation status, training records, the designated officer's appointment, SAR and CTR filings for the period, alert and case samples, CDD and beneficial-ownership files, transaction-monitoring configuration, and board minutes showing oversight. For fintechs under a sponsor bank, partner-oversight evidence is added.
Where do fintechs most often get caught?
The recurring findings are a stale risk assessment that does not match current products or volume, transaction-monitoring rules that were never tuned to the customer base, weak or undocumented CDD, SAR narratives that do not support the filing, no evidence that monitoring actually happened, and open findings from the prior independent test that were never closed.
How long does it take to prepare?
Real readiness is built continuously, not in the weeks between the entry letter and the on-site. A program that keeps its risk assessment current, closes independent-testing findings, and retains evidence as a byproduct of daily work can respond to a document request in days. A program that waits for the entry letter spends those weeks assembling evidence, which is itself a signal to the examiner.
About this library

This reference library is maintained by Rupture Labs, the company behind Compliance Command Center, compliance software built and reviewed by practitioners. Contact.

Primary sources

The authoritative texts this guide is grounded in. Government sites may block automated access but resolve in a browser.