Banks and other financial institutions have to show regulators that they know their customers, watch their accounts and report suspicious activity. AML compliance, KYC and the Bank Secrecy Act are the three terms behind that work, and they are often confused.
What is AML compliance?
Anti-money laundering (AML) compliance is the work of meeting the legal measures that countries put in place to combat money laundering and terrorist financing. The Financial Action Task Force (FATF) is an inter-governmental body, established in 1989, that develops policies to protect the global financial system against money laundering, terrorist financing and the financing of proliferation of weapons of mass destruction. Its Recommendations (October 2025 update) are "recognised as the global anti-money laundering (AML) and counter-terrorist financing (CFT) standard".
The FATF says countries implement the standard through measures adapted to their own circumstances, so the US requirements below come from US law and regulation.
FATF Recommendations for financial institutions
Two of the Recommendations frame the day-to-day AML work of a financial institution:
- Risk-based approach (Recommendation 1): countries should require financial institutions to identify, assess and take effective, risk-based action to mitigate their money laundering and terrorist financing risks.
- Programs (Recommendation 18): financial institutions implement programs against money laundering and terrorist financing.
Customer due diligence (Recommendation 10), record keeping (Recommendation 11) and suspicious transaction reporting (Recommendation 20) are covered in the sections below.
Required elements of a US bank AML program
For US banks, 31 CFR 1020.210 sets the minimum elements of an AML program. A bank regulated by a Federal functional regulator is deemed to meet the requirements of 31 U.S.C. 5318(h)(1) if its program, at a minimum, includes:
- a "system of internal controls to assure ongoing compliance"
- "independent testing for compliance", carried out by bank personnel or an outside party
- a designated individual or individuals responsible for coordinating and monitoring day-to-day compliance
- training for appropriate personnel
- risk-based procedures for ongoing customer due diligence
The bank rules sit in part 1020. Part 1010 sends each other type of financial institution to its own part of chapter X, so a broker-dealer or money services business should not rely on them. Broker-dealers are supervised by FINRA under SEC oversight, as covered in how US securities and audit oversight is divided between the SEC, FINRA and PCAOB.
What is KYC?
Know your customer (KYC) is the set of checks a financial institution carries out to identify its customers, understand their business and monitor their accounts. The FATF and US regulators call these checks customer due diligence (CDD), and in the US the customer identification program (CIP) is the part that verifies identity. Neither the FATF Recommendations nor the US regulations cited here use the phrase know your customer.
Customer due diligence under FATF Recommendation 10
Recommendation 10 sets four CDD measures, shown beside the US rules that cover the same ground. The pairing is our own mapping. The US rules shown apply to banks (part 1020) and to legal entity customers (part 1010).
| FATF Recommendation 10 measure | US counterpart |
| (a) Identify the customer and verify identity using reliable, independent source documents, data or information | Customer identification program: procedures that enable the bank to "form a reasonable belief that it knows the true identity of each customer" (31 CFR 1020.220) |
| (b) Identify the beneficial owner and take reasonable measures to verify identity, including understanding the ownership and control structure of legal persons | Identify the beneficial owner(s) of each legal entity customer "at the time a new account is opened" and verify identity using risk-based procedures (31 CFR 1010.230) |
| (c) Understand the purpose and intended nature of the business relationship | "Understanding the nature and purpose of customer relationships for the purpose of developing a customer risk profile" (31 CFR 1020.210) |
| (d) Conduct ongoing due diligence and scrutiny of transactions | "Conducting ongoing monitoring to identify and report suspicious transactions" and, on a risk basis, maintaining and updating customer information (31 CFR 1020.210) |
The FATF says institutions should undertake CDD when establishing business relations, for occasional transactions above USD/EUR 15,000, when money laundering or terrorist financing is suspected and when they doubt earlier identification data. The extent of the measures should follow a risk-based approach.
US customer identification and beneficial ownership
A US bank's customer identification program must be written, form part of its AML compliance program and include risk-based procedures for verifying identity. Before opening an account the bank must obtain at least the customer's name, date of birth (for an individual), address and an identification number, then verify identity within a reasonable time afterward (31 CFR 1020.220).
For legal entity customers, covered financial institutions must also identify each beneficial owner when the account opens and verify identity using risk-based procedures. The individual opening the account can supply the information through a certification form (31 CFR 1010.230).
What is the Bank Secrecy Act?
The Bank Secrecy Act (BSA) is the US law that lets the Department of the Treasury impose reporting and other requirements on financial institutions and other businesses "to help detect and prevent money laundering". FinCEN explains that the Currency and Foreign Transactions Reporting Act of 1970, its amendments and the other statutes relating to the subject matter of that Act have come to be referred to as the Bank Secrecy Act. FinCEN, a bureau of the Department of the Treasury, publishes its regulations in 31 CFR Chapter X and says the BSA is sometimes called an anti-money laundering law or, jointly, BSA/AML.
Reports and records under the BSA regulations
- Currency transaction reports: under 31 CFR 1010.311, each financial institution other than a casino must report each deposit, withdrawal, exchange of currency or other payment or transfer that involves "a transaction in currency of more than $10,000", subject to the exceptions in the section.
- Suspicious activity reports for banks: under 31 CFR 1020.320, a bank reports a suspicious transaction relevant to a possible violation of law or regulation when the transaction involves or aggregates "at least $5,000 in funds or other assets" and the bank knows, suspects or has reason to suspect that it involves funds from illegal activity, "is designed to evade any requirements of this chapter" or "has no business or apparent lawful purpose" and has no reasonable explanation after the bank examines the facts.
- Filing deadline: a bank files a suspicious activity report "no later than 30 calendar days after the date of initial detection" of facts that may form a basis for filing. If no suspect is identified the bank may delay filing by a further 30 calendar days, and in no case beyond 60 calendar days.
- Record retention: records the chapter requires financial institutions to keep "shall be retained for a period of five years" (31 CFR 1010.430).
How customer checks lead to suspicious activity reports
Customer checks at account opening and ongoing monitoring give an institution the information it needs to spot activity that looks unusual for that customer. Reporting rules turn what the institution finds into reports to the authorities, and record-keeping rules preserve the evidence. This is our reading of how the sources fit together, and no single source states it in these words.
A fictional case from account opening to a suspicious activity report
The scenario below is illustrative. It applies the rules above to an invented customer and does not describe a real institution or give a legal conclusion.
- Account opening. Harbor Ridge Supplies LLC, an invented company, applies for a business account at a US bank. Under the bank's customer identification program it provides its name, principal place of business and identification number before the account opens, and the bank verifies its identity within a reasonable time afterward.
- Beneficial owners. The bank identifies each beneficial owner of the company when the account opens, using a certification from the individual opening the account, and verifies each owner's identity using risk-based procedures.
- Cash deposit. Months later the company deposits $12,000 in currency. That is more than $10,000, so unless an exception in the regulation applies the bank files a currency transaction report.
- Monitoring. Over the following weeks the account receives several cash deposits just under $10,000, which differs from its earlier activity. Ongoing monitoring flags the pattern.
- Decision. If the bank knows, suspects or has reason to suspect that the deposits are designed to evade reporting requirements and they aggregate at least $5,000, the activity meets the criteria for a suspicious activity report. The bank files within 30 calendar days of initially detecting the facts and keeps the supporting documentation the section requires.
AML compliance rests on customer checks, timely reporting and five-year records
AML compliance is the set of legal measures that financial institutions use to detect and report money laundering and terrorist financing. KYC, which the FATF and US regulators call customer due diligence, covers identifying customers and beneficial owners, understanding the relationship and monitoring it over time. The Bank Secrecy Act is the US law behind the reports and records that follow, including currency transaction reports above $10,000 and suspicious activity reports, which a bank files within 30 calendar days of initial detection. Both the FATF Recommendations and the US regulations call for records to be kept for five years.
Frequently asked questions about AML, KYC and the Bank Secrecy Act
Is KYC the same as customer due diligence?
KYC is the everyday name for the customer checks that the FATF Recommendations and the US regulations call customer due diligence. Neither source uses the phrase know your customer.
Is the Bank Secrecy Act the same as AML?
The terms overlap. FinCEN says the BSA is sometimes called an anti-money laundering law or, jointly, BSA/AML. AML also describes the wider set of measures that the FATF Recommendations set out for countries.
How long must AML records be kept?
The FATF says transaction records and customer due diligence records should be kept for at least five years. The US chapter X regulations require the records they cover to be retained for five years, and individual sections can add detail.
What must a US bank report?
A bank files a currency transaction report for each reportable transaction in currency of more than $10,000 and a suspicious activity report when a transaction meets the criteria in 31 CFR 1020.320. Other institution types follow their own parts of chapter X.
Explore email management solutions
Email management solutions helps project and client-based businesses streamline their email processes.