Summary. Anti-money laundering law asks businesses to do something genuinely unusual: to police their own customers on the government's behalf, at their own expense, and to do it quietly enough that the customer never finds out. The Bank Secrecy Act and its implementing regulations create the architecture — a written compliance program, customer identification and due diligence, transaction monitoring, and a reporting obligation that runs to FinCEN rather than to law enforcement directly. The Corporate Transparency Act extended a version of this into ordinary corporate formation, though its scope has narrowed considerably since enactment. This article explains who is covered, what each of the core obligations actually requires, where the criminal exposure lies for institutions and for individuals, and how the beneficial ownership regime now stands.


Money laundering law has an odd shape. Most regulatory regimes tell a business how to conduct its own affairs. Anti-money laundering law tells a business to investigate its customers, to form suspicions about them, to report those suspicions to the federal government, and then — this is the part that surprises people — to say nothing to the customer about any of it, ever.

The obligation is deputization. Congress concluded decades ago that the financial system is the chokepoint through which criminal proceeds must pass, and that the institutions operating that system are better positioned than any agency to notice when something is wrong. The Bank Secrecy Act of 1970, codified principally at 31 U.S.C. §§ 5311–5336 and implemented at 31 C.F.R. Chapter X, is the result.

What follows is a practical account: who is covered, what the five pillars require, how the reporting obligations work, where the personal criminal exposure sits, and where the beneficial ownership rules currently stand after a genuinely turbulent two years.

Who is covered

The BSA applies to "financial institutions," and the statutory definition at 31 U.S.C. § 5312(a)(2) is far broader than the phrase suggests. It includes banks and credit unions, but also:

  • Money services businesses — money transmitters, check cashers, currency dealers, issuers and sellers of money orders and traveler's checks, and prepaid access providers. Defined at 31 C.F.R. § 1010.100(ff), with registration required under § 1022.380.
  • Broker-dealers in securities, mutual funds, futures commission merchants, and introducing brokers.
  • Casinos and card clubs above revenue thresholds.
  • Insurance companies issuing covered products.
  • Dealers in precious metals, stones, and jewels.
  • Residential mortgage lenders and originators.
  • Certain investment advisers, brought into the regime by rulemaking finalized in 2024 with a compliance date that has since been extended.

Businesses dealing in convertible virtual currency have been treated as money transmitters under FinCEN's 2013 and 2019 guidance, and that position has been enforced consistently. A cryptocurrency exchange, a hosted wallet provider, and certain kinds of anonymizing services are money transmitters whether or not they think of themselves that way, with registration, program, and reporting obligations to match.

Two categories are frequently misunderstood. Ordinary retail and service businesses are not financial institutions, but they still have an obligation under 26 U.S.C. § 6050I and 31 U.S.C. § 5331 to file Form 8300 for cash receipts over ten thousand dollars in one transaction or related transactions. And lawyers, accountants, and company formation agents have historically been outside the covered-institution definition in the United States, unlike in most peer jurisdictions — a gap that has been the subject of repeated legislative proposals.

The five pillars

A covered institution must maintain a written, risk-based AML compliance program. The requirement for banks appears at 31 C.F.R. § 1020.210 and for money services businesses at § 1022.210, with parallel provisions across Chapter X. The elements are conventionally described as five pillars.

1. Internal policies, procedures, and controls

A written program, approved by senior management or the board, calibrated to the institution's actual risk profile. The word "risk-based" does real work here: FinCEN does not prescribe a single set of controls, and a small rural bank and a correspondent-banking operation are not expected to look alike. What they share is the requirement that the program follow from a documented risk assessment rather than from a template.

2. A designated compliance officer

A named individual with the authority, seniority, and resources to run the program. The designation matters personally — see the discussion of individual liability below.

3. Ongoing training

Role-specific and recurring. Tellers need different training than wire operators, who need different training than relationship managers onboarding a foreign private banking client.

4. Independent testing

Periodic audit by someone not responsible for the program. Independent does not require an outside firm for smaller institutions, but it does require organizational separation from the people whose work is being tested.

5. Customer due diligence

Added as an express fifth pillar by FinCEN's CDD Rule, 31 C.F.R. § 1010.230, effective 2018. It requires covered institutions to identify and verify the beneficial owners of legal entity customers, and to understand the nature and purpose of customer relationships in order to develop a risk profile and conduct ongoing monitoring.

The beneficial ownership piece of the CDD Rule uses two prongs. The ownership prong captures each individual owning twenty-five percent or more of the equity interests. The control prong captures a single individual with significant responsibility to control, manage, or direct the entity — a CEO, CFO, managing member, or general partner. Note that the ownership prong can yield no one at all, if no individual crosses twenty-five percent; the control prong always yields at least one person.

Customer identification: the CIP

Layered underneath customer due diligence is the older Customer Identification Program requirement at 31 C.F.R. § 1020.220, which implements section 326 of the USA PATRIOT Act. Before opening an account, an institution must obtain, at minimum, name, date of birth for individuals, address, and an identification number — a taxpayer identification number for U.S. persons, or a passport or similar for others.

The institution must then form a reasonable belief that it knows the customer's true identity, through documentary verification, non-documentary verification, or both. And it must check the customer against government lists of known or suspected terrorists.

CIP is a rule about account opening. Due diligence is a rule about the ongoing relationship. Institutions that treat them as a single onboarding checkbox generate exactly the examination finding you would expect.

The reports

Currency transaction reports

A CTR is required under 31 C.F.R. § 1010.311 for each transaction in currency of more than ten thousand dollars, aggregated by person by business day. It is mechanical, non-discretionary, and not a suspicion report — filing a CTR says nothing about the customer except that they moved cash.

Because the threshold is mechanical, people try to evade it. Breaking a deposit into amounts under ten thousand dollars to avoid the filing is structuring, a separate federal crime under 31 U.S.C. § 5324, and it does not require that the underlying funds be dirty. Ratzlaf v. United States, 510 U.S. 135 (1994), held that a structuring conviction required proof the defendant knew structuring was unlawful; Congress promptly amended the statute to remove that element. The practical consequence is that entirely legitimate businesses have had funds seized for depositing cash in patterns that looked deliberate. Enforcement policy on structuring seizures tightened substantially after congressional attention in the mid-2010s, but the criminal statute is unchanged.

An institution that helps a customer structure, or that knowingly fails to file, commits its own offense.

Suspicious activity reports

The SAR is the heart of the regime. Under 31 C.F.R. § 1020.320 and its counterparts, a covered institution must file a SAR when it knows, suspects, or has reason to suspect that a transaction involves funds derived from illegal activity, is designed to evade BSA reporting requirements, has no apparent lawful purpose or is not the sort of transaction the customer would normally be expected to engage in, or involves use of the institution to facilitate criminal activity.

Key mechanics:

  • Thresholds vary by institution type — generally five thousand dollars for banks where a suspect can be identified, twenty-five thousand where one cannot, and two thousand for money services businesses.
  • Timing is thirty calendar days from initial detection of facts that may constitute a basis for filing, extendable to sixty days if no suspect has been identified.
  • Continuing activity requires follow-up reports, conventionally at ninety-day intervals.
  • Confidentiality is absolute. Under 31 U.S.C. § 5318(g)(2), no institution and no director, officer, employee, or agent may notify any person involved in the transaction that a SAR was filed. This prohibition survives subpoenas, discovery requests, and the customer's own questions. Courts have consistently held the privilege unqualified.
  • Safe harbor. Section 5318(g)(3) immunizes the institution from civil liability to the customer for filing, including for filings that turn out to be wrong. The safe harbor is broad and is one of the few genuinely protective provisions in the statute.

The tension in SAR practice is between under-filing, which draws examination criticism and potential enforcement, and defensive over-filing, which floods FinCEN with low-value reports. Examiners will criticize both. What they criticize most reliably is a monitoring system that generates alerts nobody investigates and dispositions nobody documents.

Form 8300 and the cash-reporting overlay

Any trade or business receiving more than ten thousand dollars in cash in one transaction or two or more related transactions must file Form 8300 within fifteen days, under 26 U.S.C. § 6050I and 31 U.S.C. § 5331. This applies to car dealers, jewelers, contractors, and law firms accepting cash fees. Note that the Infrastructure Investment and Jobs Act extended § 6050I's definition of cash to include digital assets, a provision whose implementation has been repeatedly delayed and contested.

Information sharing under sections 314(a) and 314(b)

Section 314(a) of the USA PATRIOT Act, implemented at 31 C.F.R. § 1010.520, allows FinCEN to transmit law enforcement requests to financial institutions, which must search their records for matches and report back. It is a search obligation, not a reporting one, and the requests are confidential.

Section 314(b), at § 1010.540, is voluntary and more useful: it permits financial institutions that have filed notice with FinCEN to share information with each other regarding suspected money laundering or terrorist financing, with a statutory safe harbor from liability. Institutions that have not registered for 314(b) are giving up a genuinely valuable tool.

Sanctions screening is a separate obligation

AML and sanctions compliance are administered by different agencies and rest on different authorities, and conflating them is a common structural error.

OFAC sanctions arise under the International Emergency Economic Powers Act, 50 U.S.C. §§ 1701–1708, and the Trading with the Enemy Act, and are implemented in 31 C.F.R. Chapter V. The obligation is not risk-based in the same sense: it is strict liability. A U.S. person who transacts with a blocked party violates the sanctions regardless of knowledge or intent. Civil penalties do not require scienter; criminal penalties under 50 U.S.C. § 1705 require willfulness.

The practical requirements are screening against the Specially Designated Nationals list and other OFAC lists at onboarding and on an ongoing basis, blocking or rejecting prohibited transactions, and reporting blocked property to OFAC within ten business days. Note the fifty percent rule: an entity owned fifty percent or more, directly or indirectly, in the aggregate, by one or more blocked persons is itself blocked, even though it does not appear on any list. This is where most sanctions failures actually originate.

OFAC's enforcement guidelines at 31 C.F.R. Part 501, Appendix A, set out the aggravating and mitigating factors, and voluntary self-disclosure produces a substantial reduction in the base penalty.

Beneficial ownership reporting: where the Corporate Transparency Act now stands

The Corporate Transparency Act, enacted as part of the Anti-Money Laundering Act of 2020 and codified at 31 U.S.C. § 5336, was the most significant expansion of the regime in a generation. It required most privately held U.S. entities to report their beneficial owners directly to FinCEN, creating a nationwide registry.

The reporting obligation, implemented at 31 C.F.R. § 1010.380, applied to any "reporting company" — a corporation, LLC, or other entity created by filing with a secretary of state — subject to twenty-three exemptions covering banks, insurers, registered investment companies, public companies, tax-exempt entities, and "large operating companies" with more than twenty employees, more than five million dollars in gross receipts, and a physical U.S. presence. A beneficial owner was any individual exercising substantial control or owning twenty-five percent or more.

The rollout did not go smoothly. The statute faced sustained constitutional challenge on enumerated-powers grounds, producing conflicting district court rulings and a period in which the filing deadline was enjoined, reinstated, and enjoined again. In March 2025 FinCEN issued an interim final rule that removed domestic reporting companies and U.S. persons from the reporting requirement entirely, limiting the obligation to entities formed under foreign law that register to do business in a U.S. state.

The practical position as of this writing is therefore narrower than the statute as enacted: domestic entities are not required to file beneficial ownership information reports, while foreign reporting companies remain subject to the regime. Because this area has moved repeatedly and is subject to further rulemaking and litigation, confirm the current requirement with FinCEN directly before advising a client that no filing is due.

Two points survive regardless of where the CTA lands. First, the CDD Rule obligation on financial institutions to collect beneficial ownership from entity customers is a separate requirement and remains in force. A company that never files with FinCEN will still be asked for the same information by its bank. Second, the Access Rule at 31 C.F.R. § 1010.955, which governs who may see reported information and under what conditions, reflects a deliberate policy judgment that the registry is a law enforcement tool rather than a public record.

Where the criminal exposure sits

The money laundering statutes themselves

18 U.S.C. § 1956 criminalizes conducting a financial transaction involving proceeds of specified unlawful activity with intent to promote that activity, to conceal the nature or source of the proceeds, or to evade reporting requirements. Penalties reach twenty years. Section 1957 is broader and easier: it criminalizes knowingly engaging in a monetary transaction in criminally derived property of a value greater than ten thousand dollars, with no concealment element at all.

Cuellar v. United States, 553 U.S. 550 (2008), required proof that the transportation was designed to conceal, not merely that concealment occurred. United States v. Santos, 553 U.S. 507 (2008), created a proceeds-versus-receipts problem that Congress addressed by defining proceeds as gross receipts in the Fraud Enforcement and Recovery Act of 2009.

BSA violations

Civil penalties under 31 U.S.C. § 5321 are substantial and, for willful violations, are calculated per violation — which in a recordkeeping case can mean per transaction. Criminal penalties under § 5322 reach five years, or ten where the violation occurs while violating another federal law or as part of a pattern of illegal activity involving more than one hundred thousand dollars in a twelve-month period.

Individual liability

This is the development that most changed institutional behavior. The AML Act of 2020 strengthened the tools for pursuing individuals, and FinCEN and the banking agencies have shown willingness to use them. A compliance officer who knows the program is deficient and signs off anyway is personally exposed, and the Haider matter — in which FinCEN assessed a penalty against a money services business compliance officer personally — is the case every BSA officer has heard of.

Willful blindness is sufficient. Global-Tech Appliances, Inc. v. SEB S.A., 563 U.S. 754 (2011), articulated the standard in a patent case, but the doctrine applies across federal criminal law: a defendant who subjectively believes there is a high probability of a fact and takes deliberate actions to avoid learning it is treated as knowing it.

Building a program that survives examination

The failures that generate enforcement actions are remarkably consistent.

A risk assessment that does not match the business. The program is calibrated to risks the institution does not have, and silent about the ones it does. Update it when the business changes — a new product, a new geography, a new customer segment.

Alerts without dispositions. The monitoring system fires, and nobody documents what was reviewed or why it was closed. Examiners read alert dispositions the way auditors read reconciliations.

Thresholds tuned to reduce work. Raising an alert threshold because the queue is too long, without a documented risk rationale, is the single most damaging fact in an enforcement record.

A compliance officer without authority. Titles are cheap. Reporting lines, budget, and staffing are the evidence.

Independent testing performed by the tested. Or by a firm that also built the program.

No escalation path. When the relationship manager disagrees with the AML analyst, someone has to decide, and the decision has to be recorded.

Onboarding without ongoing monitoring. The customer who was low risk three years ago has since started wiring to a jurisdiction they never mentioned.

The through-line is documentation. AML compliance is judged almost entirely on the written record of decisions, because the government cannot examine judgment it cannot see.

Primary authority

  • 31 U.S.C. §§ 5311–5336 — the Bank Secrecy Act, including § 5312(a)(2) (financial institution definition), § 5318(g) (SAR obligation, confidentiality, and safe harbor), § 5318(h) (compliance program), § 5321 and § 5322 (civil and criminal penalties), § 5324 (structuring), § 5331 (cash reporting), and § 5336 (beneficial ownership).
  • 31 C.F.R. Chapter X — the implementing regulations, including § 1010.100 (definitions), § 1010.230 (CDD Rule), § 1010.311 (CTRs), § 1010.380 (beneficial ownership reporting), § 1010.520 and § 1010.540 (sections 314(a) and 314(b)), § 1020.210 and § 1020.220 (bank program and CIP), § 1020.320 (bank SARs), and § 1022.210, § 1022.320, and § 1022.380 (MSB program, SARs, and registration).
  • 26 U.S.C. § 6050I and IRS Form 8300 — cash reporting by trades and businesses.
  • 50 U.S.C. §§ 1701–1708 and 31 C.F.R. Chapter V — IEEPA and the OFAC sanctions programs; 31 C.F.R. Part 501, App. A — the enforcement guidelines.
  • 18 U.S.C. § 1956 and § 1957 — money laundering and monetary transactions in criminally derived property.
  • USA PATRIOT Act §§ 311, 312, 314, 326, 352 — special measures, correspondent account due diligence, information sharing, customer identification, and program requirements.
  • Anti-Money Laundering Act of 2020 — including the Corporate Transparency Act and the expanded whistleblower program at 31 U.S.C. § 5323.
  • Ratzlaf v. United States, 510 U.S. 135 (1994) — structuring scienter, superseded by statute.
  • Cuellar v. United States, 553 U.S. 550 (2008) and United States v. Santos, 553 U.S. 507 (2008) — concealment and proceeds.
  • Global-Tech Appliances, Inc. v. SEB S.A., 563 U.S. 754 (2011) — willful blindness.
  • FinCEN Guidance FIN-2019-G001 — application of BSA regulations to convertible virtual currency businesses.
  • FFIEC BSA/AML Examination Manual — what examiners actually test against.

The typologies examiners expect you to know

A risk assessment written without reference to actual laundering methods reads as an abstraction. Examiners expect a program to name the typologies relevant to the institution's business and to explain what controls address each.

Placement, layering, integration. The classic three-stage model. Placement introduces cash into the system, layering moves it through transactions designed to obscure origin, and integration returns it as apparently legitimate wealth. Most institutional exposure is at layering, because placement usually happens somewhere else.

Trade-based laundering. Over- and under-invoicing, multiple invoicing of the same goods, phantom shipments, and misdescribed commodities. Value moves across borders inside apparently ordinary trade documentation. Institutions offering trade finance need controls calibrated to price benchmarks and shipping documentation, not just to counterparty screening.

Funnel accounts. An account in one jurisdiction receives structured cash deposits from many geographically dispersed locations and is drawn down elsewhere. The signature is a mismatch between deposit locations and the customer's stated footprint.

Shell and shelf companies. Entities with no operations, formed in jurisdictions with weak ownership transparency, often layered several deep. The CDD Rule's control prong exists mostly to make these harder to open.

Nominee and professional intermediaries. Accounts opened by lawyers or formation agents on behalf of undisclosed principals. In the United States, where these intermediaries are largely outside the covered-institution definition, the burden falls entirely on the bank.

Correspondent banking and nested relationships. A foreign respondent bank provides services to its own customers through a U.S. correspondent account, and sometimes to other institutions the correspondent never approved. Section 312 of the USA PATRIOT Act, at 31 C.F.R. § 1010.610, imposes enhanced due diligence for foreign correspondent accounts and specifically addresses this problem.

Cash-intensive businesses. Car washes, restaurants, parking operations, and convenience stores are legitimate businesses that are also convenient for commingling. The control is not to refuse the segment but to benchmark deposits against plausible revenue for the location and size.

Virtual assets. Chain-hopping across blockchains, mixing and tumbling services, privacy coins, peer-to-peer exchanges, and unhosted wallets. FinCEN's travel rule at 31 C.F.R. § 1010.410(f) requires transmittal of originator and beneficiary information for transmittals of funds of three thousand dollars or more, and its application to virtual asset transfers has been a persistent compliance challenge.

Human trafficking and elder exploitation. FinCEN has issued specific advisories with red-flag indicators for both, and SAR filings using the designated keywords are actively analyzed.

A worked onboarding: entity customer, moderate risk

The abstractions become concrete in the sequence a decent institution actually follows.

A logistics company applies for a business deposit account and a wire origination facility. It was formed eighteen months ago in Delaware, operates from a leased warehouse in a border state, and expects monthly wire volume to Mexico and Hong Kong.

Identification. CIP data for the entity — legal name, address, EIN, formation documents. CIP data for the individuals opening the account.

Beneficial ownership. The certification form under 31 C.F.R. § 1010.230 is completed. Two individuals hold thirty and twenty-five percent; the remaining forty-five is held by a Delaware holding company. The ownership prong requires looking through that holding company to the individuals behind it, and the answer determines whether the file is complete. A certification that stops at the intermediate entity is the most common CDD deficiency there is.

Control prong. The named CEO, verified.

Purpose and expected activity. Documented: freight forwarding, expected monthly wire volume and counterparty geographies, expected cash activity of none. This baseline is what future monitoring compares against.

Risk rating. Elevated by geography and by the trade-finance typology, but not high. Enhanced due diligence is triggered: site visit or verified lease, review of major customer contracts, and screening of principal counterparties.

Sanctions screening. Entity, individuals, and known counterparties against the SDN list, with attention to the fifty percent rule for any counterparty owned by listed persons.

Ongoing monitoring. Rules tuned to this profile: wires to jurisdictions outside the stated footprint, cash activity where none was expected, round-dollar patterns, and volume materially exceeding the stated baseline.

Twelve months later, the account begins receiving structured cash deposits at branches three states away. The alert fires. An analyst reviews, cannot reconcile the deposits with a freight forwarding model, and escalates. A SAR is filed within thirty days. Nobody tells the customer, then or ever. The relationship manager is told the account is under review and nothing more.

That last discipline — the internal information barrier around the fact of a filing — is the one institutions most often get wrong, and it is the one with no safe harbor at all.

Examination, enforcement, and what a consent order costs

BSA compliance is examined rather than litigated, which changes the incentives considerably. For banks, the federal banking agencies conduct BSA examinations alongside safety-and-soundness review, using the FFIEC BSA/AML Examination Manual. For money services businesses, the IRS Small Business/Self-Employed division conducts examinations under a delegation from FinCEN. Broker-dealers are examined by FINRA and the SEC.

The escalation ladder is predictable. A matter requiring attention is a supervisory criticism recorded in the examination report. A memorandum of understanding is an informal, non-public agreement to remediate. A consent order or cease-and-desist order under 12 U.S.C. § 1818 is public, enforceable, and frequently accompanied by a civil money penalty. FinCEN can assess penalties independently under 31 U.S.C. § 5321, and often does so in parallel with a banking agency, with the penalties partially credited against each other.

The costs that matter are rarely the fine. A public BSA order triggers:

  • Growth restrictions. Regulators routinely condition or block new branches, new products, and — most consequentially — pending mergers. A BSA order is the most reliable way to make an acquisition impossible for three years.
  • Look-back reviews. An order commonly requires a retrospective transaction review over a multi-year period, conducted by an outside consultant. These are extraordinarily expensive and frequently cost more than the penalty.
  • Independent consultants and monitors. Reporting to the regulator, on the institution's dime.
  • Correspondent de-risking. Other institutions reduce or terminate relationships with an institution under an order, which for a smaller bank or an MSB can be existential.
  • Personal consequences. Individual penalties, prohibition orders under 12 U.S.C. § 1818(e) barring participation in banking, and in serious cases criminal referral.

The asymmetry is worth stating plainly to any board that treats AML as a cost center. A well-staffed program is expensive and produces nothing visible. A deficient one produces a number in a press release, a consultant army, a frozen strategic plan, and a compliance officer who needs personal counsel.

Deferred prosecution agreements appear at the top of the ladder. Several of the largest BSA resolutions have taken this form, pairing an admitted statement of facts with a multi-year term, a monitor, and undertakings that reach into product and staffing decisions.

The practical lesson from the enforcement record is that regulators penalize the gap between what a program claimed to do and what it did. An institution with a modest, honestly scoped program that operates as written fares better than one with an ambitious program on paper and an alert queue nobody clears.

Special measures and the correspondent chokepoint

Section 311 of the USA PATRIOT Act, codified at 31 U.S.C. § 5318A, gives the Treasury a tool that operates less like a regulation than like a sanction. On finding that a foreign jurisdiction, institution, class of transaction, or type of account is of primary money laundering concern, Treasury may impose one or more special measures — enhanced recordkeeping, information collection on beneficial ownership or payable-through accounts, or, at the extreme, a prohibition on U.S. institutions maintaining correspondent accounts for the target.

The fifth special measure is effectively a death sentence for a foreign bank, because losing dollar clearing removes it from international commerce. Treasury has used it sparingly and to considerable effect, and it has extended the authority to virtual currency mixing services as a class of transaction of primary money laundering concern.

For a U.S. institution, a section 311 finding requires prompt action: identify any exposure to the named target, terminate or restrict the relationship on the timeline the order sets, and apply the due diligence the order specifies to indirect exposure through other correspondents. That last piece is the hard one, because the relationship is usually nested rather than direct, and finding it requires asking respondents about their own customers.

The de-risking problem nobody has solved

One consequence of this regime deserves acknowledgment, because it shapes client advice more than any regulation does.

When the penalty for banking a risky customer is measured in tens of millions and the revenue from that customer is measured in hundreds of dollars, the rational institutional response is not better diligence. It is exit. Whole categories of lawful business — money services businesses serving immigrant communities, cash-intensive small businesses, charities operating in conflict zones, cannabis operators, and virtual asset firms — have found it difficult or impossible to obtain banking services, not because any regulator prohibited it but because no institution wants the file.

Regulators have repeatedly said that wholesale de-risking of entire categories is not the expected outcome and that the rules contemplate risk management rather than risk avoidance. Joint statements from the banking agencies have encouraged institutions to assess customers individually. The incentives have not meaningfully changed, because the statements carry no safe harbor.

For counsel advising a client in a de-risked category, the practical path is to make the file easy for a compliance officer to defend: a documented AML program of the client's own even where none is legally required, clean and complete beneficial ownership disclosure, audited financials, an articulable and verifiable business model, and a willingness to answer questions that feel intrusive. The institution is not asking because it distrusts the client. It is asking because someone will one day read the file and ask why the account was opened.


Related articles

This article is provided for general informational purposes and does not constitute legal advice. The beneficial ownership reporting regime under the Corporate Transparency Act has been subject to repeated litigation and rulemaking, and the scope described here may have changed; confirm current requirements with FinCEN before concluding that a filing is or is not due. Sanctions lists change daily. Consult qualified counsel before designing or relying on an anti-money laundering compliance program.