Back to Articles

90 Day BSA/AML Monitoring Checklist for U.S. Banks Before an Exam

9/20/2026
10 min read
90 Day BSA/AML Monitoring Checklist for U.S. Banks Before an Exam

A compliant BSA/AML monitoring program reliably detects suspicious activity, supports timely SAR and CTR filing, and produces auditable, per-decision records regulators can sample. It has to be risk-based, not just rule-based. FinCEN sets the reporting rules, the FFIEC's BSA/AML Examination Manual defines how examiners test your program, and a $10,000 or more daily cash threshold remains a statutory tripwire for reporting in the system.


  • Maintaining risk-based monitoring that links policies, controls, testing, and staff authority is essential to passing exams and ensuring compliance.
  • Effective systems layer rule-based detection, behavioral analysis, and machine learning, with regular calibration and documented thresholds to reduce false alerts.
  • All alert handling must follow a clear lifecycle with detailed written rationales, timestamps, and signed determinations for exam sampling.
  • Independent testing should be risk-driven, covering thresholds, review logic, and SAR narrative quality at least every 12 to 18 months, with reports fed to leadership.
  • Automated tools support documentation, calibration, and decision-making, but require validated validation reports, audit logs, and tuning histories for exam readiness.
Compliance Solution

Maintain 100% NCUA & OCC Audit Readiness

Monitor regulatory updates 24/7, check internal credit policies, and generate compliance trails with Erina (AI Regulatory Agent).


Table of Contents

What Does BSA/AML Monitoring Actually Require?

The Bank Secrecy Act obligates every U.S. financial institution to record cash purchases of negotiable instruments and report activity that suggests money laundering, fraud, or other financial crime. The $10,000 daily aggregate threshold for cash transactions triggers a Currency Transaction Report, while suspicious activity, regardless of dollar amount, triggers a Suspicious Activity Report. Neither obligation is optional, and examiners treat gaps in either as programmatic failures, not paperwork errors.

Your program has to rest on five pillars examiners check line by line:

  • A board-approved BSA/AML policy that reflects your institution's actual risk profile
  • Internal controls that translate policy into daily monitoring and escalation practice
  • Independent testing conducted by qualified staff or an outside party
  • A designated BSA officer with real authority and adequate staffing
  • Training programs tied to job function, plus Customer Identification Program and Customer Due Diligence procedures

Cite the relevant CFR parts and FinCEN's guidance library directly in your workpapers. Examiners want to see the citation trail, not just the conclusion.

How Should You Design a Transaction Monitoring Program?

Effective monitoring layers three detection types. Rule-based scenarios catch known typologies like structuring or rapid movement of funds, and they're the right starting point because they're transparent and defensible in an exam. Behavioral baselines flag deviations from a customer's own history. Machine learning models, layered on top, catch subtler patterns that static rules miss, though combining rules with behavioral baselines and supervised models tends to sharpen precision more than any single layer alone.

Your data inputs matter as much as your scenarios. Build customer profiles from CDD data, product usage, channel behavior, and peer-group comparisons, then update those profiles as behavior shifts.

Alert triage follows a predictable chain:

  1. Level 1 analysts perform initial disposition and clear low-risk alerts with documented rationale.
  2. Level 2 analysts investigate escalated alerts, pull supporting transaction history, and draft findings.
  3. The BSA officer or MLRO makes the final SAR determination and signs off on the record.

Pro Tip: Keep a standing folder of "why we closed this" narratives for your highest-alert-volume scenarios. When an examiner asks why 40 similar alerts got the same disposition, a documented pattern beats reconstructing logic from memory.

How Do You Calibrate and Tune Monitoring Systems?

Calibration is not a one-time setup task. It's a recurring cycle: risk assessment, scenario selection, simulation against historical data, above-the-line/below-the-line (ATL/BTL) analysis, live threshold adjustment, then continuous review. Running scenarios through a simulation environment built on representative historical data lets you test threshold changes before they touch live alerts, which is exactly what examiners want to see documented.

Monitoring calibration cycle before live alerts

Data-driven calibration commonly cuts alert volumes by about 30%, according to Deloitte's analysis of rule-based transaction monitoring systems. That reduction isn't about generating fewer alerts for its own sake. It's about redirecting analyst hours away from noise and toward the alerts that actually produce SARs.

Build your review cadence around these habits:

  • Document quarterly tuning reviews with rationale tied to SAR outcomes, not just alert counts
  • Track precision (alerts that convert to SARs) alongside raw volume
  • Flag any scenario whose thresholds haven't moved in over a year for immediate review

Institutions that leave thresholds untouched for years are a common audit finding. Regulators don't expect zero false positives; they expect proof you're actively managing the trade-off. Our piece on enhancing compliance accuracy walks through scenario tuning in more operational detail.

What Happens After an Alert Fires?

Every alert moves through a defined lifecycle, and examiners will trace individual cases through each stage to test whether your documentation holds up.

  1. Generation: the system flags a transaction or pattern against a scenario threshold.
  2. Triage: an analyst reviews the alert against customer profile and history, deciding whether to escalate.
  3. Investigation: escalated alerts get a deeper look, including transaction history, KYC records, and any prior alerts on the account.
  4. Determination: the BSA officer decides whether the activity warrants a SAR or documented closure.
  5. Filing or closure: SARs go to FinCEN within 30 days of initial detection, extendable to 60 days when no suspect has been identified.

Every closure, whether it results in a filed SAR or a documented "no action" decision, needs a written rationale, the analyst's identity, and a timestamp. That per-decision record is what FFIEC examiners sample directly when testing SAR quality and program effectiveness.

What Does Independent Testing Need to Cover?

Independent testing is where a lot of otherwise solid programs fall apart in exams, usually because the testing scope is too narrow. A thorough review validates alert thresholds, checks the sampling logic used to select transactions for review, evaluates SAR narrative quality, and confirms the integrity of your management information systems.

Frequency should be risk-based rather than fixed, but FFIEC guidance points to roughly every 12 to 18 months as a reasonable baseline, with ad-hoc testing triggered by:

  • A significant increase in transaction volume or new product lines
  • Prior exam findings or consent orders
  • Major system changes, including new monitoring software or vendor migrations

Testing reports go directly to the board or its designated committee, not buried in a compliance file. Examiners will ask to see that reporting chain. Our guide on compliance testing programs breaks down what a defensible test plan looks like in practice.

What Governance and Metrics Reduce Exam Risk?

Boards need documented oversight of BSA/AML risk, not just a signature on an annual policy. The BSA officer needs real authority to reallocate resources when alert volumes spike, and training has to map to job function through a clear RACI structure, so examiners can see who owns each control.

Track these operational metrics closely:

  • Alert volume trends by scenario, month over month
  • Median and 95th-percentile alert age, since aging alerts signal capacity problems
  • SAR filing timeliness against the 30/60-day windows
  • Disposition precision, meaning the share of alerts that convert to filed SARs

Pro Tip: If your 95th-percentile alert age is climbing quarter over quarter, that's usually a staffing problem wearing a technology costume. Fix the headcount before you blame the scenarios.

How Does Automation Support Exam Readiness?

Automation doesn't replace the judgment calls examiners want documented. It supports them. Platforms can run scenario calibration simulations, enrich alerts with peer and profile data, and draft SAR narratives while keeping a full audit trail of every decision. When evaluating a vendor, ask for evidence of independent validation, exportable audit logs, and a documented tuning history rather than a features list. Our overview of risk process automation covers how these systems typically integrate with existing case management.

A 90-Day Checklist Before Your Next Exam

Run a calibration simulation against your last twelve months of data and document what changed and why. Sample a batch of recent SARs purely for narrative quality, not just filing timeliness. Brief your board with evidence, not assurances: show alert-age trends, precision rates, and testing findings. The goal isn't zero false positives. It's a program that can show its reasoning on every single decision.

— Raj

How Riskinmind Fits Into Your Monitoring Stack

Some platforms build scenario libraries, audit trails, and calibration history directly into their monitoring workflows, so the documentation examiners ask for already exists rather than getting reconstructed after the fact. Enterprise-grade solutions often run on SOC 2® aligned controls with rapid processing, and use specialized AI agents to handle scenario tuning, alert enrichment, and SAR drafting while keeping every decision traceable back to its underlying data.

Riskinmind

If you're evaluating whether your current stack can produce that kind of per-decision record on demand, request a pilot and ask specifically for independent validation reports and tuning history logs, not just a features walkthrough. You can review Starter, Professional, and Enterprise plans or explore the full Bank OS and monitoring modules to see how the pieces connect before you commit to a demo.

Where to Find the Rules That Matter

For workpapers and policy updates, bookmark the FFIEC BSA/AML Examination Manual for examiner procedures, FinCEN for SAR and CTR filing rules, and the FDIC's BSA/AML resource page for supervisory guidance. Cross-check any OCC-supervised institution's obligations against the OCC's own BSA index before finalizing policy language.

This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.

Sources

FAQ

What Are the Most Recent BSA/AML Regulatory Changes?

FinCEN continues to update guidance on beneficial ownership reporting and CDD requirements, and institutions should treat FinCEN's guidance and advisory library as the authoritative source for the latest rule changes. Exam procedures under the FFIEC manual are updated periodically to reflect these changes, so cross-check both before your next policy review.

Does FinCEN Administer the Bank Secrecy Act?

Yes. FinCEN is the bureau responsible for administering the BSA, and it sets the rules for SAR and CTR filing along with broader anti-money laundering requirements. The OCC's BSA overview explains how bank examiners apply those FinCEN-administered rules during supervision.

Where Can I Find the Bank Secrecy Act Text?

The BSA's statutory text and related regulations are available through FinCEN's official site and the Code of Federal Regulations rather than as a single standalone PDF. FinCEN's guidance pages link directly to the relevant regulatory sections for institutions drafting policy.

What Is the Best Software for AML Transaction Monitoring?

The strongest AML monitoring systems combine rule-based scenarios, behavioral baselines, and documented calibration history so every alert disposition can be traced and defended. Riskinmind builds these elements into one platform, with scenario libraries, audit trails, and SOC 2® aligned controls designed specifically for credit unions and community banks; pricing details are available on the Riskinmind pricing page.

Recommended

AML transaction monitoring
AML monitoring systems
BSA AML software
anti-money laundering tools
best practices for AML monitoring
BSA reporting obligations
financial crime compliance
suspicious activity detection
AML risk assessment
BSA AML monitoring
BSA AML compliance
BSA requirements
how to implement AML monitoring
transaction monitoring AI
BSA AML automation
aml monitoring best practices