Jurisdicción de Estados Unidos,
explicada con claridad.

U.S. jurisdiction,
explained clearly.

The Bank Secrecy Act Explained: What BSA Requires of Non-Bank Businesses

bank secrecy act

The name can be misleading. The Bank Secrecy Act is not about secrecy, and it is not only about banks. Established in 1970, it is the statute that obliges a defined set of U.S. businesses to keep records and file reports that are, in the words of the statute as amended, “highly useful in criminal, tax, or regulatory investigations, risk assessments, or proceedings” and in intelligence activities to protect against terrorism (31 U.S.C. 5311). Over five decades Congress kept widening the circle of who counts.

The statutory and regulatory framework reaches sectors such as jewellers, casinos, insurers, check cashers, precious-metals dealers and loan companies. It also contains a part for residential real-estate transfer reporting, although the reporting rule for closing participants is currently vacated and has no legal effect while the court order remains in force. If you run one of those businesses, the BSA is your statute too. This article explains what it requires when you are not a bank — and where the differences bite. Compliance Officers supports non-bank businesses through exactly these obligations.

How a Banking Law Ended Up Covering Jewellers

First, the expansion occurred incrementally, and each step followed a demonstrated gap:

  • 1970 — Congress enacts the BSA and creates currency-reporting and recordkeeping duties.
  • 1988 — Congress extends the financial-institution definition to businesses such as car dealers and real-estate closing personnel and adds large-currency reporting duties. The same law requires verification of identity for purchasers of monetary instruments over $3,000.
  • 1992 — the Annunzio-Wylie Act strengthens sanctions for BSA violations and creates the Suspicious Activity Report.
  • 2001 — Title III of the USA PATRIOT Act expands the BSA again and criminalizes terrorist financing.
  • 2020 — the AML Act delivers the first comprehensive update in decades.

As a result, the operative question is never “am I a bank?” but “does 31 CFR Chapter X describe my activity?”

The Non-Bank Sectors the BSA Covers

Therefore, each sector has its own part of the chapter, and the rules differ between them. This is the practical map:

SectorPart of 31 CFRNotes
Casinos and card clubs1021Long-standing coverage with sector-specific reporting
Money services businesses1022A broad non-bank category defined by the financial service performed
Brokers or dealers in securities1023Supervised through the SEC and FINRA
Mutual funds1024
Insurance companies1025Applies to specified products, not all insurance
Futures commission merchants and introducing brokers1026Supervised through the CFTC and NFA
Dealers in precious metals, precious stones, or jewels1027Coverage depends on purchase and sale volumes in covered goods
Operators of credit card systems1028
Loan or finance companies1029Includes residential mortgage lenders and originators
Housing government sponsored enterprises1030
Residential real estate transfer reporting (current rule vacated; litigation pending)1031The March 2026 court order vacated the reporting rule; FinCEN currently requires no Real Estate Reports while that order remains in force
bank secrecy act

Four Duties That Do Not Depend on Being a Bank

1. Currency Transaction Reports. Every financial institution other than a casino must report each deposit, withdrawal, exchange of currency or other payment or transfer involving a transaction in currency of more than $10,000 (31 CFR 1010.311). This rule operates mechanically: it requires no suspicion or discretionary judgment. The threshold is the trigger.

2. Suspicious Activity Reports. Second, when suspicious-activity rules apply, they impose specific thresholds and deadlines. A money services business must report a transaction of at least $2,000 when it knows, suspects or has reason to suspect that the transaction involves funds from illegal activity, is designed to evade BSA requirements, serves no apparent lawful purpose, or involves use of the business to facilitate criminal activity (31 CFR 1022.320(a)(2)). The institution generally files within 30 calendar days after initial detection; if it cannot identify a suspect, the applicable rule permits no more than 60 days.

3. A written AML program. Third, a money services business needs four minimum elements: policies, procedures and internal controls; a designated person for day-to-day compliance; training; and independent review. The program must be in writing and made available to the Treasury Department for inspection on request (31 CFR 1022.210(c)).

4. Recordkeeping. Finally, the institution must keep the SAR and its supporting documentation for five years. An MSB must also keep its registration records for five years at a location within the United States.

The independent review rule non-banks get wrong

A money services business may have its independent review conducted by its own officer or employee — but not by the person designated to assure day-to-day compliance (31 CFR 1022.210(d)(4)). If the compliance officer and reviewer are the same person, that overlap fails the independence condition for the fourth element of an MSB program.

Where Non-Bank Rules Diverge from Bank Rules

Bank guidance should not be applied automatically to a non-bank institution. Three differences are especially important:

PointBanksMoney services businesses
SAR thresholdAt least $5,000 (31 CFR 1020.320(a)(2))At least $2,000; $5,000 for issuers reviewing clearance records (31 CFR 1022.320(a)(2)-(3))
Program elementsFive, including risk-based ongoing customer due diligenceFour; no separately listed ongoing CDD element
Registration with FinCENNot applicableRequired — FinCEN Form 107, within 180 days of establishment, renewed every two years

In particular, the last row has no bank analogue and creates a separate source of regulatory exposure. Registration creates a standalone duty: an MSB that maintains a strong AML program but never files Form 107 remains in breach, and a registration violation can trigger civil and criminal penalties.

What Enforcement Looks Like

Willful Bank Secrecy Act violations can trigger criminal fines, imprisonment and remedial orders. Civil exposure depends on the violated provision, the conduct, the date, the responsible party and applicable inflation adjustments. A current enforcement review should therefore use the operative penalty schedule rather than repeat a static figure from an older article.

FinCEN’s April 2026 proposed program rule also signals an intended focus on significant or systemic implementation failures in certain banking contexts. That text remains a proposal, not current law, and it does not displace criminal statutes or existing sector-specific duties. The defensible response is to test actual implementation, document remediation and distinguish current obligations from proposed standards.

A Non-Bank BSA Review Must Separate Four Different Duties

At the classification stage, the phrase “subject to the BSA” remains too broad to function as a compliance conclusion. A non-bank business may have an AML-program rule, a transaction-reporting rule, a recordkeeping rule, a registration duty—or only some of them. Each obligation needs its own citation, threshold, responsible owner and implementation date.

For instance, money services businesses illustrate the point. A covered MSB may need FinCEN registration, an agent list, a written four-element AML program, currency reporting, suspicious-activity reporting and specified transaction records. The rules can treat an agent acting solely for another MSB differently from a principal that conducts activity on its own behalf. State licensing remains a separate analysis. Copying a bank’s five-element policy does not answer any of those classification questions.

Similarly, real estate demonstrates the danger of relying on a static sector table. FinCEN’s Residential Real Estate Rule created a transfer-reporting framework but did not impose an AML program on closing participants. A federal court vacated the rule on March 19, 2026. FinCEN says it currently requires no Real Estate Reports and imposes no nonfiling liability while that order remains in force; the government has appealed. A responsible article must state that status rather than describe the rule as fully operational.

Finally, delegation also has limits. A vendor may prepare a filing, run screening or provide software, but outsourcing the task does not automatically transfer the regulated institution’s responsibility. Contracts should define data access, escalation, quality control, retention, incident handling and the institution’s right to test the work. The Bank Secrecy Act framework is ultimately a system of accountable decisions and preserved records, not merely a collection of forms.

How Compliance Officers Works with Non-Bank Businesses

Compliance Officers provides documented AML checks and due-diligence support for U.S. and international clients. We examine the legal, financial and reputational background of the person or company in scope, verify identity and legal existence from available records, and organize the findings in a written report for the client’s decision file.

The service does not issue a legal opinion, determine guilt, replace the institution’s designated decision-maker or guarantee a regulator’s response. It helps establish facts, identify inconsistencies and preserve a review record before the company commits to a transaction or closes an alert.

A useful engagement begins with a defined subject, purpose and risk question. The client defines the review subject—a person, entity, transaction or relationship—and provides the available identifiers and context. The resulting work can address legal existence, ownership information, relevant public-record findings, sanctions and adverse-information indicators, and inconsistencies that require clarification. The report records its scope and limitations so readers do not mistake an absence of findings for proof that no risk exists.

Due diligence is also time-specific. A report reflects the sources and facts available during the review; it does not remain current indefinitely. A new owner, jurisdiction, product, payment route, regulatory event or material adverse fact can justify an update. The client should connect the report to its own risk classification, escalation process, retention rules and authorized decision-maker. That creates an auditable handoff between external research and the company’s internal compliance responsibility.

For related context, review our resources on corporate KYC, FinCEN filing and compliance and FinCEN requirements for small businesses. These topics overlap, but they are not interchangeable: counterparty due diligence, BSA program duties and beneficial-ownership reporting each have their own trigger and scope.

Frequently Asked Questions

Does the Bank Secrecy Act apply to ordinary businesses?

Only if the business falls within one of the sectors defined in 31 CFR Chapter X, parts 1020 to 1031. An ordinary trading, service or manufacturing company is not a financial institution under the BSA and owes no program duty — although the federal money laundering offenses at 18 U.S.C. 1956 and 1957 apply to everyone.

Financial institutions other than casinos must file a Currency Transaction Report for currency transactions over $10,000 under 31 CFR 1010.311. A separate IRS rule may still require a non-BSA business to report large cash payments, so the company should review that rule on its own terms.

No. An officer or employee may conduct an MSB’s review, but the business may not use the person designated under 31 CFR 1022.210(d)(2) for day-to-day compliance.

The institution must retain a SAR and its supporting documentation for five years after filing. A money services business must retain its registration form and supporting documentation for five years at a location within the United States.

The money services business definition reaches a person “wherever located” doing business wholly or in substantial part within the United States, including through any agent, agency, branch or office in the U.S. (31 CFR 1010.100(ff)). Location abroad is not, by itself, an exemption.

The BSA is a regulatory statute: it requires records and reports, and 31 U.S.C. 5321 and 5322 establish consequences for breach. The money laundering offenses at 18 U.S.C. 1956 and 1957, created by the Money Laundering Control Act of 1986, are substantive crimes and apply regardless of whether you are a financial institution.

Meet Your BSA Obligations Without a Compliance Department

Has a bank asked your non-bank business for BSA documentation, or do you need an independent counterparty review?

Compliance Officers reviews the legal, financial and reputational background of individuals and companies, confirms identity and legal existence, and delivers a written report for your file.

Request an evaluation

Phone and WhatsApp: +1 305-647-3000
Email: info@complianceofficers.org

Legal disclaimer: This article provides general information about United States anti-money laundering rules and does not constitute legal advice, a legal opinion or a guarantee of any regulatory outcome. Obligations depend on the type of institution, its activities and its regulator, and the rules change. Citations reflect the text in force on the date shown. Confirm current requirements with FinCEN, your functional regulator or qualified counsel before acting.

Related News

Compliance Officers

Consulta sin ningún costo!

Request information with no commitment

QR-Compliance Officers

Do you want to talk with us?

Últimas publicaciones