Questions about anti-money laundering become concrete when a bank freezes a transfer, a partner requests a compliance file or a regulator sends a letter. The useful question is specific: does a current rule apply to this business activity, and what must the business have in place?
U.S. anti-money laundering duties do not attach to every company, and a broad statutory definition does not by itself establish every program or reporting duty. Coverage depends on the business’s actual activities and the operative sector-specific rules under the Bank Secrecy Act and 31 CFR Chapter X. This article sets out what the law says, who it covers, and what the obligations look like in practice. Compliance Officers works with companies and individuals who need that picture clarified before they act, not after.
These obligations did not arise in isolation. Much of what U.S. law now requires tracks standards set internationally, and how FATF standards reach American companies explains why several of the rules below look the way they do.
What Money Laundering Is, in FinCEN's Own Words
The Financial Crimes Enforcement Network (FinCEN), the Treasury bureau that administers the Bank Secrecy Act, defines the problem plainly. Money laundering “involves disguising financial assets so they can be used without detection of the illegal activity that produced them.” Through it, “the criminal transforms the monetary proceeds derived from criminal activity into funds with an apparently legal source.”
Two consequences follow, and both matter commercially. First, illicit funds can move through legitimate financial mechanisms, commercial transactions, front companies or unwitting counterparties. An honest business may therefore encounter suspicious activity without participating in it. Second, the legal response is built on records and reports. The U.S. system does not ask private businesses to determine guilt. It asks them to keep a paper trail and to report what looks wrong.
The Legal Architecture: Six Statutes That Built the Regime
U.S. anti-money laundering law is not one act. It is a sequence, each layer added after a gap became visible:
| Year | Statute | What it added |
|---|---|---|
| 1970 | Bank Secrecy Act (BSA) | The foundation: currency reporting and recordkeeping duties for financial institutions. |
| 1986 | Money Laundering Control Act | Made money laundering a federal crime, at 18 U.S.C. 1956 and 1957. |
| 1988 | Anti-Drug Abuse Act | Extended the definition of financial institution to businesses such as car dealers and real estate closing personnel, and required identity verification for purchasers of monetary instruments over $3,000. |
| 1992 | Annunzio-Wylie Anti-Money Laundering Act | Created the Suspicious Activity Report and eliminated the earlier Criminal Referral Forms. |
| 2001 | USA PATRIOT Act, Title III | The International Money Laundering Abatement and Financial Anti-Terrorism Act: criminalized terrorist financing and expanded the BSA. |
| 2020 | Anti-Money Laundering Act (AML Act) | The first comprehensive update in decades, and the basis for the reform FinCEN proposed in April 2026. |
FinCEN is the designated administrator of the BSA. That single fact resolves a common confusion: your day-to-day examiner may be a banking agency, the SEC or the IRS, but the reporting rules themselves live in FinCEN’s regulations at 31 CFR Chapter X.
Who Must Comply: The Answer Is in the Chapter Number
The most reliable way to know whether U.S. anti-money laundering rules reach your business is to look for it in 31 CFR Chapter X. The chapter is organized by industry, and each part carries its own rules:
| Part | Who it covers |
|---|---|
| 1020 | Banks |
| 1021 | Casinos and card clubs |
| 1022 | Money services businesses |
| 1023 | Brokers or dealers in securities |
| 1024 | Mutual funds |
| 1025 | Insurance companies |
| 1026 | Futures commission merchants and introducing brokers in commodities |
| 1027 | Dealers in precious metals, precious stones, or jewels |
| 1028 | Operators of credit card systems |
| 1029 | Loan or finance companies |
| 1030 | Housing government sponsored enterprises |
| 1031 | Residential real estate transfer reporting (current rule vacated; litigation pending) |
A current AML-program duty depends on an operative sector-specific rule, not merely on a broad statutory definition or the presence of a heading in Chapter X. That is worth stating clearly, because a great deal of marketing implies otherwise.
Two cautions apply. A company can be covered because of one line of business while the rest of its operation is ordinary — a retailer that also transmits funds is the classic case. And sitting outside Chapter X does not put you outside the criminal law: 18 U.S.C. 1956 and 1957 apply to everyone.
What Compliance Actually Requires
For a covered institution the duties fall into four groups.
A written AML program. The content varies by industry. Banks must maintain internal controls, independent testing, a designated compliance officer, training, and risk-based ongoing customer due diligence — the five elements at 31 CFR 1020.210(a)(2). Money services businesses have four (31 CFR 1022.210(d)).
Currency reporting. A Currency Transaction Report is required for each transaction in currency of more than $10,000 (31 CFR 1010.311).
Suspicious activity reporting. Under FinCEN’s rule, banks report qualifying suspicious transactions involving at least $5,000 (31 CFR 1020.320(a)(2)); money services businesses use a $2,000 threshold under 31 CFR 1022.320(a)(2). Institution-specific rules issued by a bank’s functional regulator must also be checked. A SAR is generally due within 30 calendar days after initial detection; where no suspect is identified, the applicable bank and MSB rules allow no more than 60 days, must be retained five years, and is confidential: the report and any information revealing its existence may not be disclosed except as authorized.
Customer due diligence. When 31 CFR 1010.230 applies, a covered financial institution identifies and verifies each individual owning 25 percent or more of a legal entity customer, plus one individual with significant responsibility to control or direct it. FinCEN’s February 13, 2026 exceptive relief means an existing legal-entity customer does not automatically require a fresh identification and verification exercise every time it opens another account. The first account, facts calling earlier information into question and risk-based ongoing procedures remain relevant triggers.
A distinction that trips people up
The customer due diligence rule at 31 CFR 1010.230 obliges financial institutions to collect beneficial ownership information from their business customers. That is a different obligation from company reporting under the Corporate Transparency Act, which has been through substantial change and litigation. Do not assume that one answers the other.
What Non-Compliance Costs
Bank Secrecy Act violations can lead to civil monetary penalties, remedial orders and, for willful conduct, criminal exposure. The amount and form of a penalty depend on the violated provision, the date, the facts, the regulator and annual inflation adjustments. Static penalty figures can therefore become inaccurate and should not be used as a substitute for a current enforcement analysis.
Structuring transactions to evade a reporting requirement remains a separate offense under 31 U.S.C. 5324. A business should not advise a customer how to remain below a reporting threshold, and employees should understand that reporting avoidance can be relevant even when the source of funds has not been proven criminal.
The Rules Are Being Rewritten Right Now
On 10 April 2026 FinCEN published a proposed rule — “Anti-Money Laundering and Countering the Financing of Terrorism Programs,” RIN 1506-AB72 — to fundamentally reform program requirements across part 1010 and parts 1020 through 1030, implementing the AML Act of 2020. The comment period closed on 9 June 2026.
It is a proposal. Nothing in it binds anyone today, and FinCEN proposed an effective date twelve months after any final rule is issued. But the direction is unambiguous: a documented, risk-based program built around a written risk assessment, with supervision aimed at significant or systemic failures rather than technical ones. An institution building a program now is better served designing toward that shape than retrofitting later.
Legal Coverage and Practical Risk Management Are Not the Same Question
A company can have no direct BSA AML-program duty and still face a serious need for counterparty review. Banks, payment processors, investors, insurers and commercial partners may ask for ownership information, sanctions screening, source-of-funds context or an AML policy as a condition of doing business. Those requests are contractual or risk-management expectations unless a law or regulation separately makes them mandatory.
That distinction should appear in the company’s file. A defensible scope memo identifies the products and services actually offered, the flow of customer funds, the jurisdictions involved, any agents or intermediaries, the relevant Chapter X categories and the conclusion reached under the current rule. It should also record what was not decided. For example, concluding that a business has no BSA program duty does not decide sanctions exposure, fraud risk, licensing, state money-transmission law or a bank’s onboarding standards.
Current real-estate status shows why dated analysis matters. A federal court vacated FinCEN’s Residential Real Estate Rule on March 19, 2026, and the government appealed. While the vacatur remains in force, reporting persons are not required to file Real Estate Reports and are not liable for failing to do so. FinCEN also states that the rule did not impose an AML-program obligation on real-estate closing participants. A checklist written before that court order can therefore be materially wrong today.
Change control completes the review. Revisit the conclusion when the company launches a payment feature, begins holding customer value, adds foreign agents, changes transaction channels, acquires another business or receives a new regulatory classification. Anti money laundering coverage follows activity, and activity changes faster than corporate names.
How Compliance Officers Supports This Work
Compliance Officers provides documented AML checks and due-diligence support for U.S. and international clients. We examine the legal, financial and reputational background of the person or company in scope, verify identity and legal existence from available records, and organize the findings in a written report for the client’s decision file.
The service does not issue a legal opinion, determine guilt, replace the institution’s designated decision-maker or guarantee a regulator’s response. It helps establish facts, identify inconsistencies and preserve a review record before the company commits to a transaction or closes an alert.
A useful engagement begins with a defined subject, purpose and risk question. The client identifies the person, entity, transaction or relationship to be reviewed and provides the available identifiers and context. The resulting work can address legal existence, ownership information, relevant public-record findings, sanctions and adverse-information indicators, and inconsistencies that require clarification. The scope and limitations are recorded so that an absence of findings is not mistaken for proof that no risk exists.
Due diligence is also time-specific. A report reflects the sources and facts available during the review; it does not remain current indefinitely. A new owner, jurisdiction, product, payment route, regulatory event or material adverse fact can justify an update. The client should connect the report to its own risk classification, escalation process, retention rules and authorized decision-maker. That creates an auditable handoff between external research and the company’s internal compliance responsibility.
For related context, review our resources on corporate KYC, FinCEN filing and compliance and FinCEN requirements for small businesses. These topics overlap, but they are not interchangeable: counterparty due diligence, BSA program duties and beneficial-ownership reporting each have their own trigger and scope.
Frequently Asked Questions
Does every U.S. company need an AML program?
No. The program duty at 31 U.S.C. 5318(h) applies to entities that meet the Bank Secrecy Act definition of a financial institution, listed by industry across 31 CFR parts 1020 to 1031. Companies outside those categories carry no BSA program duty, though the federal money laundering offenses at 18 U.S.C. 1956 and 1957 apply to everyone.
What is the difference between AML and KYC?
KYC — knowing who your customer is — is one component of an AML program, not a synonym for it. In U.S. regulation the related requirements appear as the Customer Identification Program and, for legal entity customers, the beneficial ownership requirements of 31 CFR 1010.230.
At what amount must a transaction be reported?
Two thresholds do two different jobs. A Currency Transaction Report is required for currency transactions of more than $10,000 (31 CFR 1010.311) and is automatic. A Suspicious Activity Report turns on suspicion rather than size, above a floor of $5,000 for banks and $2,000 for money services businesses.
Will I be told if a SAR is filed about me?
No. A SAR, and any information that would reveal its existence, is confidential by regulation and may not be disclosed except as specifically authorized (31 CFR 1020.320(e) and 1022.320(d)). An institution that told you would itself be violating the rule.
Do the 2026 proposed changes apply to my business yet?
No. FinCEN’s April 2026 document is a notice of proposed rulemaking. It is not in force, and FinCEN proposed a twelve-month implementation period after any final rule. Current obligations remain those written in 31 CFR Chapter X today.
Can you help if my company is outside the United States?
Yes. A large part of our work is for clients abroad who need U.S. counterparties, records or entities examined, and the process is handled remotely.
Get Clarity on Your AML Obligations
Do you need to know whether U.S. anti-money laundering rules reach your business, or who you are actually dealing with?
Compliance Officers examines the legal, financial and reputational background of individuals and companies, verifies identity and legal existence, and delivers a written report you can act on.
Phone and WhatsApp: +1 305-647-3000
Email: info@complianceofficers.org
Legal disclaimer: This article provides general information about United States anti-money laundering rules and does not constitute legal advice, a legal opinion or a guarantee of any regulatory outcome. Obligations depend on the type of institution, its activities and its regulator, and the rules change. Citations reflect the text in force on the date shown. Confirm current requirements with FinCEN, your functional regulator or qualified counsel before acting.







