An AML program question usually arrives with urgency attached. A bank has asked for your AML policy. A payment processor wants to see your program before onboarding. An investor has raised it in diligence. And nobody has told you whether you actually owe one.
The good news is that the test is objective. U.S. law does not impose AML compliance obligations on companies by size, revenue or reputation. It imposes them by activity. Below is the sequence of questions that answers it, in the order a regulator would ask them. Compliance Officers runs this analysis for companies that need a defensible answer rather than a guess.
Question 1: Is Your Business a Financial Institution Under the BSA?
Everything turns on this. The Bank Secrecy Act program duty at 31 U.S.C. 5318(h) applies to financial institutions, and that term is defined by regulation, not by intuition. FinCEN sets out the covered industries in 31 CFR Chapter X, one part per sector: banks (1020), casinos and card clubs (1021), money services businesses (1022), brokers or dealers in securities (1023), mutual funds (1024), insurance companies (1025), futures commission merchants and introducing brokers (1026), dealers in precious metals, precious stones or jewels (1027), operators of credit card systems (1028), loan or finance companies (1029), housing government sponsored enterprises (1030), and persons involved in real estate closings and settlements (1031).
If none of the current sector-specific program rules describes the activity, the business generally does not owe a BSA AML program solely because it is a U.S. company. Coverage still requires a documented facts-and-circumstances review. A software company, a consultancy, a restaurant group, an ordinary importer — none of these carry the duty simply by existing.
Question 2: Are You a Money Services Business Without Realizing It?
This step deserves particular attention because an ordinary product feature can change the classification. The money services business definition at 31 CFR 1010.100(ff) captures a person doing business “wholly or in substantial part within the United States” in any of seven capacities — whether or not on a regular basis or as an organized or licensed business concern. That last clause is deliberate. Intent and licensing are irrelevant.
| Capacity | Activity threshold |
|---|---|
| Dealer in foreign exchange | More than $1,000 per person per day |
| Check casher | More than $1,000 per person per day |
| Issuer or seller of traveler's checks or money orders | More than $1,000 per person per day |
| Money transmitter | No threshold at all |
| Provider of prepaid access | Program-based; see 31 CFR 1010.100(ff)(4) |
| Seller of prepaid access | Program-based; see 31 CFR 1010.100(ff)(7) |
| The U.S. Postal Service | Covered by definition, except as to the sale of postage or philatelic products |
The money transmitter trap
Every threshold-based money services business category carries a $1,000 per person per day floor. Money transmission does not. The regulation defines money transmission services as “the acceptance of currency, funds, or other value that substitutes for currency from one person and the transmission … to another location or person by any means” — and “any means” expressly includes electronic funds transfer networks and informal value transfer systems. A marketplace, payroll intermediary or software platform that accepts value from one person and transmits it to another therefore needs a facts-and-circumstances analysis; describing the transfer as an accommodation does not resolve the classification.
Question 3: What Must an AML Program Contain?
If you are covered, the content is prescribed. It is not a document you draft freely. The following comparison shows two important sector profiles:
| Requirement | Banks — 31 CFR 1020.210(a)(2) | Money services businesses — 31 CFR 1022.210(d) |
|---|---|---|
| Internal controls | Yes — a system to assure ongoing compliance | Yes — policies, procedures and internal controls |
| Independent testing | Yes — by bank personnel or an outside party | Yes — scope and frequency commensurate with risk |
| Designated compliance person | Yes — for coordinating and monitoring day-to-day compliance | Yes — and the independent review may not be done by that same person |
| Training | Yes — for appropriate personnel | Yes — including detection of suspicious transactions |
| Ongoing customer due diligence | Yes — the fifth element, risk-based | Not a separate listed element; customer identification duties apply where applicable |
| Must be in writing | In practice, yes | Yes — expressly, and available to Treasury on request |
Note the asymmetry. Banks carry five elements; money services businesses carry four. Guidance that speaks of “the five pillars” as a universal rule is describing the bank regulation and applying it where it does not belong.
There is also a deadline that is easy to miss. A money services business must have its program in place by the later of 24 July 2002 or the end of the 90-day period beginning the day after the business is established (31 CFR 1022.210(e)). For a new entrant, that is ninety days from launch — not from the first regulatory contact.
Question 4: Has Anything Changed for 2026?
Yes, in two directions, and they point differently.
One sector got more time. The AML/CFT program and SAR filing requirements for registered investment advisers and exempt reporting advisers were due to take effect on 1 January 2026. In a final rule published on 2 January 2026, FinCEN delayed that effective date by two years, to 1 January 2028. Advisers who paused their build-out did so on a correct reading of the rule.
FinCEN also proposed a broader rewrite for the institutions covered by parts 1020 through 1030. On 10 April 2026 FinCEN published a proposed rule to fundamentally reform AML/CFT program requirements across the chapter (RIN 1506-AB72). Comments closed 9 June 2026. If finalized as proposed, programs would be judged under a two-pronged framework: whether the institution establishes a program, and whether it maintains it by implementing it in all material respects. FinCEN proposed a twelve-month runway after any final rule.
The practical reading for anyone building today: the proposal is not law, so do not comply with it as though it were. Its architecture places a documented risk assessment at the center of the program. Designing a current program so it can accommodate that structure may reduce later rework, but the resources required and the operative sector rules still need to be assessed.
The Answer Nobody Wants: “It Depends on the Facts”
The reason this question resists a one-line answer is that coverage turns on what you actually do, not on how you describe yourself. Whether a person is a check casher, the regulation says expressly, “is a matter of facts and circumstances.” The same reasoning runs through the chapter.
That is why the useful deliverable is not an opinion but a record: a written analysis of your activities against the regulatory definitions, kept on file, showing what you examined and when. If you are covered, it becomes the foundation of the program. If you are not, it is the document you hand to the bank, the processor or the investor who asked.
What a Defensible AML Coverage Memorandum Should Contain
The useful output of a coverage review is a dated memorandum, not a yes-or-no email. It should describe the legal entity, every relevant line of business, how value moves, who controls customer funds, the role of affiliates and agents, the states and countries involved, and any exemption or exclusion on which the conclusion depends. The regulation should then be matched to those facts.
That record matters when a bank or processor asks why the company does not maintain a regulated AML program. It also exposes weak assumptions. A platform may call itself “software,” but the analysis changes if it accepts value from one person and transmits it to another. A retailer may be ordinary in most respects but still conduct covered check-cashing, currency-exchange or prepaid-access activity. Conversely, commercial pressure to produce an AML policy does not itself create a BSA program obligation.
The memorandum should separate four questions: federal BSA classification, federal registration or reporting, state licensing, and voluntary or contractual controls. They can point in different directions. Federal MSB registration, for example, does not replace state money-transmitter licensing. The 2026 vacatur of the Residential Real Estate Rule likewise means that a preexisting implementation plan cannot be treated as a current filing obligation while the court order remains in force.
Finally, state the events that require re-review. New payment functionality, custody of customer assets, a new acquisition, higher-risk geography, a change in agent relationships or a final FinCEN rule can alter the result. This is the practical answer to “does my business need an AML program”: decide from current activities, preserve the reasoning and define when the decision expires.
How Compliance Officers Helps You Answer It
Compliance Officers provides documented AML checks and due-diligence support for U.S. and international clients. We examine the legal, financial and reputational background of the person or company in scope, verify identity and legal existence from available records, and organize the findings in a written report for the client’s decision file.
The service does not issue a legal opinion, determine guilt, replace the institution’s designated decision-maker or guarantee a regulator’s response. It helps establish facts, identify inconsistencies and preserve a review record before the company commits to a transaction or closes an alert.
A useful engagement begins with a defined subject, purpose and risk question. The client defines the review subject—a person, entity, transaction or relationship—and provides the available identifiers and context. The resulting work can address legal existence, ownership information, relevant public-record findings, sanctions and adverse-information indicators, and inconsistencies that require clarification. The report records its scope and limitations so readers do not mistake an absence of findings for proof that no risk exists.
Due diligence is also time-specific. A report reflects the sources and facts available during the review; it does not remain current indefinitely. A new owner, jurisdiction, product, payment route, regulatory event or material adverse fact can justify an update. The client should connect the report to its own risk classification, escalation process, retention rules and authorized decision-maker. That creates an auditable handoff between external research and the company’s internal compliance responsibility.
For related context, review our resources on corporate KYC, FinCEN filing and compliance and FinCEN requirements for small businesses. These topics overlap, but they are not interchangeable: counterparty due diligence, BSA program duties and beneficial-ownership reporting each have their own trigger and scope.
Frequently Asked Questions
My company is small. Does that exempt me?
No. The Bank Secrecy Act allocates duties by activity, not by size or revenue. The money services business definition applies “whether or not on a regular basis or as an organized or licensed business concern” (31 CFR 1010.100(ff)). A very small operation transmitting money is still a money services business.
We hold client funds briefly before paying suppliers. Are we a money transmitter?
It depends on the specific facts, and it is one of the most consequential questions a business can get wrong, because money transmission has no activity threshold. This requires analysis against 31 CFR 1010.100(ff)(5) and the relevant FinCEN administrative rulings, not a general answer.
How long do we have to put a program in place?
For a money services business, the later of 24 July 2002 or the end of the 90-day period beginning the day after the business is established (31 CFR 1022.210(e)). Other sectors have their own timing in their part of Chapter X.
Do we need five pillars or four?
It depends on your sector. Banks have five elements under 31 CFR 1020.210(a)(2), including risk-based ongoing customer due diligence. Money services businesses have four under 31 CFR 1022.210(d). Applying the bank list to a money services business is a common error in template programs.
Are investment advisers covered now?
Not yet. FinCEN’s final rule of 2 January 2026 delayed the effective date of the adviser AML/CFT program and SAR requirements by two years, to 1 January 2028.
Can a template program satisfy the requirement?
A template can supply structure, but the regulations require the program to be commensurate with the risks posed by the location, size, nature and volume of the services provided (31 CFR 1022.210(b)). A program that does not reflect the location, size, nature and volume of the actual services does not meet that risk-based requirement merely because it follows a template.
Find Out Whether the Rules Reach Your Business
Do you need a documented answer on whether your company owes a Bank Secrecy Act AML program?
Compliance Officers analyses your activities and counterparties against the regulatory definitions, verifies identity and legal existence, and delivers a written report you can keep on file.
Phone and WhatsApp: +1 305-647-3000
Email: info@complianceofficers.org
Legal disclaimer: This article provides general information about United States anti-money laundering rules and does not constitute legal advice, a legal opinion or a guarantee of any regulatory outcome. Obligations depend on the type of institution, its activities and its regulator, and the rules change. Citations reflect the text in force on the date shown. Confirm current requirements with FinCEN, your functional regulator or qualified counsel before acting.







