The United States regulates anti-money laundering through the Bank Secrecy Act, administered by the Financial Crimes Enforcement Network and codified at 31 CFR Chapter X. Covered institutions must run a written AML/CTF programme, verify customers, file suspicious activity and currency transaction reports, and screen independently against OFAC sanctions lists.
Key takeaways
- A currency transaction report is required for currency transactions over USD 10,000, filed within 15 days. A bank suspicious activity report is triggered at USD 5,000 and due within 30 calendar days.
- Corporate Transparency Act beneficial ownership reporting no longer applies to US-formed entities. FinCEN removed them from scope on 26 March 2025, so only foreign reporting companies still file.
- OFAC sanctions liability is strict and sector-agnostic: the maximum civil penalty per violation is the greater of USD 377,700 or twice the transaction value.
- TD Bank's USD 3.09 billion resolution in October 2024 is the largest Bank Secrecy Act penalty ever imposed, after 92% of its transaction volume went unmonitored.
Which laws make up the US AML/CTF framework?
Four instruments do most of the work. The Bank Secrecy Act of 1970 (31 U.S.C. 5311 et seq.) is the foundation, requiring recordkeeping and reporting by defined financial institutions; its operative detail sits in 31 CFR Chapter X, maintained by the Financial Crimes Enforcement Network (FinCEN).
The USA PATRIOT Act of 2001 added customer identification, correspondent banking controls and information sharing. The Anti-Money Laundering Act of 2020 added whistleblower incentives, brought antiquities dealers into scope and raised penalties for repeat violators. The Corporate Transparency Act, enacted alongside it, created a federal beneficial ownership registry whose scope has since been cut back sharply.
Criminal exposure sits at 31 U.S.C. 5322: up to USD 250,000 and five years' imprisonment for a wilful violation, rising to USD 500,000 and ten years where the violation forms part of a pattern of illegal activity exceeding USD 100,000 in twelve months.
Which agencies supervise AML compliance in the United States?
There is no single US AML supervisor. FinCEN writes the rules and receives the filings, but examination is delegated to whichever regulator already supervises the institution. That is why a national bank, a broker-dealer and a money services business answer to different examiners for the same underlying obligations. Our United States country coverage page sets out the list-level detail.
| Body | Role in the US AML/CTF regime |
|---|---|
| FinCEN | Administers the Bank Secrecy Act and Chapter X rules; receives SARs, CTRs and FBARs |
| OFAC | Administers sanctions; maintains the Specially Designated Nationals (SDN) list |
| OCC | Examines national banks and federal savings associations |
| FDIC | Examines state non-member banks and state savings associations |
| Federal Reserve | Examines state member banks and US branches of foreign banks |
| SEC and FINRA | Examine broker-dealers, mutual funds and, from 2028, investment advisers |
| IRS Small Business/Self-Employed | Examines money services businesses and casinos |
Who counts as a "financial institution" under the Bank Secrecy Act?
The definition is far broader than "bank". 31 CFR 1010.100(t) captures banks, broker-dealers in securities, money services businesses, futures commission merchants, mutual funds, insurance companies, operators of credit card systems, loan and finance companies, dealers in precious metals, stones or jewels, and, since the Anti-Money Laundering Act of 2020, dealers in antiquities.
Casinos are covered where gross annual gaming revenue exceeds USD 1 million, with card clubs alongside them. Each category has its own part of Chapter X, so obligations differ by entity type even where the statutory hook is identical.
Two sectors sit in transition, and neither carries a live obligation today. Registered investment advisers and exempt reporting advisers were brought in by a 2024 rule, but FinCEN has postponed its effective date to 1 January 2028. The Residential Real Estate Rule, which would have made certain non-financed residential transfers reportable from 1 March 2026, was vacated on 19 March 2026 by the US District Court for the Eastern District of Texas. FinCEN and the Department of Justice have appealed, and FinCEN states that while the court's order stands, reporting persons are not required to file Real Estate Reports and are not liable for failing to do so.
Which reports must US institutions file, and by when?
The distinction that trips teams up is that suspicious activity reporting is judgement-based and confidential, while currency reporting is mechanical and threshold-driven. Structuring transactions to avoid the second is itself a federal offence. Thresholds and clocks come from 31 CFR 1010.311 and 31 CFR 1020.320.
| Report | Trigger | Threshold | Deadline | Filed with |
|---|---|---|---|---|
| SAR (bank) | Suspicious transaction, actual or attempted | USD 5,000 with suspect; USD 25,000 without | 30 calendar days; 60-day maximum | FinCEN |
| SAR (money services business) | Suspicious transaction, actual or attempted | USD 2,000 | 30 calendar days | FinCEN |
| CTR | Currency transaction through the institution | Over USD 10,000 per business day | 15 days | FinCEN |
| FBAR (Form 114) | US person with foreign financial accounts | Aggregate over USD 10,000 in the year | 15 April; extension to 15 October | FinCEN |
| Form 8300 | Cash received in a trade or business | Over USD 10,000, one or related transactions | 15 days | FinCEN and the IRS |
FBAR dates follow FinCEN's post-2015 filing schedule, not the older 30 June date still shown in some references.
What does the CDD Rule require after FinCEN's February 2026 relief?
The Customer Due Diligence Rule at 31 CFR 1010.230 obliges covered institutions (banks, broker-dealers, mutual funds, futures commission merchants and introducing brokers) to identify and verify the beneficial owners of legal entity customers. Two prongs apply: every individual owning 25% or more of the equity interests, plus a single individual with significant responsibility to control or manage the entity.
What changed is frequency. Under FinCEN Order FIN-2026-R001, issued on 13 February 2026, covered institutions no longer have to re-identify and re-verify beneficial owners at every new account opening for an existing legal entity customer.
Verification is now required when the customer first opens an account, when facts call the existing information into question, and otherwise as risk-based ongoing due diligence dictates. Monitoring and screening obligations are unchanged. The relief removes duplicated effort, not the underlying control.
Is Corporate Transparency Act beneficial ownership reporting still in force?
Only for foreign entities. This is the most misreported point about the US regime, and older guidance is now wrong. FinCEN's interim final rule, published on 26 March 2025, revised "reporting company" to cover only entities formed under the law of a foreign country that have registered to do business in a US state or tribal jurisdiction.
All entities created in the United States, previously known as domestic reporting companies, and their beneficial owners are exempt from beneficial ownership reporting. Foreign reporting companies registered before 26 March 2025 had until 25 April 2025 to file. Those registering afterwards have 30 calendar days, and none report beneficial owners who are US persons.
A final rule remained pending as of mid-2026, so treat the interim rule as the operative position and re-check before relying on it. Firms that expected to use the registry for entity verification need commercial ownership screening instead. See our explainer on shell companies.
How do OFAC sanctions obligations differ from Bank Secrecy Act obligations?
They are separate regimes with separate liability models, and conflating them is a recurring audit finding. Bank Secrecy Act obligations attach only to defined financial institutions and are judged on whether the programme was reasonably designed. OFAC sanctions bind every US person, including corporates, individuals and non-financial businesses, with no de minimis threshold and no sector gate.
OFAC also applies strict liability, so an unwitting breach is still a breach. The maximum civil penalty per violation is the greater of USD 377,700 or twice the value of the underlying transaction, and wilful violations carry criminal exposure of up to USD 1 million and 20 years' imprisonment.
Screening scope differs too. Sanctions obligations extend beyond named parties on the SDN list to entities 50% or more owned by blocked persons, which is why sanctions and PEP screening must resolve ownership as well as names.
Which USA PATRIOT Act sections drive day-to-day compliance?
Five sections of the 2001 Act still shape operational controls, and FinCEN's own summary remains the reference point. Section 311 lets Treasury impose special measures against foreign jurisdictions, institutions or account types identified as primary money laundering concerns.
Section 312 requires enhanced due diligence on foreign correspondent accounts and private banking accounts for non-US persons. It is the provision behind most correspondent banking questionnaires. Section 313 prohibits US institutions from maintaining correspondent accounts for foreign shell banks with no physical presence.
Section 314(a) obliges institutions to search records against law enforcement requests, while the voluntary 314(b) safe harbour lets institutions share information with each other on suspected money laundering. Section 326 produced the Customer Identification Program rule underneath every US onboarding flow. Definitions sit in our glossary of AML terms.
What do recent US enforcement actions show?
Penalties track the duration and scale of the control failure, not institution size. US jurisdiction is also broad. Danske Bank and Standard Chartered are not US institutions, but access to the US financial system was enough.
| Case | Date | Amount | Failure |
|---|---|---|---|
| TD Bank | 10 October 2024 | USD 3.09 billion | 92% of transaction volume (USD 18.3 trillion) unmonitored between 2018 and 2024 |
| Danske Bank | 13 December 2022 | USD 2 billion forfeiture, plus USD 413 million to the SEC | Roughly USD 160 billion routed through its Estonia branch |
| Standard Chartered | 9 April 2019 | About USD 1.1 billion, US and UK combined | Sanctions breaches, including a USD 639 million OFAC settlement |
| Société Générale | 19 November 2018 | USD 420 million to New York DFS, in a USD 1.34 billion resolution | Sanctions violations and New York AML breaches |
| Interactive Brokers | 19 August 2020 | USD 38 million across the SEC, FINRA and CFTC | Repeated SAR filing failures on microcap trading |
The recurring theme is transaction monitoring coverage. TD Bank added no new scenarios between 2014 and 2022, per the Department of Justice resolution.
What is changing in US AML regulation between now and 2028?
US rules are moving towards risk-based tailoring rather than prescriptive checklists. On 7 April 2026 FinCEN issued a proposed rule reforming AML/CFT programme requirements, superseding and withdrawing its July 2024 proposal, with comments closing on 9 June 2026.
Rather than adding risk assessment as a standalone sixth pillar, the 2026 proposal folds both risk assessment and customer due diligence into the internal policies, procedures and controls requirement. Institutions would document ML/TF risks arising from products, services, distribution channels, customers and geographies, and allocate resources accordingly.
One sector expansion is still queued: the investment adviser rule from 1 January 2028. Residential real estate transfer reporting is not, its rule having been vacated in March 2026 and now under appeal. Expect examiners to ask for evidence that resourcing follows the jurisdictional and customer risk assessment, not the other way round. Further analysis sits under jurisdictions and regulation, including our piece on the SEC's role in US financial regulation.



