The Bank Secrecy Act (BSA) is the US law, passed in 1970, that first required financial institutions to keep records and file reports capable of identifying unlawful use of the financial system. It's the foundation the entire modern US AML/KYC framework was built on top of, and its reporting thresholds still shape day-to-day compliance work more than 50 years later.
What does the BSA actually require?
At its core, the BSA requires financial institutions to track three things about currency moving through the system: its volume, its source, and its movement. In practice, that means banks must file a Currency Transaction Report (CTR) for cash transactions exceeding $10,000, and any business receiving $10,000 or more in a single transaction (or related transactions) must file Form 8300 with the IRS and FinCEN. Reports are filed electronically through the BSA e-Filing system. This $10,000 threshold is also the reference point that makes structuring — deliberately breaking up transactions to stay under it — a federal crime in its own right.
How did the BSA evolve into today's AML law?
The BSA didn't originally make money laundering itself a crime — that came 16 years later, with the Money Laundering Control Act of 1986, which built directly on the BSA's recordkeeping and reporting foundation and made laundering a distinct federal offence. Since then, Know Your Customer (KYC) obligations, suspicious activity reporting, and beneficial ownership verification have all been added as amendments and rules layered on top of the original 1970 statute, rather than replacing it — which is why US AML practitioners still refer to the whole body of law informally as "BSA/AML."
What does a BSA/AML compliance programme need to include?
US regulators expect a documented programme built around what are commonly called the BSA's pillars: a designated compliance officer, written internal policies and controls, an ongoing employee training programme, independent testing or audit of the programme's effectiveness, and — since a 2018 FinCEN rule — customer due diligence procedures that identify and verify beneficial owners of legal entity customers. A Suspicious Activity Report (SAR) generally must be filed within 30 days of detecting activity that meets the reporting criteria, and SARs themselves are confidential — a financial institution cannot disclose to the customer that one has been filed.
Why does a 1970s US law still matter for AML programmes everywhere?
Because so much of the vocabulary and structure the rest of the world's AML frameworks now use — CTRs, SARs, a risk-based approach, designated compliance officers — trace back to the BSA and the US regulatory apparatus (FinCEN, OFAC, the OCC) that enforces it. A business operating internationally that deals with US correspondent banks or US dollar-denominated transactions will find BSA-derived expectations showing up indirectly even outside US borders, which is part of why PEP and sanctions screening built around US list sources like OFAC's SDN list has become close to a de facto global baseline.



