BSA/AML Risk Assessment
Produces examination-ready BSA Risk Assessments evaluating inherent AML/CFT risks against mitigating controls per FFIEC BSA/AML Examination Manual methodology.
Prerequisites
Gather before drafting:
- Institution profile — entity type, charter/regulator, total assets, branch footprint, international relationships
- Products & services — inventory with volumes for high-risk products (wires, monetary instruments, prepaid, trade finance, crypto on/off ramps)
- Customer data — segments with counts of high-risk categories (cash-intensive businesses, PEPs, NRAs, MSBs, foreign correspondents)
- BSA/AML program docs — policies, CIP/CDD/EDD procedures, monitoring system specs, training records
- Filing history — annual CTR/SAR counts by category
- Independent testing — most recent scope, findings, remediation status
- Regulatory history — outstanding MRAs, MOUs, enforcement actions
Document Sections
1. Executive Summary
Overall risk rating (Low/Moderate/High), key concentrations, control gaps, priority recommendations with owners and target dates.
2. Introduction
- Regulatory basis: 31 U.S.C. § 5318(h); 31 C.F.R. § 1020.210
- Scope: all business lines, products, customers, geographies
- Assessment period and update frequency (typically annual)
- FFIEC risk-based methodology alignment
3. Institution Overview
Table covering: entity type, charter/regulator, total assets, branch count, high-risk products offered, customer segments, annual CTR/SAR filing counts.
4. Inherent Risk Identification
Five risk dimensions, each rated High/Moderate/Low:
- Customer — cash-intensive businesses, MSBs, NBFIs, PEPs, NRAs, nonprofits, foreign correspondents, FATF-listed jurisdiction customers
- Product & Service — flag products enabling anonymity, rapid movement, or cross-border activity (wires, prepaid, private banking, trade finance, digital channels, crypto)
- Geographic — HIDTA/HIFCA areas, FATF grey/black list jurisdictions, FinCEN GTO zones, OFAC sanctioned countries
- Transaction — high-volume cash, structuring patterns, funnel accounts, rapid cycling, shell companies, trade-based ML
- Third-Party — independent agents, outsourced onboarding/processing, fintech partnerships
5. Risk Assessment Matrix
Per risk category:
| Risk |
Inherent |
Likelihood |
Impact |
Mitigating Controls |
Residual |
| [Category] |
H/M/L |
H/M/L |
H/M/L |
[Description] |
H/M/L |
Reference FATF typology reports and FinCEN advisories for current typologies (ransomware, elder exploitation, human trafficking, real estate, virtual assets).
6. Controls & Mitigation
Evaluate each BSA program component against its regulatory basis:
| Component |
Citation |
| CIP |
31 C.F.R. § 1020.220 |
| CDD / Beneficial Ownership |
31 C.F.R. § 1010.230 |
| EDD |
FFIEC Manual |
| Transaction Monitoring |
FFIEC Manual |
| OFAC Screening |
31 C.F.R. Part 501 |
| CTR Filing |
31 U.S.C. § 5313 |
| SAR Filing |
31 U.S.C. § 5318(g) |
| BSA Officer / Governance |
31 C.F.R. § 1020.210 |
| Training |
31 C.F.R. § 1020.210 |
| Independent Testing |
31 C.F.R. § 1020.210 |
For each: document current status and adequacy rating.
7. Conclusions & Recommendations
- Overall risk determination with narrative justification
- Residual risks where controls are insufficient
- Prioritized remediation table (recommendation, priority, owner, target date)
Verification Requirements
These items change over time — confirm before finalizing:
Pitfalls
- Quantitative support required — risk ratings must cite transaction volumes, SAR counts, or alert rates; qualitative assertions alone are insufficient
- Board presentation — document must be board-approved or presented to senior management with evidence of review
- Version retention — keep prior assessments; regulators compare year-over-year
- Privilege risk — do not include attorney-client privileged material if document will be produced to examiners
- FFIEC citations — reference specific Examination Manual sections when evaluating control adequacy
1---2name: bsa-risk-assessment3description: Drafts a BSA/AML Risk Assessment for U.S. financial institutions per FinCEN, FFIEC, and OCC standards. Evaluates inherent risks (customer, product, geographic, transaction, third-party), control adequacy, and residual risk. Use when preparing annual BSA compliance assessments, post-acquisition integration reviews, or when business changes trigger reassessment under 31 U.S.C. § 5318(h).4---56# BSA/AML Risk Assessment78Produces examination-ready BSA Risk Assessments evaluating inherent AML/CFT risks against mitigating controls per FFIEC BSA/AML Examination Manual methodology.910## Prerequisites1112Gather before drafting:13141. **Institution profile** — entity type, charter/regulator, total assets, branch footprint, international relationships152. **Products & services** — inventory with volumes for high-risk products (wires, monetary instruments, prepaid, trade finance, crypto on/off ramps)163. **Customer data** — segments with counts of high-risk categories (cash-intensive businesses, PEPs, NRAs, MSBs, foreign correspondents)174. **BSA/AML program docs** — policies, CIP/CDD/EDD procedures, monitoring system specs, training records185. **Filing history** — annual CTR/SAR counts by category196. **Independent testing** — most recent scope, findings, remediation status207. **Regulatory history** — outstanding MRAs, MOUs, enforcement actions2122## Document Sections2324### 1. Executive Summary2526Overall risk rating (Low/Moderate/High), key concentrations, control gaps, priority recommendations with owners and target dates.2728### 2. Introduction2930- Regulatory basis: 31 U.S.C. § 5318(h); 31 C.F.R. § 1020.21031- Scope: all business lines, products, customers, geographies32- Assessment period and update frequency (typically annual)33- FFIEC risk-based methodology alignment3435### 3. Institution Overview3637Table covering: entity type, charter/regulator, total assets, branch count, high-risk products offered, customer segments, annual CTR/SAR filing counts.3839### 4. Inherent Risk Identification4041Five risk dimensions, each rated High/Moderate/Low:4243- **Customer** — cash-intensive businesses, MSBs, NBFIs, PEPs, NRAs, nonprofits, foreign correspondents, FATF-listed jurisdiction customers44- **Product & Service** — flag products enabling anonymity, rapid movement, or cross-border activity (wires, prepaid, private banking, trade finance, digital channels, crypto)45- **Geographic** — HIDTA/HIFCA areas, FATF grey/black list jurisdictions, FinCEN GTO zones, OFAC sanctioned countries46- **Transaction** — high-volume cash, structuring patterns, funnel accounts, rapid cycling, shell companies, trade-based ML47- **Third-Party** — independent agents, outsourced onboarding/processing, fintech partnerships4849### 5. Risk Assessment Matrix5051Per risk category:5253| Risk | Inherent | Likelihood | Impact | Mitigating Controls | Residual |54|---|---|---|---|---|---|55| [Category] | H/M/L | H/M/L | H/M/L | [Description] | H/M/L |5657Reference FATF typology reports and FinCEN advisories for current typologies (ransomware, elder exploitation, human trafficking, real estate, virtual assets).5859### 6. Controls & Mitigation6061Evaluate each BSA program component against its regulatory basis:6263| Component | Citation |64|---|---|65| CIP | 31 C.F.R. § 1020.220 |66| CDD / Beneficial Ownership | 31 C.F.R. § 1010.230 |67| EDD | FFIEC Manual |68| Transaction Monitoring | FFIEC Manual |69| OFAC Screening | 31 C.F.R. Part 501 |70| CTR Filing | 31 U.S.C. § 5313 |71| SAR Filing | 31 U.S.C. § 5318(g) |72| BSA Officer / Governance | 31 C.F.R. § 1020.210 |73| Training | 31 C.F.R. § 1020.210 |74| Independent Testing | 31 C.F.R. § 1020.210 |7576For each: document current status and adequacy rating.7778### 7. Conclusions & Recommendations7980- Overall risk determination with narrative justification81- Residual risks where controls are insufficient82- Prioritized remediation table (recommendation, priority, owner, target date)8384## Verification Requirements8586These items change over time — confirm before finalizing:8788- [ ] FATF grey/black list countries — verify at fatf-gafi.org89- [ ] Active FinCEN GTOs — jurisdiction-specific and time-limited90- [ ] Beneficial ownership threshold (currently 25%) — check for subsequent FinCEN rulemaking91- [ ] FinCEN advisory numbers — verify FIN numbers and dates before citing9293## Pitfalls9495- **Quantitative support required** — risk ratings must cite transaction volumes, SAR counts, or alert rates; qualitative assertions alone are insufficient96- **Board presentation** — document must be board-approved or presented to senior management with evidence of review97- **Version retention** — keep prior assessments; regulators compare year-over-year98- **Privilege risk** — do not include attorney-client privileged material if document will be produced to examiners99- **FFIEC citations** — reference specific Examination Manual sections when evaluating control adequacy