Five pillars of a BSA AML compliance program for crypto and MSB businesses — Hodder Law

The Five Pillars of an AML Compliance Program

Five pillars of a BSA AML compliance program for crypto and MSB businesses — Hodder Law

If your business is registered with FinCEN as a Money Services Business, or if you operate a cryptocurrency exchange, Bitcoin ATM, payment processor, or wallet service, you are legally required to maintain a written Anti-Money Laundering compliance program under the Bank Secrecy Act. These are the five pillars of an AML compliance program.

That program must be built around five specific pillars. They are mandatory components, and the absence of any one of them is a program deficiency that can be cited during a Title 31 examination and result in civil money penalties.

This post breaks down each pillar, what it actually requires in practice, and where crypto businesses most commonly fall short.

What Is a BSA AML Compliance Program?

The Bank Secrecy Act (BSA), enforced by the Financial Crimes Enforcement Network (FinCEN), requires MSBs to establish, implement, and maintain an effective written AML compliance program. The statutory basis is found at 31 U.S.C. §5318(h), with MSB-specific requirements codified at 31 CFR §1022.210.

The program must be reasonably designed to prevent the business from being used to facilitate money laundering and the financing of terrorism. “Reasonably designed” is the operative phrase; your program must be risk-based, meaning it should reflect the actual money-laundering risks posed by your specific business model, products, customer base, and geographies.

A generic, off-the-shelf AML policy is not sufficient. FinCEN examiners and IRS agents conducting Title 31 audits assess whether your program is tailored to your business, not whether you have a document that checks a box. 

There are five pillars of an AML compliance program that need to be considered:

Five required pillars of a Bank Secrecy Act AML compliance program for money services businesses

Pillar One: Written Policies, Procedures, and Internal Controls

Your AML program must be documented in writing. Verbal commitments, informal understandings, and ad hoc practices don’t satisfy the BSA, and they certainly don’t hold up during an examination.

Your written policies and procedures must address how your business will:

  • Identify and verify customers (CIP/KYC)
  • Monitor transactions for suspicious activity
  • Detect and report red flags
  • File Suspicious Activity Reports (SARs) and Currency Transaction Reports (CTRs) where required
  • Screen customers and transactions against OFAC’s sanctions lists
  • Maintain required records for the BSA’s five-year retention period

For crypto businesses specifically, your written controls need to reflect the realities of your products. If you operate a Bitcoin ATM network, your policies should address cash transaction thresholds, structuring red flags, and geographic risk. If you run an exchange, they should cover blockchain analytics, Travel Rule compliance for transfers over $3,000, and your treatment of high-risk wallet addresses.

Where businesses fall short: Policies copied from a template without customization to the actual business. Procedures that describe what should happen without documenting who is responsible for each step and how it gets done. No version control, so there’s no evidence that the program has been updated as regulations have evolved.

Pillar Two: A Designated Compliance Officer

Every BSA-compliant AML program must designate a specific individual as the compliance officer responsible for the day-to-day management of the program. This is not a title you assign to whoever has capacity; it is a role with specific responsibilities and, critically, specific authority.

Your designated compliance officer is responsible for:

  • Ensuring the AML program is implemented and followed
  • Overseeing transaction monitoring and SAR filing decisions
  • Keeping the program updated as regulations change
  • Coordinating employee training
  • Serving as the primary point of contact for regulators during an examination

The compliance officer does not need to be an attorney or a credentialed compliance professional. But they must have genuine operational authority, the ability to escalate concerns, halt transactions, and make filing decisions without interference. A compliance officer who exists on paper but has no real power over compliance decisions is a liability, not an asset.

Where businesses fall short: Assigning the role to a founder or executive who lacks the bandwidth to manage it. Designating someone without giving them access to the systems, data, or decision-making authority they need. No documented evidence of the compliance officer’s activities, meeting notes, review logs, or training records that would demonstrate the role is functioning.

Pillar Three: Ongoing Employee Training

Every employee whose job function touches AML-relevant activities must receive regular, documented AML training. This includes customer-facing staff, operations personnel, and anyone involved in transaction processing, onboarding, or compliance review.

Training must cover:

  • The basics of money laundering and why it matters
  • Red flags specific to your business and customer base
  • Your internal procedures for escalating suspicious activity
  • SAR filing obligations and the prohibition on tipping off subjects
  • Any regulatory developments relevant to your operations

Training must be documented. That means training logs showing who completed what, when, and, ideally, with what result. A verbal briefing during a team meeting, with no record of who attended, is not sufficient evidence of a functioning training program.

For crypto businesses, training should be calibrated to the specific red flags that appear in digital asset transactions: structuring across multiple wallets, use of mixers or privacy coins, rapid conversion patterns, and transactions involving high-risk jurisdictions or sanctioned addresses.

Where businesses fall short: Annual training that is never updated to reflect regulatory changes or new enforcement trends. No documentation beyond “we trained our team.” Training that covers generic AML concepts without addressing the specific risks of the business’s actual products and customers.

Pillar Four: Independent Testing (The AML Audit)

This is the pillar that crypto businesses most frequently overlook, and the one IRS examiners are most likely to cite as deficient.

Your AML program must be tested periodically by an independent party: someone who is not involved in the day-to-day operation of your compliance program. The purpose is to verify that your controls are actually working as designed, not just that your policies say they should. This is known as an independent AML review.

Independent testing must:

  • Be conducted by a qualified person with no operational role in your AML program
  • Evaluate all five pillars of the program, not just policies on paper
  • Be documented with a written report identifying findings and deficiencies
  • Occur with sufficient frequency given your risk profile (annually is the industry standard)

The independent tester can be an outside attorney, a qualified compliance consultant, or, in limited circumstances for smaller businesses, a qualified internal auditor who is genuinely independent of the compliance function. At Hodder Law, we conduct independent AML audits for crypto businesses and MSBs, producing written reports and remediation roadmaps that satisfy FinCEN and IRS examiner requirements.

Where businesses fall short: Never conducting independent testing at all. Relying on the compliance officer to “review” their own program and calling it independent. Conducting a review but producing no written documentation of findings. Going years between audits without a documented justification for the extended interval.

Pillar Five: Customer Due Diligence (CDD) and Know Your Customer (KYC)

Know Your Customer procedures are the operational front line of your AML program. Before you onboard a customer, and on an ongoing basis throughout the relationship, you must understand who they are, what they do, and whether their activity is consistent with what you know about them.

A complete CDD framework includes:

  • Customer Identification Program (CIP): Collecting and verifying the information required to identify each customer — name, date of birth, address, and an identification number. For legal entities, this extends to beneficial ownership: identifying the individuals who own or control the entity.
  • Customer Due Diligence (CDD): Understanding the nature and purpose of the customer relationship well enough to establish a baseline for what “normal” activity looks like for that customer.
  • Enhanced Due Diligence (EDD): Applying heightened scrutiny to higher-risk customers. Politically exposed persons (PEPs), customers transacting in high-risk jurisdictions, cash-intensive businesses, or customers using privacy-enhancing technologies.
  • Ongoing monitoring: Keeping customer information up to date and flagging any activity that deviates from the established baseline.

For crypto businesses, CDD presents distinct challenges. Pseudonymous wallets, cross-border transactions, DeFi interactions, and the speed of blockchain settlement all create pressure on traditional CDD frameworks. Your KYC procedures need to account for these realities, not just satisfy a checklist designed for traditional financial institutions.

Where businesses fall short: CIP procedures that collect information without verifying it. No beneficial ownership collection for business accounts. EDD that exists in policy but isn’t actually triggered for high-risk customers in practice. No process for updating customer profiles when their risk level changes.


How the Five Pillars Work Together

Each pillar from the five pillars of the AML compliance program reinforces the others. Written policies are only useful if employees are trained to follow them. Training only works if there’s a compliance officer making sure it happens. The compliance officer’s work only stays on track if independent testing identifies drift before it becomes a deficiency. And all of it depends on CDD actually surfacing the customer risk information your monitoring system needs to do its job.

Examiners don’t evaluate pillars in isolation. They look at whether your program functions as a coherent system and whether there’s documented evidence of that.

What Happens If a Pillar Is Missing?

A BSA examination finding that your AML program lacks one of the five pillars of an AML compliance program is not a warning. It is a program deficiency with real consequences:

  • Civil money penalties under 31 U.S.C. §5321, which can reach $100,000 per violation per day for willful violations
  • Cease-and-desist orders requiring immediate remediation under regulatory supervision
  • Enhanced scrutiny in future examinations
  • Reputational damage with banking partners, payment processors, and institutional counterparties who conduct their own due diligence on your compliance program

The IRS has actively examined and penalized crypto businesses operating as MSBs. The enforcement environment is not theoretical.

Building a Program That Actually Works

Attorney reviewing AML compliance program documentation — Hodder Law crypto compliance services

The five pillars of an AML compliance program is not a document you create once and file. It is a functioning compliance system that must be maintained, tested, and updated as your business grows and regulations evolve.

At Hodder Law, we help crypto businesses and MSBs build AML compliance programs from the ground up, conduct independent AML audits that satisfy FinCEN and IRS examiner requirements, and represent clients during Title 31 examinations when deficiencies are found.

If you’re not sure whether your current program covers all five pillars or would hold up to scrutiny, contact Hodder Law now for a consultation.


This post is intended for informational purposes only and does not constitute legal advice. For advice specific to your business, contact a qualified AML attorney.


References & Legal Authority

Federal Statutes

  • Bank Secrecy Act — 31 U.S.C. §5311 et seq.
  • AML Program Requirement — 31 U.S.C. §5318(h)
  • Civil Money Penalties — 31 U.S.C. §5321

Code of Federal Regulations

  • MSB AML Program Requirements — 31 CFR §1022.210
  • FinCEN Customer Due Diligence Rule — 31 CFR §1010.230
  • MSB Definition — 31 CFR §1010.100(ff)
  • Beneficial Ownership Requirements — 31 CFR §1010.230

FinCEN Guidance & Resources

  • FinCEN, Guidance on Existing AML Program Rule Applicability to Money Services Businesses (April 2008)
  • FinCEN, Application of FinCEN’s Regulations to Persons Administering, Exchanging, or Using Virtual Currencies (FIN-2013-G001, March 2013)
  • FinCEN, SAR Activity Review — Trends, Tips & Issues (ongoing publication series)
  • FinCEN Form 107 — Registration of Money Services Business

IRS / Title 31

  • IRS, Bank Secrecy Act Examination Procedures for Money Services Businesses (IRS Publication 3416)
  • IRS Small Business/Self-Employed Division — Title 31 Examination Program

OFAC

  • U.S. Department of the Treasury, Office of Foreign Assets Control — Specially Designated Nationals (SDN) List
  • OFAC, A Framework for OFAC Compliance Commitments (May 2019)

Travel Rule

  • FinCEN, Funds Travel Regulations — 31 CFR §1010.410(f)

Similar Posts