United States KYC & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in United States.

Direct answer
What does the United States compliance checklist cover?
The United States checklist translates primary KYC, KYB and AML rules into 11 control areas and 44 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- Primary federal AML framework
- Bank Secrecy Act and 31 CFR Chapter X, with sector-specific rules
- Financial intelligence unit
- Financial Crimes Enforcement Network (FinCEN)
- Bank SAR trigger and timing
- $5,000 aggregate threshold; generally 30 days, or 60 days if no suspect is identified
- Currency transaction report
- More than $10,000 in currency aggregated by person and business day; file within 15 days
- Funds-transfer record / travel rule
- $3,000 or more, subject to exclusions and role-specific data requirements
- Covered-institution CDD ownership prong
- Each individual owning 25% or more, plus one control person, subject to exemptions and 2026 relief
- Corporate Transparency Act BOI
- U.S.-created entities and U.S. persons are exempt under the current rule; qualifying foreign registered entities remain in scope
- Core federal AML retention
- Generally 5 years, but the event that starts the clock varies by record
- Money transmission licensing
- FinCEN MSB registration may apply federally; separate state licences or exemptions must be analysed
- OFAC block / reject reporting
- Generally within 10 business days; blocked property also has an annual 30 September report
- Privacy and breach rules
- Sectoral federal rules plus state-by-state privacy, biometric and breach-notification requirements
- FATF public lists
- The United States was not named on the FATF public-list page reviewed 31 July 2026
Implementation detail
United States compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities and licensing perimeterResolve the legal entity, activity, charter, product, customer location and state nexus first. U.S. AML duties differ materially by sector and federal registration does not replace state authorisation.4 items+
BSA obligations in 31 CFR Chapter X are defined by institution type; a bank, broker-dealer, casino and money services business do not share one identical programme or reporting rule set.
- Implementation action
- Build an entity-activity matrix that maps each product and customer flow to the relevant Chapter X part, federal functional regulator and examination manual.
- Evidence to retain
- Signed perimeter memorandum, charter and entity records, activity map, regulator mapping and counsel conclusions.
- Primary citation
- 31 CFR Chapter X; FinCEN, Financial Institutions
A business that meets a money services business definition must register with FinCEN unless an exception applies; initial registration is generally due within 180 days and renewal is every two calendar years.
- Implementation action
- Classify each money transmission, exchange, cheque, prepaid-access and related service; register on time and calendar biennial renewal.
- Evidence to retain
- MSB analysis, Form 107 filing, acknowledgement, agent list, renewal calendar and exemption rationale where used.
- Primary citation
- 31 CFR 1022.380; FinCEN, MSB Registration
FinCEN MSB registration is not a substitute for state money-transmitter or virtual-currency licensing, and requirements vary by state and activity.
- Implementation action
- Complete a state-by-state licensing and exemption analysis before serving residents or taking regulated activity into a state; track licence conditions and change triggers.
- Evidence to retain
- Fifty-state matrix, legal opinions, NMLS records, licences, exemptions, surety bonds and renewal controls.
- Primary citation
- California Financial Code, Money Transmission Act; NYDFS, Virtual Currency Businesses
The federal investment-adviser AML and SAR rule is not effective in 2026; FinCEN postponed its effective date to 1 January 2028.
- Implementation action
- Do not mislabel the postponed rule as a current federal duty. Track the rulemaking and separately implement obligations arising from other status, contracts, sanctions or risk policy.
- Evidence to retain
- Applicability memo, rule-change register, board decision and implementation roadmap for any future effective rule.
- Primary citation
- FinCEN final rule postponing IA AML Rule, 31 Dec. 2025
02AML programme, governance and risk assessmentDesign the programme for the institution category actually in scope and document why its controls are reasonably designed for the business's products, customers, channels and geographies.4 items+
Covered financial institutions must maintain a written, risk-based AML programme containing the elements prescribed for their sector, commonly internal controls, a responsible person, training and independent testing.
- Implementation action
- Map the applicable programme regulation to owned policies and controls; obtain governing-body approval where required and document independence and authority.
- Evidence to retain
- Approved AML programme, responsibility charter, organisation chart, training records, test plan, findings and remediation log.
- Primary citation
- 31 U.S.C. 5318(h); applicable 31 CFR Chapter X sector part
The CDD Rule requires covered institutions to understand the nature and purpose of customer relationships, develop risk profiles, monitor for suspicious activity and update customer information on a risk basis.
- Implementation action
- Define risk factors, scoring logic, expected-activity capture, event-driven refresh triggers and escalation rules; do not rely solely on fixed periodic review dates.
- Evidence to retain
- Risk methodology, customer profile, model governance, alert scenarios, trigger catalogue, review samples and approvals.
- Primary citation
- 31 CFR 1010.210; FinCEN, CDD Final Rule; FFIEC BSA/AML Manual, CDD
An effective programme must address products, services, customers, entities, delivery channels and geographic exposure, including new or materially changed activity.
- Implementation action
- Run a documented enterprise and product risk assessment before launch and after material change; link residual risks to controls and accepted exceptions.
- Evidence to retain
- Enterprise risk assessment, product approval, control inventory, residual-risk decisions and change log.
- Primary citation
- 31 U.S.C. 5318(h); FFIEC BSA/AML Manual, BSA/AML Risk Assessment
Outsourcing a control does not remove the regulated institution's responsibility for compliance and effective oversight.
- Implementation action
- Perform due diligence before appointment, set measurable contractual requirements, control data and model changes, test performance and maintain exit capability.
- Evidence to retain
- Vendor due diligence, contract, service levels, audit rights, monitoring reports, issue register and exit plan.
- Primary citation
- FFIEC BSA/AML Manual, Developing Conclusions and Finalizing the Exam
03Customer identification and identity verificationCustomer Identification Program rules are sector-specific. The bank rule below is a useful control benchmark but must not be copied to an entity governed by a different CIP provision without confirming scope.4 items+
Before opening a bank account, the CIP must obtain at least name, date of birth for an individual, address and an identification number, subject to the rule's detailed alternatives and exceptions.
- Implementation action
- Configure mandatory fields by person and entity type; prevent opening or restrict use when required information is missing under the approved policy.
- Evidence to retain
- CIP policy, field rules, onboarding screenshots, test cases, exception approvals and sampled customer files.
- Primary citation
- 31 CFR 1020.220(a)(2)
A bank CIP must contain risk-based procedures to verify identity to the extent reasonable and practicable within a reasonable time after account opening, using documentary, non-documentary or combined methods.
- Implementation action
- Define acceptable documents, database and device checks, fraud controls, discrepancy handling and a reasonable verification deadline by risk and channel.
- Evidence to retain
- Verification matrix, vendor configuration, decision logs, false-positive testing, discrepancy cases and quality assurance results.
- Primary citation
- 31 CFR 1020.220(a)(2)(ii)
The CIP must explain when the institution will not open an account, restrict it, close it or file a SAR when it cannot form a reasonable belief that it knows the customer's true identity.
- Implementation action
- Implement explicit unresolved-identity states, permitted activity, time limits, escalation ownership, closure and SAR decisioning.
- Evidence to retain
- CIP failure procedure, case workflow, restriction rules, closure samples and SAR decision records.
- Primary citation
- 31 CFR 1020.220(a)(2)(iii)
Bank CIP notice must be provided before account opening in a form reasonably designed to inform the customer that identifying information is being requested.
- Implementation action
- Place approved notice before submission in every assisted and digital channel and retain the deployed version and effective date.
- Evidence to retain
- Notice text, channel screenshots, version history, localisation review and deployment record.
- Primary citation
- 31 CFR 1020.220(a)(5)
04Legal entities and beneficial ownershipKeep customer due diligence under 31 CFR 1010.230 separate from Corporate Transparency Act reporting. They have different covered parties, tests and current exemptions.4 items+
Covered institutions identify and verify each individual owning 25 percent or more of a legal-entity customer and one control person, subject to exclusions and exemptions.
- Implementation action
- Separate ownership and control prongs, test direct and indirect holdings, document exclusions and verify each in-scope person.
- Evidence to retain
- Ownership chart, certification, calculations, identity evidence, control-person rationale and exemption.
- Primary citation
- 31 CFR 1010.230(d)-(e); FinCEN, CDD Final Rule
FinCEN's 2026 relief permits covered institutions to limit collection to the first account, when reliability is questioned and as needed through risk-based ongoing CDD.
- Implementation action
- Use the relief only within its terms, retain the verified record and refresh when facts call its reliability into question.
- Evidence to retain
- Relief analysis, policy, first-account marker, trigger logic, refresh cases and audit trail.
- Primary citation
- FinCEN Ruling FIN-2026-R001; 2026 CDD Rule FAQs
U.S.-created entities and U.S. persons are exempt from CTA BOI reporting; qualifying foreign-formed entities registered in the U.S. remain potentially in scope.
- Implementation action
- Classify formation and registration, document exemptions and keep CTA status separate from financial-institution CDD.
- Evidence to retain
- Formation and registration records, CTA memo, exemption proof and CDD-to-CTA reconciliation.
- Primary citation
- 31 CFR 1010.380 as amended by 2025 interim final rule; FinCEN IFR Q&A
A qualifying foreign company registered on or after 26 March 2025 generally has 30 days from the earlier of actual or public registration notice to file initial BOI; U.S. persons are not reported.
- Implementation action
- Calendar each deadline, collect only reportable BOI, file through FinCEN and monitor final-rule changes.
- Evidence to retain
- Deadline calculation, filing and receipt, supporting records, update monitoring and rule watch.
- Primary citation
- FinCEN, BOI Interim Final Rule Questions and Answers
05Higher-risk customers, PEPs and enhanced due diligenceUse risk-based enhanced diligence. U.S. rules do not impose a single general domestic PEP-screening mandate, but specific foreign private-banking and correspondent-account rules can apply.4 items+
The CDD Rule does not create a unique general requirement to screen for or apply specific procedures to customers solely because they may be politically exposed persons.
- Implementation action
- Treat PEP information as a risk factor within CDD rather than an automatic prohibition; document the risk rationale, source of wealth or funds work and approval proportionate to the case.
- Evidence to retain
- PEP policy, risk factors, screening configuration, enhanced review, approvals and periodic quality testing.
- Primary citation
- Joint Statement on BSA Due Diligence Requirements for Customers Who May Be Considered PEPs, 2020
Covered U.S. financial institutions that maintain qualifying private-banking accounts for non-U.S. persons must perform enhanced scrutiny where a senior foreign political figure is involved.
- Implementation action
- Detect private-banking accounts and beneficial interests in scope; establish source-of-funds, purpose, expected activity and corruption-proceeds controls before and during the relationship.
- Evidence to retain
- Account classification, ownership analysis, source-of-wealth and funds evidence, senior approval, monitoring and reviews.
- Primary citation
- 31 CFR 1010.620
Correspondent accounts for specified foreign financial institutions require due diligence and, for higher-risk categories, enhanced due diligence under the conditions in the rule.
- Implementation action
- Inventory foreign correspondent accounts, classify the foreign institution and jurisdiction, assess ownership and shell-bank exposure, and apply the required enhanced measures.
- Evidence to retain
- Correspondent inventory, foreign-bank questionnaire, ownership and licence checks, risk assessment and monitoring results.
- Primary citation
- 31 CFR 1010.610; 31 CFR 1010.630
Customer information must be updated through risk-based ongoing monitoring when events reveal material changes or call existing information into question.
- Implementation action
- Trigger review for ownership, control, product, geography, sanctions, adverse activity and unexplained behaviour changes; record why the profile remains reliable or was revised.
- Evidence to retain
- Trigger catalogue, event logs, refreshed files, investigator rationale, approvals and overdue-review reporting.
- Primary citation
- FinCEN, CDD Final Rule; 2026 CDD Rule FAQs; FFIEC BSA/AML Manual, CDD
06Monitoring, suspicious activity and information sharingSAR thresholds and obligations depend on institution type. The bank rule below must be replaced with the applicable sector rule for MSBs, broker-dealers, casinos and other covered businesses.4 items+
A bank generally files a SAR for a transaction conducted or attempted by, at or through it involving at least $5,000 in aggregate when it knows, suspects or has reason to suspect one of the regulatory bases.
- Implementation action
- Map scenarios to the exact bank or other sector SAR rule, aggregate related activity, investigate promptly and document both filing and non-filing decisions.
- Evidence to retain
- Scenario inventory, alert and case data, aggregation tests, decision rationale, approvals and filed SAR receipt.
- Primary citation
- 31 CFR 1020.320(a); use applicable sector rule
A bank SAR is generally due within 30 calendar days after initial detection of facts that may constitute a basis for filing, extended to 60 days only when no suspect is identified; urgent ongoing threats require immediate contact with appropriate law enforcement in addition to filing.
- Implementation action
- Start and evidence the regulatory clock at initial detection, distinguish research from impermissible delay, escalate deadline risk, and maintain an emergency contact procedure.
- Evidence to retain
- Clock logic, case timestamps, deadline dashboard, escalation records, law-enforcement contact log and filing confirmation.
- Primary citation
- 31 CFR 1020.320(b)
SARs and information revealing their existence are confidential, with disclosure limited by the applicable regulation.
- Implementation action
- Restrict SAR access, redact customer-facing material, train staff against tipping off, control subpoenas and external requests, and log permitted disclosures.
- Evidence to retain
- Access-control list, training, disclosure procedure, audit logs, legal holds and tested response playbook.
- Primary citation
- 31 CFR 1020.320(e); applicable sector SAR rule
Section 314(a) requests and voluntary 314(b) information sharing operate under defined scope, confidentiality and procedural protections; 314(b) participation requires a current notice to FinCEN.
- Implementation action
- Separate compulsory 314(a) search workflow from voluntary 314(b) sharing, validate counterparties and notices, secure transmissions and document use limitations.
- Evidence to retain
- 314 procedures, current certification or notice, request log, search proof, response record and access controls.
- Primary citation
- 31 CFR 1010.520; 31 CFR 1010.540; FinCEN Section 314 resources
07Currency, funds transfers and cash reportingBuild separate decision paths for financial-institution CTRs, funds-transfer records and non-financial trade-or-business cash reports. They are not interchangeable with SARs.4 items+
A financial institution files a CTR for each deposit, withdrawal, exchange or other payment or transfer involving more than $10,000 in currency, aggregated for the same person during one business day when the institution has the required knowledge.
- Implementation action
- Aggregate across branches, channels and accounts; identify conductors and beneficiaries; apply exemptions only when documented and current.
- Evidence to retain
- Aggregation logic, CTR file and acknowledgement, identity record, exemption status, tests and exception report.
- Primary citation
- 31 CFR 1010.311; 31 CFR 1010.313; FinCEN CTR FAQs
A CTR is generally filed within 15 calendar days after the reportable transaction date.
- Implementation action
- Calculate and monitor the deadline from transaction date, reconcile reportable activity to accepted filings and remediate rejects promptly.
- Evidence to retain
- Filing calendar, transaction-to-filing reconciliation, BSA E-Filing acknowledgement and reject handling.
- Primary citation
- 31 CFR 1010.306(a)(1); FinCEN CTR FAQs
For transmittals of funds of $3,000 or more, covered roles must collect, retain and transmit specified information, subject to exclusions and the precise role-based requirements.
- Implementation action
- Determine whether the business is an originator's, intermediary or beneficiary's institution; configure the required data, preservation and transmission for domestic and cross-border flows.
- Evidence to retain
- Funds-flow map, message-field rules, transfer samples, exception logic, retention proof and quality tests.
- Primary citation
- 31 CFR 1010.410(e)-(f); FinCEN Funds Travel Regulations FAQs
A trade or business that receives more than $10,000 in cash in one or related transactions generally files Form 8300 within 15 days and provides the required annual written statement to each named person by 31 January.
- Implementation action
- Detect cash and related transactions outside financial-institution CTR scope, file electronically when required, provide statements and retain records for five years.
- Evidence to retain
- Form 8300 assessment, filing and receipt, aggregation workpaper, customer statement and retention log.
- Primary citation
- 26 U.S.C. 6050I; 31 U.S.C. 5331; IRS, Form 8300 guidance
08Sanctions and prohibited activityOFAC sanctions are separate from the BSA and can apply without a monetary threshold. Screening alone is insufficient without ownership, blocking, reporting and programme controls.4 items+
U.S. persons must comply with applicable OFAC sanctions, including U.S.-organised entities and their foreign branches; some programmes also extend to foreign subsidiaries or non-U.S. persons in specified circumstances.
- Implementation action
- Map persons, entities, branches, products, currencies, locations and counterparties to each applicable sanctions programme and licence.
- Evidence to retain
- Sanctions applicability map, programme inventory, licences, legal interpretations and geographic controls.
- Primary citation
- OFAC FAQ 11; applicable sanctions programme regulations
Property owned 50 percent or more in the aggregate, directly or indirectly, by one or more blocked persons is itself blocked even when the entity is not named on OFAC's list.
- Implementation action
- Collect and calculate relevant ownership chains, aggregate blocked interests, assess control-related risk and escalate uncertainty before releasing property.
- Evidence to retain
- Ownership chart, calculations, screening result, legal escalation, disposition decision and audit trail.
- Primary citation
- OFAC, Revised Guidance on Entities Owned by Persons Whose Property and Interests in Property Are Blocked
Initial reports of blocked or rejected transactions are generally due to OFAC within 10 business days; holders of blocked property file an annual report by 30 September.
- Implementation action
- Freeze or reject as the programme requires, preserve funds, notify OFAC through the current channel, reconcile blocked property and calendar annual reporting.
- Evidence to retain
- Block or reject decision, account restriction, report and acknowledgement, blocked-property ledger and annual filing.
- Primary citation
- 31 CFR 501.603-604; OFAC Reporting FAQ
OFAC expects a risk-based sanctions compliance programme; its framework describes management commitment, risk assessment, internal controls, testing or auditing and training as essential components.
- Implementation action
- Implement the five components, tune screening for names, ownership, geography, IP and transaction context, and independently test end-to-end effectiveness.
- Evidence to retain
- Sanctions programme, risk assessment, screening configuration, alert decisions, test report, training and remediation.
- Primary citation
- OFAC, A Framework for OFAC Compliance Commitments
09Records, audit trail and regulator accessRetention periods often last five years, but different records use different start events. Preserve provenance and retrieval as well as the document itself.4 items+
Bank CIP identifying information is retained for five years after the account is closed or becomes dormant; descriptions of verification documents, methods, results and discrepancy resolution are retained for five years after the record is made.
- Implementation action
- Configure separate retention clocks for identifying data and verification records and test closure, dormancy and record-creation events.
- Evidence to retain
- Retention schedule, data map, clock logic, deletion holds, retrieval test and sampled records.
- Primary citation
- 31 CFR 1020.220(a)(3)
A bank retains each SAR and supporting documentation for five years from filing and provides supporting documentation to FinCEN or appropriate law enforcement on request.
- Implementation action
- Bind supporting evidence to the filing, preserve confidentiality, control authorised requests and prove complete retrieval within the response procedure.
- Evidence to retain
- SAR archive, supporting-document index, request log, access audit and retrieval test.
- Primary citation
- 31 CFR 1020.320(d)
Unless a more specific rule provides otherwise, records required under 31 CFR Chapter X are generally retained for five years and kept accessible as specified by the rule.
- Implementation action
- Map every BSA record to its governing provision, trigger event, format, location, owner, legal hold and destruction approval.
- Evidence to retain
- Regulatory retention schedule, data inventory, immutable logs, legal-hold procedure and destruction certificates.
- Primary citation
- 31 CFR 1010.430
MSBs must maintain the registration form and specified supporting and agent-list records for five years and make them available as required.
- Implementation action
- Keep the registration package, owner or controlling-person records and agent list current, retrievable and linked to renewal and material changes.
- Evidence to retain
- Registration archive, agent list, update log, renewal file and retrieval test.
- Primary citation
- 31 CFR 1022.380; FinCEN, MSB Registration
10Privacy, biometrics, security and breach responseThere is no single general U.S. privacy rule or regulator for every business. Determine sector, state, data type, residency and threshold before selecting notices, rights, security and breach deadlines.4 items+
FTC-jurisdiction financial institutions maintain a written security programme; specified events involving at least 500 consumers' unencrypted information require FTC notice no later than 30 days after discovery.
- Implementation action
- Confirm scope, appoint a qualified individual, assess risk, implement the prescribed safeguards, oversee providers and apply the 500-consumer notice test.
- Evidence to retain
- Scope memo, security programme, qualified-individual report, risk assessment, tests, vendor oversight and notice decision.
- Primary citation
- 16 CFR Part 314; FTC, Safeguards Rule guidance
Covered SEC institutions maintain incident-response policies and generally notify affected individuals as soon as practicable, no later than 30 days after awareness of unauthorised access or use, subject to the rule's investigation-based exception.
- Implementation action
- Confirm scope, assess customer-information incidents, document any exception and oversee service-provider notice duties.
- Evidence to retain
- Scope memo, response programme, investigation, notice, exception rationale and vendor contract.
- Primary citation
- SEC Regulation S-P amendments, Release No. 34-100155 (2024)
A banking organisation notifies its primary federal regulator no later than 36 hours after determining that a qualifying computer-security incident occurred.
- Implementation action
- Define the incident test and decision authority, maintain regulator contacts and preserve each determination and notice timestamp.
- Evidence to retain
- Incident taxonomy, decision log, regulator notice, acknowledgement, contacts and exercise results.
- Primary citation
- 12 CFR 53.3, 225.302 and 304.23; federal banking-agency notification rule
State privacy, biometric and breach laws apply independently; examples include California's CCPA and breach rules and Illinois BIPA's biometric-data controls.
- Implementation action
- Map state scope by person, data and threshold; implement the required notices, consent, rights, retention, security and breach workflows.
- Evidence to retain
- State matrix, notices, biometric consent, retention schedule, rights log, breach analysis and filings.
- Primary citation
- California Consumer Privacy Act and regulations; California Civ. Code 1798.82; Illinois 740 ILCS 14
11Product overlays and regulatory change controlApply product-specific overlays without importing vacated, postponed or proposed requirements into the current-law checklist.4 items+
A person engaged as a business in accepting and transmitting convertible virtual currency, or buying or selling it, may be a FinCEN money transmitter unless an exemption applies; a person using it solely to purchase goods or services is not an MSB on that basis.
- Implementation action
- Document each custody, exchange, transmission, hosted-wallet, kiosk and payment flow against FinCEN's function-based CVC analysis and state virtual-currency rules.
- Evidence to retain
- CVC flow diagrams, legal classification, MSB registration, state licences, exemptions and transaction-monitoring design.
- Primary citation
- FinCEN FIN-2013-G001; FinCEN CVC Business Models Guidance, 2019
Virtual-currency transactions are subject to the same OFAC compliance obligations as transactions involving traditional currency.
- Implementation action
- Screen wallet and counterparty data, blockchain exposure, geolocation and ownership; apply blocking or rejection and reporting according to the relevant programme.
- Evidence to retain
- Blockchain-risk policy, analytics configuration, address and party screening, case files, block or reject reports and testing.
- Primary citation
- OFAC FAQ 560; OFAC Sanctions Compliance Guidance for the Virtual Currency Industry
The federal Residential Real Estate Rule currently has no legal effect while the March 2026 vacatur order remains in force; reporting persons are not presently required to file Real Estate Reports and FinCEN's appeal is pending.
- Implementation action
- Do not present Real Estate Reports as currently mandatory. Monitor the appeal and FinCEN guidance, preserve launch readiness and apply other existing BSA, sanctions or state duties that independently cover the activity.
- Evidence to retain
- Court-status watch, FinCEN update log, applicability memo, dormant control plan and reactivation checklist.
- Primary citation
- FinCEN Residential Real Estate FAQs, issued 18 May 2026
Material legal, court, product, channel, vendor, model and geographic changes require reassessment before the affected control or customer flow is released.
- Implementation action
- Operate a dated regulatory inventory and change process with accountable owners, source snapshots, impact assessment, implementation testing and approval.
- Evidence to retain
- Regulatory inventory, change tickets, source archive, impact assessment, test results, approvals and next-review date.
- Primary citation
- 31 U.S.C. 5318(h); risk-based programme and supervisory expectations
Primary-source register
39 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Bank Secrecy ActU.S. Government Publishing Office · Official statutory compilation
- 31 CFR Chapter X - Financial Crimes Enforcement NetworkElectronic Code of Federal Regulations · Primary regulation
- Customer Identification Program for banksElectronic Code of Federal Regulations · Primary regulation
- Customer Due Diligence requirements for legal entity customersElectronic Code of Federal Regulations · Primary regulation
- CDD Final Rule overview and 2026 exceptive reliefFinancial Crimes Enforcement Network · Official regulator guidance
- CDD Rule consolidated FAQs updated May 2026Financial Crimes Enforcement Network · Official regulator guidance
- Suspicious Activity Reports by banksElectronic Code of Federal Regulations · Primary regulation
- Records relating to funds transfers and transmittalsElectronic Code of Federal Regulations · Primary regulation
- General BSA record retention ruleElectronic Code of Federal Regulations · Primary regulation
- Due diligence for foreign correspondent accountsElectronic Code of Federal Regulations · Primary regulation
- Due diligence for private-banking accountsElectronic Code of Federal Regulations · Primary regulation
- Section 314(a) information requestsElectronic Code of Federal Regulations · Primary regulation
- Section 314(b) voluntary information sharingElectronic Code of Federal Regulations · Primary regulation
- Currency Transaction Report FAQsFinancial Crimes Enforcement Network · Official regulator guidance
- Funds Travel Regulations FAQsFinancial Crimes Enforcement Network · Official regulator guidance
- Money Services Business registrationFinancial Crimes Enforcement Network · Official regulator guidance
- Convertible virtual currency guidance FIN-2013-G001Financial Crimes Enforcement Network · Official regulator guidance
- Convertible virtual currency business models guidanceFinancial Crimes Enforcement Network · Official regulator guidance
- BOI interim final rule questions and answersFinancial Crimes Enforcement Network · Official regulator guidance
- Investment Adviser AML Rule effective date postponed to 2028Financial Crimes Enforcement Network · Official regulator publication
- Residential Real Estate Rule current status FAQsFinancial Crimes Enforcement Network · Official regulator guidance
- Joint PEP due-diligence statementFederal banking agencies, FinCEN and State Bank Regulators · Official interagency statement
- FFIEC BSA/AML Manual - Customer Due DiligenceFederal Financial Institutions Examination Council · Official examination guidance
- Form 8300 cash-reporting guidanceInternal Revenue Service · Official regulator guidance
- OFAC compliance frameworkOffice of Foreign Assets Control · Official regulator framework
- OFAC 50 Percent Rule guidanceOffice of Foreign Assets Control · Official regulator guidance
- OFAC FAQ 11 - persons required to complyOffice of Foreign Assets Control · Official regulator guidance
- OFAC reporting requirements FAQsOffice of Foreign Assets Control · Official regulator guidance
- OFAC virtual-currency FAQ 560Office of Foreign Assets Control · Official regulator guidance
- FTC Safeguards Rule guidanceFederal Trade Commission · Official regulator guidance
- SEC Regulation S-P amendmentsU.S. Securities and Exchange Commission · Official regulator publication
- Computer-security incident notification ruleFederal Deposit Insurance Corporation · Official interagency rule guidance
- California Consumer Privacy Act regulationsCalifornia Privacy Protection Agency · Primary and official state material
- California data-breach reporting guidanceCalifornia Department of Justice · Official state guidance
- Illinois Biometric Information Privacy ActSupreme Court of Illinois · Official judicial explanation of state legislation
- California money-transmitter laws and regulationsCalifornia Department of Financial Protection and Innovation · Official state material
- New York virtual-currency business licensingNew York State Department of Financial Services · Official state guidance
- FATF United States country pageFinancial Action Task Force · Official international assessment
- FATF black and grey listsFinancial Action Task Force · Official current-status source
Direct answers
United States KYC, KYB and AML questions
Is there one AML checklist for every U.S. business?+
No. BSA programme, customer-identification and SAR rules vary by institution type, while licensing, privacy and some financial-services requirements vary by state. Start with an entity, activity, product and state-nexus analysis.
What is the bank SAR deadline?+
A bank generally files within 30 calendar days after initial detection of facts that may require a SAR, extended to 60 days only when no suspect is identified. Other institution types must use their own sector rule.
What is the U.S. currency-reporting threshold?+
A financial institution generally files a CTR for more than $10,000 in currency aggregated for the same person during one business day, normally within 15 days.
Does the CDD Rule still require beneficial ownership at every account opening?+
Not if the institution elects to use FinCEN's February 2026 relief. It may limit collection and verification to the first account, when prior information's reliability is questioned and as needed through risk-based ongoing CDD.
Must a U.S.-created company file BOI with FinCEN?+
Not under the current rule. U.S.-created entities and U.S. persons are exempt; qualifying foreign-formed entities registered to do business in a U.S. jurisdiction remain potentially in scope. This does not remove a financial institution's separate CDD duties.
Does FinCEN MSB registration authorise nationwide money transmission?+
No. Federal MSB registration and state licensing are separate. Each activity and state nexus needs a licensing or exemption analysis.
Are investment advisers subject to the new FinCEN AML rule in 2026?+
No. FinCEN postponed the rule's effective date to 1 January 2028. Other laws or statuses can still create separate obligations.
Are Real Estate Reports currently required?+
No. FinCEN states that the Residential Real Estate Rule has no legal effect while the March 2026 court order vacating it remains in force; the appeal is pending.
Is there one nationwide privacy and breach deadline?+
No. U.S. privacy and breach obligations are sectoral and state-specific. The applicable regulator, consumer state, data type and threshold must be mapped for each event.
Is the United States on a FATF public list?+
The United States was not named on FATF's current public-list page reviewed on 31 July 2026. It remains a FATF member with a published mutual evaluation and follow-up history.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
This checklist is general regulatory information, not legal advice, a licence determination or a statement that every row applies to every U.S. business. It reflects primary and authoritative material reviewed on 31 July 2026. Confirm entity type, activity, customer, product, charter, federal functional regulator, state nexus, tribal or territorial issues, licensing exemptions, live BSA E-Filing instructions, sanctions programmes, privacy scope and later legal or court developments with qualified U.S. counsel and the competent authorities before launch.