Key takeaways
- 31 CFR Β§ 1022.210(d)(4) requires U.S. MSBs to provide for independent AML program review, with scope and frequency commensurate with the risk of the financial services provided.
- An outside CPA or audit firm is not universally required; the reviewer cannot be the designated compliance officer, and FinCEN guidance says the reviewer should not report directly to that officer.
- A defensible review should test how controls operate in practice, including applicable SAR/CTR reporting, recordkeeping, transaction monitoring, agent oversight, training, systems, and remediation.
- FinCEN does not prescribe one universal annual review schedule or transaction sample size; frequency, depth, and sampling should be risk-based and documented.
- The April 2026 AML/CFT Program rulemaking remains a proposal in this article; the checklist is based on the current operative Β§ 1022.210 requirements.
Quick answer: Every U.S. money services business must provide for an independent review of its AML program under 31 CFR Β§ 1022.210(d)(4). "Independent review" does not require hiring a CPA or outside audit firm β it can be performed by a qualified employee, so long as that person is not the designated compliance officer and does not report directly to them. Scope and frequency are risk-based, not fixed at once a year. A meaningful review tests whether the program's policies, procedures and internal controls, compliance function, training, reporting and recordkeeping controls are actually implemented and operating as designed β not merely whether the documents exist. The MSB's risk assessment should inform the scope and frequency of that testing.
Most MSBs already know an independent review is required. What's harder to find is a straight answer on what that review should actually test, what evidence a reviewer should pull, and how to prepare for it without over- or under-scoping the engagement. This checklist works through the regulation, FinCEN's own guidance on conducting these reviews, and a practical, section-by-section testing framework a compliance officer, founder, or reviewer can use directly.
What Does 31 CFR Β§ 1022.210(d)(4) Actually Require?
The regulatory text is short. Under 31 CFR Β§ 1022.210(d)(4), an MSB's AML program must:
"Provide for independent review to monitor and maintain an adequate program. The scope and frequency of the review shall be commensurate with the risk of the financial services provided by the money services business. Such review may be conducted by an officer or employee of the money services business so long as the reviewer is not the person designated in paragraph (d)(2) of this section."
That's the core regulatory requirement under Β§ 1022.210(d)(4): independent review, risk-based scope and frequency, and a single named restriction β the reviewer cannot be the person designated under (d)(2) as responsible for day-to-day compliance. Everything about who else may not conduct the review, what the review should test, and how it should be documented comes from FinCEN guidance layered on top of that text, not the regulation itself. This article is careful to separate the two.
Section 1022.210(d) sets out the program's other three minimum elements alongside independent review: (d)(1) policies, procedures, and internal controls reasonably designed to assure BSA compliance; (d)(2) designation of a person responsible for day-to-day compliance; and (d)(3) ongoing training of appropriate personnel. Independent testing exists to evaluate whether all four elements β including itself, in effect β actually function, not just whether they're written down.
Does an MSB Need an External BSA/AML Auditor?
No. FinCEN's guidance on this point is direct: MSBs are not required to hire a certified public accountant or an outside consultant to conduct the review. The regulation requires an independent review, not a formal audit by a CPA or third-party firm.
According to FinCEN's Frequently Asked Questions guidance (FIN-2006-G012), the review may be conducted by an officer, employee, or group of employees, so long as two conditions are met:
- The reviewer is not the designated compliance officer. This is the regulation's own restriction, from 1022.210(d)(4) itself.
- The reviewer does not report directly to the compliance officer. This second condition comes from FinCEN's guidance, not the regulation's text β it's an interpretive expectation, not a separately codified rule, but FinCEN states it plainly as part of what independence requires.
So the realistic options are: a qualified internal employee outside the compliance function's direct reporting line, an internal audit function if the business has one, or an external consultant or audit firm. None of these is legally mandatory on its own β the choice is a business decision shaped by the MSB's size, internal expertise, and how much weight a banking partner, investor, or acquirer places on external validation. That commercial reasoning is discussed later in this article; it should not be confused with what the regulation itself demands.
How Often Must an MSB Conduct Independent AML Testing?
There is no universal annual requirement. The regulation's own words are "commensurate with the risk of the financial services provided" β a risk-based standard, not a calendar. FinCEN's guidance reinforces this directly: the scope and frequency of the review depend on the MSB's risk assessment, considering its products, services, customers, and geographic locations. For some MSBs, based on that risk assessment, an annual review may not be necessary; for others, more frequent review may be warranted.
FinCEN gives examples of circumstances that may justify an earlier review, rather than naming fixed triggers: more frequent review may be prudent following a change in the MSB's risk assessment, and advancing the timing of the next review may be advisable where a previous review identified problems, so the business can confirm corrective action was actually taken.
Beyond those examples, businesses reasonably treat several other developments as risk-relevant when setting review frequency, even though FinCEN does not name them individually: entering new products or corridors, rapid transaction-volume growth, onboarding new agents or expanding an agent network, a change in ownership or business model, or a banking partner's own periodic due-diligence cycle. These are practical risk-management judgments, not independently codified requirements β they matter because they change the risk picture the regulation ties frequency to, not because a rule names them.
Independent BSA/AML Audit Checklist for U.S. MSBs
This is the core of the article: what an independent reviewer should actually examine, section by section. Not every item applies to every MSB β a check casher, a money transmitter with an agent network, and a virtual-currency exchanger carry different obligations, and scope should reflect the specific business, not a generic template.
1. Review Scope and Risk Assessment
Before testing begins, the reviewer needs to understand the entity being reviewed: its legal structure, MSB activities, products and services, customer types, transaction channels, geographic exposure, agents or delegates, transaction volumes, delivery methods, virtual-currency exposure if applicable, and what has changed since the previous review.
The risk assessment should directly drive testing depth elsewhere in the review β a business with concentrated high-risk corridors or an active agent network warrants deeper testing there than a simple, single-location retail operation. There is no single standard scope that fits every MSB; the risk assessment is what should determine it.
2. Written AML Policies, Procedures, and Internal Controls
3. AML Compliance Officer Oversight
The reviewer evaluates how the compliance function operates β its authority, resources, and access to senior management β without the reviewer being, or reporting to, that same officer.
Independent testing evaluates how this function operates; it does not substitute for management's own responsibility for running the program.
4. MSB Registration and Regulatory Status
FinCEN federal MSB registration is a separate regulatory obligation from Β§ 1022.210(d)(4) itself, and testing here is about registration hygiene, not the AML program's substantive design. Most MSBs must register with FinCEN by filing FinCEN Form 107 and must renew that registration every two years; a narrow exception applies to a person who is an MSB solely because it acts as an agent of another registered MSB.
Do not confuse FinCEN registration with state money transmitter licensing. These are separate regimes administered by different authorities β federal registration does not itself authorize money transmission in any state, and not every MSB activity requires the same state licensing footprint. A broader compliance engagement may test both, but they should never be treated as one requirement.
5. Customer Identification and Verification Controls
MSBs are not subject to a single, universal, bank-style Customer Identification Program rule. The applicable identification and customer-information obligations depend on the MSB's specific activities and transaction types, so testing here has to start from what actually applies to this business, not an assumed standard.
Keep legal requirement and company policy distinct in the write-up: a control an MSB has chosen to adopt as good practice is not the same as a federal identification obligation, even if both appear in the same policy manual.
6. Suspicious Activity Monitoring and SAR Compliance
Where SAR obligations apply, this is typically one of the highest-value areas to test in depth. Under 31 CFR Β§ 1022.320, a transaction generally requires SAR reporting where it's conducted or attempted by, at, or through an MSB, involves or aggregates at least $2,000, and the MSB knows, suspects, or has reason to suspect it's connected to illegal activity, is structured to evade BSA reporting, has no lawful purpose, or facilitates criminal activity β with a $5,000 threshold specifically for money order or traveler's check issuers identifying transactions through clearance-record review.
Sample selection should be risk-based and documented β there is no FinCEN-prescribed minimum number of files or transactions that applies to every engagement. What matters is that the sample lets the reviewer actually evaluate the specific control being tested, and that the selection method is recorded.
7. Currency Transaction Reporting and Other BSA Reports
Only test report types that apply to the MSB's actual activities. Under 31 CFR Β§ 1010.311, each financial institution other than a casino β a category that includes MSBs β generally must file a report of each deposit, withdrawal, exchange of currency, or other payment or transfer involving a transaction in currency of more than $10,000, except as otherwise provided in that section. The reviewer should first determine whether the MSB actually handles transactions that trigger CTR obligations before including CTR testing in scope, rather than assuming every MSB has them.
8. Funds Transfer / Transmittal Recordkeeping
Under 31 CFR Β§ 1010.410(e) and (f), nonbank financial institutions must retain specified records for, and include specified information with, transmittals of funds of $3,000 or more β the "Recordkeeping Rule" and "Travel Rule," respectively. This $3,000 threshold remains the current operative figure; a 2020 proposal to lower it to $250 for cross-border transfers was never finalized and has no bearing on current compliance.
9. Monetary Instrument and Transaction Recordkeeping
Recordkeeping obligations differ meaningfully by MSB type β check cashers, money transmitters, issuers or sellers of monetary instruments, providers or sellers of prepaid access, and currency dealers/exchangers each carry different specific requirements. This is a checklist of what to consider by category, not a claim that every MSB carries every obligation listed.
10. Transaction Monitoring and Transaction Testing
This is where the review moves from reading policy to testing whether transactions were actually handled the way the policy says they should be.
Define population, sample, and selection method clearly, and use risk-based judgment in what to target β root-cause analysis of any exceptions found matters more than the raw count tested. There is no fixed FinCEN-prescribed number of files to test; inventing one would misstate the rule.
11. Agent Monitoring and Agent Oversight
For MSB principals operating through agents, this is a distinct and often under-tested area. FinCEN's guidance (FIN-2016-G001) is explicit that a principal MSB and its agents are each independently responsible for their own AML compliance, regardless of contractual arrangements β a contract that allocates responsibility to an agent does not eliminate the principal's own obligation. At minimum, FinCEN's guidance expects principals to identify the owners of their agents, evaluate agents' operations on an ongoing basis and monitor for variations, and evaluate agents' actual implementation of policies, procedures, and controls.
12. Employee and Agent AML Training
FinCEN's guidance uses this exact framing as an example of what independent testing should determine: if the program requires training every six months for a given role, testing should confirm both that the training occurred and that it was adequate β not just that it appears on a calendar.
13. OFAC / Sanctions Controls
OFAC sanctions compliance is a legally distinct framework from the BSA AML-program regulation FinCEN administers β 31 CFR Β§ 1022.210(d)(4) does not itself require OFAC screening. Many MSBs nonetheless include sanctions controls within a broader financial-crime compliance review, and that's a reasonable scope decision, but the article and any report resulting from it should label which requirement is which.
14. Virtual Currency / Crypto MSB Controls
For MSBs engaged in convertible virtual currency activity, additional practical risk areas are worth including in scope where they're supported by the business's actual activity β not because a rule universally mandates a specific technology.
Blockchain analytics software is a risk-management practice many virtual-currency MSBs adopt, not a universal legal mandate β describe it as such rather than as a regulatory requirement.
15. Record Retention and Audit Trail
Under 31 CFR Β§ 1010.430(d), records required to be retained under BSA regulations generally carry a five-year retention period.
16. Information Systems and AML Technology
Sophisticated monitoring software does not prove program effectiveness on its own β data completeness, rule configuration, and how alerts are actually handled matter more than the tool itself.
17. Previous Findings and Remediation
Repeat findings deserve particular attention in the report β they indicate the underlying control gap, not just the individual instance, was never actually fixed.
18. Management Reporting and Governance
Scale expectations to the business β a small MSB with an owner-operator does not need a bank-style board committee structure to satisfy this element; what matters is that issues genuinely reach whoever is accountable for the program.
How Should Transaction Samples Be Selected?
There is no universal sample size that automatically proves a program adequate β this bears repeating, because it's one of the most common misconceptions in the market. Sampling generally falls into three approaches, often combined:
- Risk-based sampling β targeting populations most likely to reveal a control weakness: high-value transactions, high-risk customers or geographies, alerts closed without a SAR, transactions near reporting thresholds, agent activity, or manual overrides.
- Random sampling β a broader, less targeted population check, useful for confirming general population health.
- Judgmental/targeted sampling β reviewer judgment applied to specific transactions of interest, such as new products or structuring indicators.
Whatever combination is used, the methodology should be documented β what population it was drawn from, how it was selected, and why β so the resulting evidence can withstand a reader (a bank partner, an examiner, or an acquirer) asking why that sample was sufficient to draw a conclusion.
Documents an MSB Should Prepare Before Independent Testing
Not every category applies to every business β request only what's relevant to the entity's actual activities and the agreed scope.
What Should the Final Independent Review Report Include?
FinCEN's guidance sets a clear floor: the review should be documented, covering the scope, procedures performed, transaction testing completed (if any), findings, and recommendations for corrective action, with deficiencies and corrective actions tracked afterward. That's what FinCEN expects the review to accomplish.
Beyond that floor, a well-structured professional report commonly includes an executive summary, defined scope, period reviewed, legal entities and activities covered, the regulatory criteria applied, methodology, documents reviewed, interviews conducted, sampling approach, tests performed, findings with supporting evidence, a severity or risk rating if the provider uses one, recommendations, management's response where applicable, a corrective-action plan, a follow-up or retesting plan, and any limitations on scope. This fuller structure is recommended professional practice, not a federal formatting requirement β don't present it to a reader as though it is.
Common Independent Testing Findings for MSBs
These are examples of issues an independent review may identify β not a claim that these are FinCEN's officially reported "most common" findings, since no such official ranking is being cited here:
- AML manual that doesn't match the current product set
- Risk assessment not updated after a business change
- Monitoring rules not aligned with the business's own stated risk profile
- SAR case files that are poorly documented or lack a clear decision rationale
- Late or inaccurate BSA reports
- Missing transaction records for a specific product or agent
- Weak agent oversight beyond initial onboarding
- Incomplete or unevidenced training records
- Repeat findings from a prior review left unremediated
- Inconsistent customer risk ratings
- Controls that operate differently in practice than written procedure describes
- A compliance officer with no documented evidence of active oversight
- Data gaps in monitoring or case-management systems
- Policies updated on paper without a corresponding change in actual operations
Internal Review vs. External Independent AML Testing
None of these options is legally superior to the others under Β§ 1022.210(d)(4) β the regulation's own bar is met by any of them, so long as the named restriction on the reviewer is respected. The choice between them is a business decision.
Does a Bank or Banking Partner Require the Same Thing as FinCEN?
Not exactly. A sponsor bank or payment partner will often request an MSB's AML program, risk assessment, independent testing report, and evidence of agent controls and remediation as part of its own due diligence β but that private due-diligence expectation is not identical to FinCEN's regulatory requirement, and not every bank collects an independent audit report from every MSB it works with. A bank's request reflects its own risk appetite and counterparty-due-diligence practice, which can be more demanding than the federal floor in some respects and different in scope in others. Treat the two as related but separate expectations.
Independent Review vs. FinCEN / IRS Examination
An independent review is part of the MSB's own AML-program requirement β something the business arranges for itself. A regulatory examination is government testing of BSA compliance, conducted by FinCEN or, where delegated, the IRS for many MSBs. Independent testing does not guarantee a successful examination outcome; no responsible reviewer or advisor should represent that it does. What a well-executed independent review can do is surface weaknesses the business can fix on its own timeline, rather than have them surface for the first time during a government examination.
2026 AML/CFT Program Rulemaking Watch
On April 7, 2026, FinCEN issued a Notice of Proposed Rulemaking (Docket FINCEN-2026-0034, RIN 1506-AB72) proposing to fundamentally reform AML/CFT program requirements across the eleven categories of financial institutions covered by the BSA, including MSBs under 31 CFR Β§ 1022.210. The proposal would shift program requirements toward an "effectiveness"-based standard and was published in the Federal Register on April 10, 2026, with a comment period that closed June 9, 2026. As of this writing, no final rule has been issued; FinCEN has proposed a 12-month effective date from issuance if the rule is finalized as proposed.
A proposed rule is not current law. The checklist above reflects the operative requirements in effect under Β§ 1022.210(d)(4) as of the publication date of this article. If FinCEN finalizes changes to the independent-review or broader program requirements, this checklist will need to be updated to the effective rule text β current law controls until then.
Does Independent Testing Cover State Money Transmitter Licensing?
No, not as part of the Β§ 1022.210(d)(4) requirement itself β that's a federal BSA AML-program rule. State money transmitter licensing is a separate regime, administered state by state, and federal FinCEN registration does not itself authorize money transmission in any state. A broader compliance engagement may include state-law testing as an added scope item, but the two regimes and their respective requirements should never be merged into one description.
How ComplyFactor Can Support Independent BSA/AML Testing
ComplyFactor performs independent BSA/AML review and testing engagements for U.S. MSBs, money transmitters, remittance companies, and payment businesses, scoped to the specific business model and risk profile rather than a fixed template. Reviewer independence is assessed during scoping in line with 31 CFR Β§ 1022.210(d)(4) and FinCEN's guidance, and where ComplyFactor has also advised on a client's program design, that work is kept separate from any later independent review of the same program. Engagements conclude with a documented report covering scope, procedures performed, findings, and recommendations. Discuss your BSA/AML audit scope.
FAQ
What should an MSB do if independent testing finds a material control failure?
Document the finding and its root cause, assign corrective action to a named owner with a due date, and preserve evidence of the remediation actually taken. Depending on the risk involved, follow-up or retesting may be appropriate to confirm the fix holds. FinCEN's guidance does not prescribe one universal remediation workflow β this reflects general practice for tracking and closing findings, not a single mandated process.
Should an independent reviewer test alerts that were closed without a SAR?
Where suspicious-activity monitoring and SAR obligations apply to the business, reviewing a risk-based sample of alerts closed without a filing can help test whether investigation and decision-making controls are functioning consistently. There is no universal sample size for this β the sample should be large and targeted enough to let the reviewer draw a supportable conclusion about that specific control.
Can independent testing focus on one high-risk product or business line?
A review may place deeper testing on a business's higher-risk areas, and that's consistent with the regulation's own risk-based standard. But the overall review still needs to be sufficient to evaluate the MSB's AML program as a whole, based on the business's actual risk and applicable requirements β a narrowly scoped single-product review does not, by itself, satisfy the full independent-review obligation.
Should a newly launched MSB wait a full year before conducting its first independent review?
No fixed rule requires that. The regulation is risk-based and doesn't prescribe a universal waiting period. Timing should reflect when there's enough operating activity to test meaningfully, together with the business's risk profile, program maturity, any business changes, and any banking-partner or contractual expectations that may apply β a practical judgment call, not a regulatory deadline.
What evidence should an MSB keep to show that prior audit findings were remediated?
Useful evidence includes a corrective-action tracker, revised policies or procedures, system-change records, training records, updated system configurations, testing results, closure approvals, and any follow-up or retesting evidence. Keeping this organized makes the next independent review, and any banking-partner or examiner request, considerably faster to satisfy.
Can a banking partner require an external review even when FinCEN does not?
Yes. A bank or payment partner may impose contractual or due-diligence requirements that are stricter than, or different from, FinCEN's federal minimum under Β§ 1022.210(d)(4). A private banking-relationship requirement like this is a separate expectation from the federal rule, not a restatement of it.
Can an external consultant help remediate findings after completing the independent review?
This is primarily an engagement-design and objectivity question rather than a fixed prohibition β FinCEN's guidance doesn't set a specific rule governing this scenario beyond the reviewer/compliance-officer restriction already described. Many firms choose to separate review work from later remediation work on the same program specifically to preserve clear objectivity and avoid a future engagement reviewing their own prior work.
Do crypto MSBs have the same independent-review requirement?
Where a virtual-currency business falls within FinCEN's MSB framework, the same 31 CFR Β§ 1022.210(d)(4) independent-review requirement applies. Whether a specific virtual-currency business is covered depends on its actual activities under applicable FinCEN rules.
How long should an MSB keep its independent-review report?
No specific report-retention rule for the independent-review report itself was identified in the sources reviewed. Many MSBs retain the report and related testing documentation with their compliance records; specified BSA records have their own retention requirements β for example, a general five-year retention period applies to records required to be kept under 31 CFR Β§ 1010.430(d) β but that provision should not be treated as an express rule for the independent-review report itself unless a current authoritative source specifically confirms it applies.
Related insights
Book a free Canada AML consultation
Tell us about your business and we'll confirm which services you need β free, no obligation, 30 minutes.
(4)%20Testing.avif)