BSA/AML

Independent BSA/AML Audit Checklist for U.S. MSBs: 31 CFR Β§ 1022.210(d)(4) Testing

Use this independent BSA/AML audit checklist to see what U.S. MSBs should test under 31 CFR Β§ 1022.210(d)(4), from controls to transaction testing.

On this page
Get Expert Help

Key takeaways

  • 31 CFR Β§ 1022.210(d)(4) requires U.S. MSBs to provide for independent AML program review, with scope and frequency commensurate with the risk of the financial services provided.
  • An outside CPA or audit firm is not universally required; the reviewer cannot be the designated compliance officer, and FinCEN guidance says the reviewer should not report directly to that officer.
  • A defensible review should test how controls operate in practice, including applicable SAR/CTR reporting, recordkeeping, transaction monitoring, agent oversight, training, systems, and remediation.
  • FinCEN does not prescribe one universal annual review schedule or transaction sample size; frequency, depth, and sampling should be risk-based and documented.
  • The April 2026 AML/CFT Program rulemaking remains a proposal in this article; the checklist is based on the current operative Β§ 1022.210 requirements.

Quick answer: Every U.S. money services business must provide for an independent review of its AML program under 31 CFR Β§ 1022.210(d)(4). "Independent review" does not require hiring a CPA or outside audit firm β€” it can be performed by a qualified employee, so long as that person is not the designated compliance officer and does not report directly to them. Scope and frequency are risk-based, not fixed at once a year. A meaningful review tests whether the program's policies, procedures and internal controls, compliance function, training, reporting and recordkeeping controls are actually implemented and operating as designed β€” not merely whether the documents exist. The MSB's risk assessment should inform the scope and frequency of that testing.

Most MSBs already know an independent review is required. What's harder to find is a straight answer on what that review should actually test, what evidence a reviewer should pull, and how to prepare for it without over- or under-scoping the engagement. This checklist works through the regulation, FinCEN's own guidance on conducting these reviews, and a practical, section-by-section testing framework a compliance officer, founder, or reviewer can use directly.

What Does 31 CFR Β§ 1022.210(d)(4) Actually Require?

The regulatory text is short. Under 31 CFR Β§ 1022.210(d)(4), an MSB's AML program must:

"Provide for independent review to monitor and maintain an adequate program. The scope and frequency of the review shall be commensurate with the risk of the financial services provided by the money services business. Such review may be conducted by an officer or employee of the money services business so long as the reviewer is not the person designated in paragraph (d)(2) of this section."

That's the core regulatory requirement under Β§ 1022.210(d)(4): independent review, risk-based scope and frequency, and a single named restriction β€” the reviewer cannot be the person designated under (d)(2) as responsible for day-to-day compliance. Everything about who else may not conduct the review, what the review should test, and how it should be documented comes from FinCEN guidance layered on top of that text, not the regulation itself. This article is careful to separate the two.

Section 1022.210(d) sets out the program's other three minimum elements alongside independent review: (d)(1) policies, procedures, and internal controls reasonably designed to assure BSA compliance; (d)(2) designation of a person responsible for day-to-day compliance; and (d)(3) ongoing training of appropriate personnel. Independent testing exists to evaluate whether all four elements β€” including itself, in effect β€” actually function, not just whether they're written down.

Does an MSB Need an External BSA/AML Auditor?

No. FinCEN's guidance on this point is direct: MSBs are not required to hire a certified public accountant or an outside consultant to conduct the review. The regulation requires an independent review, not a formal audit by a CPA or third-party firm.

According to FinCEN's Frequently Asked Questions guidance (FIN-2006-G012), the review may be conducted by an officer, employee, or group of employees, so long as two conditions are met:

  1. The reviewer is not the designated compliance officer. This is the regulation's own restriction, from 1022.210(d)(4) itself.
  2. The reviewer does not report directly to the compliance officer. This second condition comes from FinCEN's guidance, not the regulation's text β€” it's an interpretive expectation, not a separately codified rule, but FinCEN states it plainly as part of what independence requires.

So the realistic options are: a qualified internal employee outside the compliance function's direct reporting line, an internal audit function if the business has one, or an external consultant or audit firm. None of these is legally mandatory on its own β€” the choice is a business decision shaped by the MSB's size, internal expertise, and how much weight a banking partner, investor, or acquirer places on external validation. That commercial reasoning is discussed later in this article; it should not be confused with what the regulation itself demands.

How Often Must an MSB Conduct Independent AML Testing?

There is no universal annual requirement. The regulation's own words are "commensurate with the risk of the financial services provided" β€” a risk-based standard, not a calendar. FinCEN's guidance reinforces this directly: the scope and frequency of the review depend on the MSB's risk assessment, considering its products, services, customers, and geographic locations. For some MSBs, based on that risk assessment, an annual review may not be necessary; for others, more frequent review may be warranted.

FinCEN gives examples of circumstances that may justify an earlier review, rather than naming fixed triggers: more frequent review may be prudent following a change in the MSB's risk assessment, and advancing the timing of the next review may be advisable where a previous review identified problems, so the business can confirm corrective action was actually taken.

Beyond those examples, businesses reasonably treat several other developments as risk-relevant when setting review frequency, even though FinCEN does not name them individually: entering new products or corridors, rapid transaction-volume growth, onboarding new agents or expanding an agent network, a change in ownership or business model, or a banking partner's own periodic due-diligence cycle. These are practical risk-management judgments, not independently codified requirements β€” they matter because they change the risk picture the regulation ties frequency to, not because a rule names them.

Independent BSA/AML Audit Checklist for U.S. MSBs

This is the core of the article: what an independent reviewer should actually examine, section by section. Not every item applies to every MSB β€” a check casher, a money transmitter with an agent network, and a virtual-currency exchanger carry different obligations, and scope should reflect the specific business, not a generic template.

1. Review Scope and Risk Assessment

Before testing begins, the reviewer needs to understand the entity being reviewed: its legal structure, MSB activities, products and services, customer types, transaction channels, geographic exposure, agents or delegates, transaction volumes, delivery methods, virtual-currency exposure if applicable, and what has changed since the previous review.

What to test Evidence to request Red flags
Whether the current risk assessment reflects the business as it actually operates today Current risk assessment; product/service inventory; org chart; agent list; transaction-volume data; prior audit and examination findings; remediation tracker Risk assessment last updated at registration and never since; new products or corridors not reflected; volume figures that don't match actual system data

The risk assessment should directly drive testing depth elsewhere in the review β€” a business with concentrated high-risk corridors or an active agent network warrants deeper testing there than a simple, single-location retail operation. There is no single standard scope that fits every MSB; the risk assessment is what should determine it.

2. Written AML Policies, Procedures, and Internal Controls

What to test Evidence to request Red flags
Whether policies reflect current operations, procedures match actual workflows, obligations are incorporated, roles and escalation paths are assigned, and controls described in policy are actually used AML manual; SOPs; process maps; escalation procedures; system rules; case-management procedures; approval logs; revision history A generic template that doesn't match the business; procedures referencing discontinued products; controls that exist only in the policy document; undocumented manual workarounds; staff performing tasks differently from written procedure

3. AML Compliance Officer Oversight

The reviewer evaluates how the compliance function operates β€” its authority, resources, and access to senior management β€” without the reviewer being, or reporting to, that same officer.

What to test Evidence to request Red flags
Whether the compliance officer has real authority, resources, and access to senior management; how oversight, escalation, and issue tracking actually work Job description; appointment documentation; committee minutes; compliance reports to management; issue logs; remediation tracking Compliance officer with no documented access to senior management; no evidence of actual oversight activity; issues identified but never tracked to resolution

Independent testing evaluates how this function operates; it does not substitute for management's own responsibility for running the program.

4. MSB Registration and Regulatory Status

FinCEN federal MSB registration is a separate regulatory obligation from Β§ 1022.210(d)(4) itself, and testing here is about registration hygiene, not the AML program's substantive design. Most MSBs must register with FinCEN by filing FinCEN Form 107 and must renew that registration every two years; a narrow exception applies to a person who is an MSB solely because it acts as an agent of another registered MSB.

What to test Evidence to request Red flags
Current registration status, renewal timing, information consistency, and whether material business changes have been reflected in the registration FinCEN Form 107 filing and renewals; agent list, where required; records of material business changes Registration lapsed or renewal overdue; agent list not updated after network changes; registered activities that no longer match what the business does

Do not confuse FinCEN registration with state money transmitter licensing. These are separate regimes administered by different authorities β€” federal registration does not itself authorize money transmission in any state, and not every MSB activity requires the same state licensing footprint. A broader compliance engagement may test both, but they should never be treated as one requirement.

5. Customer Identification and Verification Controls

MSBs are not subject to a single, universal, bank-style Customer Identification Program rule. The applicable identification and customer-information obligations depend on the MSB's specific activities and transaction types, so testing here has to start from what actually applies to this business, not an assumed standard.

What to test Evidence to request Red flags
Whether the MSB follows the identification requirements that actually apply to its activities, its own CDD procedures, beneficial ownership procedures where applicable, and risk-based enhanced measures for higher-risk relationships Customer files; identification records; CDD procedures; beneficial ownership documentation, where applicable; risk-tiering methodology; enhanced-measures procedures Identification steps skipped or inconsistently applied; risk tiers that don't drive different treatment; enhanced measures described in policy but absent from actual files

Keep legal requirement and company policy distinct in the write-up: a control an MSB has chosen to adopt as good practice is not the same as a federal identification obligation, even if both appear in the same policy manual.

6. Suspicious Activity Monitoring and SAR Compliance

Where SAR obligations apply, this is typically one of the highest-value areas to test in depth. Under 31 CFR Β§ 1022.320, a transaction generally requires SAR reporting where it's conducted or attempted by, at, or through an MSB, involves or aggregates at least $2,000, and the MSB knows, suspects, or has reason to suspect it's connected to illegal activity, is structured to evade BSA reporting, has no lawful purpose, or facilitates criminal activity β€” with a $5,000 threshold specifically for money order or traveler's check issuers identifying transactions through clearance-record review.

What to test Evidence to request Red flags
The full path from alert generation through escalation, investigation, decision, and filing; timeliness and completeness of filed SARs; continuing-activity procedures; confidentiality controls Alert population; case files; filed SARs; decision logs; escalation records; monitoring rules and any tuning or change history Alerts closed without documented rationale; SARs filed late relative to the applicable timeline; decision logic not documented; monitoring rules never revisited after a risk-profile change

Sample selection should be risk-based and documented β€” there is no FinCEN-prescribed minimum number of files or transactions that applies to every engagement. What matters is that the sample lets the reviewer actually evaluate the specific control being tested, and that the selection method is recorded.

7. Currency Transaction Reporting and Other BSA Reports

Only test report types that apply to the MSB's actual activities. Under 31 CFR Β§ 1010.311, each financial institution other than a casino β€” a category that includes MSBs β€” generally must file a report of each deposit, withdrawal, exchange of currency, or other payment or transfer involving a transaction in currency of more than $10,000, except as otherwise provided in that section. The reviewer should first determine whether the MSB actually handles transactions that trigger CTR obligations before including CTR testing in scope, rather than assuming every MSB has them.

What to test Evidence to request Red flags
Whether CTR and other applicable report types are triggered by this MSB's actual transactions, and if so, aggregation logic, filing timeliness, accuracy, and any claimed exemptions Filed reports; aggregation logs; exemption documentation, if claimed Aggregation across related transactions not performed; reports filed late; exemptions claimed without supporting analysis

8. Funds Transfer / Transmittal Recordkeeping

Under 31 CFR Β§ 1010.410(e) and (f), nonbank financial institutions must retain specified records for, and include specified information with, transmittals of funds of $3,000 or more β€” the "Recordkeeping Rule" and "Travel Rule," respectively. This $3,000 threshold remains the current operative figure; a 2020 proposal to lower it to $250 for cross-border transfers was never finalized and has no bearing on current compliance.

What to test Evidence to request Red flags
Whether required transmittor and recipient information is captured and retained at or above the $3,000 threshold, and whether the information travels with the transaction as required Sample of transmittal records at or above threshold; system configuration governing data capture; exception logs Missing required fields on transmittals at or above $3,000; system not configured to capture threshold transactions consistently; manual exception-handling with no documentation

9. Monetary Instrument and Transaction Recordkeeping

Recordkeeping obligations differ meaningfully by MSB type β€” check cashers, money transmitters, issuers or sellers of monetary instruments, providers or sellers of prepaid access, and currency dealers/exchangers each carry different specific requirements. This is a checklist of what to consider by category, not a claim that every MSB carries every obligation listed.

What to test Evidence to request Red flags
Whether the specific recordkeeping rules applicable to this MSB's activity category are being met Transaction records relevant to the entity's specific MSB category; retention logs Records missing for the entity's specific activity type; retention periods shorter than required for that record category

10. Transaction Monitoring and Transaction Testing

This is where the review moves from reading policy to testing whether transactions were actually handled the way the policy says they should be.

What to test Evidence to request Red flags
Select a transaction sample; trace customer data; check risk rating applied; identify whether reporting obligations were triggered and met; verify alert generation, investigation, filing, and retention; check approval and escalation Transaction population; sampling methodology documentation; case files; approval logs Population and sample not reconciled; risk ratings inconsistent with the customer's actual profile; triggered obligations not met; root causes of exceptions not investigated

Define population, sample, and selection method clearly, and use risk-based judgment in what to target β€” root-cause analysis of any exceptions found matters more than the raw count tested. There is no fixed FinCEN-prescribed number of files to test; inventing one would misstate the rule.

11. Agent Monitoring and Agent Oversight

For MSB principals operating through agents, this is a distinct and often under-tested area. FinCEN's guidance (FIN-2016-G001) is explicit that a principal MSB and its agents are each independently responsible for their own AML compliance, regardless of contractual arrangements β€” a contract that allocates responsibility to an agent does not eliminate the principal's own obligation. At minimum, FinCEN's guidance expects principals to identify the owners of their agents, evaluate agents' operations on an ongoing basis and monitor for variations, and evaluate agents' actual implementation of policies, procedures, and controls.

What to test Evidence to request Red flags
Agent onboarding and due diligence; risk classification; ongoing transaction monitoring of agent activity; training; suspicious-activity escalation from agents; termination procedures for noncompliant agents; concentration and geographic risk across the agent network Agent onboarding files; agent risk classifications; agent monitoring records; agent training records; termination files Agents onboarded without documented due diligence; no evidence of ongoing monitoring beyond onboarding; high-risk or high-volume agents receiving the same oversight as low-risk agents; noncompliant agents retained without documented corrective action

12. Employee and Agent AML Training

What to test Evidence to request Red flags
Who received required training, whether frequency matched the program's own stated schedule, content relevance to role, and whether training actually occurred as documented β€” not merely whether it was scheduled Attendance logs; LMS records; training materials; assessment results, if used; training calendar Training scheduled but not evidenced as completed; generic content with no role-specific relevance; new hires handling transactions before required training

FinCEN's guidance uses this exact framing as an example of what independent testing should determine: if the program requires training every six months for a given role, testing should confirm both that the training occurred and that it was adequate β€” not just that it appears on a calendar.

13. OFAC / Sanctions Controls

OFAC sanctions compliance is a legally distinct framework from the BSA AML-program regulation FinCEN administers β€” 31 CFR Β§ 1022.210(d)(4) does not itself require OFAC screening. Many MSBs nonetheless include sanctions controls within a broader financial-crime compliance review, and that's a reasonable scope decision, but the article and any report resulting from it should label which requirement is which.

What to test (if in scope) Evidence to request Red flags
Screening coverage and list currency; transaction and customer screening; escalation of potential matches; blocking/rejection processes; recordkeeping; false-positive handling Screening logs; list-update records; escalation records; blocked-transaction records Sanctions lists not updated on a defined schedule; potential matches closed without documented review; no distinction between BSA and OFAC findings in the resulting report

14. Virtual Currency / Crypto MSB Controls

For MSBs engaged in convertible virtual currency activity, additional practical risk areas are worth including in scope where they're supported by the business's actual activity β€” not because a rule universally mandates a specific technology.

What to test (where applicable) Evidence to request Red flags
Wallet and customer information capture; transaction monitoring calibrated to virtual-currency activity; source/destination exposure analysis; applicable Travel Rule considerations; SAR decisioning for virtual-currency transactions; recordkeeping Wallet-related customer records; monitoring rule configuration for virtual-currency activity; blockchain-analytics output, if used No monitoring calibration specific to virtual-currency risk; source/destination exposure not assessed for high-risk counterparties; recordkeeping gaps specific to virtual-currency transaction data

Blockchain analytics software is a risk-management practice many virtual-currency MSBs adopt, not a universal legal mandate β€” describe it as such rather than as a regulatory requirement.

15. Record Retention and Audit Trail

Under 31 CFR Β§ 1010.430(d), records required to be retained under BSA regulations generally carry a five-year retention period.

What to test Evidence to request Red flags
Whether required records exist, are retained for the applicable period, are accessible, and can be linked across alerts, cases, and filings Sample of records across categories; system logs; amendment/correction history Records missing or incomplete for the required retention window; gaps linking an alert to its eventual case file or filing; corrections made without an audit trail

16. Information Systems and AML Technology

Sophisticated monitoring software does not prove program effectiveness on its own β€” data completeness, rule configuration, and how alerts are actually handled matter more than the tool itself.

What to test Evidence to request Red flags
Transaction-monitoring and case-management system configuration, data feeds, access controls, change management, and exception handling Rule configuration documentation; change logs; access lists; exception reports; data-quality checks Rules never tuned after a risk-profile or volume change; manual overrides undocumented; access controls not reviewed periodically; data feeds with known gaps left unaddressed

17. Previous Findings and Remediation

What to test Evidence to request Red flags
Status of findings from the previous independent review, any regulator or examiner findings, and internal QA findings β€” open, partially remediated, closed, or reopened Prior review report; examination findings, if any; corrective-action plan with owners and due dates; closure evidence Repeat findings from the prior review with no documented remediation; corrective-action plans with no assigned owner or due date; findings marked closed with no supporting evidence

Repeat findings deserve particular attention in the report β€” they indicate the underlying control gap, not just the individual instance, was never actually fixed.

18. Management Reporting and Governance

What to test Evidence to request Red flags
Whether material AML issues actually reach appropriate management, scaled to the size and structure of the business Compliance committee minutes, where applicable; management reports; escalation logs; open-issue summaries Material issues never reaching senior management; no evidence any report was reviewed or acted on

Scale expectations to the business β€” a small MSB with an owner-operator does not need a bank-style board committee structure to satisfy this element; what matters is that issues genuinely reach whoever is accountable for the program.

How Should Transaction Samples Be Selected?

There is no universal sample size that automatically proves a program adequate β€” this bears repeating, because it's one of the most common misconceptions in the market. Sampling generally falls into three approaches, often combined:

  • Risk-based sampling β€” targeting populations most likely to reveal a control weakness: high-value transactions, high-risk customers or geographies, alerts closed without a SAR, transactions near reporting thresholds, agent activity, or manual overrides.
  • Random sampling β€” a broader, less targeted population check, useful for confirming general population health.
  • Judgmental/targeted sampling β€” reviewer judgment applied to specific transactions of interest, such as new products or structuring indicators.

Whatever combination is used, the methodology should be documented β€” what population it was drawn from, how it was selected, and why β€” so the resulting evidence can withstand a reader (a bank partner, an examiner, or an acquirer) asking why that sample was sufficient to draw a conclusion.

Documents an MSB Should Prepare Before Independent Testing

Category Typical documents
Corporate / business Legal entity information; organizational chart; product/service inventory; state-license matrix, if relevant
FinCEN MSB registration and renewals; related registration records
AML program Current AML manual and prior versions; risk assessment; compliance-officer designation; training program
Transactions Transaction population; monitoring data; alerts; case files; SARs; CTRs; transfer records
Customers Customer files; identity records; risk ratings; enhanced-review records
Agents Agent list; onboarding files; monitoring records; training records; termination files
Governance Management reports; committee minutes; issue logs
Previous reviews Prior independent review; examination findings; remediation evidence
Systems Monitoring rules and configuration; change logs; access lists

Not every category applies to every business β€” request only what's relevant to the entity's actual activities and the agreed scope.

What Should the Final Independent Review Report Include?

FinCEN's guidance sets a clear floor: the review should be documented, covering the scope, procedures performed, transaction testing completed (if any), findings, and recommendations for corrective action, with deficiencies and corrective actions tracked afterward. That's what FinCEN expects the review to accomplish.

Beyond that floor, a well-structured professional report commonly includes an executive summary, defined scope, period reviewed, legal entities and activities covered, the regulatory criteria applied, methodology, documents reviewed, interviews conducted, sampling approach, tests performed, findings with supporting evidence, a severity or risk rating if the provider uses one, recommendations, management's response where applicable, a corrective-action plan, a follow-up or retesting plan, and any limitations on scope. This fuller structure is recommended professional practice, not a federal formatting requirement β€” don't present it to a reader as though it is.

Common Independent Testing Findings for MSBs

These are examples of issues an independent review may identify β€” not a claim that these are FinCEN's officially reported "most common" findings, since no such official ranking is being cited here:

  • AML manual that doesn't match the current product set
  • Risk assessment not updated after a business change
  • Monitoring rules not aligned with the business's own stated risk profile
  • SAR case files that are poorly documented or lack a clear decision rationale
  • Late or inaccurate BSA reports
  • Missing transaction records for a specific product or agent
  • Weak agent oversight beyond initial onboarding
  • Incomplete or unevidenced training records
  • Repeat findings from a prior review left unremediated
  • Inconsistent customer risk ratings
  • Controls that operate differently in practice than written procedure describes
  • A compliance officer with no documented evidence of active oversight
  • Data gaps in monitoring or case-management systems
  • Policies updated on paper without a corresponding change in actual operations

Internal Review vs. External Independent AML Testing

Approach Potential advantages Potential limitations Independence considerations When it may be appropriate
Qualified internal reviewer Lower cost; institutional knowledge of the business May lack specialist MSB regulatory depth; harder to stay current on evolving expectations Must not be the designated compliance officer and should not report directly to them Smaller MSBs with a clearly separated reviewer and straightforward risk profile
Internal audit function Institutional knowledge combined with an internal audit discipline Requires a business large enough to support a separate internal audit function Same reporting-line restriction applies Larger MSBs with an established internal audit department
External independent consultant/auditor Specialist MSB and BSA/AML expertise; independence is structurally clearer; often expected by banking partners, investors, or acquirers Higher direct cost; requires effective knowledge transfer into the business Same regulatory restrictions apply β€” the reviewer cannot be the designated compliance officer, and FinCEN guidance says the reviewer should not report directly to that officer. Beyond that, objectivity should be assessed carefully as a matter of firm practice: some firms, including ComplyFactor, may apply stricter internal separation where they previously designed or materially revised the program being reviewed Complex transaction monitoring, crypto exposure, prior findings, rapid growth, acquisition due diligence, or when a banking partner specifically requests external validation

None of these options is legally superior to the others under Β§ 1022.210(d)(4) β€” the regulation's own bar is met by any of them, so long as the named restriction on the reviewer is respected. The choice between them is a business decision.

Does a Bank or Banking Partner Require the Same Thing as FinCEN?

Not exactly. A sponsor bank or payment partner will often request an MSB's AML program, risk assessment, independent testing report, and evidence of agent controls and remediation as part of its own due diligence β€” but that private due-diligence expectation is not identical to FinCEN's regulatory requirement, and not every bank collects an independent audit report from every MSB it works with. A bank's request reflects its own risk appetite and counterparty-due-diligence practice, which can be more demanding than the federal floor in some respects and different in scope in others. Treat the two as related but separate expectations.

Independent Review vs. FinCEN / IRS Examination

An independent review is part of the MSB's own AML-program requirement β€” something the business arranges for itself. A regulatory examination is government testing of BSA compliance, conducted by FinCEN or, where delegated, the IRS for many MSBs. Independent testing does not guarantee a successful examination outcome; no responsible reviewer or advisor should represent that it does. What a well-executed independent review can do is surface weaknesses the business can fix on its own timeline, rather than have them surface for the first time during a government examination.

2026 AML/CFT Program Rulemaking Watch

On April 7, 2026, FinCEN issued a Notice of Proposed Rulemaking (Docket FINCEN-2026-0034, RIN 1506-AB72) proposing to fundamentally reform AML/CFT program requirements across the eleven categories of financial institutions covered by the BSA, including MSBs under 31 CFR Β§ 1022.210. The proposal would shift program requirements toward an "effectiveness"-based standard and was published in the Federal Register on April 10, 2026, with a comment period that closed June 9, 2026. As of this writing, no final rule has been issued; FinCEN has proposed a 12-month effective date from issuance if the rule is finalized as proposed.

A proposed rule is not current law. The checklist above reflects the operative requirements in effect under Β§ 1022.210(d)(4) as of the publication date of this article. If FinCEN finalizes changes to the independent-review or broader program requirements, this checklist will need to be updated to the effective rule text β€” current law controls until then.

Does Independent Testing Cover State Money Transmitter Licensing?

No, not as part of the Β§ 1022.210(d)(4) requirement itself β€” that's a federal BSA AML-program rule. State money transmitter licensing is a separate regime, administered state by state, and federal FinCEN registration does not itself authorize money transmission in any state. A broader compliance engagement may include state-law testing as an added scope item, but the two regimes and their respective requirements should never be merged into one description.

How ComplyFactor Can Support Independent BSA/AML Testing

ComplyFactor performs independent BSA/AML review and testing engagements for U.S. MSBs, money transmitters, remittance companies, and payment businesses, scoped to the specific business model and risk profile rather than a fixed template. Reviewer independence is assessed during scoping in line with 31 CFR Β§ 1022.210(d)(4) and FinCEN's guidance, and where ComplyFactor has also advised on a client's program design, that work is kept separate from any later independent review of the same program. Engagements conclude with a documented report covering scope, procedures performed, findings, and recommendations. Discuss your BSA/AML audit scope.

FAQ

What should an MSB do if independent testing finds a material control failure?

Document the finding and its root cause, assign corrective action to a named owner with a due date, and preserve evidence of the remediation actually taken. Depending on the risk involved, follow-up or retesting may be appropriate to confirm the fix holds. FinCEN's guidance does not prescribe one universal remediation workflow β€” this reflects general practice for tracking and closing findings, not a single mandated process.

Should an independent reviewer test alerts that were closed without a SAR?

Where suspicious-activity monitoring and SAR obligations apply to the business, reviewing a risk-based sample of alerts closed without a filing can help test whether investigation and decision-making controls are functioning consistently. There is no universal sample size for this β€” the sample should be large and targeted enough to let the reviewer draw a supportable conclusion about that specific control.

Can independent testing focus on one high-risk product or business line?

A review may place deeper testing on a business's higher-risk areas, and that's consistent with the regulation's own risk-based standard. But the overall review still needs to be sufficient to evaluate the MSB's AML program as a whole, based on the business's actual risk and applicable requirements β€” a narrowly scoped single-product review does not, by itself, satisfy the full independent-review obligation.

Should a newly launched MSB wait a full year before conducting its first independent review?

No fixed rule requires that. The regulation is risk-based and doesn't prescribe a universal waiting period. Timing should reflect when there's enough operating activity to test meaningfully, together with the business's risk profile, program maturity, any business changes, and any banking-partner or contractual expectations that may apply β€” a practical judgment call, not a regulatory deadline.

What evidence should an MSB keep to show that prior audit findings were remediated?

Useful evidence includes a corrective-action tracker, revised policies or procedures, system-change records, training records, updated system configurations, testing results, closure approvals, and any follow-up or retesting evidence. Keeping this organized makes the next independent review, and any banking-partner or examiner request, considerably faster to satisfy.

Can a banking partner require an external review even when FinCEN does not?

Yes. A bank or payment partner may impose contractual or due-diligence requirements that are stricter than, or different from, FinCEN's federal minimum under Β§ 1022.210(d)(4). A private banking-relationship requirement like this is a separate expectation from the federal rule, not a restatement of it.

Can an external consultant help remediate findings after completing the independent review?

This is primarily an engagement-design and objectivity question rather than a fixed prohibition β€” FinCEN's guidance doesn't set a specific rule governing this scenario beyond the reviewer/compliance-officer restriction already described. Many firms choose to separate review work from later remediation work on the same program specifically to preserve clear objectivity and avoid a future engagement reviewing their own prior work.

Do crypto MSBs have the same independent-review requirement?

Where a virtual-currency business falls within FinCEN's MSB framework, the same 31 CFR Β§ 1022.210(d)(4) independent-review requirement applies. Whether a specific virtual-currency business is covered depends on its actual activities under applicable FinCEN rules.

How long should an MSB keep its independent-review report?

No specific report-retention rule for the independent-review report itself was identified in the sources reviewed. Many MSBs retain the report and related testing documentation with their compliance records; specified BSA records have their own retention requirements β€” for example, a general five-year retention period applies to records required to be kept under 31 CFR Β§ 1010.430(d) β€” but that provision should not be treated as an express rule for the independent-review report itself unless a current authoritative source specifically confirms it applies.

ComplyFactor Advisory Team

ComplyFactor specializes in FINTRAC MSB and PSP registration, independent AML effectiveness reviews, and compliance program design for Canadian and foreign money services businesses, payment service providers, fintechs, and virtual asset service providers.

Get started

Book a free Canada AML consultation

Tell us about your business and we'll confirm which services you need β€” free, no obligation, 30 minutes.

Free, no obligation, 30 minutes
Senior consultant on every engagement
Aligned with PCMLTFA & FINTRAC standards
+1 807 806 0444 Β· Suite 211, 320 Matheson Blvd West, Mississauga, ON

Talk to an AML expert

Thank you. Your message has been received β€” we'll be in touch within one business day.
Something went wrong while submitting the form. Please try again.