Key Takeaways
- There is no regulator-set price. FinCEN does not publish a fee schedule for independent reviews, and 31 CFR § 1022.210(d)(4) prescribes neither a fixed scope nor an annual price. It requires an independent review whose scope and frequency are commensurate with the risk of the financial services the MSB provides.
- Under the federal MSB rule, an outside reviewer is not universally required. FinCEN guidance allows a qualified officer, employee or group of employees to perform the review if the reviewer is not the designated compliance officer and does not report directly to that officer. Whether to use an outside reviewer may also be influenced by internal capability, reviewer independence, banking-partner expectations, contractual requirements or other applicable obligations.
- Two quotes differ because two scopes differ. They are comparable only when they state the same review period, transaction population, sampling approach, agent coverage, systems testing and follow-up.
- Transaction testing, agent networks, monitoring systems and record quality drive the most reviewer hours. Headline volume matters less than how much has to be extracted, sampled, traced and documented.
- Public pricing is sparse and not comparable. Publicly available U.S. pricing for MSB-focused reviews is too sparse and inconsistent in scope to support a defensible market range, so this article does not publish an average. ComplyFactor scopes and quotes each engagement and does not publish a price list.
- A low quote is not automatically inadequate, and a high quote is not automatically thorough. Check what each one includes, especially transaction testing, agents and validation of fixes.
- Preparation reduces wasted hours, not necessary scope. A clean population, a current risk assessment and an organized evidence set shorten fieldwork without narrowing what a risk-appropriate review has to test.
There is no FinCEN fee schedule for independent BSA/AML reviews, and 31 CFR § 1022.210(d)(4) does not prescribe a fixed scope, sample size or annual price. Two money services businesses can therefore receive very different quotes, and both may be reasonable, because the reviewers are pricing different amounts of testing.
This guide explains what drives a quote, what a quote should state, how to compare proposals and what to prepare before asking for one. It does not repeat the testing methodology. For what a review should examine, see our Independent BSA/AML Audit Checklist for U.S. MSBs.
A note on terminology. “BSA/AML audit” is the common commercial and search term. The regulation uses “independent review,” and FinCEN guidance also refers to independent testing. We use them interchangeably.
Who this applies to. Section 1022.210 applies to money services businesses as defined in 31 CFR § 1010.100(ff). Some fintechs are MSBs, for example as money transmitters. Others operate under different legal structures and may face independent-testing expectations under their own frameworks or contracts instead. The pricing discussion below is written for U.S. MSBs and fintech or payment businesses that need an independent BSA/AML review under an applicable framework. It does not decide whether your business is an MSB.
How much does an independent BSA/AML audit cost?
It depends on scope, and most providers quote rather than publish. Publicly available U.S. pricing for MSB-focused independent BSA/AML reviews is too sparse and inconsistent in scope to support a defensible market range. Pricing is not standardized: some providers publish no price, some bundle the review with other services, and some publish fixed-fee tiers aimed at other regulated sectors. For that reason, this article does not present an “average” price. It explains the scope factors that determine a usable quote.
Two reviews are not comparable unless their scope is comparable. A quote for a narrow documentation review and a quote for a review that includes transaction testing, agent sampling and validation of fixes are pricing different engagements, even if both are called an independent BSA/AML audit.
A more useful way to budget is to treat a quote as an estimate of four things:
- how much evidence has to be gathered and tested;
- how much of that work needs senior or specialist judgment;
- how clean and complete your records are; and
- how much reporting, discussion and follow-up the engagement includes.
The rest of this article breaks those down. ComplyFactor quotes after a scoping discussion and does not publish fixed prices, because a number given without the scope behind it would mislead.
What does FinCEN actually require?
Under 31 CFR § 1022.210(d)(4), an MSB’s AML program must provide for independent review to monitor and maintain an adequate program. The scope and frequency must be commensurate with the risk of the financial services provided. The review may be conducted by an officer or employee so long as the reviewer is not the person designated under paragraph (d)(2) to assure day-to-day compliance.
FinCEN’s guidance on these reviews (FIN-2006-G012) adds four points that matter for pricing:
- MSBs are not required to hire a CPA or an outside consultant. An officer, employee or group of employees may perform the review if the reviewer is not the designated compliance officer and does not report directly to that officer.
- The review should include testing of internal controls and transactional systems, and should cover the actions taken by, or assigned to, the designated compliance officer.
- Scope and frequency follow the MSB’s risk assessment. For some MSBs an annual review may not be necessary. A change in the risk assessment, or problems found in a prior review, may justify an earlier one.
- The reviewer should document the scope, procedures performed, transaction testing completed (if any), findings and recommendations.
- obtain the population and confirm it is complete, for example by reconciling it to system totals or filed reports;
- define a risk-based sample and record why it was selected;
- pull source records for each item and trace customer data, risk rating, alerts, decisions and filings;
- test timeliness, accuracy and retention against the applicable requirement;
- document every exception, investigate root cause and follow up with management; and
- write up findings with supporting evidence.
- A clean, reconcilable transaction population
- A complete and current AML manual
- A current risk assessment
- Documented history of prior testing
- Organized SAR, CTR and case files
- A current agent list
- Access to system owners who can explain configuration
- A prior-findings and remediation tracker
- One central evidence location
- An agreed scope before fieldwork starts
FinCEN does not publish a universal sample size or review calendar. That risk-based standard is the reason price varies so widely.
The biggest factors that drive BSA/AML audit cost
These are pricing drivers, not regulatory red flags. A driver raises cost because it adds work for the reviewer, not because it signals a compliance problem.
Volume and population size
Higher volume increases extraction, completeness checking and exception analysis. It does not mean the sample rises in proportion. Sample design is a judgment about what is needed to draw a supportable conclusion about a specific control, and FinCEN does not prescribe one. A reviewer may test a modest, well-targeted sample from a very large population, and a messy small population can cost more than a clean large one.
Agents and authorized delegates
A principal MSB and its agents are each responsible for their own AML compliance, and a contract that assigns responsibility to an agent does not remove the principal’s obligation (FinCEN guidance FIN-2016-G001). Where the program relies on agents, the reviewer has to test how they are onboarded, monitored, trained and terminated, which can add sampling, interviews and travel. Our article on authorized delegate oversight covers the controls themselves.
Systems, data and record quality
Reviewers cannot test what they cannot obtain. Poor exports, incomplete case files, missing training records, inconsistent agent files and policy-to-workflow mismatches all create follow-up requests and rework. Data quality can be a major swing factor between businesses that look similar on paper.
Virtual currency exposure
Where an MSB handles virtual currency, the review may need to address wallet information, monitoring calibrated to that activity, blockchain analytics outputs and applicable Travel Rule handling. That adds data sources and test steps. It does not automatically double the cost. A narrow pass-through product and a full trading platform are different engagements.
Footprint, entities and state-law scope
A federal § 1022.210 review is not a state money transmitter examination. A multi-state footprint may add business complexity, but state-law controls are part of a review only if the scope expressly includes them. If a quote includes them, that is added scope and should be priced and described separately. See our article on FinCEN registration and state licensing for the distinction.
Prior findings
Findings from a prior review, an examination or a banking partner add a status check for each item and often a focused look at repeat issues. FinCEN guidance notes that it may be advisable to advance the next review to confirm corrective action, so prior problems can change both timing and scope.
What transaction testing does to cost
Transaction testing can be one of the largest blocks of reviewer hours because it is where the review moves from reading policy to tracing what happened. For a given population, the reviewer typically has to:
Deeper SAR and CTR population testing increases hours because every one of those steps repeats for each population tested. More populations (alerts closed without a filing, transactions near reporting thresholds, agent activity, manual overrides) mean more repetitions.
There is no universal sample size. What matters for price is that the quote says how the sample will be determined and who selects it. For the detailed methodology, see the testing sections of our audit checklist.
Can an MSB reduce cost by using an internal reviewer?
Sometimes, if the MSB has a genuinely separate reviewer. The regulation and FinCEN guidance permit an officer, employee or group of employees to perform the review, provided the reviewer is not the designated compliance officer and does not report directly to that officer. External review is not legally superior. It is a commercial and capability choice.
Why some businesses buy external review anyway. Reasons include banking-partner diligence, investor or acquirer diligence, prior findings, examination readiness and contractual expectation. These are commercial drivers and not federal requirements. An external review does not guarantee bank onboarding, and it does not protect against penalties.
Independence and cost
Independence shapes who can be hired and what else they have done for you. In a 2014 civil money penalty assessment, FinCEN described as a conflict of interest an MSB’s reliance on one consultant that created its written AML program, performed its only independent testing and supplied its only training. Where an adviser built or materially revised the program, independence should be assessed before that same firm conducts the review.
ComplyFactor assesses reviewer independence during scoping. Where it has advised on a client’s program design, that work is kept separate from any later independent review, and no one who helped design or revise the program is assigned to review it. The same person cannot run the program and independently review it. See our article on fractional BSA officers and independent reviewers and our fractional BSA/AML officer service for the distinction between ongoing officer coverage and independent testing.
How independent reviews are priced
Providers use different structures, and not every provider uses every one. We have not established which is most common, so treat the table as a menu of options to discuss and not as a description of the market.
What should an audit quote include?
A low quote with vague scope may not be comparable to a higher quote that covers transaction testing, agents and validation of fixes. Neither is necessarily wrong. Ask each provider to state:
What can reduce the cost without reducing scope?
Preparation removes wasted reviewer time. It should never be used to justify narrowing the review below what the risk profile requires.
What to have ready before you request a quote
These are scoping inputs, not the evidence the reviewer will later test. For the testing evidence, see the checklist.
Illustrative scoping scenarios
These are hypothetical profiles to show how scope moves. They are not clients and carry no prices.
Audit, remediation and retesting are different scopes
An independent review identifies findings. Remediation fixes them. Retesting or validation checks whether the fixes work. FinCEN guidance says the reviewer or the designated compliance officer should track deficiencies and document corrective actions after a review, which is different from designing the fixes. Quotes often treat validation of remediation as a separate scope, so confirm whether it is included.
Advisory remediation is separate work. See compliance remediation services for findings from a review, examiner or partner, and BSA/AML compliance program services where the program itself needs to be rebuilt. A firm that designs or implements a fix should not be the one to independently test that same work without a separate independence assessment.
2026 AML/CFT program rulemaking: does it change audit pricing yet?
No. On April 7, 2026, FinCEN issued a notice of proposed rulemaking (Docket FINCEN-2026-0034) to revise AML/CFT program requirements across covered financial institutions, including MSBs. It was published in the Federal Register on April 10, 2026, comments closed June 9, 2026, and it supersedes and withdraws FinCEN’s July 2024 proposal.
FinCEN’s fact sheet says the proposal would keep the independent testing requirement and clarify that testing should assess compliance, focus on program effectiveness, use objective criteria, be performed by parties truly independent of the AML/CFT function and avoid conflicts of interest. FinCEN proposed a 12-month implementation period after a final rule. We found no final rule as of October 1, 2026.
A proposal is not current law. This article is based on § 1022.210(d)(4) and FinCEN’s existing guidance. If a final rule changes the scope of independent testing, it could affect what a review includes and therefore what it costs. That is worth building flexibility for in multi-year engagements, but it cannot yet be quantified.
How ComplyFactor supports independent BSA/AML reviews
ComplyFactor’s BSA/AML audit services scope each independent review around the client’s actual business model and risk profile rather than a fixed template, covering the applicable controls, testing population, systems, agents and prior issues. A written scope of work is agreed before testing begins, and the document request is confirmed during scoping. Engagements end with a documented scope and testing summary, a findings matrix prioritized by severity, a written report, corrective-action recommendations and a management discussion before the report is finalized.
Pricing is scope-based and quoted after that conversation. For broader consulting, see our U.S. AML consulting hub. Nothing here guarantees a particular examination, banking or audit outcome.
Frequently asked questions
Should we collect more than one quote, and how do we compare them?
Yes where practical. Give each provider the same scoping inputs and ask for written assumptions. Compare line by line before comparing totals: population, sampling approach, agents, systems, state or OFAC add-ons and retesting. Do not treat a lower quote as equivalent if it leaves out transaction testing or agents, and do not assume a higher one includes them.
Can we lower cost by reviewing less often?
Frequency is set by risk, not budget. FinCEN guidance says an annual review may not be necessary for some MSBs, but also that a change in the risk assessment or problems found in a prior review can justify an earlier one. Document the rationale in the program. Longer gaps can also mean more activity and change to test in a single review, and a banking partner may set its own cadence.
Can one report serve the federal requirement, a bank request and a state examination?
It can, if the scope covers each. A § 1022.210(d)(4) review does not automatically cover state licensing requirements, OFAC screening (a separate legal framework) or a bank’s own questionnaire. Ask the provider to map each test to the requirement it supports and to price the extra modules separately.
What happens to the price if the reviewer finds our records are incomplete?
That depends on the quote terms. A fixed fee rests on stated assumptions, so ask before signing what happens when an assumption fails: a change order, a pause while records are fixed, or time-and-materials for the extra work. Raising data gaps at scoping is cheaper than discovering them in fieldwork.
Can our team assemble the evidence without compromising independence?
Yes. Management can produce, organize and explain documents and exports. The reviewer should define and control the population, select the samples, verify completeness against source systems and reach conclusions without direction from the designated compliance officer. The compliance officer cannot be the reviewer and the reviewer should not report directly to that officer.
Need a scoped view of what your review would involve? Discuss your BSA/AML audit scope with ComplyFactor. We confirm the relevant risks, scope and timing before anything begins.
Related insights
Book a free Canada AML consultation
Tell us about your business and we'll confirm which services you need — free, no obligation, 30 minutes.
