BSA/AML

How Much Does an Independent BSA/AML Audit Cost for a U.S. MSB or Fintech?

What drives the cost of an independent BSA/AML review for a U.S. money services business: scope, transaction testing, agents, data quality and quote mechanics, without invented prices.

On this page
Get Expert Help

Key Takeaways

  • There is no regulator-set price. FinCEN does not publish a fee schedule for independent reviews, and 31 CFR § 1022.210(d)(4) prescribes neither a fixed scope nor an annual price. It requires an independent review whose scope and frequency are commensurate with the risk of the financial services the MSB provides.
  • Under the federal MSB rule, an outside reviewer is not universally required. FinCEN guidance allows a qualified officer, employee or group of employees to perform the review if the reviewer is not the designated compliance officer and does not report directly to that officer. Whether to use an outside reviewer may also be influenced by internal capability, reviewer independence, banking-partner expectations, contractual requirements or other applicable obligations.
  • Two quotes differ because two scopes differ. They are comparable only when they state the same review period, transaction population, sampling approach, agent coverage, systems testing and follow-up.
  • Transaction testing, agent networks, monitoring systems and record quality drive the most reviewer hours. Headline volume matters less than how much has to be extracted, sampled, traced and documented.
  • Public pricing is sparse and not comparable. Publicly available U.S. pricing for MSB-focused reviews is too sparse and inconsistent in scope to support a defensible market range, so this article does not publish an average. ComplyFactor scopes and quotes each engagement and does not publish a price list.
  • A low quote is not automatically inadequate, and a high quote is not automatically thorough. Check what each one includes, especially transaction testing, agents and validation of fixes.
  • Preparation reduces wasted hours, not necessary scope. A clean population, a current risk assessment and an organized evidence set shorten fieldwork without narrowing what a risk-appropriate review has to test.

There is no FinCEN fee schedule for independent BSA/AML reviews, and 31 CFR § 1022.210(d)(4) does not prescribe a fixed scope, sample size or annual price. Two money services businesses can therefore receive very different quotes, and both may be reasonable, because the reviewers are pricing different amounts of testing.

This guide explains what drives a quote, what a quote should state, how to compare proposals and what to prepare before asking for one. It does not repeat the testing methodology. For what a review should examine, see our Independent BSA/AML Audit Checklist for U.S. MSBs.

A note on terminology. “BSA/AML audit” is the common commercial and search term. The regulation uses “independent review,” and FinCEN guidance also refers to independent testing. We use them interchangeably.

Who this applies to. Section 1022.210 applies to money services businesses as defined in 31 CFR § 1010.100(ff). Some fintechs are MSBs, for example as money transmitters. Others operate under different legal structures and may face independent-testing expectations under their own frameworks or contracts instead. The pricing discussion below is written for U.S. MSBs and fintech or payment businesses that need an independent BSA/AML review under an applicable framework. It does not decide whether your business is an MSB.

How much does an independent BSA/AML audit cost?

It depends on scope, and most providers quote rather than publish. Publicly available U.S. pricing for MSB-focused independent BSA/AML reviews is too sparse and inconsistent in scope to support a defensible market range. Pricing is not standardized: some providers publish no price, some bundle the review with other services, and some publish fixed-fee tiers aimed at other regulated sectors. For that reason, this article does not present an “average” price. It explains the scope factors that determine a usable quote.

Two reviews are not comparable unless their scope is comparable. A quote for a narrow documentation review and a quote for a review that includes transaction testing, agent sampling and validation of fixes are pricing different engagements, even if both are called an independent BSA/AML audit.

A more useful way to budget is to treat a quote as an estimate of four things:

  • how much evidence has to be gathered and tested;
  • how much of that work needs senior or specialist judgment;
  • how clean and complete your records are; and
  • how much reporting, discussion and follow-up the engagement includes.

The rest of this article breaks those down. ComplyFactor quotes after a scoping discussion and does not publish fixed prices, because a number given without the scope behind it would mislead.

What does FinCEN actually require?

Under 31 CFR § 1022.210(d)(4), an MSB’s AML program must provide for independent review to monitor and maintain an adequate program. The scope and frequency must be commensurate with the risk of the financial services provided. The review may be conducted by an officer or employee so long as the reviewer is not the person designated under paragraph (d)(2) to assure day-to-day compliance.

FinCEN’s guidance on these reviews (FIN-2006-G012) adds four points that matter for pricing:

  1. MSBs are not required to hire a CPA or an outside consultant. An officer, employee or group of employees may perform the review if the reviewer is not the designated compliance officer and does not report directly to that officer.
  2. The review should include testing of internal controls and transactional systems, and should cover the actions taken by, or assigned to, the designated compliance officer.
  3. Scope and frequency follow the MSB’s risk assessment. For some MSBs an annual review may not be necessary. A change in the risk assessment, or problems found in a prior review, may justify an earlier one.
  4. The reviewer should document the scope, procedures performed, transaction testing completed (if any), findings and recommendations.
    1. obtain the population and confirm it is complete, for example by reconciling it to system totals or filed reports;
    2. define a risk-based sample and record why it was selected;
    3. pull source records for each item and trace customer data, risk rating, alerts, decisions and filings;
    4. test timeliness, accuracy and retention against the applicable requirement;
    5. document every exception, investigate root cause and follow up with management; and
    6. write up findings with supporting evidence.

    • A clean, reconcilable transaction population
    • A complete and current AML manual
    • A current risk assessment
    • Documented history of prior testing
    • Organized SAR, CTR and case files
    • A current agent list
    • Access to system owners who can explain configuration
    • A prior-findings and remediation tracker
    • One central evidence location
    • An agreed scope before fieldwork starts

FinCEN does not publish a universal sample size or review calendar. That risk-based standard is the reason price varies so widely.

The biggest factors that drive BSA/AML audit cost

These are pricing drivers, not regulatory red flags. A driver raises cost because it adds work for the reviewer, not because it signals a compliance problem.

Cost driver Why it affects audit effort
Business model and product mix Money transmission, check cashing, currency exchange, prepaid access, virtual currency and payment services carry different reporting and recordkeeping requirements, so each adds its own test steps.
Transaction population Larger or more fragmented data sets take longer to extract, reconcile and sample. See the note below on why the effect is not linear.
Corridors, customers and risk profile Higher-risk exposures justify deeper targeted testing, because scope must be commensurate with risk.
Agent or authorized delegate network Agent onboarding, monitoring, training and termination files have to be sampled, and some providers visit or interview agents.
Monitoring and case-management systems Reviewers test rules, thresholds, tuning history, data feeds, access and change logs. Several systems multiply the work.
SAR, CTR and recordkeeping testing Each population has to be obtained, sampled, traced to source records and tested for timeliness and accuracy.
Virtual currency exposure (where applicable) Wallet data, blockchain analytics outputs and Travel Rule handling add data sources and test steps.
Prior findings and remediation Open or repeat findings require status review and evidence of closure.
Record and data quality Incomplete files, inconsistent exports and policies that do not match workflows cause rework and follow-up requests.
Number of legal entities or programs Each entity may have its own population, policies and systems to test.
Changes since the last review New products, corridors, agents or ownership changes alter the risk picture and what must be retested.
State-law or OFAC scope, if requested These are separate frameworks. If a quote includes them, treat them as added scope.

Volume and population size

Higher volume increases extraction, completeness checking and exception analysis. It does not mean the sample rises in proportion. Sample design is a judgment about what is needed to draw a supportable conclusion about a specific control, and FinCEN does not prescribe one. A reviewer may test a modest, well-targeted sample from a very large population, and a messy small population can cost more than a clean large one.

Agents and authorized delegates

A principal MSB and its agents are each responsible for their own AML compliance, and a contract that assigns responsibility to an agent does not remove the principal’s obligation (FinCEN guidance FIN-2016-G001). Where the program relies on agents, the reviewer has to test how they are onboarded, monitored, trained and terminated, which can add sampling, interviews and travel. Our article on authorized delegate oversight covers the controls themselves.

Systems, data and record quality

Reviewers cannot test what they cannot obtain. Poor exports, incomplete case files, missing training records, inconsistent agent files and policy-to-workflow mismatches all create follow-up requests and rework. Data quality can be a major swing factor between businesses that look similar on paper.

Virtual currency exposure

Where an MSB handles virtual currency, the review may need to address wallet information, monitoring calibrated to that activity, blockchain analytics outputs and applicable Travel Rule handling. That adds data sources and test steps. It does not automatically double the cost. A narrow pass-through product and a full trading platform are different engagements.

Footprint, entities and state-law scope

A federal § 1022.210 review is not a state money transmitter examination. A multi-state footprint may add business complexity, but state-law controls are part of a review only if the scope expressly includes them. If a quote includes them, that is added scope and should be priced and described separately. See our article on FinCEN registration and state licensing for the distinction.

Prior findings

Findings from a prior review, an examination or a banking partner add a status check for each item and often a focused look at repeat issues. FinCEN guidance notes that it may be advisable to advance the next review to confirm corrective action, so prior problems can change both timing and scope.

What transaction testing does to cost

Transaction testing can be one of the largest blocks of reviewer hours because it is where the review moves from reading policy to tracing what happened. For a given population, the reviewer typically has to:

Deeper SAR and CTR population testing increases hours because every one of those steps repeats for each population tested. More populations (alerts closed without a filing, transactions near reporting thresholds, agent activity, manual overrides) mean more repetitions.

There is no universal sample size. What matters for price is that the quote says how the sample will be determined and who selects it. For the detailed methodology, see the testing sections of our audit checklist.

Can an MSB reduce cost by using an internal reviewer?

Sometimes, if the MSB has a genuinely separate reviewer. The regulation and FinCEN guidance permit an officer, employee or group of employees to perform the review, provided the reviewer is not the designated compliance officer and does not report directly to that officer. External review is not legally superior. It is a commercial and capability choice.

Factor Qualified internal reviewer External reviewer
Direct cash cost Lower or none Fee for the engagement
Internal staff time Reviewer time is diverted from other work; training and tooling may be needed Staff time goes to document requests, interviews and follow-up
Independence Must be outside the compliance officer’s direct reporting line; hard to structure in very small teams Structurally clearer, but still needs an assessment of any prior work for the business
Specialist expertise Depends on the individual’s MSB and BSA/AML depth Can bring MSB-specific and system-specific experience
Bank, investor or acquirer expectations May not satisfy a counterparty that expects outside validation Often what such counterparties ask for, though requirements vary
Documentation quality Varies with experience and time Often structured for third-party readers
Remediation follow-through Close to the business, but can be deprioritized Depends on how follow-up is scoped

Why some businesses buy external review anyway. Reasons include banking-partner diligence, investor or acquirer diligence, prior findings, examination readiness and contractual expectation. These are commercial drivers and not federal requirements. An external review does not guarantee bank onboarding, and it does not protect against penalties.

Independence and cost

Independence shapes who can be hired and what else they have done for you. In a 2014 civil money penalty assessment, FinCEN described as a conflict of interest an MSB’s reliance on one consultant that created its written AML program, performed its only independent testing and supplied its only training. Where an adviser built or materially revised the program, independence should be assessed before that same firm conducts the review.

ComplyFactor assesses reviewer independence during scoping. Where it has advised on a client’s program design, that work is kept separate from any later independent review, and no one who helped design or revise the program is assigned to review it. The same person cannot run the program and independently review it. See our article on fractional BSA officers and independent reviewers and our fractional BSA/AML officer service for the distinction between ongoing officer coverage and independent testing.

How independent reviews are priced

Providers use different structures, and not every provider uses every one. We have not established which is most common, so treat the table as a menu of options to discuss and not as a description of the market.

Pricing model Best suited to Tradeoffs
Fixed project fee Population, systems, locations, agents and review period are known and stable Needs a tight scope and written assumptions. Changes become change orders.
Hourly or time-and-materials (often with an estimate or cap) Uncertain scope, exploratory work, validation of fixes Less budget certainty. Ask about caps, hour reporting and seniority mix.
Day rate Fieldwork-heavy work such as agent visits or system walkthroughs Travel and expenses are usually separate. The deliverable must be defined elsewhere.
Base scope plus add-ons Multi-product businesses where state-law, OFAC or crypto modules are optional You must compare what counts as “base” across providers.
Phased engagement Large or uncertain programs, or businesses with prior findings Several scopes of work. Total cost is less predictable up front, but data problems surface early.
Separate retest or validation fee Businesses expecting findings that need confirmation of fixes Confirm whether retesting is included and on what timeline.

What should an audit quote include?

A low quote with vague scope may not be comparable to a higher quote that covers transaction testing, agents and validation of fixes. Neither is necessarily wrong. Ask each provider to state:

Quote item What to look for
Legal entities and MSB activities covered Which entities and which activities (for example transmission, exchange, prepaid access, virtual currency) are in scope.
Review period The dates covered and what happens to activity after the period ends.
Regulations and control areas Which requirements are tested, and whether OFAC or state-law controls are in or out.
Transaction population and methodology Which populations are tested, how completeness is checked and how the sample size is determined.
Who selects samples The reviewer should control selection.
Agents and delegates Whether agent files, monitoring and training are sampled, and whether visits are included.
Systems Whether rules, configuration, data feeds and access or change controls are tested or only described.
Interviews, fieldwork and travel What is on-site or remote, and who pays travel.
Report and findings rating The deliverable, how findings are rated and whether recommendations are included.
Management discussion Whether a readout before finalization is included.
Remediation and retesting Whether they are included or separate, and how independence is protected if the same firm offers both.
Who performs the work Seniority mix, and whether the people who scope the work are the people who do it.
Exclusions and assumptions What is left out and what must be true for the price to hold.

What can reduce the cost without reducing scope?

Preparation removes wasted reviewer time. It should never be used to justify narrowing the review below what the risk profile requires.

What to have ready before you request a quote

These are scoping inputs, not the evidence the reviewer will later test. For the testing evidence, see the checklist.

Scoping input Why the reviewer needs it
Legal entities and MSB type Defines which requirements and programs are in scope.
Business model and products Determines which control areas and recordkeeping rules apply.
States of operation Shows footprint and whether state-law scope is being requested.
Customer base and corridors Drives risk-based testing depth.
Transaction volumes and populations Sizes extraction and sampling work.
Agent count and structure Sizes agent testing and any fieldwork.
Virtual currency exposure Adds data sources and test steps where applicable.
SAR and CTR volumes Sizes filing and recordkeeping tests.
Monitoring and case-management tools Determines systems testing needed.
Date and scope of the prior review Sets the period and the change to be tested.
Prior findings and open items Adds status and closure checks.
Examiner or bank requests received May shape scope and timing.
Desired review period and deadline Sets the window and scheduling.

Illustrative scoping scenarios

These are hypothetical profiles to show how scope moves. They are not clients and carry no prices.

Illustrative profile What increases or decreases scope Workstreams that matter most Likely pricing model
A. Small single-entity MSB, straightforward operations One entity, few products and low volume reduce scope. Clean, organized records reduce it further. Program and risk assessment, limited SAR and CTR sample, training, recordkeeping Fixed fee is often workable. An internal reviewer may be feasible if truly separate.
B. Growing multi-state money transmitter New states, corridors and recent growth raise scope. A recently updated risk assessment helps. Risk assessment refresh, monitoring configuration, sampled populations, changes since the last review Fixed fee with optional add-ons for state-law or OFAC modules
C. Remittance MSB with a large agent network Agent count, geographic spread and uneven agent files raise scope. Agent onboarding, monitoring, training and termination testing; agent sampling method Base scope plus agent module; day rate for fieldwork
D. Crypto or digital-asset MSB Complex monitoring, wallet data and multiple data sources raise scope where applicable. Monitoring calibration, wallet and blockchain analytics outputs, Travel Rule handling, data extraction Phased or fixed fee gated on data readiness; hourly where scope is uncertain
E. MSB with prior findings Open or repeat findings add status review and validation. Findings status, closure evidence, repeat-issue analysis Separate retest or validation scope

Audit, remediation and retesting are different scopes

An independent review identifies findings. Remediation fixes them. Retesting or validation checks whether the fixes work. FinCEN guidance says the reviewer or the designated compliance officer should track deficiencies and document corrective actions after a review, which is different from designing the fixes. Quotes often treat validation of remediation as a separate scope, so confirm whether it is included.

Advisory remediation is separate work. See compliance remediation services for findings from a review, examiner or partner, and BSA/AML compliance program services where the program itself needs to be rebuilt. A firm that designs or implements a fix should not be the one to independently test that same work without a separate independence assessment.

2026 AML/CFT program rulemaking: does it change audit pricing yet?

No. On April 7, 2026, FinCEN issued a notice of proposed rulemaking (Docket FINCEN-2026-0034) to revise AML/CFT program requirements across covered financial institutions, including MSBs. It was published in the Federal Register on April 10, 2026, comments closed June 9, 2026, and it supersedes and withdraws FinCEN’s July 2024 proposal.

FinCEN’s fact sheet says the proposal would keep the independent testing requirement and clarify that testing should assess compliance, focus on program effectiveness, use objective criteria, be performed by parties truly independent of the AML/CFT function and avoid conflicts of interest. FinCEN proposed a 12-month implementation period after a final rule. We found no final rule as of October 1, 2026.

A proposal is not current law. This article is based on § 1022.210(d)(4) and FinCEN’s existing guidance. If a final rule changes the scope of independent testing, it could affect what a review includes and therefore what it costs. That is worth building flexibility for in multi-year engagements, but it cannot yet be quantified.

How ComplyFactor supports independent BSA/AML reviews

ComplyFactor’s BSA/AML audit services scope each independent review around the client’s actual business model and risk profile rather than a fixed template, covering the applicable controls, testing population, systems, agents and prior issues. A written scope of work is agreed before testing begins, and the document request is confirmed during scoping. Engagements end with a documented scope and testing summary, a findings matrix prioritized by severity, a written report, corrective-action recommendations and a management discussion before the report is finalized.

Pricing is scope-based and quoted after that conversation. For broader consulting, see our U.S. AML consulting hub. Nothing here guarantees a particular examination, banking or audit outcome.

Frequently asked questions

Should we collect more than one quote, and how do we compare them?

Yes where practical. Give each provider the same scoping inputs and ask for written assumptions. Compare line by line before comparing totals: population, sampling approach, agents, systems, state or OFAC add-ons and retesting. Do not treat a lower quote as equivalent if it leaves out transaction testing or agents, and do not assume a higher one includes them.

Can we lower cost by reviewing less often?

Frequency is set by risk, not budget. FinCEN guidance says an annual review may not be necessary for some MSBs, but also that a change in the risk assessment or problems found in a prior review can justify an earlier one. Document the rationale in the program. Longer gaps can also mean more activity and change to test in a single review, and a banking partner may set its own cadence.

Can one report serve the federal requirement, a bank request and a state examination?

It can, if the scope covers each. A § 1022.210(d)(4) review does not automatically cover state licensing requirements, OFAC screening (a separate legal framework) or a bank’s own questionnaire. Ask the provider to map each test to the requirement it supports and to price the extra modules separately.

What happens to the price if the reviewer finds our records are incomplete?

That depends on the quote terms. A fixed fee rests on stated assumptions, so ask before signing what happens when an assumption fails: a change order, a pause while records are fixed, or time-and-materials for the extra work. Raising data gaps at scoping is cheaper than discovering them in fieldwork.

Can our team assemble the evidence without compromising independence?

Yes. Management can produce, organize and explain documents and exports. The reviewer should define and control the population, select the samples, verify completeness against source systems and reach conclusions without direction from the designated compliance officer. The compliance officer cannot be the reviewer and the reviewer should not report directly to that officer.

Need a scoped view of what your review would involve? Discuss your BSA/AML audit scope with ComplyFactor. We confirm the relevant risks, scope and timing before anything begins.

ComplyFactor Advisory Team

ComplyFactor specializes in FINTRAC MSB and PSP registration, independent AML effectiveness reviews, and compliance program design for Canadian and foreign money services businesses, payment service providers, fintechs, and virtual asset service providers.

Get started

Book a free Canada AML consultation

Tell us about your business and we'll confirm which services you need — free, no obligation, 30 minutes.

Free, no obligation, 30 minutes
Senior consultant on every engagement
Aligned with PCMLTFA & FINTRAC standards
+1 807 806 0444 · Suite 211, 320 Matheson Blvd West, Mississauga, ON

Talk to an AML expert

Thank you. Your message has been received — we'll be in touch within one business day.
Something went wrong while submitting the form. Please try again.