home
/
services
/
U.S. BSA/AML β€’ FinCEN β€’ 31 CFR Β§ 1022.210

BSA/AML Audit Services

ComplyFactor provides BSA audit and AML audit services for U.S. Money Services Businesses, money transmitters, remittance companies, payment businesses, and virtual-currency businesses subject to the Bank Secrecy Act. Under 31 CFR Β§ 1022.210(d)(4), every MSB's AML program must include an independent review β€” testing performed by someone other than the person designated as your day-to-day compliance officer.

We test whether your program works in practice, not just whether the policy binder exists: how alerts actually get escalated, how due diligence is actually documented, and where the real gaps are β€” scoped to your money-transmission model and risk profile rather than a generic template.

No single nationwide license

31 CFR Β§ 1022.210(d)(4)

Independent review is one of the minimum elements every U.S. MSB's AML program must include β€” testing performed by someone other than your designated compliance officer, with scope and frequency set by your own risk assessment.

The terminology

How ComplyFactor Delivers BSA/AML Audit Services for U.S. MSBs

ComplyFactor performs independent BSA/AML review and testing engagements for U.S. MSBs, money transmitters, remittance companies, and payment businesses β€” with scope built around the client's business model and risk profile rather than a fixed template. BSA audit and AML audit are the terms most businesses search for β€” some also describe it as an anti-money laundering audit β€” but the regulatory term that applies to MSBs is independent review, sometimes called independent testing. 31 CFR Β§ 1022.210(d)(4) requires it as one of the minimum elements of an MSB's AML program. The regulation itself sets one clear rule: the reviewer cannot be the person designated under paragraph (d)(2) as responsible for day-to-day compliance.

FinCEN's guidance on conducting these reviews (FIN-2006-G012) adds a further expectation: the reviewer also should not report directly to that compliance officer, and the review should test internal controls and how transactions are actually handled β€” not just confirm that a policy document exists.

ComplyFactor's standard

Reviewer independence is assessed during engagement scoping in line with applicable requirements and FinCEN guidance. Where ComplyFactor has also advised on a client's program design, that scope is kept separate from any later independent review of the same program.
Scope

Scope reflects your license type, products, and risk profile β€” not every item applies identically to every business. It's shaped by your money-transmission model: direct customers or an agent network, which corridors and currencies you handle, whether virtual-currency activity is involved, your transaction volume, and which reporting obligations actually apply to you.

Program & Governance

We assess whether the written AML program, internal controls and compliance-officer function align with actual day-to-day practice, not just the policy document.

BSA/AML Risk Assessment

Our review assesses whether the current risk framework reflects your business model, products, corridors, and geographic exposure β€” not a stale document from onboarding.

Customer Controls

Testing covers customer identification, verification, and risk-based customer controls where applicable to the MSB's activities and specific BSA obligations.

Monitoring, Reporting & Recordkeeping

Our review extends to transaction monitoring and suspicious-activity escalation, plus applicable SAR, CTR, and other reporting and recordkeeping requirements.

Training & Agent Oversight

Training content and completion records are reviewed, along with agent or authorized-delegate oversight where relevant to your business model.

Testing & Remediation

We test actual implementation against written policy, review the status of prior findings, and assess OFAC/sanctions controls where relevant and included in the agreed scope.

Who needs this

Who Needs a BSA/AML Audit

Every MSB must arrange periodic independent review under 31 CFR Β§ 1022.210(d)(4). FinCEN guidance confirms there's no fixed interval β€” the right frequency depends on the business's own risk assessment; for some businesses an annual review isn't necessary, for others more frequent review is appropriate. Beyond that baseline legal requirement, most engagements are triggered commercially:

Regulatory Independent Review

Periodic review under applicable MSB AML program requirements β€” the one legal baseline behind every engagement.

Banking & Payment Partner Due Diligence

A current review requested during onboarding or periodic relationship review by a sponsor bank or payment partner.

Business Change or
Growth

New products, corridors, transaction volume, agents, or a material change to the business model.

Findings, Examination & Due Diligence

Prior findings needing remediation evidence, examination readiness, or investor/acquirer/partner due diligence.

These commercial triggers aren't independently mandated by federal rule β€” the underlying legal requirement is the periodic review itself.

If your business is approaching an independent-review deadline, responding to partner due diligence, or preparing after a material change, ComplyFactor can scope the review around the risks and testing areas that actually apply.

How it works

Our BSA Audit Process

01

Scope & Risk Review

We confirm the products, corridors, licensing profile and risk factors that determine testing depth.

02

Document Request

We request the policies, prior reviews, risk assessment, training records and other material required for the agreed scope.

03

Interviews & Control Testing

Our review includes interviews with relevant compliance and operational personnel and testing of applicable controls.

04

Transaction / Sample Testing

Transaction or sample testing is performed where appropriate to the agreed scope and risk profile.

05

Findings Analysis

We assess the significance and root cause of identified issues rather than simply listing observations.

06

Management Discussion & Finalization

We discuss findings with management before finalizing the written report.

Deliverables

What You Receive From Our BSA/AML Audit

Scope & Testing Summary
Documented scope of the review and a summary of the procedures and testing performed.
Findings Matrix
Findings prioritized by severity, so nothing in the final report is a surprise.
Final Written Report
A documented record of scope, procedures performed, findings, and recommendations.
Corrective-Action Recommendations
Practical, prioritized recommendations, where appropriate to the findings.
Close-Out Discussion
A management discussion to walk through the report before the engagement closes.

The engagement concludes with documented scope, procedures performed, findings and recommendations that can support management, banking-partner, and regulatory review.

What we see

Depending on the agreed scope, business model and risk profile, an independent review may identify issues such as:

#
Scenario
What's typically needed
01
Outdated risk assessment
Not updated after a product, corridor, or volume change.
02
Policy-practice gap
Written policies that no longer match actual operations.
03
Weak alert escalation
Alerts generated but not consistently escalated or documented.
04
Incomplete recordkeeping
Gaps across products or agents.
05
Weak training evidence
Records that don't evidence role-specific content.
06
Unresolved prior findings
Left open with no documented remediation.
The distinction

Independent Testing vs. BSA/AML Consulting

These are different services. BSA/AML consulting and advisory work helps you build, improve, or remediate a program β€” writing policies, designing controls, or fixing issues a review identified. Independent testing assesses whether the program you already have works as designed.

Looking for broader AML consulting?

ComplyFactor's consulting services β€” program design, gap remediation, and FinCEN registration support β€” are covered on our U.S. AML consulting hub. This page is specifically about the independent review function. Related: BSA/AML Compliance Program, Fractional BSA/AML Officer, FinCEN MSB Registration.
The difference

There's no single timeline, and any number quoted without qualification should be treated with caution. Review time depends on factors including:

Specialist BSA/AML Focus

Not a generalist accounting or law firm β€” AML/BSA is the whole practice.

MSB-Specific Scope

Testing built around your money-transmission model, not a retail-bank template.

Independent-Review Methodology

Independence assessed during scoping, in line with applicable requirements and FinCEN guidance.

Documented Findings

A written report with prioritized recommendations your team, bank, or examiner can actually act on.

faq

FAQs

How often should independent BSA/AML testing be performed?

There's no fixed interval that applies to every MSB. FinCEN guidance ties frequency to your own risk assessment β€” for some businesses an annual review isn't necessary, for others more frequent review is appropriate, particularly after a risk profile change or if a prior review found problems.

Can the same consultant who built our AML program perform the independent review?

The regulation's only requirement is that the reviewer isn't the designated compliance officer. FinCEN guidance goes further and says the reviewer also shouldn't report directly to that officer. ComplyFactor applies a stricter standard still, and doesn't assign anyone who helped design or revise the program to review it.

Is a BSA audit the same as a regulatory examination?

No. An independent BSA/AML audit is a private review your business commissions; a FinCEN or state examination is conducted by a regulator with statutory authority. A well-documented independent review is commonly requested as part of the examination process, but it isn't a substitute for one.

Does independent BSA/AML testing require transaction sampling?

FinCEN guidance expects the review to test internal controls and how transactions and procedures actually operate, and documentation should record the transaction testing completed, if any. There's no fixed universal sample size β€” the extent of sampling is set by the agreed scope and your risk profile.

Will a banking partner ask to see the independent review?

Many sponsor banks and payment partners request a current independent review as part of onboarding or periodic due diligence, though exact requirements vary by partner. This is a banking-relationship expectation rather than something the federal rule itself dictates.

What information will we need to provide?

Typically your written AML policies and procedures, prior AML audits or examination reports, current risk assessment, training records, and a sample of transaction and case data for testing. The exact document request is confirmed during scoping.

Get started

Discuss Your BSA/AML Audit With Our Team

Tell us about your business model, the reason for the review, and your current AML program β€” we'll confirm the relevant risks, scope, and timing before anything begins.

Risk-based scope, built around your business model
Written scope of work agreed before testing begins
Documented final report with findings and recommendations

Book a U.S. AML consultation

Thank you. Your message has been received β€” we'll be in touch within one business day.
Something went wrong while submitting the form. Please try again.