ComplyFactor provides BSA audit and AML audit services for U.S. Money Services Businesses, money transmitters, remittance companies, payment businesses, and virtual-currency businesses subject to the Bank Secrecy Act. Under 31 CFR Β§ 1022.210(d)(4), every MSB's AML program must include an independent review β testing performed by someone other than the person designated as your day-to-day compliance officer.
We test whether your program works in practice, not just whether the policy binder exists: how alerts actually get escalated, how due diligence is actually documented, and where the real gaps are β scoped to your money-transmission model and risk profile rather than a generic template.
Independent review is one of the minimum elements every U.S. MSB's AML program must include β testing performed by someone other than your designated compliance officer, with scope and frequency set by your own risk assessment.
ComplyFactor performs independent BSA/AML review and testing engagements for U.S. MSBs, money transmitters, remittance companies, and payment businesses β with scope built around the client's business model and risk profile rather than a fixed template. BSA audit and AML audit are the terms most businesses search for β some also describe it as an anti-money laundering audit β but the regulatory term that applies to MSBs is independent review, sometimes called independent testing. 31 CFR Β§ 1022.210(d)(4) requires it as one of the minimum elements of an MSB's AML program. The regulation itself sets one clear rule: the reviewer cannot be the person designated under paragraph (d)(2) as responsible for day-to-day compliance.
FinCEN's guidance on conducting these reviews (FIN-2006-G012) adds a further expectation: the reviewer also should not report directly to that compliance officer, and the review should test internal controls and how transactions are actually handled β not just confirm that a policy document exists.
Scope reflects your license type, products, and risk profile β not every item applies identically to every business. It's shaped by your money-transmission model: direct customers or an agent network, which corridors and currencies you handle, whether virtual-currency activity is involved, your transaction volume, and which reporting obligations actually apply to you.
We assess whether the written AML program, internal controls and compliance-officer function align with actual day-to-day practice, not just the policy document.
Our review assesses whether the current risk framework reflects your business model, products, corridors, and geographic exposure β not a stale document from onboarding.
Testing covers customer identification, verification, and risk-based customer controls where applicable to the MSB's activities and specific BSA obligations.
Our review extends to transaction monitoring and suspicious-activity escalation, plus applicable SAR, CTR, and other reporting and recordkeeping requirements.
Training content and completion records are reviewed, along with agent or authorized-delegate oversight where relevant to your business model.
We test actual implementation against written policy, review the status of prior findings, and assess OFAC/sanctions controls where relevant and included in the agreed scope.
Every MSB must arrange periodic independent review under 31 CFR Β§ 1022.210(d)(4). FinCEN guidance confirms there's no fixed interval β the right frequency depends on the business's own risk assessment; for some businesses an annual review isn't necessary, for others more frequent review is appropriate. Beyond that baseline legal requirement, most engagements are triggered commercially:
Periodic review under applicable MSB AML program requirements β the one legal baseline behind every engagement.
A current review requested during onboarding or periodic relationship review by a sponsor bank or payment partner.
New products, corridors, transaction volume, agents, or a material change to the business model.
Prior findings needing remediation evidence, examination readiness, or investor/acquirer/partner due diligence.
These commercial triggers aren't independently mandated by federal rule β the underlying legal requirement is the periodic review itself.
If your business is approaching an independent-review deadline, responding to partner due diligence, or preparing after a material change, ComplyFactor can scope the review around the risks and testing areas that actually apply.
We confirm the products, corridors, licensing profile and risk factors that determine testing depth.
We request the policies, prior reviews, risk assessment, training records and other material required for the agreed scope.
Our review includes interviews with relevant compliance and operational personnel and testing of applicable controls.
Transaction or sample testing is performed where appropriate to the agreed scope and risk profile.
We assess the significance and root cause of identified issues rather than simply listing observations.
We discuss findings with management before finalizing the written report.
The engagement concludes with documented scope, procedures performed, findings and recommendations that can support management, banking-partner, and regulatory review.
Depending on the agreed scope, business model and risk profile, an independent review may identify issues such as:
These are different services. BSA/AML consulting and advisory work helps you build, improve, or remediate a program β writing policies, designing controls, or fixing issues a review identified. Independent testing assesses whether the program you already have works as designed.
There's no single timeline, and any number quoted without qualification should be treated with caution. Review time depends on factors including:
Not a generalist accounting or law firm β AML/BSA is the whole practice.
Testing built around your money-transmission model, not a retail-bank template.
Independence assessed during scoping, in line with applicable requirements and FinCEN guidance.
A written report with prioritized recommendations your team, bank, or examiner can actually act on.
There's no fixed interval that applies to every MSB. FinCEN guidance ties frequency to your own risk assessment β for some businesses an annual review isn't necessary, for others more frequent review is appropriate, particularly after a risk profile change or if a prior review found problems.
The regulation's only requirement is that the reviewer isn't the designated compliance officer. FinCEN guidance goes further and says the reviewer also shouldn't report directly to that officer. ComplyFactor applies a stricter standard still, and doesn't assign anyone who helped design or revise the program to review it.
No. An independent BSA/AML audit is a private review your business commissions; a FinCEN or state examination is conducted by a regulator with statutory authority. A well-documented independent review is commonly requested as part of the examination process, but it isn't a substitute for one.
FinCEN guidance expects the review to test internal controls and how transactions and procedures actually operate, and documentation should record the transaction testing completed, if any. There's no fixed universal sample size β the extent of sampling is set by the agreed scope and your risk profile.
Many sponsor banks and payment partners request a current independent review as part of onboarding or periodic due diligence, though exact requirements vary by partner. This is a banking-relationship expectation rather than something the federal rule itself dictates.
Typically your written AML policies and procedures, prior AML audits or examination reports, current risk assessment, training records, and a sample of transaction and case data for testing. The exact document request is confirmed during scoping.
Tell us about your business model, the reason for the review, and your current AML program β we'll confirm the relevant risks, scope, and timing before anything begins.