home
/
services
/
us
/
U.S. BSA/AML β€’ FinCEN β€’ 31 CFR Β§ 1022.210

BSA/AML Compliance Program Services

ComplyFactor designs and strengthens risk-based BSA/AML compliance programs for U.S. Money Services Businesses, fintechs, payment companies, and remittance and digital-asset businesses. The program should reflect how funds actually move through the business, who its customers are, where it operates, and which risks actually drive its controls β€” not a starting point borrowed from somewhere else.

Whether you're building a program from scratch, updating one that hasn't kept pace with growth, or responding to gaps a review identified, we scope the work around what your business actually does.

No single nationwide license

31 CFR Β§ 1022.210(d)(4)

Independent review is one of the minimum elements every U.S. MSB's AML program must include β€” testing performed by someone other than your designated compliance officer, with scope and frequency set by your own risk assessment.

The service

BSA/AML Program Design, Enhancement and Remediation

Program work generally starts from one of three places: a new business building its first program, an existing business whose program hasn't kept up with its growth or its risk, or a business responding to findings from a prior review. ComplyFactor supports all three β€” assessing where the program stands today, building or rewriting the components that need it, and helping put the result into practice rather than leaving it as a document nobody actually uses.

Three starting points

New program Β· Program enhancement Β· Gap remediation. Every engagement begins at one of these three, scoped to where your business actually stands.
The concept

What Is a BSA/AML Compliance Program?

A BSA/AML compliance program is the set of policies, procedures, and controls a business uses to detect and prevent money laundering and related financial crime, built around its own risk assessment rather than a generic template. For MSBs, 31 CFR Β§ 1022.210 sets out four minimum elements: written policies and procedures, a designated compliance officer, an ongoing training program, and independent review. The regulation states the minimum elements; it doesn't supply the content β€” that's built around the business's actual products, customers, and geography.

An effective anti money laundering compliance program translates that risk assessment into practical policies, controls, training, and review procedures β€” not a document that sits separately from how the business actually operates.

Four minimum elements

Written policies & procedures Β· Designated compliance officer Β· Ongoing training Β· Independent review. All four required; none of them pre-written for you.
What shapes it

BSA/AML Program Requirements for U.S. MSBs

What a program needs to actually cover depends on the business behind it. A single-location check casher, a multi-corridor remittance company with sub-agents, and a virtual-currency exchange are all MSBs, and none of them need an identical program.

MSB Category

Category and licensed activities.

Products & Corridors

Products and payment corridors offered.

Customer Base & Channel

In-person, online, or agent network.

Geographic Footprint

Including any foreign exposure.

Transaction Volume & Risk

Volume and the risk it carries.

No Fill-in-the-Blank Template

FinCEN doesn't publish one β€” the risk assessment determines which controls the program actually needs.

Scope

Not every engagement includes every item below in the same form β€” scope reflects what your program actually needs, not a fixed package.

Business-Specific Risk
Assessment

Built around your products, customers, and geography.

Written Policies &
Procedures

The documented core of the program.

Internal Controls
Design

How the policies actually get enforced day to day.

Monitoring, Reporting & Recordkeeping

Responsibilities and reporting lines within the business.

Training & Agent
Oversight

Role-relevant, not generic, content.

Independent-Review
Readiness

Built to withstand the separate testing function.

Monitoring & SAR Procedures

Transaction monitoring and suspicious-activity procedures, where applicable.

Recordkeeping & Reporting

Procedures for applicable filings and records.

Customer Identification

Due-diligence processes, where applicable.

OFAC/Sanctions Integration

Screening integration, where relevant.

Two paths

Building New vs. Strengthening Existing

New

Building a New AML Compliance Program

A first program usually comes from one of a few situations: a business newly registering as an MSB, a business entering a regulated activity for the first time, or a product launch that brings a company within FinCEN's MSB definitions. Starting from the risk assessment, rather than a boilerplate document, keeps the resulting program sized to what the business actually does.
vs
Existing

How We Strengthen an Existing BSA/AML Program

Programs age faster than businesses expect. A policy written for one product line doesn't automatically cover the next one; a risk assessment from three states ago doesn't reflect ten. Common triggers include new products or geographies, transaction-volume growth, staff or ownership changes, and findings from a banking partner, examiner, or independent review.
Advisory work

A gap assessment reviews the current program against how the business actually operates, identifies where the two have drifted apart, and prioritizes findings by risk rather than treating every gap as equally urgent.

Current Program

Where it stands today

Gap Assessment

Reviewed against actual operations

Prioritized Findings

Ranked by risk

Remediation Roadmap

A sequence for fixing them

Implementation Support

Where agreed

This is advisory work and is separate from the independent testing required under 31 CFR Β§ 1022.210(d)(4). Where both services are needed, reviewer independence is addressed during engagement scoping. See Independent BSA/AML Audit Services.

How it works

Our BSA/AML Program Development Process

typical engagement timeline
Built from the risk assessment up
Policies, procedures and controls mapped to your business model
01

Business & Risk-Profile Review

Understanding the business behind the program.

02

Risk Assessment

New or updated, depending on scope.

03

Policy & Control Design or Revision

Building or rewriting what the risk assessment calls for.

04

Training Framework Development

Content matched to actual roles.

05

Management Review & Sign-Off

Reviewed with your team before finalization.

06

Implementation Support

Where agreed as part of the engagement.

Deliverables

What You Receive From Your BSA/AML Program Engagement

Written Risk Assessment
The foundation the rest of the program is built on.
Policies & Procedures
The documented program itself.
Compliance Framework Documentation
Governance and responsibilities set out clearly.
Remediation Roadmap
Where a gap assessment is in scope.
Implementation Recommendations
Practical next steps for putting the program into practice.
Training Framework
Ready for delivery to relevant staff.

Deliverables are scoped to the engagement β€” a new-program build and a targeted policy update don't produce the same set of documents.

Timing

There's no fixed renewal date FinCEN attaches to a program document the way there is for MSB registration. In practice, a program is due for review when the business has changed in ways the written program hasn't caught up with:

New products
New geographies
Transaction-volume changes
Compliance leadership changes
Partner-bank findings
Independent-review findings

Many businesses choose an internal review cadence so program updates aren't triggered only by an external request or finding.

The difference

Why Work With ComplyFactor for BSA/AML Program Support

Programs Built Around MSB Risk

Shaped by how the business actually operates.

Specialist BSA/AML Support

Focused on program design, enhancement and remediation.

Independent-Review Readiness

Built in from the start, not bolted on later.

Coordinated Compliance Work

Aligned with the compliance-officer and registration work alongside it.

faq

FAQs

What are the minimum elements of an MSB AML compliance program?

31 CFR Β§ 1022.210 sets four minimum elements: written policies and procedures, a designated compliance officer, ongoing training, and independent review. The specific content of each is shaped by the business's own risk assessment, not a fixed checklist.

Is an AML gap assessment the same as an independent BSA/AML audit?

No. A gap assessment is advisory β€” it reviews the program and helps fix what it finds. Independent review under 31 CFR Β§ 1022.210(d)(4) is a separate testing function performed at arm's length, and the two aren't interchangeable even when both apply to the same business.

Can ComplyFactor build a BSA/AML program from scratch?

Yes. ComplyFactor can build a BSA/AML program from scratch or enhance and remediate an existing program.

Can you update only part of our existing AML program?

Yes. The engagement can be scoped to specific policies, controls, a risk-assessment update, or another agreed area, rather than requiring a full rebuild.

What information does ComplyFactor need to review an existing AML program?

Typically the current written program and risk assessment, a description of products and customer base, transaction volume, and any recent findings from a partner, examiner, or prior review. The exact scoping request depends on what the engagement covers.

Can BSA/AML program support be coordinated with FinCEN MSB registration?

Yes. These are separate requirements β€” one is a program you build and maintain, the other is a federal filing β€” but they can be coordinated, particularly for a business registering for the first time. ComplyFactor's FinCEN MSB Registration Services cover the federal filing itself. See FinCEN MSB Registration Services.

Does implementation support form part of the engagement?

Implementation support may be included where it's agreed as part of the engagement scope β€” it isn't automatically included in every program engagement by default.

Get started

Discuss Your BSA/AML Program With Our Team

Tell us whether you need a new program, an enhancement, or remediation after a review β€” we support U.S. MSBs, fintechs, and payment businesses at any of those stages.

New program build or existing program enhancement
Gap assessment with a prioritized remediation roadmap
Scoped to your business, not a fixed package

Book a U.S. AML consultation

Thank you. Your message has been received β€” we'll be in touch within one business day.
Something went wrong while submitting the form. Please try again.