ComplyFactor designs and strengthens risk-based BSA/AML compliance programs for U.S. Money Services Businesses, fintechs, payment companies, and remittance and digital-asset businesses. The program should reflect how funds actually move through the business, who its customers are, where it operates, and which risks actually drive its controls β not a starting point borrowed from somewhere else.
Whether you're building a program from scratch, updating one that hasn't kept pace with growth, or responding to gaps a review identified, we scope the work around what your business actually does.
Independent review is one of the minimum elements every U.S. MSB's AML program must include β testing performed by someone other than your designated compliance officer, with scope and frequency set by your own risk assessment.
Program work generally starts from one of three places: a new business building its first program, an existing business whose program hasn't kept up with its growth or its risk, or a business responding to findings from a prior review. ComplyFactor supports all three β assessing where the program stands today, building or rewriting the components that need it, and helping put the result into practice rather than leaving it as a document nobody actually uses.
A BSA/AML compliance program is the set of policies, procedures, and controls a business uses to detect and prevent money laundering and related financial crime, built around its own risk assessment rather than a generic template. For MSBs, 31 CFR Β§ 1022.210 sets out four minimum elements: written policies and procedures, a designated compliance officer, an ongoing training program, and independent review. The regulation states the minimum elements; it doesn't supply the content β that's built around the business's actual products, customers, and geography.
An effective anti money laundering compliance program translates that risk assessment into practical policies, controls, training, and review procedures β not a document that sits separately from how the business actually operates.
What a program needs to actually cover depends on the business behind it. A single-location check casher, a multi-corridor remittance company with sub-agents, and a virtual-currency exchange are all MSBs, and none of them need an identical program.
Category and licensed activities.
Products and payment corridors offered.
In-person, online, or agent network.
Including any foreign exposure.
Volume and the risk it carries.
FinCEN doesn't publish one β the risk assessment determines which controls the program actually needs.
Not every engagement includes every item below in the same form β scope reflects what your program actually needs, not a fixed package.
Built around your products, customers, and geography.
The documented core of the program.
How the policies actually get enforced day to day.
Responsibilities and reporting lines within the business.
Role-relevant, not generic, content.
Built to withstand the separate testing function.
Transaction monitoring and suspicious-activity procedures, where applicable.
Procedures for applicable filings and records.
Due-diligence processes, where applicable.
Screening integration, where relevant.
A gap assessment reviews the current program against how the business actually operates, identifies where the two have drifted apart, and prioritizes findings by risk rather than treating every gap as equally urgent.
Where it stands today
Reviewed against actual operations
Ranked by risk
A sequence for fixing them
Where agreed
This is advisory work and is separate from the independent testing required under 31 CFR Β§ 1022.210(d)(4). Where both services are needed, reviewer independence is addressed during engagement scoping. See Independent BSA/AML Audit Services.
Understanding the business behind the program.
New or updated, depending on scope.
Building or rewriting what the risk assessment calls for.
Content matched to actual roles.
Reviewed with your team before finalization.
Where agreed as part of the engagement.
Deliverables are scoped to the engagement β a new-program build and a targeted policy update don't produce the same set of documents.
There's no fixed renewal date FinCEN attaches to a program document the way there is for MSB registration. In practice, a program is due for review when the business has changed in ways the written program hasn't caught up with:
Many businesses choose an internal review cadence so program updates aren't triggered only by an external request or finding.
Shaped by how the business actually operates.
Focused on program design, enhancement and remediation.
Built in from the start, not bolted on later.
Aligned with the compliance-officer and registration work alongside it.
31 CFR Β§ 1022.210 sets four minimum elements: written policies and procedures, a designated compliance officer, ongoing training, and independent review. The specific content of each is shaped by the business's own risk assessment, not a fixed checklist.
No. A gap assessment is advisory β it reviews the program and helps fix what it finds. Independent review under 31 CFR Β§ 1022.210(d)(4) is a separate testing function performed at arm's length, and the two aren't interchangeable even when both apply to the same business.
Yes. ComplyFactor can build a BSA/AML program from scratch or enhance and remediate an existing program.
Yes. The engagement can be scoped to specific policies, controls, a risk-assessment update, or another agreed area, rather than requiring a full rebuild.
Typically the current written program and risk assessment, a description of products and customer base, transaction volume, and any recent findings from a partner, examiner, or prior review. The exact scoping request depends on what the engagement covers.
Yes. These are separate requirements β one is a program you build and maintain, the other is a federal filing β but they can be coordinated, particularly for a business registering for the first time. ComplyFactor's FinCEN MSB Registration Services cover the federal filing itself. See FinCEN MSB Registration Services.
Implementation support may be included where it's agreed as part of the engagement scope β it isn't automatically included in every program engagement by default.
Tell us whether you need a new program, an enhancement, or remediation after a review β we support U.S. MSBs, fintechs, and payment businesses at any of those stages.