Financial Crime Network Regulations: What Institutions Must Meet

What a BSA program must operate: CIP, CDD, SAR and CTR filings, sanctions screening, and risk-based controls.
Alexandre Berkovic

TL;DR: Financial crime network regulations are the BSA program a covered institution has to run as one system: customer identification, customer due diligence, suspicious activity reporting, currency transaction reporting, sanctions screening, and risk-based controls. In fiscal year 2025, IRS Criminal Investigation searched 94% of its cases against BSA data. Those filings build a case when the customer file, the cash report, and the suspicion report describe the same relationship.

What the institution has to operate

Financial crime network regulations are the program rules FinCEN administers under the BSA, and the compliance requirements a covered institution meets by running that program every day. A bank's version sits inside the five pillars of an AML compliance program: a designated officer, internal controls, independent testing, training, and customer due diligence. The pillars are the container. The operating question is what has to come out of them, on one customer record.

Identity at account opening

A customer identification program has to support a reasonable belief that the institution knows the true identity of the person or entity opening the account. Collection, verification, and the decision to open are one process, and the record has to be the record screening and monitoring use. A scanned identity document that never leaves the onboarding archive leaves every later control guessing who was boarded.

The relationship after opening

Customer due diligence covers the nature and purpose of the account, the beneficial owners of a legal-entity customer, and updates when activity stops matching what the institution was told. Ongoing monitoring belongs in that duty, because the profile is what a later SAR decision has to stand on.

The BSA/AML risk assessment decides which relationships get that attention. Customer risk rating scores one relationship. The assessment scores the book: products, customers, geographies, and delivery channels. When the assessment says wires to a high-risk corridor are the exposure, and the monitoring rules still treat those wires like domestic payroll, the assessment and the program have come apart.

Two reports, two questions

A SAR is required when a transaction is conducted or attempted by, at, or through the bank, involves or aggregates at least $5,000, and the bank knows, suspects, or has reason to suspect that the funds are illicit, that the transaction is designed to evade BSA reporting, or that it has no apparent lawful purpose and no reasonable explanation after the available facts are examined. Under 31 CFR 1020.320, the clock starts at initial detection: 30 calendar days, plus up to 30 more when no suspect was identified on the detection date, and never more than 60. The bank keeps the SAR and supporting records for five years. The report, and any information that would reveal it, stays confidential.

A currency transaction report records currency over $10,000 by or for one person in a business day, including cash that aggregates across transactions. Suspicion is irrelevant to the form. The teller platform, the monitoring queue, and the customer file still have to see the same person on the same day, or a filed CTR and a closed SAR never meet.

A decision not to file belongs in the same file. When the facts fall short of the suspicion standard, the record should say what was reviewed and why the activity fits the customer. Examiners sample those closures.

Sanctions hits and information requests

Sanctions screening applies at onboarding and again when ownership, counterparties, or payment paths change. A sanctions conclusion and a BSA conclusion are separate decisions on the same customer. A cleared alert leaves the sanctions question standing. A block or reject still leaves the SAR question, which the institution answers on the suspicion standard.

Information sharing sits beside both duties. A 314(a) subject list FinCEN posts is a mandatory search for accounts and transactions, with matches returned through FinCEN. 314(b) is voluntary sharing with another institution, and only after the safe-harbor conditions are met. A match can inform a SAR. The filing decision, the write-up, and the confidentiality of the request stay with the institution.

The BSA officer coordinates those joins: which alerts escalate, which SARs are filed, and which 314(a) searches go out inside the response window. When a partner boards customers or drafts the reports, the covered institution still owns the program and still has to produce the customer record behind it.

The filings only work as one trail

Diagram of CIP, CDD, SAR, CTR, and sanctions feeding one program file
CIP, CDD, SAR, CTR, and sanctions screening are separate filings that only work as one program trail.

Law enforcement consumes BSA data as a set, which is why the workstreams have to share a customer record. IRS Criminal Investigation reported that in fiscal year 2025 it searched 94% of its cases against BSA data, more than 3.9 million searches. Nearly 80% of investigations had a primary subject associated with a SAR. Nearly 67% had a primary subject associated with a CTR. Identity, cash reporting, and suspicion reporting are how a case gets built.

Volume is the scale of that output, and a poor proxy for whether the output is useful. Forvis Mazars, compiling FinCEN figures, reported that SAR filers submitted more than 4.105 million SARs in 2025, 7.99% more than in 2024. Banks, savings associations, and credit unions filed more than 2.193 million of them. Late, thin, or repetitive narratives can reach numbers like that and still fail the exam question, which is whether reportable activity was detected and explained.

Duty What the institution produces What breaks in isolation
Customer identification A reasonable belief of true identity at account opening A verified document that never reaches screening or monitoring
Customer due diligence Nature and purpose, beneficial owners, and a profile that updates Alerts that cannot be compared to the stated purpose of the account
Suspicious activity reporting A SAR within 30 days of detection, or 60 when no suspect was known Closures with no record of why the activity was left unreported
Currency transaction reporting A CTR for currency over $10,000 by one person in a business day Cash aggregated at the teller line and invisible to the SAR desk
Sanctions screening A block, reject, or clear at onboarding and when the relationship changes A BSA clear treated as permission to process a prohibited payment
314(a) and 314(b) A completed search, or a share that meets the safe-harbor conditions A request aged in the alert queue, or used as a watchlist

Exam findings cluster at the handoff

Crowe's analysis of 2024 BSA/AML enforcement actions counted 42 actions from the federal banking agencies, the New York State Department of Financial Services, and FinCEN, compared with 29 in 2023. Deficiencies in suspicious activity monitoring and reporting appeared in 28 of the 42. Customer due diligence gaps appeared in 26. BSA officer failures appeared in 23. The three numbers describe one broken handoff. A weak profile produces alerts nobody can explain. Those alerts become missing or late SARs. An officer without staff or authority cannot close the loop, so the finding arrives from the examiner.

Sanctions enforcement ran on its own docket that year. OFAC issued 12 actions totaling $48.8 million, a large share of them involving the use of U.S. financial services to reach sanctioned persons. Screening has to run at account opening and again when ownership or a payment path changes. A current SAR log leaves that duty where it sits.

Anyone evaluating a program, or the vendors around it, can test the joins directly.

The 2026 proposal changes the score

FinCEN's proposed AML/CFT program rule, published in the Federal Register on April 10, 2026, would withdraw the July 2024 proposal and give institutions 12 months after a final rule to comply. Comments closed on June 9, 2026. The notice is still a proposed rule, so the program an institution runs now is the one already on the books. The explainer on FinCEN's effectiveness-based AML rule covers the proposed split between establishing a program and implementing it. Supervision would look at whether the program detects illicit finance, produces information law enforcement can use, and puts more resources on higher-risk activity than on lower-risk activity.

Current duties continue while that proposal is open. CIP still has to produce a reasonable belief of identity. Currency over $10,000 still has to be reported. Suspicious transactions at the regulatory threshold still have to be reported on the clock in 31 CFR 1020.320. Sanctions obligations sit outside the program proposal. Waiting on new pillar language leaves those duties running on the current rules.

Where Sphinx fits

Sphinx operates as an AI-native compliance layer inside the systems analysts already use. Agents review alerts against the customer and transaction record the rest of the program depends on, and they document the reasoning for each disposition. Sphinx's production record on that handoff is 98% of cases resolved the same day.

Frequently Asked Questions

What are financial crime network regulations?

Financial crime network regulations are the BSA program obligations FinCEN administers and a covered institution has to operate: customer identification, customer due diligence, suspicious activity reporting, currency transaction reporting, sanctions screening, and a risk-based set of controls. The phrase names that workload. Banks, credit unions, money services businesses, broker-dealers, and other covered firms each have program rules under the same framework.

What does a financial institution have to run day to day?

A designated compliance officer, written controls, independent testing, and training, aimed at a few concrete outputs. The institution has to know who the customer is, keep a current picture of the relationship, report suspicious activity, report large currency transactions, screen for sanctions, and answer law-enforcement information requests. Policies that stop at the manual are the inventory of a program, which is where an exam starts.

How does a SAR differ from a CTR?

A SAR records a judgment: for a bank, it is required when a transaction involves or aggregates at least $5,000 and the bank knows, suspects, or has reason to suspect illicit funds, evasion of reporting, or activity with no apparent lawful purpose. A CTR records currency over $10,000 by or for one person in a business day and requires no suspicion. One filing leaves the other duty standing, and the existence of a SAR is confidential.

Where does sanctions screening fit in a BSA program?

Sanctions screening is a separate legal duty that examiners review alongside BSA controls, because the same customer can raise both questions. Screening runs at onboarding and when ownership, counterparties, or payment paths change. A BSA disposition and a sanctions disposition are recorded as separate conclusions.

Has FinCEN's 2026 program proposal replaced current requirements?

FinCEN published the proposal in the Federal Register on April 10, 2026, and the notice remains a proposed rule after the June 9, 2026 comment deadline. FinCEN has proposed 12 months after a final rule for institutions to implement it. Until a final rule is effective, current identification, due diligence, reporting, and program requirements are what an exam tests.

Get Your Free AI Compliance Handbook

What compliance leaders need to know about AI-driven fraud, autonomous laundering, and how your team can
fight back.
Submit
Thank you! Your submission has been received!
Something went wrong while submitting the form. Please try again.