FFIEC BSA/AML Examination Manual Explained: What Examiners Look For and How to Prepare 

The Federal Financial Institutions Examination Council’s (FFIEC) BSA/AML Examination Manual is the official guidance document used by US federal and state examiners to assess the compliance of financial institutions with the Bank Secrecy Act (BSA), USA PATRIOT Act, and related anti-money laundering (AML) / combating the financing of terrorism (CFT) regulations. Last updated in February 2026, the manual establishes uniform examination procedures for the FFIEC member agencies: Federal Reserve, Federal Deposit Insurance Corporation (FDIC), National Credit Union Administration (NCUA), Office of the Comptroller of the Currency (OCC), Consumer Financial Protection Bureau (CFPB) and the State Liaison Committee representing state banking regulators. The manual is not a regulation in and of itself. It is the playbook used by examiners during an institution’s examination that translates BSA requirements into testable procedures, a reference of more than 400 pages organized by topic.

For the compliance officer, the manual is best thought of as the exam syllabus. The rule applies to all banks, credit unions, savings associations, trust companies, and US branches of foreign banks supervised by the US. Knowing what’s in the manual tells you what the examiners will be looking for. It is used by BSA officers, internal auditors, consultants and compliance teams to prepare for examinations and by examiners during examinations. Both sides are working from the same script. That is precisely why getting a head start on the script is the single highest-leverage exam preparation an institution can do.

This guide explains what the manual is, how examiners actually use it, which sections matter most in practice, and the substantive changes that landed in 2026. The sections below explain in further detail:

  • Five Pillars of a BSA/AML Compliance Program
  • How the manual is used by examiners: The examination workflow
  • Important Manual Sections for All Compliance Teams
  • What Financial Institutions Need to Be Prepared for an Exam
  • Latest Updates: What Changed in 2025-2026
  • Typical examination findings: What fails most often
  • How Can Sanction Scanner Help You Pass Your BSA/AML Exam?

Mceclip4 8

1. Five Pillars of a BSA/AML Compliance Program

Examiners test each of the five components required for every US BSA/AML program. There are four original pillars codified under the Bank Secrecy Act framework and the fifth was formally added in 2018 through FinCEN’s Customer Due Diligence Rule. A sixth expectation, risk assessment, is the bedrock underneath all five. FinCEN's April 2026 AML/CFT Program Rule proposal would require a risk assessment process, but as part of the internal controls requirement rather than as a standalone sixth pillar. We discuss the first five, and then the risk assessment expectation.

System of internal controls. Policies, procedures and processes to ensure ongoing compliance with BSA requirements. What examiners will look for are: Policies are documented and board approved policies are aligned with what is actually happening on the ground; escalation workflows are clear; high risk products, customers and geographies are managed; customer due diligence (CDD), customer identification programme (CIP) and beneficial ownership procedures are documented; transaction monitoring is well set up for the risk profile of the institution

Independent testing (Audit).  Regular independent assessment of the BSA/AML program by qualified personnel who are not involved in the day-to-day BSA compliance. When was the last independent test performed? Who performed the test (internal audit, external firm, or a combination)? Did the test include all of the BSA components or selected areas? Were findings reported to the board? Were identified deficiencies remediated? What was the remediation timeline? Under the OCC’s 2026 Community Bank Procedures (more fully discussed below), examiners now able to rely on satisfactory independent testing as a basis for certain examination conclusions making the quality of that testing materially more important.

BSA compliance officer designated. A qualified person with sufficient authority and resources to run the program and who is responsible for the day to day BSA compliance. Examiners will look at whether the BSA officer is formally designated in writing, whether he or she is qualified for the job and has the right credentials (CAMS or CGSS certifications are common), whether he or she has direct access to the board and senior management, whether staffing is appropriate for the institution’s risk profile, whether he or she has real authority to effect change rather than nominal authority only, and whether there is a succession plan in place.

Training.  Ongoing BSA/AML training for all relevant personnel, tailored to their respective roles. Things examiners look for are: conducting training at least annually; role specific training (frontline staff, compliance personnel and board members receive appropriate content for their respective positions); current typologies and red flags including emerging risks (e.g., crypto, elder financial exploitation, and pig butchering); maintaining training records (i.e., dates, topics, and attendees); updating training when new risks emerge; and including board and senior management training.

Customer Due Diligence (CDD). Formalized as the fifth pillar in May 2018 with the implementation of the CDD Rule of the FinCEN. Institutions must develop and implement risk-based CDD policies and procedures for all customers, including developing a customer risk profile for each customer, ongoing monitoring for suspicious activity, and for legal entity customers, identifying and verifying beneficial owners at the 25% ownership level plus one control person. The examiners will look to see whether the four elements of CIP are collected for individual customers (name, date of birth, address, ID number), whether beneficial ownership is identified for entity customers, whether ongoing monitoring is configured based on the risk of the customer, and whether higher risk customers are subject to enhanced due diligence. 

Risk assessment as the basic expectation. In the April 2020 manual update, the FFIEC formally elevated risk assessment to a fundamental expectation that supports all five pillars, and it is the artifact that examiners now ask for first in the scoping phase of the examination. FinCEN's April 2026 AML/CFT Program Rule proposal, which withdrew and replaced an earlier June 2024 version, would codify the risk assessment as a mandatory legal obligation. Notably, it would fold that requirement into internal controls rather than establish a separate sixth pillar. The comment period closed June 9, 2026. Today, examiners will be looking to see if the risk assessment is current; if it covers customer types, products and services, geographies and channels in a comprehensive way; if it is refreshed annually and after material changes in the business; and if it actually drives the monitoring program and the pillar level controls beneath it. 

The table below maps each pillar and risk assessment layer to examiner testing, common findings and the supporting Sanction Scanner capability.

 

Pillar

What It Is

What Examiners Test

Common Findings

Sanction Scanner Capability

Internal Controls

Written, board-approved policies and procedures

Do policies match practice? Are workflows clear?

Policies exist but not enforced

Transaction Monitoring, Fusion

Independent Testing

Independent audit of BSA program

Scope, qualifications, board reporting, remediation

Scope too narrow; no board escalation

Audit-ready case management

BSA Officer

Designated qualified individual

Authority, resources, succession plan

Part-time officer; inadequate staffing

Workflow tooling that scales with team

Training

Ongoing role-specific training

Annual cadence, role-specific content, records

Generic training; no board coverage

Documented training-linked workflows

CDD (2018)

Customer due diligence + beneficial ownership

CIP elements, UBO at 25%+, ongoing monitoring, EDD

Missing UBO records; static risk profile

Customer Risk Assessment, KYB, Ongoing Monitoring

Risk Assessment (foundational)

Enterprise-wide ML/TF risk assessment

Currency, comprehensiveness, drives program

Outdated; not tied to monitoring config

Risk-based rule configuration

 

2. How the Manual is Used by Examiners: The Examination Workflow

If you know how examiners really work through the manual, it demystifies the process and BSA officers can prepare much more effectively. The workflow of every BSA/AML exam consists of three phases.

Scoping (before the exam starts). Examiners will review the institution’s prior examination findings including but not limited to matters requiring attention, the current risk assessment, changes in the business model since the last exam, volume and quality of SAR filings, and any enforcement actions or consent orders in place. The examination “scopes” to determine where to apply effort; higher risk areas may be examined more closely, and lower risk areas examined less. The manual explicitly instructs examiners to adjust the scope in accordance with the bank’s risk profile, devoting more resources to higher risk areas and less to lower risk areas.

Risk based testing. Then examiners will move into sample-based testing. They pull customer files to test CDD and CIP docs. They sample SARs to determine narrative quality and timeliness of filing. They review transaction monitoring alerts and dispositions to evaluate if rules are adequate, whether false positive rates are being monitored and whether alert resolutions are documented. They review CTR filings for accuracy and completeness. They review the outcomes of OFAC screening and how potential hits are cleared. They pull training records to see who was trained, when and on what. They read the independent testing reports of the institution for scope, findings and remediation. Importantly, testing is sample-based, not comprehensive. Examiners do not examine everything, but select strategically, and the samples they select are based on the risk analysis during the scoping phase.

Results & conclusions. Findings are graded for severity. An ‘Observation’ is a small issue which requires no formal action but is noted for the next exam cycle. A ‘Matter Requiring Attention’ (MRA) is a serious deficiency that must be addressed with a written remediation plan and timeline. ‘Formal Enforcement Action’ is reserved for serious violations such as a consent order, civil money penalty, or cease and desist. All findings are reported to the institution's board and senior management and the BSA officer is required to present a remediation plan for anything above an observation.

The process is deliberately open, and examiners will explain what they are testing and why if they are asked. Institutions that are not performing well almost always view this as an adversarial process; institutions that are performing well view this as a structured conversation about the quality of the program.

Mceclip0 24

3. Important Manual Sections for All Compliance Teams

The manual contains dozens of sections. They are not all equally examined. In practice, five sections get most of the examiner's attention and any credible exam preparation programme should be built on them.

BSA/AML Risk Assessment. The first document requested by examiners. If the risk assessment is out of date, everything downstream is suspect, because every other component of the program should trace back to what the risk assessment identifies as material risk. A defensible risk assessment includes customer risk (customer types, geographies, PEP, industry concentrations), product and service risk (wires, ACH, correspondent banking, private banking, crypto services, prepaid), geographic risk (FATF jurisdictions, conflict zones, drug source countries, high risk corridors), and channel risk (digital vs. in person, agent networks, third party introducers).

Customer Due Diligence (CDD) and Customer Identification Program (CIP). Examiners check that all four CIP elements are obtained for individual customers, name, date of birth, address and identification number. For legal entity customers, they verify that beneficial ownership is identified at the 25% ownership threshold plus a control person and that the information is verified using documentary or non documentary methods. The review also includes the establishment of ongoing monitoring based on customer risk rating and increased due diligence for higher risk customers. 

Suspicious activity report (SAR). Examiners sample SARs for four attributes: Timeliness (30 days after detection), narrative quality (clear, complete, and useful to law enforcement), coverage (all suspicious activities, not just the easy ones, being identified and reported), and documentation (underlying evidence held and available on request). In the February 2026 update, the FFIEC removed references to 'reputational risk' from the SAR section. 

Transaction Monitoring. Are the thresholds calibrated with documented rationale? The focus is on whether the monitoring scenarios and rules are appropriate for the specific risk profile of the institution and not whether they are “industry standard.” Is the false positive rate monitored and controlled? How are alerts triaged, investigated and documented? Is there evidence for each alert disposition? Is there independent testing of the monitoring parameters? Any level of examination cannot accept the answer “We’ve always used this threshold.” 

OFAC/Sanctions Compliance. OFAC compliance is examined alongside BSA/AML but under a separate legal authority. The manual makes that distinction clear: OFAC regulations are not part of the BSA, but are in the same cycle. Examiners will examine sanctions screening at onboarding and on an ongoing basis, screening of all transactions (wires, ACH, and other), handling of potential matches, blocked property reporting and the OFAC risk assessment itself

Mceclip5 4

4. What Financial Institutions Need to Be Prepared for an Exam

Good exam preparation is basically a checklist exercise and those institutions that approach it as such materially outperform those that improvise. The working list below is for pre, mid and post exam .

Before the exam:

☐ Risk assessment current, updated within the last 12 months or after material business changes

☐ All BSA policies and procedures board-approved and dated

☐ Prior exam MRAs and findings remediated with documentation

☐ Independent testing report complete and covering all BSA areas

☐ BSA officer designation current and documented in writing

☐ Training records complete for all staff, including dates, topics, attendees

☐ SAR filing log current with evidence of timely filing

☐ CTR filing accuracy verified

☐ Transaction monitoring rules documented with calibration rationale

☐ OFAC screening records accessible, onboarding, ongoing, and transactions

☐ CDD and CIP files for sampled customers complete

☐ Beneficial ownership records for entity customers current

☐ Section 314(a) response records documented

☐ Alert disposition documentation complete, no open or aging alerts without explanation

During the exam. Have an exam liaison, usually the BSA officer, and channel all requests for information through the liaison. Turn in documents requested quickly, as delays imply disorganization and distract the examiner from his or her primary job of finding out what the delay might be concealing. Acknowledge gaps. Examiners respect honesty and especially do not respect hiding. Gaps voluntarily identified by the institution are treated materially differently than gaps identified by the examiner. Make detailed notes on examiner questions because those questions reveal focus areas for the next exam cycle even more than the formal findings do.

After the exam. Review findings with senior management and the board immediately. Create a remediation plan with specific timelines for each finding, not aspirational language. Monitor the progress of remediation and record completion for each item, which will provide evidence at the next exam that deficiencies identified were corrected. Update the risk assessment if exam findings reveal risks not previously identified. Failure to update the risk assessment is a compounding problem, as the next exam will find the same gap and ask why it was not addressed.

Mceclip2 12

5. Latest Updates: What Changed in 2025-2026

This manual has been extensively revised in the past 24 months. Four are worth knowing in some detail.

February, 2026: "Reputational risk" mentions removed. In accordance with Executive Order 14331 of August 7, 2025, the FFIEC revised the BSA/AML Examination Manual to eliminate any mention of reputation risk. Revised sections include Introduction, Suspicious Activity Reporting, Payable Through Accounts, Electronic Banking, and Nondeposit Investment Products. The updates do not establish new requirements. The takeaway for institutions in the real world is that examiners should not use reputational risk as a basis for BSA findings. This resolves some of the issues raised in the debanking debate in terms of institutions over-restricting customers in an effort to control reputational exposure. The Federal Reserve, FDIC, and OCC have each undertaken steps to eliminate reputational risk from their broader examinations and supervisory frameworks, and the Federal Reserve is now trying to codify that practice.

February, 2026: OCC Community Bank Minimum Procedures. Effective for examinations beginning February 1, 2026, OCC Bulletin 2025 37 introduced examination procedures tailored to community banks and lless burdensome than the standard procedures The Community Bank Procedures help ease the burden by highlighting examiner discretion to use satisfactory independent testing as the basis for specific examination conclusions; allowing examiners to carry forward prior cycle examination conclusions for one exam cycle for the Training and BSA Compliance Officer pillars; and reducing documentation requirements for lower risk institutions. In practice, community banks will be subject to less intense examinations if they can continue to perform independent testing that is acceptable. Institutions with thin or perfunctory independent testing lose under the new regime the primary tool for reduced examination burden.

August, 2023: Manual reorganization. The FFIEC reorganized portions of the manual to form new, individual sections by specific regulations. Sections were moved out of the “Risks Associated with Money Laundering and Terrorist Financing” section and concepts were added to related sections of “Assessing Compliance with BSA Regulatory Requirements.” There were no new regulatory requirements that resulted from the reorganization, but the structural change matters for anyone using the manual as a reference; the section numbering and organization changed materially.

April 2020: Risk Assessment elevated as foundational expectation. Now the FFIEC formally elevated the risk assessment to a fundamental expectation that supports all five pillars, and made it the first artifact examiners request in the scoping phase. In April 2026, FinCEN issued a new AML/CFT Program Rule proposal that withdrew and replaced its June 2024 version. It would make the risk assessment a legal requirement, but incorporate it into the internal controls pillar rather than create a separate sixth one. As of mid-2026 the rule remains in the rulemaking process with the comment period closed, but the direction is clear: Risk assessment is the foundational layer beneath the five pillars, not a sixth pillar of its own.

Mceclip3 11

6. Typical Examination Findings: What Fails Most Often

The same handful of findings are repeated across all sizes of institutions. The cheapest way to prepare for the exam is to learn them ahead of time.

Finding 1: Risk assessment is not current or not complete. The most common finding of root cause. The risk assessment has not been reviewed and updated following the introduction of a new product, a new market or a material change in customer base. The examiners describe this as the root cause of downstream failures; all other program elements depend on the risk assessment, so an outdated assessment trickles down into misaligned controls throughout the program.

Finding 2: Transaction monitoring rules not calibrated to risk profile. The institution uses “industry standard” thresholds but does not document why the thresholds are appropriate for its specific customer base, product mix and geographic exposure. That’s not a good enough answer, “We’ve always used this threshold.” The examiners want a statistical or typological justification for each production threshold. 

Finding 3. The quality of SAR narratives is low. Narratives are too short, too formulaic, or don’t offer law enforcement enough context to act on them. The story should answer the typical investigative questions of who, what, when, where, why, and how, and include any relevant FinCEN key terms for the relevant advisories (e.g. "EFE FIN-2022-A002" for elder financial exploitation cases). If key terms are missing, the SAR is not included in FinCEN’s type-specific analysis, thus diminishing its value as intelligence.

Finding 4. Independent testing was not adequately scoped. Testing on only some BSA elements, not all, or by people without BSA expertise, or testing results are not reported to the board. Under the OCC’s 2026 Community Bank Procedures, weak independent testing has implications beyond the finding itself: it loses the reduced examination burden that satisfactory testing affords.

Finding 5: Incomplete alert disposition documentation. There is no documentation of why an alert was closed, so examiners cannot follow up on why an alert was closed as a false positive or was resolved without escalation. Each alert disposition should have a documented rationale for a reviewer to follow. This is one of the most consistently cited findings across exam cycles and one of the easiest to fix with the right case management workflow

Finding 6. Staffing not aligned to risk profile. The BSA officer is a part time position or wears multiple hats. Alert backlogs are a sign of not enough analysts. There is no succession plan for the BSA officer position. This finding often occurs when growth outpaces investment in the compliance function, and the institution that was adequately staffed 18 months ago no longer is.

Finding 7: Training is not role specific. No differentiation for what each role actually needs to know, the same generic training for frontline staff and senior management. If the training doesn’t include current typologies (crypto, pig butchering, EFE, deepfake fraud) then it’s effectively out of date, even if delivered on time.

 

Finding

Frequency

Pillar Affected

How to Avoid

Sanction Scanner Feature

Outdated risk assessment

Very high

Risk Assessment / all

Refresh annually and after material changes; document rationale

Risk-based rule configuration

Uncalibrated TM thresholds

Very high

Internal Controls

Document statistical or typology basis for every threshold

Transaction Monitoring rule builder + threshold tuning

Poor SAR narratives

High

Internal Controls

Structured narrative templates; include FinCEN key terms

Case management with narrative support

Insufficient independent testing

Medium-High

Independent Testing

Full-scope testing by qualified personnel; board reporting

Audit-ready reporting

Incomplete alert disposition

Very high

Internal Controls

Mandatory disposition rationale field per alert

Case management with full audit trail

Inadequate staffing

Medium

BSA Officer

Track case-per-analyst load; document succession plan

Workflow tooling that scales

Generic training

Medium

Training

Role-specific content; refresh for new typologies

Documented training-linked workflows

 

7. How Can Sanction Scanner Help You Pass Your BSA/AML Exam?

Sanction Scanner is founded on a simple premise: Software should not only help you comply, it should help you prove that you comply. The BSA/AML examination audit trail is exam documentation. Every screening, every alert, every investigation, every disposition needs to be exportable, reviewable, and defensible on demand, and the platform is built for that expectation.

As examiners test your screening, Sanction Scanner provides sanctions, PEP and adverse media screening at onboarding and ongoing, with a full audit trail of every screen performed and every match resolved. When they test your transaction monitoring, AI-native risk intelligence platform FUSION has configurable rules with documented calibration rationale and alert disposition data with full audit trail. A case management workflow supports your SAR program test with SAR ready documentation, alert-to-SAR pathways. The platform conducts customer risk scoring, continuously monitors for changes in risk profile and adverse media alerts to keep the customer risk profile current in between formal reviews when it tests your CDD. When they test your documentation the core question in most exam workflows    the platform provides complete, exportable audit trails across all modules.

The Fraud Detection and unified FUSION platform provides a single operational layer instead of a collection of disconnected tools. Platforms that produce audit trails as a byproduct of day to day work are different from platforms that require them to be assembled after the fact. In an exam environment, this is material as documentation quality is often what separates an observation from an MRA.

Mceclip6 3

Sources

[1] Federal Financial Institutions Examination Council. FFIEC BSA/AML Examination Manual. 2026.

[2] Federal Financial Institutions Examination Council. What's New in the BSA/AML Examination Manual. 2026.

[3] Office of the Comptroller of the Currency. Community Bank Minimum Bank Secrecy Act/Anti-Money Laundering Examination Procedures (OCC Bulletin 2025-37). 2025.

[4] Financial Crimes Enforcement Network. Customer Due Diligence Requirements for Financial Institutions (CDD Rule). 2018.

[5] Financial Crimes Enforcement Network. Fact Sheet: Proposed Rule to Fundamentally Reform Financial Institution AML/CFT Programs. 2026.