Independent BSA/AML Review

The independent test your examiner, bank partner and board will ask for.

Annual independent BSA/AML reviews for money services businesses and fintechs, second- and third-line testing for banks, and validation of remediation under enforcement. Risk-based test scripts, workpapers an examiner can follow, and findings your board can act on.

Independent Testing

An Independent Test That Holds Up to a Second Look

A BSA/AML program generally has to be tested by someone independent of the people who run it. For banks, independent testing is one of the required pillars of the program. For money services businesses, the BSA rules require the AML program to provide for an independent review, with its scope and frequency commensurate with the risk of the services offered. Fintechs under a sponsor bank often find the same expectation written into their program agreement.

A review is only as useful as the testing behind it. Your examiner, your bank partner and your board may each read the report, and each tends to ask the same questions: what was tested, how, and what the evidence showed. We build the review so every conclusion traces back to a test script, a sample and a workpaper.

Independent testing is part of our bank and fintech compliance practice, and every review is principal-led, with direct access to senior expertise from scoping to the final report. Our principal brings 15+ years across Big 4 advisory firms and Fortune 500 financial institutions, and has led AML/BSA validations and consent order remediation programs, most recently leading third-line FDIC consent order validation.

Regulator-facing experience: direct engagement with FinCEN, state banking departments, FDIC and OCC exam teams and the DOJ, plus Big Four and national-firm validation work.

Common Challenges

Where Clients Start

The need for an independent review usually arrives with a date attached. Start where you are.

An exam is on the calendar

Your federal examiner or state regulator has scheduled a visit. The first request list typically asks for your most recent independent test, its scope, and what you did about its findings.

Your bank partner asked for the annual review

Your program agreement calls for an independent review, and the bank wants the report, the scope and the reviewer's qualifications by a set date.

Sponsor bank readiness

The program changed since the last test

A new product, a new market, a new monitoring system or a rebuilt program since your last review. Examiners and bank partners are likely to want evidence that the new version works, not only that it is written.

Under a consent order or MRA

Remediation is done, or close to it, and you need independent validation that each corrective action is in place and operating before you ask for closure.

Consent order and MRA remediation
Three Kinds of Review
Scope

One Testing Discipline, Three Settings

The method is the same wherever we test: risk-based scripts, documented evidence and findings management can act on. What changes is who relies on the result.

MSBs & Fintechs

Annual Independent Review

For money transmitters, payments companies and other money services businesses, and for fintechs under a sponsor bank. The review tests the whole AML program against the BSA rules that apply to you, any state license requirements and your program agreement, and is built for your state examiner and your bank partner to review. Remittance MSBs can also start with U.S.-Africa remittance corridor compliance.

Which U.S. rules require an independent review
Banks

2LOD and 3LOD Testing

For community banks, regional institutions and larger banks. We test as part of a second-line compliance testing function, or alongside internal audit as a third-line co-source or outsourced provider, across the full BSA/AML program or targeted areas such as transaction monitoring, sanctions or CDD/EDD. Sponsor banks can extend the same testing to the fintech programs they oversee.

Fintech partner oversight for sponsor banks
Under Enforcement

Remediation Validation

For institutions under a consent order or working through MRAs. We test whether each corrective action addresses the finding and is operating as intended, using risk-based test scripts and sampling, and document the evidence that supports closure for your board and your regulator.

Consent order and MRA remediation
Independence

We Do Not Test What We Built

An independent review is only independent if the reviewer had no hand in the work being tested. We decline to test programs we designed. If Ethixera wrote your policies, built your procedures, tuned your monitoring or holds your compliance seat, we will tell you so at scoping and will not take on the review of that work.

The rules leave some room in who performs the test. Banks can use internal audit, outside auditors or consultants. For money services businesses, the BSA rule allows the review to be done by an officer or employee, as long as the reviewer is not the person designated as compliance officer.

Examiners generally look at whether the reviewer is independent of the function tested and qualified to test it, and, for banks, whether results are reported to the board or a committee of it.

If you need a program built and later tested, plan for two providers. Ethixera can be either one, not both. If what you need is someone in the seat rather than someone testing it, see BSA/AML officer of record.

How We Work

Scope, Test, Report, Validate

Every review runs in four steps. Timing depends on your size, your products and the period under review, and we confirm it at scoping.

  1. 01

    Scope

    We start from your risk assessment, your license or charter, your products and customers, prior findings, and what your regulator and bank partner require. We confirm independence, then agree the areas in scope, the review period, the sampling approach and the timeline in writing.

  2. 02

    Test

    We write a risk-based test script for each area, walk through processes with the people who run them, review documentation, re-perform key controls, and sample customer files, alerts, cases, SAR decisions and screening hits. Every test is documented in workpapers with the evidence behind it.

  3. 03

    Report

    Findings are rated by severity, tied to a root cause and paired with a recommendation. Exceptions go back to management before anything is final, management responses are recorded with owners and dates, and the report goes to your board or its committee.

  4. 04

    Validate

    When management reports a finding as fixed, we test that the fix is in place and operating, and document the closure evidence finding by finding, so the next examiner or bank review sees closure, not a promise.

Deliverables
Deliverables

What You Receive

Each deliverable is built so someone who was not in the room, whether an examiner, a bank partner or next year's reviewer, can follow it.

Scope and Test Plan

The areas in scope, the review period, the risk basis for each area, the sampling approach and the timeline, agreed with you before testing starts.

Test Scripts

A risk-based script for each area, setting out the requirement, the test steps, the sample and what counts as an exception. Scripts are written for your program, not pulled from a generic checklist.

Workpapers

The record of every test performed: what was sampled, what was reviewed, what was found and the evidence behind each conclusion, organized so a reviewer can follow it from start to finish.

Findings Report

Findings rated by severity, with root cause, recommendation, management response, owner and target date, alongside the areas tested without exception.

Board and Bank-Partner Summary

A short summary for your board or committee, and a version for your bank partner where your program agreement calls for one, covering scope, overall conclusion, findings and remediation status, written with SAR confidentiality in mind.

Closure Evidence

For each finding, the evidence that the fix is in place and the follow-up testing that confirms it operates, ready for the next exam, bank review or independent test.

Client Outcomes
Client Outcomes

Testing and Validation Experience

Anonymized engagements reflecting the scope and impact of our work.

FDIC Consent Order

Mid-Size Community Bank · Southeast

Led independent 3rd-line validation testing under FDIC consent order. Developed risk-based test scripts and executed validation across 20+ remediation initiatives spanning AML, GRC, and enterprise governance workstreams.

Engagement via Top 10 National Advisory Firm

Multi-Year Consent Order

Top 10 U.S. Financial Institution

Directed BSA/AML testing and MRA validation across a multi-year remediation program. Managed quality assurance across the KYC customer file refresh program evaluating CDD/EDD standards.

Engagement via Big 4 Advisory Firm

Enterprise Compliance

Top 25 U.S. Banking Institution

Conducted comprehensive 2LOD compliance testing and transactional reviews across the Banking division. Identified deficiencies and recommended actionable remediation strategies.

18-Month Embedded Engagement

FAQ

Questions we hear

How often does an MSB need an independent review?

The BSA rules require a money services business's AML program to provide for an independent review, and they tie its scope and frequency to the risk of the services the business provides. They do not set a fixed calendar interval.

In practice, many state regulators and bank partners expect a review at least annually, and some put that expectation in writing, for example in a program agreement. A higher-risk profile, such as cross-border transfers, cash-intensive agents or rapid growth, can justify more frequent or deeper testing of specific areas.

We recommend an interval based on your risk and on what your regulators and bank partner require. Our guide to which U.S. rules require an independent BSA/AML review sets out where the requirement comes from. Ethixera Advisory is not a law firm and does not provide legal advice, so the legal reading of what your license requires stays with your counsel.

Can the firm that built the program test it?

Not if the test is meant to be independent. A reviewer who designed the policies, built the procedures or tuned the monitoring is testing their own work, and examiners and bank partners are likely to discount that. We decline to test programs we designed, and we will not review a program where Ethixera holds the BSA/AML officer or compliance seat.

For money services businesses, the BSA rule does allow the review to be done internally, by an officer or employee other than the designated compliance officer. Examiners still generally expect the reviewer to be independent of the work tested and qualified to test it. If Ethixera built your program, plan for a different reviewer. If another firm or your own team built it, we can test it.

What do you deliver?

Six things. A scope and test plan agreed before testing starts. Risk-based test scripts for each area in scope. Workpapers documenting every test, sample and conclusion, with the evidence behind it. A findings report with severity, root cause, recommendation, management response, owner and target date. A summary for your board or committee, and for your bank partner where your program agreement calls for one. And, once remediation is done, closure evidence and follow-up testing for each finding.

The report is a compliance testing report, not a legal opinion.

Do you test transaction monitoring and sanctions screening?

Yes. Both are core to the review. For transaction monitoring, we test whether the scenarios and thresholds cover the risks in your risk assessment, whether the data feeding the system is complete and accurate from source to alert, whether alerts are worked on time and to a documented standard, and whether investigations reach sound, timely SAR decisions.

For sanctions screening, we test which lists you screen against and whether that matches your program, how matching is configured, whether customers and transactions are screened and rescreened when lists change, and how alerts are dispositioned and documented.

We test inside the systems you already run. If we tuned your monitoring or screening, that area goes to a different reviewer. Tuning is a separate service in our bank and fintech compliance practice.

Will the review satisfy our sponsor bank?

The bank decides that, not the reviewer, so we start from what the bank asks for. Program agreements can specify the scope of the independent review, how often it happens, who may perform it, what qualifications the reviewer needs and how the report is delivered.

We ask for those terms, and for any prior bank findings, before we scope, and we build the review to meet them. Where the bank's requirements go beyond the BSA minimum, the review follows the bank's requirements. The report and workpapers are organized so the bank's own reviewers can follow each conclusion back to the evidence. For the rest of the file a bank will ask for, see sponsor bank readiness.

An Independent Review Coming Due?

Tell us what you are licensed or chartered to do, what your examiner or bank partner expects, and when your program was last tested. We will scope a review that fits your risk and confirm our independence before we start.