← Back to InsightsAML/BSA

The independent BSA/AML review for MSBs: what examiners and bank partners expect to see

Every money services business must have its AML program independently reviewed. Here is what the rule requires, what a credible review covers, who may perform it, and what examiners and bank partners look for when they open the report.

For a money services business, the independent review is the document that answers the question every regulator and bank partner eventually asks: does the program work the way it says it does? A state examiner typically asks for it early in an exam, and a bank partner commonly asks for it at onboarding and again at periodic review.

Some MSBs treat the review as an annual formality: a read of the policy and a letter saying the program is adequate. That rarely holds up when an examiner or a bank reads it closely. A credible review tests the program, documents the evidence and produces findings that someone owns.

What the rule requires

The BSA program rule for money services businesses, 31 CFR 1022.210, requires a written AML program commensurate with the risks posed by the location and size of the business and the nature and volume of the services it provides. At a minimum, the program must include four elements:

  • Policies, procedures and internal controls reasonably designed to assure compliance, including customer identification, reporting, recordkeeping and responding to law enforcement requests.
  • A designated person responsible for day-to-day compliance with the program and the BSA rules.
  • Training for appropriate personnel, including training in detecting suspicious transactions.
  • An independent review to monitor and maintain an adequate program.

The scope and frequency of the review must be commensurate with the risk of the financial services you provide. An officer or employee of the MSB may perform it, as long as that person is not the designated compliance person.

The rule does not set a fixed calendar interval. In practice, state regulators and bank partners commonly expect a review at least once a year, and license conditions or bank agreements may write that expectation in. Plan to whichever party asks for the most. Ethixera Advisory is not a law firm, so confirm the current rule text, and how your license conditions and agreements should be read, with your counsel.

What examiners and bank partners read for

Federal BSA examinations of MSBs are carried out by the IRS under authority delegated by FinCEN, and state regulators generally examine the money transmitters they license. Examiners typically use your independent review to decide where to point their own testing. They commonly look for:

  • A scope that follows the risk assessment and covers every product, channel and agent network the business runs.
  • Transaction testing, not only a read of the written program, with samples and results documented.
  • A reviewer independent of the work tested and qualified to test it.
  • Findings reported to senior management, and to the board where there is one, with management responses and dates.
  • Evidence that findings from the last review and from prior exams were actually closed.

Bank partners read the same report with a different question: can the bank rely on this MSB as a customer or partner? Long-standing interagency guidance from FinCEN and the federal banking agencies on providing banking services to MSBs lists a review of the MSB's independent testing results among the additional due diligence a bank may perform on a higher-risk MSB customer.

Banks commonly ask for the full report rather than a summary letter, along with the reviewer's qualifications, management responses and remediation status. They also compare it with what you told them in diligence, so a review that tested a different product mix raises questions of its own.

What a credible review covers

A review scoped to risk looks different for a single-location check casher than for a remittance company with agents in several states and payout partners abroad. Most credible reviews still cover the same core areas.

AreaWhat the reviewer testsEvidence commonly requested
Risk assessmentWhether it reflects current products, corridors, agents, customer types and volumes, and whether the program follows from it.The current assessment, its approval date and the data behind it.
Written program and controlsWhether procedures match what staff actually do, and whether controls are built into the systems you run.The written program, approval records and system walkthroughs.
Designated compliance personAuthority, time, resources and knowledge to run the program.The designation, the reporting line and compliance reports to management.
Customer identification and recordsIdentity verification and recordkeeping at the thresholds that apply to your services, such as records for funds transfers of $3,000 or more.Transaction samples with the required records attached.
ReportingCurrency transaction reports for more than $10,000 in cash in a business day, including aggregation, and suspicious activity decisions that are documented and timely.Alert and case samples, filing timeliness and aggregation logic.
Sanctions screeningWho and what is screened, against which lists, and how potential matches are cleared. OFAC obligations sit in separate regulations but are commonly tested alongside.Screening logs and cleared-match files.
Agents and partnersAgent due diligence, monitoring, training and termination, including agents and payout partners outside the United States.The agent list, monitoring reports and site visit records.
TrainingContent fitted to each role and its risks, and completion.Training materials and completion records.
Registration and prior findingsFinCEN registration where required, a current agent list, and prior findings closed with evidence.Registration records and the findings tracker.

One area needs care. The SAR confidentiality rules generally bar an MSB from disclosing a SAR, or information that would reveal that one exists. The reviewer tests SAR decisions, but a report you share with a bank partner should not reveal whether any particular SAR was filed. Settle how that works with your counsel before the report is drafted.

Who should perform the review

The rule allows an internal reviewer, but independence is judged on substance. An employee who helped write the procedures, works alerts or reports to the compliance person may be testing their own work or their manager's. Examiners and bank partners commonly ask three things: did the reviewer have a hand in the work tested, can they test it competently, and do results reach someone with authority to act?

For smaller MSBs, an outside reviewer is often the more defensible choice, because no one inside may be both qualified and uninvolved. The same test applies to outside firms: one that designed your program, tuned your monitoring or holds your compliance seat should not test it. We decline to test programs we designed, and we confirm our independence before we agree the scope.

Where reviews commonly fall short

The same weaknesses tend to repeat:

  • A read, not a test. The report restates the policy and concludes the program is adequate, with no samples, no exceptions and no workpapers.
  • A scope frozen in time. A new corridor, product, agent network or payout partner was added since the last review and left out of this one.
  • Periods that do not join up. The review period starts months after the last one ended, leaving activity no one tested.
  • Findings without owners. The same findings repeat from one review to the next, with no dates and no closure evidence.
  • A report no one with authority read. No record that it reached senior management or the board.

Much of my own work has been on the testing side of the table. Across Big 4 advisory firms and Fortune 500 financial institutions, I have led AML/BSA validations and consent order remediation programs, most recently leading third-line FDIC consent order validation. The discipline carries over directly to an MSB. An examiner reading your review asks the same questions a consent order validator asks: what was tested, how, and what did the evidence show?

FDIC Consent Order

Mid-Size Community Bank · Southeast

Led independent 3rd-line validation testing under FDIC consent order. Developed risk-based test scripts and executed validation across 20+ remediation initiatives spanning AML, GRC, and enterprise governance workstreams.

Engagement via Top 10 National Advisory Firm

What to do this quarter

  1. Find your last review report, note the period it covered, and confirm when the next one is due.
  2. Refresh your risk assessment so the next review is scoped to your current products, corridors, agents and volumes.
  3. Put every open finding from the last review, prior exams and bank reviews on one tracker with an owner, a date and closure evidence.
  4. Ask your bank partner what it requires of the review: scope, frequency, reviewer qualifications and how the report is delivered.
  5. Choose a reviewer with no hand in the program, confirm independence in writing, and agree the scope and review period before testing starts.
  6. Test a small sample yourself: a handful of transactions, closed alerts and cleared screening matches, each checked against your written procedures.

The independent review is your chance to have the program tested by someone who did not build it, before an examiner or bank partner tests it for you. Treat it as evidence, not paperwork.

Related: how Ethixera scopes and performs an independent BSA/AML review and program testing, the wider bank and fintech compliance practice it sits in, and which U.S. rules require a compliance officer or an independent review for your market.

Is your independent review coming due?

Tell us what services you provide, what your examiners and bank partner expect, and when your program was last tested. We will scope a review that fits your risk and confirm our independence before we start.