U.S. entities covered by the Bank Secrecy Act must maintain a reasonably designed, risk-based AML/CFT program, not a stack of unused policies. FinCEN and the Banking Agencies enforce this standard, and the immediate step for any lender or financial institution is to conduct or refresh a written risk assessment, then document how Customer Identification Program (CIP) and Suspicious Activity Report (SAR) workflows actually operate day to day.
TL;DR:
- Building a risk-based AML program requires conducting a thorough risk assessment before writing policies and ensuring controls are directly linked to identified risks.
- Non-bank lenders, including mortgage originators and real estate finance companies, are subject to AML regulations and must maintain AML programs and file SARs, regardless of lending capital source.
- The proposed 2026 AML rule would make risk assessments and the appointment of a U.S.-based compliance officer mandatory, shifting focus to program effectiveness rather than paper compliance.
- Regular documentation of SAR decisions, independent testing, staff training, and ongoing risk assessment updates are critical to withstand regulatory examination.
- Private lenders can streamline compliance by integrating controls with their risk profile, using technology that supports FinCEN’s e-filing system, and ensuring data protects client confidentiality.
Table of Contents
- What Is AML Compliance in the USA, and Who Enforces It?
- The Core Components Every AML Program Must Have
- Does Your Business Fall Under AML Requirements in the USA?
- What Changed With AML Requirements in 2026?
- Building an AML/CFT Program That Actually Works
- How Regulators Enforce AML Rules and What Penalties Look Like
- A Private Lender’s AML Compliance Checklist
- Risk Assessment Methods That Hold Up Under Examination
- Red Flags and Money Laundering Typologies in Real Estate Lending
- Privacy, Data Protection, and AML Compliance
- The Compliance Gap Nobody Wants to Talk About
- A Compliance-Aware Path to Funding Your Next Deal
- Sources
- FAQ
What Is AML Compliance in the USA, and Who Enforces It?
AML compliance in the USA means building a program that detects, prevents, and reports money laundering and terrorist financing, structured around statutes and agency rules rather than internal preference. Two laws form the backbone: the Bank Secrecy Act (BSA), which dates to 1970 and created recordkeeping and reporting duties for financial institutions, and the Anti-Money Laundering Act of 2020 (AML Act), which modernized that framework and folded counter-terrorist financing directly into it.
The AML Act did more than update language. It directed the Treasury Department to publish national AML/CFT Priorities, giving institutions a ranked list of risks (corruption, cybercrime, fraud, and others) that examiners expect programs to reflect. A program that ignores the Priorities entirely is harder to defend during an exam, even if every policy document looks complete on paper.
FinCEN, a bureau of the Treasury Department, writes the implementing regulations, issues guidance, and runs the filing infrastructure banks and lenders depend on. But FinCEN doesn’t examine most institutions directly. That job falls to the Banking Agencies:
- The OCC examines national banks and federal savings associations.
- The FDIC examines state-chartered banks that aren’t Federal Reserve members, and publishes extensive AML/CFT guidance for bankers.
- The Federal Reserve (FRB) examines state member banks and bank holding companies.
- The NCUA examines federally insured credit unions.
- The SEC and FINRA oversee broker-dealers’ AML obligations.
For actual filings, FinCEN operates the BSA e-filing portal, the system every covered institution uses to submit SARs, Currency Transaction Reports, and related BSA forms. Bookmark it. You’ll use it more than any policy manual you write.
The Core Components Every AML Program Must Have
Regulators don’t grade AML programs on length. They grade them on whether five statutory and regulatory pillars actually function together.
- Written policies and procedures, approved by the board or senior management. A program without documented sign-off from leadership is treated as unofficial, regardless of how detailed it is.
- A designated compliance officer, based in the United States. This person needs real authority, not just a title, and needs to be reachable by examiners and law enforcement.
- Customer Identification Program (CIP), Customer Due Diligence (CDD), and beneficial ownership verification. CIP confirms who a customer claims to be; CDD assesses the risk that customer poses over the relationship’s life; beneficial ownership rules require identifying the natural persons who actually own or control entity customers.
- Suspicious Activity Reporting and currency reporting. Institutions file SARs when they detect activity that appears designed to evade reporting requirements or has no clear lawful purpose, and FinCEN’s October 2025 SAR FAQs clarify timing and threshold questions that trip up newer filers. OFAC sanctions screening runs alongside this, since a SAR obligation and an OFAC match are legally distinct issues that both require action.
- Independent testing and ongoing training. Testing has to be performed by someone outside day-to-day AML operations. A compliance officer testing their own program does not meet supervisory expectations, no matter how thorough the review.
Pro Tip: Keep a running log of every SAR decision, including the cases you reviewed and chose not to file on. Examiners ask to see the “no file” reasoning almost as often as the filings themselves.
None of these pillars work in isolation. A well written CIP process feeds the CDD risk rating, which determines how closely a transaction monitoring system watches that account, which determines whether an alert becomes a SAR. Treat them as one connected system, not five separate checkboxes.
Does Your Business Fall Under AML Requirements in the USA?
The BSA defines “financial institution” broadly, and the list surprises people outside traditional banking. It covers banks and credit unions, broker-dealers, money services businesses (currency exchangers, check cashers, money transmitters), casinos, and, critically for real estate finance, non-bank residential mortgage lenders and originators (RMLOs).
FinCEN’s 2012 final rule brought RMLOs squarely within BSA scope, requiring written AML programs and SAR filing capability. That rule predates the 2026 headlines and remains fully in force. A FinCEN notice to non-bank RMLOs makes the point explicitly: many private lenders assume they’re exempt because they aren’t depository institutions, and that assumption is wrong.
Common misconceptions worth correcting:
- “We only lend our own capital, so BSA doesn’t apply.” Lending your own capital doesn’t remove RMLO or loan/finance company status.
- “We’re too small to be a target.” Program requirements scale with risk, not headcount.
- “Broker-dealers and MSBs are the only real targets.” Non-bank lenders face growing scrutiny, particularly around entity borrowers and rapid cash-out transactions.
If your business originates, funds, or brokers residential mortgages, or moves money on behalf of customers in ways resembling an MSB, assume BSA coverage applies until counsel confirms otherwise.
What Changed With AML Requirements in 2026?
Two events define 2026 for AML compliance, and conflating them causes real confusion.
First, FinCEN’s Residential Real Estate Rule (RRE) took effect March 1, 2026, requiring certain reporting on non-financed residential real estate transfers to legal entities and trusts. A federal court vacated the rule on March 19, 2026, just eighteen days later.
FinCEN is not currently requiring RRE filings while that court order remains in force. That’s a narrow, specific outcome. It does not touch the 2012 RMLO rule, which continues to require AML programs and SAR filings from non-bank mortgage lenders exactly as before. Confusing the two leads some operators to wrongly assume their entire AML obligation disappeared in March. It didn’t.
Second, and more consequential long term, the Banking Agencies and FinCEN have jointly proposed an AML/CFT program rule that would formalize risk assessment as the explicit first component of every program, require a U.S.-based compliance officer by rule rather than by guidance, and judge programs on demonstrated effectiveness rather than paperwork completeness.
What this means operationally: if finalized, the rule would push institutions to show their controls trace directly back to specific risk-assessment findings, not generic industry templates.
- Keep monitoring FinCEN and the Banking Agencies for the final rule text.
- Don’t wait for finalization to build a documented risk assessment. It’s already expected practice.
- Confirm your RMLO obligations under the 2012 rule are current, separate from any RRE-related confusion.
Building an AML/CFT Program That Actually Works
An effective program follows a sequence, and skipping steps out of order is the most common reason programs fail examination even when every individual document exists.
- Conduct the risk assessment first. Map customer types, geographies, products, and delivery channels against known money laundering typologies before writing a single policy.
- Write policies and procedures around what the assessment found. Generic templates fail here; policies need to reference your actual risk profile.
- Build CIP and CDD workflows, including beneficial ownership collection for entity borrowers, and set risk ratings that drive monitoring intensity.
- Implement transaction monitoring calibrated to those risk ratings, not a one-size-fits-all threshold.
- Define escalation and SAR decision paths, including who reviews alerts, who decides to file, and how long each step takes.
- Schedule independent testing performed by staff outside daily AML operations.
- Train staff at every level and report results to the board or senior management on a recurring cycle.
Examiners want to see specific documentation at each step: investigative decision logs showing why an alert did or didn’t become a SAR, independent testing reports with findings and remediation dates, and training rosters showing attendance by role, not just by department. A compliance officer’s guide to beneficial ownership verification walks through the kind of documentation format that holds up under review.
Private lending carries specific risk patterns worth naming directly. Entity borrowers (LLCs, trusts, foreign corporations) obscure beneficial ownership more than individual borrowers do. Rapid cash-out refinances move large sums quickly, a pattern that overlaps with common laundering typologies even when the underlying deal is legitimate. Foreign national borrowers add cross-border complexity to source-of-funds verification. Programs that treat every borrower type identically miss the risk differences that examiners expect to see reflected in your CDD ratings.
Pro Tip: Build your risk assessment around loan product type, not just borrower type. A fix-and-flip bridge loan closing in days carries a different risk profile than a five-year DSCR rental loan, even for the same borrower.
Vendor selection matters here too. Whatever screening and SAR e-filing technology you choose needs to integrate with FinCEN’s e-filing portal, support OFAC list updates without manual intervention, and produce audit trails examiners can review without a translator. A commercial lending matrix that documents underwriting criteria alongside compliance controls gives examiners a single reference point instead of scattered files.
How Regulators Enforce AML Rules and What Penalties Look Like
Examiners increasingly ask one question above all others: does this program actually work, or does it just exist? The proposed AML/CFT rule makes that focus explicit, directing examiners to weigh program effectiveness and risk-based resource allocation over isolated technical violations.
That shift matters for how enforcement plays out in practice.
- Weak risk assessments that don’t connect to actual monitoring thresholds draw criticism even when every required document technically exists.
- Independent testing performed by the compliance officer, rather than an outside party or separate internal function, is a recurring finding in enforcement actions.
- Remedial requirements typically include enhanced monitoring, third-party program reviews, and board reporting commitments, often before any monetary penalty is assessed.
- Civil monetary penalties can reach into the millions for sustained, willful failures, and severe cases involving deliberate evasion can trigger criminal referrals.
Documentation and prompt remediation consistently reduce enforcement severity. An institution that self-identifies a gap, documents the fix, and shows a timeline of corrective action fares differently than one that waits for an examiner to find the same gap first.
A Private Lender’s AML Compliance Checklist
Use this as a working document, not a one-time exercise.
- Written risk assessment, updated annually or after a material change in products or markets. Keep the prior version for comparison.
- Board-approved AML policy, with a dated approval record.
- CIP and CDD procedures, with beneficial ownership collection forms for every entity borrower.
- SAR decision log, covering both filed and declined cases with reasoning.
- Independent testing report, performed by staff outside daily AML operations, at least annually.
- Training records by role, refreshed at least annually and immediately for new compliance staff.
- OFAC screening confirmation for every new borrower and periodic rescreening for existing ones.
Engage outside counsel or an external auditor when a risk assessment reveals a new customer segment (foreign national borrowers, crypto-adjacent transactions), when an examination finding requires remediation, or when independent testing can’t be performed internally without a conflict of interest.
| Checklist Item | Frequency | Keep on File |
|---|---|---|
| Risk assessment | Annual or after material change | Current and prior version |
| Independent testing | At least annual | Testing report with findings |
| Staff training | Annual, role-based | Attendance rosters |
| SAR decision log | Ongoing | Filed and declined cases |
| OFAC screening | Per new customer, periodic rescreen | Screening confirmations |
Risk Assessment Methods That Hold Up Under Examination
A risk assessment isn’t a narrative description of your business. It’s a structured analysis mapping specific risk categories against your actual customer base, and the proposed AML/CFT rule would make this the formal starting point of every program rather than an optional first step.
The methodology examiners recognize breaks risk into layers: customer risk (entity structure, foreign national status, politically exposed persons), product risk (cash-out refinances versus purchase loans, bridge loans versus long-term rental financing), geographic risk (proximity to high-risk jurisdictions, cross-border wire activity), and delivery channel risk (in-person origination versus fully remote digital onboarding).

Each layer gets scored, and the scores combine into an overall institutional risk rating that determines resourcing. A lender with a large foreign national borrower base and heavy entity-borrower volume needs deeper CDD staffing than one serving mostly domestic, individual borrowers on standard purchase loans, even if total loan volume is identical.
The critical operational link: your transaction monitoring thresholds, your CDD enhanced due diligence triggers, and your staff training curriculum should all trace back to specific findings in this assessment. If the risk assessment identifies foreign national wire transfers as elevated risk, but your monitoring system uses the same threshold for every borrower type, that gap is exactly what examiners flag first. Reassess annually, and reassess immediately after entering a new loan product or geographic market.
Red Flags and Money Laundering Typologies in Real Estate Lending
Money laundering through real estate follows recognizable patterns, and private lenders sit closer to some of them than traditional banks do.
Layered entity ownership is the most common flag: a borrower structured through multiple LLCs or trusts, sometimes across state lines, where the ultimate beneficial owner takes real effort to identify. This isn’t automatically suspicious, plenty of legitimate investors use entity structures for liability protection, but it demands verification rather than acceptance at face value.
Rapid cash-out refinancing shortly after a purchase, particularly with limited documented improvement to the property, is a classic typology because it converts illicit funds used at purchase into clean loan proceeds. All-cash purchases followed by quick refinancing compound the signal. Third-party payoffs, where loan proceeds or payoff funds route through parties unconnected to the transaction, deserve the same scrutiny.
Source-of-funds inconsistencies matter just as much: a borrower whose stated income doesn’t support the down payment size, or wire transfers originating from jurisdictions with weak AML enforcement. Structuring, breaking transactions into smaller amounts specifically to avoid reporting thresholds, remains a persistent pattern federal guidance continues to flag.
None of these signals alone proves wrongdoing. Together, and unexplained, they’re exactly what a properly calibrated CDD program is built to catch.
Privacy, Data Protection, and AML Compliance
AML programs collect sensitive personal and financial data: Social Security numbers, bank account details, beneficial ownership information, source-of-funds documentation. That creates real tension with data protection expectations, and lenders need to manage both obligations simultaneously rather than treating them as separate departments.
The BSA and AML Act don’t override state or federal privacy law; they create a parallel obligation to collect and retain specific information for compliance purposes. FinCEN’s information-sharing provisions, including the 314(b) safe harbor allowing institutions to share suspicious activity information with each other, operate under strict confidentiality rules. SAR filings themselves are confidential by law. Disclosing that a SAR was filed, even to the subject of the report, is a federal violation.
Practically, this means access controls matter as much as collection procedures. Beneficial ownership data, SAR-related files, and CDD risk ratings should be restricted to compliance staff with a legitimate need, logged for access, and retained for the periods BSA rules require (generally five years for most records) rather than indefinitely. Retention beyond the required period increases data breach exposure without adding compliance value.
The Compliance Gap Nobody Wants to Talk About
Most AML guidance treats compliance as a paperwork exercise: write the policy, file it, move on. That framing is backwards, and the 2026 rulemaking proves it. Regulators have spent years watching institutions produce technically complete programs that catch almost nothing, and the proposed rule’s emphasis on demonstrated effectiveness is a direct response to that pattern.
The RRE vacatur is a useful case study in how compliance confusion actually spreads. A rule existed for eighteen days, got struck down, and somehow that became a talking point suggesting AML obligations for real estate had loosened broadly. They hadn’t. The 2012 RMLO rule never moved. If anything, the RRE episode should make private lenders more cautious, not less, because it shows how quickly the regulatory landscape can shift and how important it is to separate what changed from what didn’t.
What the reader should prioritize first isn’t a new policy document. It’s the connection between your risk assessment and your actual controls. A beautifully written policy manual that doesn’t drive real monitoring thresholds is worth less to an examiner than a rougher document that clearly shapes daily decisions. Build the risk assessment honestly, let it dictate your CDD tiers and monitoring rules, and the paperwork will follow naturally instead of existing as a separate performance for regulators.
— Robert
A Compliance-Aware Path to Funding Your Next Deal
If you’re a real estate investor or business owner weighing private lending options while sorting through AML and compliance questions, Some lenders treat documentation as part of the deal, not an afterthought. Certain U.S.-based direct lenders fund their own loans and publish advance-rate grids before you apply, so pricing and leverage assumptions are visible upfront rather than negotiated case by case.
Transparent underwriting processes involve real estate and business loan programs moving through documented procedures built around the asset and the deal, not just paperwork review, with decisions possible in as little as several hours on qualifying files. If you’re a broker or capital partner looking for a lending relationship that takes compliance seriously without slowing down your closing timeline, submit your deal for review and get a direct read on how it fits.
FAQ
What Are the AML Regulations in the USA?
The Bank Secrecy Act and the Anti-Money Laundering Act of 2020 require covered financial institutions to maintain written, risk-based AML/CFT programs, including CIP, CDD, SAR filing, and independent testing.
Does the U.S. Have AML Laws?
Yes. The BSA has required AML compliance since 1970, and the AML Act of 2020 modernized that framework by adding national AML/CFT Priorities and strengthening enforcement tools.
Who Regulates AML in the USA?
FinCEN writes and interprets the rules, while the OCC, FDIC, Federal Reserve, NCUA, and SEC examine different categories of institutions for compliance under their supervisory authority.
Are Non-Bank Lenders Covered by AML Requirements?
Yes. FinCEN’s 2012 rule requires non-bank residential mortgage lenders and originators to maintain AML programs and file SARs, and that obligation remains intact after the 2026 RRE Rule vacatur.
What Changed in AML Regulations in 2026?
FinCEN’s Residential Real Estate Rule took effect March 1, 2026, and was vacated by a federal court on March 19, 2026, while a separate proposed rule from FinCEN and the Banking Agencies would formalize risk assessments and require a U.S.-based compliance officer if finalized.


